Security Confidential S19 E7 Bronwen Aker

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Bronwen Aker. Bronwen is an AI Security Strategist and cybersecurity expert who works at the intersection of artificial intelligence, governance, and security. Bronwen helps organizations evaluate and deploy AI technologies safely while understanding the risks that come with them. With years of experience in penetration testing, digital forensics, and AI security research, she’s uniquely positioned to explain both what AI can do and how attackers might exploit it. 

00:00 Intro

02:30 Our Guest

05:45 Treat AI as a drunk Intern

11:10 Overuse of your chatbot

18:00 Modern AI in the medical space

21:57 Myth#1: Computers are more intelligent than we are

24:04 Microsoft Co-pilot

32:05 Grok Dossing story

36:30 Retrieval Augmented Generation (R.A.G)

39:55 Responsible data handling

Transcript

Manoj Tandon
Hello everyone, this is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security’s Security Confidential. We have another great episode for you today. And a fantastic guest, a very timely guest. Before I announce her, though, I gotta remind you to hit the like and subscribe button. It helps us out. Please show us some love. So down there, please click the like and subscribe, and it’ll allow us to keep bringing you this great content. So without further delay.

I’d love to introduce to you Ms. Bronwen Aker. She is an AI security strategist. So this is going to be a really fun conversation. And she’s also a cybersecurity expert. So it’s a double whammy. So she works at the intersection of artificial intelligence, governance, and security. Bronwen helps organizations evaluate and deploy AI technologies safely while understanding the risks that come with them. With years of experience in penetration testing, digital forensics, and AI security research, she is uniquely positioned to explain both what AI can do and how attackers might abuse it. So with that, Bronwen, welcome to the show.

Bronwen Aker
Thank you for having me, Manoj. This is a pleasure.

Manoj Tandon
The pleasure is all ours. Give us a little bit about your background. Yeah, you know, off here you told us you’re the only technologist in your family, but give us a little bit about your background. How did you get in here with a bunch of cybersecurity misfits? And join the rest of us.

Bronwen Aker
Wow, y you know, it has really been a very long and very strange trip, I’m not gonna lie. No, I started just as a normal kid, and in the very, very early nineteen nineties,s there was this new thing that started coming out called the web. And I built my first web page in nineteen ninety two. By nineteen ninety-five I was a webmaster for a small ISP in the Inland Empire of Southern California. So it’s been an evolutionary process working in IT, writing that whole new wave before Y2K with this new technology, surviving the dot-com bubble burst, and then watching the refactoring. And then after twenty-odd years in web development, well, web mobile, and other software development, I realized I was burned out and bored. I’d been there, I’d done that, the new kids would come in, and they’d go, here’s this new framework. And I’m looking at something going, you know, kid. And you know, I’m having an Arlo Guthrie moment here. Kid Kid, do you know that that infrastructure is gonna have a three to five year shelf life? And that’s what I want to tell these kids. And you know, under the covers, it’s all client-server anyway. So I had years before gotten a bachelor’s through an online university program. And it was actually one of the first online training programs where the college training was fully accredited. And so I get an email as an alum, and they say,” Hey, You know how we’ve had this cybersecurity program at the master’s level? Well, we brought it down to the bachelor’s. I’d never gotten a bachelor’s because back when I started in web development, they didn’t have those sorts of things. So I went back to school, and lo and behold, I did some research, heard about this company called the Sands Institute. And they have done a lot to give back.

Manoj Tandon
I know them well.

Bronwen Aker
First, through the Vet Success program. And then what came into my life was the Women’s Immersion Academy. And I saw a talk very similar to this, but it was Sunny Sandelius from the Sands Institute talking about the Women’s Immersion Academy. And I wound up applying for the second-ever cohort and, you know, six months. Three certifications and a dean’s list, because I was in college at that point. You know, my life has never been the same. Truly, the Sands Immersion Academy was life-changing for me and allowed me to pivot careers late in life. What I’ve found as a result is the wealth of knowledge that I acquired over decades of working on the internet.

Manoj Tandon
Surely the status of the company is like changing email numbers, any events like mine. Okay, we need to run it.

Bronwen Aker
Consultant and whatnot has transitioned beautifully into the cybersecurity space. And it was, you know, see, first I went through the Sands Academy. I built a really good relationship with the subject matter experts, the SMEs that were there to support students going through the courses, to the point that when I graduated from the Immersion Academy, they poached me and brought me on board at SANS. Asana SME. So, but I loved it though. I mean, I mean, just going through the SANS material is like drinking through a fire hose anyway.

Manoj Tandon
Moving on, getting into AI.

Bronwen Aker
Hmm.

Manoj Tandon
You’re an expert in this thing. So–

Bronwen Aker
I know more than some and less than others. I have a problem at this point calling myself an expert because I I’ve I’ve learned so much and I feel like there’s so much more that I just don’t know. Which makes it very exciting because every day I get to learn so many more things.

Manoj Tandon
Which is the hallmark of an expert. Because if you know everything, then you’re a lot of things, but an expert you’re not. That’s right. So give us some of your favorite myths about AI that you hear that you want to correct people on. Because I’ll tell you one of my favorites is, and then I’ll use it as an example.

Bronwen Aker
I can accept that. Beaver the consciousness one is a big one.

Manoj Tandon
That, you know, it can do everything. I can just ask OpenAI, Claude, or whatever your flavor, you know, who knows? There’s d whatever you’re using, ch Gemini as your and give it a problem and it’ll solve it, and I am done.

Bronwen Aker
Yeah. So not true. What I tell people is they need to treat AI like it’s a drunk intern. It may have moments of brilliance, but most of what it generates is going to be suboptimal at best.

Manoj Tandon
Thank you. You know, it has to be because look at its origin. I mean, I don’t know if you ever had the chance to read the Transformer White Paper from Google, which enabled the whole approach with GPUs and turned what we saw with OpenAI into reality. But it’s essentially a word guesser.

Bronwen Aker
It’s sophisticated and advanced, and autocomplete is basically all it is. And it is a wonderful predictive model in terms of predicting what the most likely next word or word fragment is going to be, but there is no consciousness, there is no comprehension, and this is a big challenge because, of course,e normal people, people who are not.

Manoj Tandon
It’s a weighted word. Yeah.

Bronwen Aker
Technologists who do not work with technology professionally, they are going to interact with these tools in an organic and natural fashion. And if something looks and sounds like it has intelligence, they’re going to assume that the intelligence is actually there. It’s an honest mistake. It’s a mo an honest misunderstanding. And it could be argued that the technology misrepresents itself.

As being intelligent when it really isn’t. But it is also more sophisticated than any other tools we’ve had as far as being able to take spoken or written instruction and then go in with agent AI to now perform actions based on that communication. Historically, the only way that we’ve been able to teach computers skills was through programming.

Manoj Tandon
Right.

Bronwen Aker
The way, excuse me. The way I like to describe it is that when it comes to computers, we give them knowledge through data. And it can be in the form of flat files, documents, or an actual database of some flavor. We teach computer skills through programming. Well, now through the innovation of artificial intelligence and the tokenization and all of the stuff that goes into primarily the large language models. Now we have something that can take what we say and interpret it, and then go further and act on it. And we’ve never been in a position like that. Historically, as a human species, we’ve never been in a similar technological situation to what we have now.

Manoj Tandon
Don’t get me wrong. This thing is a massive accelerator. But that drunken intern is an analogy that no one should forget. And it’s a word of caution because I’ve seen it. You have to use your intelligence to govern what it’s doing and direct it in a way that it can accelerate things for you. But would I trust a molecule that it created?

Bronwen Aker
Yes.

Manoj Tandon
To inject into someone. No.

Bronwen Aker
Not without rigorous verification.

Manoj Tandon
Not without rigorous verification. That’s that’s exactly that’s exactly correct. And you see it now, where I just recently ran across an article where people are becoming addicted to their chatbots. You know, they’re using them as therapists. Now I as long as you’re using it as a mechanism like journaling or something like that, I don’t see any issue with it. But does it really replace a human psychologist? I find that a little difficult to Tádem.

Bronwen Aker
Mm. I think that at some point in the future, it will become the norm where there will be support tools like a counselor or something that has been structured in such a way. So let’s let’s let’s roll back a little bit. Your typical let’s let’s roll back and and dec dissect a couple of

Manoj Tandon
Sure.

Bronwen Aker
Things, because I want to have a baseline of understood assumptions. So artificial intelligence, of course, is a huge, vast, enormous field. It’s almost as vast as space itself, which of course is really, really big, especially if you’re a Douglas Adams fan. So always. And the Pangalactic Gargle Blaster is the best drink on the planet. We’ll get into that another time.

Manoj Tandon
Please.

Bronwen Aker
So the thing about artificial intelligence is that, as a field, it actually is not new. What has happened, though, is that as our ability to accumulate data has grown and as we’ve had more and more quantities, larger quantities of data, we’ve had to develop new ways to take care of it. I mean, originally, scrolls were fine, and then we got into books.

Manoj Tandon
Yes.

Bronwen Aker
And then we got into flat file,d text files, and other kinds of files. And then we got into databases. And now we have this new way of organizing data, which is a new way of approaching data. So what, of course, OpenAI and other AI companies did was they went and they scraped the internet. This is where a lot of the garbage in, garbage out comes in, because

Manoj Tandon
Sure.

Bronwen Aker
There are tons of bad, inaccurate, wrong, and just weird stuff on the internet, as we all know. And all of that got thrown into a hopper and was used as the seed content for creating the first LLM models. And it was with that that we started getting this new ability to speak to a digital compilation of tools, either verbally or through written text, and then have it reply in a human-like manner because it’s using the predictive algorithms that have been baked into it to emulate how we behave when we speak and when we communicate.

So what I think the biggest benefit of this new artificial intelligence revolution innovation, whatever you want to call it, is going to be long term is going to be that just as the iPhone revolutionized our ability to interact with the internet, now the large language models and the other accessibility innovations that have Come out of that as an a natural outgrowth, they’re allowing us to communicate more effectively and more clearly with our digital devices and ever before and ask them to do things that they’ve never been asked to do before. So all of this opens up so many doors, both good and bad. On the one hand, the potential of AI to unleash human creativity.

I don’t think we’ve even scratched the surface yet. Yet at the same point, humans as a species, we are still fairly primitive as a civilization. And when we look at what civilizations could potentially be, we’re so young, we’re so new, we are so flawed intrinsically. Of course.

Manoj Tandon
Agree. Yeah, very much so.

Bronwen Aker
Our AI is going to have biases. We are intrinsically biased.

Manoj Tandon
That’s human nature.

Bronwen Aker
Exactly.

Manoj Tandon
So everything we write has gonna have some bias. It’ll always there’s nothing that’s truly objective. It can’t be done. Cause you put a little bit of yourself into whatever it is that you’re writing. So whatever you’re biased towards is gonna be on the page, man.

Bronwen Aker
Well, and as I’ve said, bias in and of itself is not inherently bad. All bias means is that you have a limited scope perspective of whatever. And this is where we get into the whole ant and the elephant analogy. Are you familiar with that, Minoj?

Manoj Tandon
Yes, I am.

Bronwen Aker
Okay. Well, for those listening at home who may not be familiar with it, the idea is that if I have an elephant and ants are standing on various parts of the elephant, each ant will experience the elephant in a different way. And this analogy is used a lot in terms of comparative theology for one, but it also applies to any situation where you have

Manoj Tandon
Yes.

Bronwen Aker
Different populations with varying perspectives. So, getting back to the analogy, if an ant is on the tail of the elephant, the entire experience that ant is going to have will reflect that it’s on the tail. If an ant is on the trunk, its experience of the world will be all about the trunk. Neither one is wrong, but neither one is complete either. And this is

Manoj Tandon
Yeah.

Bronwen Aker
where the arguments against diversity really get my goat. Because if all I know is the trunk, but if for some reason something should come up that deals with the tail, but I don’t know about the tail, if all I have are people who know about the trunk, I’m going to be at a disadvantage. Then, if I have a robust, diverse stream team where I have some people who know about the trunk, some people know about the year. Some people know about the tail, some people know about the foot. A diverse team like that in any environment is always going to be better prepared for whatever comes up than a team that only knows one perspective. There was a point.

Manoj Tandon
So, by core, the corollary is that AI is incomplete in many ways, and it only knows what it knows. And that’s what people should understand who are listening to this, that it’s not complete. So, in its rendition, it got whatever it could, even on a particular topic, if it wasn’t able to have all that data as part of its

Bronwen Aker
Exactly,

Manoj Tandon
Training model. So let’s go to something extreme. Like, if you’re if it’s going to read an MRI of a human being, it only knows what part of its general training in that arena. It doesn’t have the depth of knowledge that a radiologist does by viewing millions and millions and millions of MRIs. Unless somebody specifically

Bronwen Aker
Mm-hmm.

Manoj Tandon
With intention, it trains it on that data and completes the foundation of current human knowledge. Let’s leave it at that.

Bronwen Aker
And modern AI is doing phenomenal things in the medical space because what the technology makes possible is better pattern matching across millions, you know, thousands, hundreds, thousands, or even millions of data points. And that’s the type of thing that computers do very well. Computers are very good at repetitive tasks. They’re very good at tasks that involve the comparison and contrast of bits. And that’s not what humans do best. So the ideal at this stage combination would be in the case of a radiology department, having a radiology AI that could scan and flag potential. Cancers or other issues from a client scan, but with the human oversight of verifying, hey, did you think about this other thing as well? Because they’re only the machines are only going to know what they’ve been trained on. Humans are much better at making intuitive leaps.

Manoj Tandon
Sure. There you go. So it’s going to be your co-pilot. I’m not referring to the Microsoft version, but it is your assistant or your drunken intern. Because in that example that you just gave, the physician is still in control. They just have an additional data point that they may choose to investigate based on the evidence provided back. Right.

Bronwen Aker
Mm. Exactly. Another area in medicine, yeah.

Manoj Tandon
Right. But it’s not you, you’re not using it as a diagnostic tool and saying, you know what? You definitely have this, it’s based on you know.w

Bronwen Aker
No, it it’s it’s much better to be used to advise an actual clinician, have the clinician say, Yes, I agree, or ” No, you need to check this other thing. A human is always, and this is a thing. We our our most advanced models do have billions of transforms. They’ve got billions with a B, billions of points of data. But

Manoj Tandon
Yep.

Bronwen Aker
A brand-new human will have tens of trillions of data points already pre-programmed into their wetware. And the reality is, you were asking about myths. Here’s another myth. Computers are smarter than we are. No, they’re not. They’re faster. They have no intelligence. They can emulate human intelligence, but they are not intelligent themselves.

Manoj Tandon
They have no intelligence.

Bronwen Aker
And they only know what we’ve taught them. Now, machine learning is expanding the boundaries of that, but still, they’re operating in the sandboxes that we’ve established. So it’s a brave new world. Things are changing very quickly. It’s kind of scary to think that you and I are of the last generation that knows what life was like before the internet.

Manoj Tandon
Yes, and much more rapidly.

Bronwen Aker
And AI is transforming things every bit as much, if not more so, than the web did. Yes, very much so.

Manoj Tandon
The acceleration is what’s mind-boggling. It’s the speed at which I mean literally twenty-four hours, you can have another advancement take place.

Bronwen Aker
I was about to say, back when the web was new, it felt like we were downloading a new web browser from whichever it was, whether it was Mozilla, Netscape, or any of the other players that came along. It was really that intense, where it was like, great, I have to download another browser. Now, I mean what was it last year I did Two different talks talking about Co-Pilot in enterprise environments. The first one I did in January was based on information that I gathered from October through December of the year before. And then in May, I did another one, and easily three-quarters of the information that I had acquired for the first one was obsolete in one quarter.

Manoj Tandon
Copilot, tell us what couldn’t go wrong. What are your concerns with it?

Bronwen Aker
Everything. My concerns about Copilot are very similar to my concerns about any other AI that is given lots of access to stuff. So if you are in the Microsoft environment, you have Microsoft 365, you have your tenants established, you’re doing all of the things. Copilot is automatically integrated into that offering. You don’t have a choice but to turn it off. It does not exist. You do have the opportunity to change the degree of integration you have, with the understanding that the more integration you have, the more interaction you have with Copilot, and the more you pay. So it’s one of those things where it’s kind of surprising. The cheap option is actually the least or is actually the most secure because it has the least access to sensitive information. So, back this up a little bit. Plain vanilla, Microsoft 365, you get Copilot, but it doesn’t have access to your email, your documents, or any of the sensitive bits that may be within the tenant.

When you get one of the subscription-level licenses, things change, especially once you get into the enterprise licenses. Because now, if my account is licensed for enterprise-level access to Copilot, Copilot can now read everything that I can read. So

Manoj Tandon
So if you are an HR and you have everybody’s salary on your computer, you just trained it on that, and now Judy down in shipping can let me look up Manoj’s salary. He makes nothing. Too bad. Yeah.

Bronwen Aker
So if you are an IT person or a security person working in an organization that is heavily reliant on Microsoft 365 products, you want to make sure that your RBAC rules-based access control is as secure and as tight as possible. Because the RBAC rules, along with other controls, Will dictate what Copilot can and cannot interact with. And so obviously, if I’m using Co-Pilot and I’m an HR manager, it should legitimately have access to what I can access so that it can serve as an assistant to help me with whatever my HR-related tasks are, whether it’s employee reviews, salary reviews, etc., etc. Now

The flip side is that if Judy Down in Shipping has access to Copilot as well, she should only have access to things that are appropriate for her job and her role. If the organization’s RBAC is done well, this will be a non-issue. If the RBAC is loose or poorly defined, we’ve got problems.

Manoj Tandon
Even if it’s defined well, I have not tried the experiment. Maybe you have, but what would prevent Judy from prompting to jail breaking and getting at the data.

Bronwen Aker
Excellent question. Truthfully, every single LLM, Copilot, OpenAI, Gemini, Deep Seek, and all of them are vulnerable to jailbreaking and social engineering. It’s the nature of the beast. And the guardrails can help, guardrails being restrictions and constraints at a programmatic level that are part of the harness and the infrastructure.

Manoj Tandon
Yeah, absolutely.

Bronwen Aker
supporting the model itself, all of that can assist. But it’s like asking. You’re asking it to be something other than what it is. I mean, if I have a sword, the characteristics of the sword, well, it’s going to be an iron alloy, it’s going to have some mix of iron and other metals to create specific characteristics. Every one of those characteristics is both a strength and a weakness if I understand how they work. The same thing applies to your large language models. They have characteristics. They are trained to interact with us in a social manner. That makes them vulnerable to social engineering the same way that humans are. And it’s not going to change until we get away from the probabilistic tendencies of the AIs and allow more deterministic controls. Now, I just threw out a lot of polys.

Manoj Tandon
Well, but the values and the probabilistic nature of it.

Bronwen Aker
Some of the value is, but that’s also where some of the problems come in. Because if you ask the same question three different times, you’re going to likely get three different answers. They may or may not be similar, depending on what the question is and how it was phrased, and a whole bunch of other things that you have no control over, but that the model developer does. Things like temperature. Temperature is used in developing specific models, and it determines. How creative they are. If I have the temperature set at one, which is a max, it’s a value between zero and one, a sliding not Boolean. If I have the temperature set at one, I’m gonna get the most variety, but I’m also gonna get the most hallucinations. If I dial the temperature back down to 0.01, I’m going to get more consistent responses, but I’m also going to get less. Quote creativity, but I’m also gonna get fewer hallucinations. So there are so many ways that there are trade-offs, and we’re still figuring all this stuff out. And even the people who are developing the technology truly do not understand what’s going on at the heart of these models. They know that it has to do with tokens; they know it has to do with the neural processing, but

They’re having to figure out after the fact how these tools think to provide those guardrails, those safety controls, and figure out how to take these tools to the next level.

Manoj Tandon
See, so Bronwen, here’s the thing with that: what you just stated is you’re correct on all of it, but once I give that data to the model, it is part of its neural net. There is no delete function.

Bronwen Aker
Correct. And that is a huge problem as far as intellectual property.

Manoj Tandon
That’s a huge problem. It’s intellectual property, it is cyber security, you know, it’s about, you know, d data containment, it’s data governance, it’s like you can’t do GDPR with it. Once you train it, that Judy likes apples. Some may say that’s personally identifiable information. And if she wants that deleted, you can’t. Ever.

Bronwen Aker
Mm-hmm. No, it can’t. It’s kind of like it’s almost alchemical. Because if I take two components of something, heck, if I just take salt and water and I combine them, I’m making a third thing, which is saline. I can separate them, but it’s really hard to do. And we haven’t developed a way to extract specific training data out of a model once it’s been baked in. So, this has been a problem. I know that there have been reports where Grok has DOS more than one person, one person notably, that individual happened to be a sex worker. Her address, her contact information, were all baked into the Grok model, and Grok doxed her. And there’s the yeah, we can put up guardrails, or we can put up safeguards, but the problem is the data was baked into the model. What does her PII belong to? What possible rational reason would anyone put my or someone else’s personal information into an LLM model?

Manoj Tandon
Well, it may not even be done intentionally. See, it could show up on a Reddit page, and that was scraped as part of its training. It could show up in a presentation somewhere that was behind closed doors for a certain organization, but I’ve seen this often, where people will put presentations out thinking they’re in secure places.

Bronwen Aker
Exactly.

Manoj Tandon
But they’re really not. And now they might never share that document with you if you ask them for it. But if you go ask ChatGPT for it, it’ll be only too happy to tell you all about it. You know.

Bronwen Aker
And and this is and this is a an ongoing problem that we’re gonna have to be dealing with much more. But again, it’s so new. Most people don’t realize that if you go to ChatGPT, it’s actually getting its information from multiple different sources. First and foremost, every model has the data that’s been baked into it. And this is also why any model will have a cutoff point. Beyond that, it won’t know anything unless it accesses it through some other means. So you have your baked-in data, which helps train how the model itself thinks. Beyond that point, then you have the support system, which is referred to as scaffolding or the harness. Now the harness may allow internet access. So if I ask

A specific model, hey, what’s the latest over at Jerry’s Deli down the road? The baked-in model isn’t going to have that information, but if it has a capability to do a web search, it can go out, find that out, and then come back and tell me. Then you have the new quote and deep research activities. And with deep research, what is happening is the same kind of thing that happened when I wanted to know about Jerry’s Deli. But in a more intense manner. Multiple searches will be initiated. And the model itself will review the data that comes back and has some programmatic evaluations where it will determine: okay, is this sufficient to answer this question, or do I need to go and do additional searches? And until the

The support system has been satisfied that it has performed sufficient research, then it’ll come back, and it’ll parse, and it’ll analyze,e and it will generate whatever report it is going to give to the user. So those are just three ways that a model may access different information. Now you add RAG, retrieval, augmented generation. Hate the acronym, just saying. Because it is really retrieval augmented generation. Okay, in English, what does that mean? Well, what that means is I can stack a bunch of data in the form of a database or document or some hybrid combination of it all. And now I can say to an LLM, this data stack is your authoritative source for any questions that I ask you. And then

What I can do is use the LLM, use a chatbot, or whatever to interrogate my data stack and get information out of it in a much easier manner than I ever could have done before. We’ve had structured query language, we’ve had databases for decades, but now I can have a conversation with one. How cool is that?

Manoj Tandon
Yeah, you can, you can, you don’t need to know the sequel at all to do what you’re doing. Don’t know need to know how to create tables. But I will say back in the day of databases, dropping a table would remove the data. There’s no such thing; there’s no such command for an AI framework. If you can’t do it. But so with RAG, you are not actually training a new LLM, correct?

Bronwen Aker
It’s, yeah, once. Precisely. Precisely. So the data is kept separate from the model. The model, however, has the ability to interact in terms of and if it’s agentic, it may not only have the ability to extract information, but it may also have the ability to contribute back to it. Again, if you’ve added in agentic capabilities and permissions. So, the rag stack is separate from the model and expands that as much as you can. So now I’ve got the Encyclopedia Galactica over here, and I’ve got an LLM, you know, Claude, OpenAI, ChatGPT, what you want, and now it can talk, or I might even set up a local LLM yo, ow get get Mistral or something, and run it on my local systemand have it interrogate this data stack to answer questions about what is the ultimate recipe for a pangalactic cargo blaster. I know I keep throwing out the check. Well, we’re also good.

Manoj Tandon
I you know, Douglas Adams, great author, I’d e enjoyed his. That turns back the clock to my youth, but that’s another time. You just got me distracted.

Bronwen Aker
I I have I have hitchhikers on the mind because at BHIS, we have our annual conference in Deadwood, South Dakota. As I say, I like to make my annual pilgrimage to the wilds of South Dakota. And this year’s theme is very much Hitchhiker’s Guide to the Galaxy. So I’ve been helping with some of the preparations, and I have it on my mind a little bit more than usual.

Manoj Tandon
Okay. No worries. Great book. Fun book to read. So let me ask you, can I give you a scenario? Tell me if this would legitimately be okay to do. So I am the scenario is I’m I I’m a scientist, which I’m not, but let’s just say so. I can play one on TV. How about that? All right.

Bronwen Aker
Yeah.

Manoj Tandon
And I have a bunch of PII. Okay. It’s about diseases and about demographics, economics, really sensitive stuff. It gets the patient’s name, their social security number, the disease types they had, their socioeconomic status, their religion, everything that you don’t want to be publicly released. But it’s relevant for statistical analysis. So you end up creating a rag structure. That’s that may be documents, databases, or various storage mechanisms. And you let loose your favorite tool, whatever it may be, an AI tool, on that rag structure and say, here is what I want you to query for, and I want you to compile. All this data. After you’re done with this, what I want you to do is anonymize the data. So create new data, generate new data. I want you to anonymize it. But anybody who subsequently queries that data is going to end up with the same result that we just did with the identifiable information. It’s kind of a quality check. And then I want you to delete all the PII.

Legit or not?

Bronwen Aker
Well, any data can be anonymized. That is nothing new. If I guess,m I’m curious, are you asking if it’s feasible or is it something that should be done in a specific manner, different or similar to what you described?

Manoj Tandon
I’m asking, is that scenario in today, with our today’s knowledge, is that doable? And would it cause the release of that identifiable information? Is there a huge risk to doing that? Because you could see areas like medicine, law, and criminal justice, there are so many statistics that you might want to compile in this manner. I just gave a general example.

Bronwen Aker
Right. Well, I the one of the beauties of databases in general is the ability to extract just what you need in order to analyze something very specific. And the trick is deciding if this is something that I really need to have baked into a database, or if this is something where I should be pulling just what is needful on the fly from the master repository? Baking baking data into any model is

Always going to have some inherent risk because if that data hasn’t been sanitized appropriately, as in the case of that one woman and her PII being divulged by Grok, that is just one potentially minor outcome. Now, of course, we have the various AI providers soliciting your health information and health documents. And I understand. They’re trying to bring more value to potential clients in order to become more profitable. I get it. But the responsible handling of data is something that I’ve had more deep conversations about what is and isn’t responsible data handling in the past two to three years than I did in the seven prior. And it’s specifically because of AI.

Could AI be used to create anonymized databases? Yes, with the caveat that the instructions were appropriately detailed. And this is getting back to that whole drunk intern thing. The advantages and disadvantages of these agentic tools are that they can do amazing things very quickly. And they can also really cause you to have a bad day if you left one detail out that was critical, or you gave ins insufficient instructions and made the wrong assumption about what it was you wanted. So it’s the drunk intern approach in dealing with AI, I can’t stress it enough because we really are smarter than they are. And it comes back to the same thing that has been true of computing for decades. Computers are going to do what you tell them to do, not what you want them to do. All AI does is ramp that up on steroids and jet fuel. So it’s even more aggressive in terms of both processing and the potential for catastrophic failure if something was left out or was mis said.

Manoj Tandon
Hmm. That is a good stopping point, but we’re gonna need you to come back, Bronwen, because we want to talk about governance, which we didn’t even get to. And I don’t even know. That’s kind of an oxymoron right now, as far as I’m concerned, but I think it would be good to have that conversation. But it’s good.

Bronwen Aker
Okay. We didn’t even get to governance. The Europeans are still doing governance, but we’re not.

Manoj Tandon
Well, we gotta get you back. I’m gonna, you know, we just gotta get you back. But I do wanna give you a couple minutes to just say anything you want to our audience, whatever you want them to know about. Floor’s yours.

Bronwen Aker
Well, if you want to know more about artificial intelligence, you really need to learn it. I’ve done several webcasts through BHIS and our training arm, anti-siphon training. So you can look it up on YouTube. I think there’s so much to learn. And the thing that I really want to impress upon people

Whether you’re in cybersecurity or not, just don’t assume that all of these wonderful shiny tools are built with your best interests in mind. Because for the most part, they’re not. You always want to reality check anything that you get from an AI because you have the best of intentions in asking your questions and wanting to have things solved for you. But again, you’re the one who’s ultimately responsible. The AI is just a tool. And you’re the one who needs to accept your own accountability in terms of what happens when you’re using these tools. And yes, definitely caveat MTOR, buyer beware. There are many, many resources for information. Start by learning a little bit about prompt engineering. When you go beyond the prompt engineering, if you want to go deeper into artificial intelligence, you want to bone up on your maths, especially statistics and other things like that. Machine learning is a huge, growing field, and it’s only going to continue to deepen. Also, for those of you

If you have any listeners who are very new in their careers, like two years or less, Claude, excuse me, Anthropic has opened up an academy. I’ll have to send you the link separately, which allows people to apply for an internship that is sponsored by Anthropic. Anthropic will train people on how to use AI in a deep and sophisticated manner and then place them with nonprofits to help the nonprofits continue to make the world a better place. So that’s if you go to the anthropic news area, I know that there is a press release on that, but I can give you the link. That right there, if I were in my twenties again, if I had to do it all over again, starting from today forward, I would want to get into that program because I guarantee it is going to be life-changing.

Manoj Tandon
That is actually a cool program. I didn’t even know it existed.

Bronwen Aker
I found out about it very recently, earlier this week. And it’s, I’ve spoken from personal experience, I’ve benefited so much from the SANS immersion academy. I can only imagine what kind of benefit this other Academy bianthropic and placing trained students with non-profits whose entire purpose is to help make the world a better place, that seems like a good way to spend one’s time.

Manoj Tandon
It does. It does. That’s very cool, Bronwen. Very cool. Thank you so much for doing this episode. And like I said, we

Bronwen Aker
And I’m sorry for my work system blowing up over here.

Manoj Tandon
No, no, not at all. And we gotta get you back because I want to talk about governance with you, and we would love to get your opinion about that. Butt thank you so much. This was fantastic. Appreciate it.

Bronwen Aker
My pleasure. Completely my pleasure. It’s been a delight. And I look forward to it. If you have any other questions on the side, you know how to reach me.

Manoj Tandon
Absolutely.

Read more about Bronwen on her LinkedIn.

Check out the vCISO bot we created

Check out the other episodes in Season 19:

Ep. 0 Diyar Saadi – How Hackers Exploit Hidden Vulnerabilities

Ep. 1 Krisztian Kiraly – Who Really Controls Your Algorithm Data?

Ep. 2 Jason Roos – What the U.S.–Saudi Relationship Means for Cybersecurity

Ep. 3 Jasson Casey – Identity Attacks Are the #1 Threat

Ep. 4 Andy Smith – What Good Is Cybersecurity Tech… If It Still Fails?

Ep. 5 Murphy John – The Future of Decentralized Data

Ep. 6 David Linthicum – Artificial Intelligence Mistakes Every Company is Making Right Now

Ep. 7 Bronwen Aker – Treat Artificial Intelligence like a Drunk Intern

Ep. 8 Yagub Rahimov – You Can Get Hacked With Emojis

Ep. 9 David B. Cross – The Future of Cyber Threats

Ep. 10 Mark Kreitzman – The Hidden Cost of Mobile Identity Theft

Bronwen Aker's profile picture for Dark Rhiino Security's Security Confidential podcast

Bronwen Aker is an AI Security Strategist, cybersecurity researcher, and penetration testing expert. on helping organizations adopt AI securely and responsibly.

As an AI Researcher & Strategist at Black Hills Information Security (BHIS), she evaluates enterprise AI platforms, develops AI governance frameworks, and helps organizations balance innovation with risk.

With a master’s degree in cybersecurity, multiple GIAC certifications, and extensive experience in penetration testing, digital forensics, and AI security, Bronwen brings a unique perspective on how attackers can exploit emerging AI technologies.

A longtime educator, speaker, and former SANS subject matter expert, she specializes in translating complex AI and cybersecurity concepts into practical guidance for technical teams and executives alike.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host Manoj Tandon talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, YouTube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top