The ITPro Podcast

ITPro

The ITPro Podcast is a weekly show for technology professionals and business leaders. Each week hosts Rory Bathgate and Jane McCallion are joined by an expert guest to take a deep dive into the most important issues for the IT community. New episodes premiere every Friday. Visit itpro.com/uk/the-it-pro-podcast for more information, or follow ITPro on LinkedIn for regular updates.

  1. 3d ago

    Agents on the frontline: How Box is using AI to supercharge cybersecurity

    Findings from Box’s State of AI in the Enterprise survey show 83% of enterprises are now running agents in some capacity. These bots are enabling teams to drive productivity and efficiency, but as with any new technology, smooth integration can be a challenge - and security risk. Recent agent-related incidents in the tech industry have sparked concerns about long-term security implications. In this week’s episode of the ITPro Podcast, Ross Kelly and Bobby Hellard speak with Box CISO Heather Ceylan to discuss how Box is using agents internally, and how enterprises can adopt the technology in a safe and secure manner. Highlights“I think for security teams, we can finally, you know, start having the capacity to outpace these attackers. So we've got five core areas of investment for agents for our security team in particular that we've invested in over probably the last year, and we're starting to measure ROI on those right now. “So the first one is in the SOC. I think that's probably the most obvious choice where we've got a lot of operational work. We see the same kinds of incidents. We're automating the triage, we're automating the enrichment, the log correlation, things like that that take a lot of human effort. “But there's still human judgment in the end in terms of what gets escalated to be an incident and what doesn't.” “We're not going to be able to move fast enough. So, we have agents kind of built throughout our software development process, doing those security design and architecture reviews, and if you think about it, it’s way more powerful than a human can be because those agents don't just necessarily call out design flaws; they can enforce fixes for those flaws.” “Things are changing quickly. Sometimes it feels like you take two steps forward and then you read something in the news and you're like, oh my gosh, we need to rethink everything. “So I think a lot of security teams are really feeling that now and getting a little bit of fatigue from that.“ “One of the things that we're trying to carry across all of these that I wasn't really thinking about a year ago, but I'm thinking a lot about now is having that multi-model approach. “We're not in a place where most of the work we do, we can't be reliant on a single model. If you look at vulnerability discovery, we're moving away from being tied to any one specific vendor or any one specific model because you're going to get better results when you take a multi-model approach.” LinksAI is getting better at security – and it's doing it faster than expectedTop security teams use AI agents, says Hack The BoxAI is changing team structures in cybersecurity and creating new roles – here are the jobs in hot demandCan AI fight AI? Where the security gap still exists in cybersecurity, and how MSPs can help

    Agents on the frontline: How Box is using AI to supercharge cybersecurity
  2. Aug 14

    Stopping supply chain attacks

    Supply chain attacks are increasingly common and increasingly disruptive, but organizations still struggle to defend against them properly. In this episode of the ITPro Podcast, Jane and Ross are joined by Haydn Brooks, CEO of supply chain security firm Risk Ledger, to talk about what threats businesses are facing, what mitigation strategies could work well, and why cyber teams need to work together throughout the supply chain. Highlights"Most of the attacks that you find in in kind of the supply chain main are untargeted. So it's where you've had a threat actor launch a lot of attacks against a lot of different targets, they've breached a company without really knowing who that company is or was, and then they've basically passed that access on to somebody else, or they've gone on and leaked data or taken that company offline. And it's not really like a targeted attack against someone else, it's just that other companies who use that supply ... experience that as a supply chain attack, and very few of them are targeted. Where they are targeted, they are very hard to defend against because essentially, as the end target, I'm having to worry about an attack against somebody else, which I have no control over, being able to detect that and then being able to somehow respond to it as well." "I think actually the regulation has kind of followed the the movement that we've seen within the industry rather than the other way around ... we're seeing a lot of these regulations also requiring companies to be either taking threat intelligence from others or sharing threat intelligence with others, as well as reporting incidents. So all of the regulation and the way security teams operate is moving in that direction of being more open, sharing more to benefit for the wider industry." LinksCyber resilience in the UK: learning to take the punchesDORA and why resilience (once again) matters to the boardSecuring the supply chain: Why zero trust and recovery readiness are non-negotiableLogistics firm supply chain breach hits Valve and other customersFormer NCSC head says the Jaguar Land Rover attack was the 'single most financially damaging cyber event ever to hit the UK' as impact laid bareThe LiteLLM supply chain attack this year could be the biggest everWhy supply chain resilience is under the spotlightJaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack

    Stopping supply chain attacks
  3. Aug 7

    Can responsible AI beat hallucinations?

    Hallucinations are an eternal problem in generative AI in particular, and while it’s true that large language models (LLMs) require vast amounts of data, the quality of that information will affect the quality of the output. What can businesses do to ensure they’re using AI both effectively and responsibly? In this episode of the ITPro Podcast, Jane and Ross are joined by Amanda Stent, head of AI strategy and research in the office of the CTO at Bloomberg, to examine what responsible AI is, how organizations can use it, and what has been achieved at Bloomberg. Highlights"The (Bloomberg) terminal gives users access to more than 17,000 news providers, not just Bloomberg News, more than 1000 research brokers, more than 400 million documents from companies themselves, and billions and billions and billions of ticks – that's prices – every day for equities, bonds, commodities, derivatives, any kind of financial instrument you can think of. So, in that context, accuracy is paramount. If we hallucinate or do something that's otherwise incorrect, markets may move, and that might be bad." "We have guardrails that we run on every input to and output from a Gen AI system ... (which) are specific to financial services. For example, we don't want users to be injecting code into our systems. That's a generic guardrail, and we also are in the business of offering financial information, but not financial advice. So if you say. What's a buy case for IBM? We should give it to you. If you say, 'Should I buy IBM?' we should say, 'Nope, I can't answer that question because that's not something we're in the business of doing', and that's a finance-specific guardrail." "We have analysts using our AI systems to ... help them write their research reports more quickly, more easily to cover more companies, to understand the context of a company with its sector and its industry, to write on-demand reports for clients instead of a monthly or a quarterly report. We have portfolio managers doing the same thing, writing on-demand reports for clients using AI instead of quarterly reports. So these are some of the new ways in which people are using AI. But to me, traditionally it was about efficiency and signal generation. And today I think it's about effectiveness. So it's helping people become more effective in how they use AI." LinksAI hallucinations, accuracy still top concerns for UK tech leaders as adoption continuesThis new technique could improve AI output accuracy by 80% – and tackle hallucinations once and for allThe ITPro Podcast: Why doesn't more data produce better results?Bloomberg’s Responsible AI Research: Mitigating Risky RAGs & GenAI in FinanceBloomberg Survey: How London’s finance workforce is embracing AI on its own terms

    Can responsible AI beat hallucinations?

About

The ITPro Podcast is a weekly show for technology professionals and business leaders. Each week hosts Rory Bathgate and Jane McCallion are joined by an expert guest to take a deep dive into the most important issues for the IT community. New episodes premiere every Friday. Visit itpro.com/uk/the-it-pro-podcast for more information, or follow ITPro on LinkedIn for regular updates.

You Might Also Like