---
title: 'What Should Security Leaders Do with AI? They Don''t Know.'
source: 'https://youtube.com/watch?v=3zhveTN1VzE'
video_id: '3zhveTN1VzE'
date: 2026-08-19
duration_sec: 1755
channel: 'IBM Technology'
---

# What Should Security Leaders Do with AI? They Don't Know.

> Source: [What Should Security Leaders Do with AI? They Don't Know.](https://youtube.com/watch?v=3zhveTN1VzE)

## Summary

In this episode of Security Intelligence, the panel discusses the decision paralysis security leaders face when adopting AI, the emerging threat of ghostjacking, and the reality of AI-generated patches. They offer practical advice on starting small with repetitive tasks and emphasize the importance of human oversight.

### Key Points

- **AI adoption gap and attack surge** [01:27] — 64% of organizations report limited or no use of AI in security functions, while AI-generated attacks jumped 56% year-over-year.
- **Start with repetitive tasks** [00:02] — Start with repetitive tasks like L1/L2 alert triage to reduce alert fatigue and build confidence.
- **Red team empowerment** [06:44] — Arm the red team with AI tools to understand attacker techniques and develop better defenses.
- **Automate known parameters** [08:56] — Automate vendor risk assessments and contract analysis to free up staff for higher-value work.
- **Ghostjacking explained** [10:56] — Ghostjacking is a sophisticated prompt injection that sneaks malicious commands into trusted systems like logs and alerts.
- **Ghostjacking success rate** [11:33] — Claude Code fell for the ghostjacking trick 9 out of 10 times.
- **Defense against ghostjacking** [18:25] — Limit agent permissions, keep humans in the loop, and apply zero-trust principles to prevent agent misuse.
- **AI patch success rate** [21:08] — Only 46% of AI-generated patches solved the underlying vulnerability, often creating new issues.
- **Human patch comparison** [22:05] — Human patches also fail about 50% of the time, so AI performance should be contextualized.
- **Human-AI partnership** [23:42] — Pair AI with human oversight and validate code through multi-agent review to improve security.

## Transcript

where to deploy AI. Panelists, where do you think they should start? Dave, we'll teams. &gt;&gt; Start with AI in the repetitive tasks, they can chew. &gt;&gt; It's good for repetitive tasks,
especially those kind of like L1, L2 ones, looking at alerts and stuff, ones, looking at alerts and stuff, preventing alert fatigue.
Intelligence, IBM's weekly cyber security podcast where our expert panelists turn the biggest industry news stories into practical takeaways that and joining me this week, we've got Claire Nunees, creative director, IBM X
Force Cyber Range. We've got Curtis Pittz, lead CISO Trust. And we've got Dave Bales, North American lead managing consultants at the Exports Cyber Range. ghost jacking and whether AI is actually good at patching or not. But first,
security leaders are feeling paralyzed by AI. struggling with the question of how they should invest in AI. Many of them have
the budget and the buyin to do it, but they feel overwhelmed by the options and think we can all kind of sympathize with. You know, ever since Mythos came out, I feel like there's a new giant AI security story every single week. And
cost of a databach report, which found that 64% of organizations report limited or no use of AI in security functions. Meanwhile, AI generated attacks jumped 56% year-over-year. So, there is some real urgency to address this problem,
Claire, I want to start with you and I want to ask specifically because I know with clients. Have you seen this kind of decision fatigue with anybody in in your line of work? Have you experienced this? &gt;&gt; I think AI transformations are really
scary um you know for security whether they're in the security function itself or in the business side of things. So in the business side of things it's really and maybe we're not encompassing everything. And then on the security
side, it's like how do I get my staff to understand that this is going to help them and not just kind of burden them. So I think it's it's there's a lot of partners also that clients can work with. So it's it's I think there's so
much decision fatigue in general around like what can I do, who can I work with, of the business, where can I automate in my side of the business? Like how is everything still secure? So I I think
and they get very frazzled especially about like the mythos everything going on there. So once you kind of combine all that people are a little bit like I
just don't know what's going on. That's kind of where where people land. Uh and it's hard to kind of get your footing and make a good decision or what you think is a good decision rather. I was just going to agree there and and say
that the other thing that they have to focus on is how do I keep my employees from going crazy thinking that AI is going to take over every facet of their job. We see it. Every other company in the world sees it. It's it's a scary
thing for somebody who's not used to that. You know, growing up when I did, if you'd have told me that there was an artificial intelligence, I would have thought we're living in the Jetson's world here. Where's my flying car?
&gt;&gt; I think part of the problem too is there it's it's been made to be such a big deal that everyone now fears the consequences of making the wrong decision, right? Like in the business world, we know that you fail fast,
right? You fail fast, you fail cheap, you move on. In the AI world, that feels business decision, right? It feels like business or get you breached and all
world. So, I understand the the apprehension, but also I still think we need to fail fast, right? Like there's so many I mean, imagine if the day the car was invented, everything that existed today existed, right? You'd have
a hundred cars to choose from. It's not just the Model T, right? There's so many options out there. That didn't really happen before to the scale that it's happened now. Um, everyone was in the market incredibly fast, right? And so it
bit, I think. &gt;&gt; Yeah. And piggybacking off of what Curtis said, failing fast isn't a bad thing. Everybody has to fail in order to succeed. If no one ever failed, no one would succeed. It would just be the
status quo, which, you know, nobody really wants to be the status quo. We all want to achieve better than that. &gt;&gt; That's a really good point and and it's something I hadn't thought of because especially the way that AI is kind of
doesn't help, which is like here's your silver bullet. we're going to solve everything, yada yada yada. You almost feel like if I deploy this AI tool and You know what I mean? Like there's almost a kind of like shame around if
you can make it work or not. And this idea of just embracing failing fast, I been with us for a while, but I don't know. It seems like it got lost in some which I I think just in general doesn't help with this sort of thing.
and the way that that it's rolled out, right? there's so much cost involved in rolling out AI. Failing fast isn't failing cheap, right? It's failing very expensive. Um, and that matters, right? So, I think I mean, not I know this
think there needs to be kind of a re-wizzling, if you will, of of the way that we contract AI stuff and the way we procure some of those. you know, the government, not that they're very good at contracts, but they had a good model
with deliver now, but if you don't deliver, I'm not ex exercising my option years, right? Like they're short-term multi-renewal contracts. Um, where we tend to be in, you know, 3 to 5year contracts. They need to be one to
business conversation, but like cyber security is a business part. It's part of the business, right? And like that's I think why there is this paralysis a major investment that I'm asking my organization to make like I need to be
I do like that idea Curtis. So maybe being a little bit more I don't know maybe the word is nimble with how we approach these contracts but like making commitment isn't so large so you're freer to fail fast. Um but we opened up
this episode with you asking you all where do you start? Right? So, we've reasons for the paralysis, but now I want to dig into the okay, how do we shake ourselves out of that? And Dave, you opened first with talking about
thinking red team and what you like to see people do with it there? &gt;&gt; I'm going to go back to a sports analogy, but a great offense is just as good as a good defense. So if you if you put the put the AI in the hands of the
red team, let them learn and figure out exactly what the threat actors are doing, that makes them better prepared to face off against those challenges. So give the red team something to do, you know, when it comes to figuring out how
are we going to protect against these threat actors that are always, always, always coming after us. Give us the same tools. Let us figure out what they're doing. We know how they're doing it. let us figure out defenses for that.
Especially again, I keep going back to Costa data breach because it's relatively recent. It's fresh in my mind, but I think about that that 56% like we see attackers are moving very fast and there's a lot of pressure to
as they say, we should do it too. I think it makes sense, Dave. You're right. Arm the red team with those tools so they can basically get into that hacker mindset, see what they're doing so that they can develop those defenses.
I like that a lot. Um Claire, you had mentioned kind of uh automating those bit more about that? &gt;&gt; Yeah, I think that's where AI can really shine also is is repetitive tasks. Um so, you know, if you're getting the same
kind of alerts kind of triaging those kinds of um incoming kind of events, that's really helpful. Um it it also just reduces the the fatigue, right? like if you're going to be implementing AI in a in a very not I don't want to
say simplistic way but a baseline way it's a really good way to help your it's a really good way to help your organization kind of start with an AI security journey and there's a lot of options there as well to kind of build
those into your security culture. &gt;&gt; Yeah. And what I like about that is that it's a kind of baseline level activity, the activity itself is very well understood. So it's not like you're trying to work AI into a complex
works. Let me put an AI to work here. That seems like a very nice way to test it. Um Curtis, you also were were on that repetitive task tip. Can you &gt;&gt; Yeah, one of the things my team is doing is we're we're doing our best to
automate the things that I have people doing thousands of times a year, right? So, vendor risk assessments, um contract analysis, that kind of stuff where the parameters are known, right? The values are known. And so just setting an agent
to consistently validating against known parameters um both takes two people's worth of time off of that they can do more important things um but also allows more important things um but also allows us to find novel ways to branch that
capability out internally without a ton of risk um but also gives us the time back to do that right to try to figure out well where can I expand this to so there's I mean across the sales teams there are probably tens of thousands of
things that come in every year that are super repetitive. And we're doing our best um within my specific trust team to alleviate those repetitive tasks from the sellers as it comes to engagements and and risk assessments and client
conversations and all the fun stuff that goes into cyber security and sales. mention something here that IBM's Dimple Alawalia shared with me in a recent We're talking about where do you start with with with AI adoption and her words
of advice were basically almost like stop thinking about the AI tool. stop about what are you trying to achieve. Start there and once you know what out whether or not AI is the way to do it. Sometimes it will be, sometimes it
really useful advice. So, I just wanted to share it here. And for the listeners, know that we'll be releasing a bonus episode with Dimple later this month all about that conversation so you can hear her whole take. Uh, but I do have to
watching on YouTube, leave us some comments. Let us know how you're feeling experiencing you're seeking your organization? and what are you doing about it? I love to read it. I love to respond. But our next story today, this
respond. But our next story today, this is ghostjacking. new way attackers can poison content in trusted systems to trick agents. The
jacking, is essentially like a a like an extra sophisticated prompt injection, because it sneaks malicious commands into some of the most highly trusted systems we have, right? Alerts,
logs, error reports, things that we assume are are good things, right? One example they gave was attackers embedding the prompt in a connection request that Cloudflare that a CloudFlare firewall successfully and
accurately blocked, but then when the agent read the log recording the the blocking of the con connection request, it read the malicious prompt in the So, it's like the firewall worked, but the agent still got compromised. This is
very interesting to me. And ten it says clawed code fell for this trick nine out of 10 times, which was a lot. Uh, and we've just been talking about incorporate AI into security. How can they do it? Something like this comes
out, maybe you think, should I do it? I don't know. And and and Dave, I'll start there. Does this complicate any of your feelings about security, AI and situation? &gt;&gt; It doesn't complicate things that much.
It's it's now it's known. It's out there. You know, the the the good people at Defcon have have opened our eyes to a myriad of just crazy things that we &gt;&gt; And [laughter] &gt;&gt; because that's what they do at Defcon.
They open our eyes. But this ghost jacking thing that that was extremely interesting to me to see how you go back and you read the logs and and boom, and you read the logs and and boom, there it is. you know, it it I I can't
wrap my head around how someone sat down and figured out how to do that, much less how to make it work. &gt;&gt; Yeah. It's it's you know, the prompt pernitious problem and they we just thankfully security researchers keep
ways to do it. But that also means we have to figure out new and exciting ways to fight back and and and and I don't know what to do about that. Uh Curtis, how about you? Uh any thoughts on this story? And it's got you rethinking AI
landing here? No, I mean if you remember the last chat that we had on this particular podcast, what's old is new again, right? Like when we when the internet was young, right? DNS spoofing was just injecting DNS into a cache
table, right? And so really, we use an agent that's designed to read something and execute it. There's not, unless you design it that way, there's not a lot of logic or or necessarily parameters built into things you think are secure, right?
And we had to figure out DNS security way back then. And now we have to figure out AI prompt injection security now to stop those types of things from happening. You presume this happens across the entire security landscape,
right? You presume that certain things are secure automatically because there's considered secure. And then as you create new tools and new capabilities and new agentic stuff, we run into the problem of like, oh, this isn't as
secure as we thought, right? And luckily there are teams of good people that are Dave's point, like the folks at Defcon have showed us a lot of things over the years. Um, and it wasn't some bad guy figuring it out the wrong way. Like at
least at least we've got insight from from the good guys. Um, but I think it's it it doesn't scare me. It doesn't slow me down. It's just we overlook things because we assume the things that have always been secure are always going to
be secure. uh zero trust says not to do that but as we well know we skip over are easy and have been taken care of for years. So we find ourselves in this bucket periodically as we invent new things and people find new ways to hack
them. I think the zero trust mention is is really salient there because I think that like when AI enters our the enterprise, it brings a new emphasis to thing because like you said Curtis, so many of these things that we assume are
figured it out already. They get upended when you introduce something in there that like doesn't differentiate between the code that's running it and and the untrusted user input, right? That used to be like that was, you know, part of
those things separated. LLMs by nature don't do that. And so now it's like okay we got to figure out how we approach this and and and that you know leads to tenant their argument basically that like this is kind of an identity and
okay we know that agents can be compromised in this way we should them the proper permissions and harnesses so that they don't do anything bad. Claire I'm wondering uh you know from your perspective do you think an
the right way to approach this? Any other thoughts you have about this situation? Where you where you landed on ghost jacking? I think it's like a very true form of hacking uh in terms of like making something do something it's not
supposed to do. Um and as Curtis mentioned, it is something that's new, but we will adapt to that. So, it's really scary right now. Um and it may not be as scary. Well, it will probably be scary in a different way uh in a
couple months, but it it is it's something like we can figure out, right? Because as as we hack things and make things do things that they shouldn't do, we we kind of like counter hack and do the same thing to defend in a different
way that we wouldn't have defended before. Um so I think it's really interesting. Um I think it plays into a lot of aspects I think it plays into a lot of aspects of yes ident identity and access, but it
also plays a lot into just kind of security broadly, which is also a short way of saying it. It's just like something that um you know if you're not expecting it, you're not going to to look for it. So I think it's something
that you know we can kind of work on discovering as time goes forward. off nicely about what you know Curtis kind of you know in a lot of ways it's very similar to what we're doing with
right? And and we're not starting from zero here, right? when like when when AI are tried and true principles we can look at. You know, one of the kind of slogans that's popped up on the show over and over again is we know how to
fix this. We know how to fix this and we can we have the tools at our disposal. right way. Uh Dave, you know, any kind of last thoughts for folks in terms of, for defenders today, what prompt injection might mean in general? Any any
Landon? &gt;&gt; Learning about the prompt injection uh on the AI side is is the biggest key. It's it's not something that's going to go away. It's just going to get more sophisticated the longer we go. And it's
always going to be scary. It's never going to not be scary because it's it's one of those easy things to do. It looks so simple when it's written down. When it's written out for you, it's it's completely simple. having these proofs
of concept around that we look at as helpful um sometimes actually are helpful. They're not they're not these oh let me throw a proof of concept out the world can do this. This is so simple that every other hacker in the world can
do this and at some point probably will do this. So we need to figure out all of the ways that we can tie those things down a little bit and And you know, this got me thinking, this really supports your idea about putting
is what you're talking about, right? We discover the attackers techniques so against them, right? This is a perfect example of this. Like you said, look, new type of attack, but it's not because they're going to unleash it. It's cuz,
hey, you should know that hackers can do this and now you can defend against it. end? &gt;&gt; Really only limit what your agents can &gt;&gt; Really only limit what your agents can do, right? and and set clear boundaries
on what is the no-go land, right? Because if you think about I mean [clears throat] I'm a I'm sure in a lot of scenarios because people are errant in the way that we do things usually uh they probably don't limit the agents the
way that they should, right? They hope that they can get more out of them than they maybe should in first at first glance and so they give them more they really think about or they don't think about uh how to limit what
think about uh how to limit what functions an agent can have. So, I mean, if if the agent that's reading logs can't elevate privileges, right, or can't submit a command to do that and it needs to then go to a person to validate
those types of high-risk maneuvers, if you will, then then I think that's a good safeguard to start. Obviously, it's not going to fix the problem, right? But don't remove people from the loop, right? There has to be eyes in the loop
of a person who knows what they're doing. When you remove that entirely, you run into problems where the agents can do what they want, right? Or your agents, like we learned, start hacking other agents because that's the stuff
that is, you know, just out there and AI is having a good time right now. Uh, &gt;&gt; And I think the over permissioning point is is a really important one, especially non-human identities, especially agents where the whole promise is like look at
all the cool things they can do. There's a there's a real incentive almost to be it can do." Which sounds cool until, like you point out, they start hacking into Hugging Face to cheat on a test, right? Like, this is what happens. Uh uh
end here for ghost jacking? &gt;&gt; I just agree that you need to really think about what your agents have access to, where where they live, everything that they can do, because they they might just like break out of their pen a
little bit if you're not careful. &gt;&gt; Absolutely. And I, you know, I not to be overly self-promotional, but or but, you know, IBM has been working in the kind lot. There's some really cool stuff that's happening there. So, I encourage
out. There's there's some interesting things happening. Uh, but we're going to move on here to our final story for this week. Is AI actually any good at week. Is AI actually any good at patching?
pretty big deal, right? a pretty hot topic basically ever since I feel like thing was like look how fast they can find vulnerabilities and exploit them and now we can use it too blah blah blah. Well, new research from one
password raises some questions about this because researchers generated 540 patches for six vulnerabilities using GPT 5.5 with trusted cyber access uh and Opus 4.8 with cyber verification. And of these 540 patches, only 46% solved the
underlying vulnerability. And when they did, they often created new problems anyway. So you solve one and you open up a new issue. Um, again, given that the kind of theme of this episode has been organizations are looking for ways to
adopt AI and security, they're not sure how to. This is another one where I look at this and I say, does it change how we feel about this? And and Dave, I'll here? Does this make you reconsider how we use AI and security at all?
&gt;&gt; Not really. And and the reason I say that is because what is the the success rate of human created patches? [laughter] something and then break something else because we're not doing our due
diligence of testing in non-production environments, testing in offline environments. The 6,000 patches where 51, what was it? The 6,000 patches where 51, what was it? 51% failed or 49% failed. It's like 50%
&gt;&gt; 50%. Yeah, about 50%. It's not much different than than what humans are way to make that better. And I don't know the answer to making that better. Do we need to have more programmers looking at more things or do we need to
narrow that scope, get it perfected in one area and then start branching off into other areas where we can make it better across the board? You know, that's a really good point and and I think I I myself looking at this
research kind of fell into the mindset of like expecting AI to do more than it actually could. Maybe some unrealistic expectations because you're right, Dave, it's not like people are perfect at writing patches. We break stuff all the
&gt;&gt; which is why we have patch Tuesdays every month. it's one of those things where I think in isolation maybe the number looks a contextualize it, you know. I mean, it it might not be as big a deal as it as
it can seem. Um, Claire, how about you? Any thoughts looking at this in terms of cyber security? &gt;&gt; I love how the picture for this article was also a bunch of gene patches. Um, [laughter] it's just it's just kind of
funny to me and that's like the one thing that kind of ultimately stuck out. Um, I I think like as as Dave mentioned, patching by humans is not perfect. I patching by humans is not perfect. I think maybe a AI patching when partnered
with a human may be a little bit more effective. It's just kind of like when we're rushing to do anything, we miss things. Um, and you know, if you're giving AI specific instructions doesn't it's still going to somewhat miss
things, but I think if you put them hand in hand together, it may help a little bit. It's not going to be perfect, but I think with all AI transformations in general, like it's a transformation, right? So, it's like you you can't
expect to send AI out to do something on its own and be perfect 100% right out of the start gate. It helps if you have a human in the loop for a while to start to make sure that it's still, you know, working properly, nothing is is going
going together, maybe that will be a little bit more helpful. I don't I don't &gt;&gt; Yeah. No, that makes a lot of sense to me and and I also had got me thinking either, but I do wonder if the results would be different if you're talking
about an AI model that you have deployed in your own enterprise and is working it might learn about that codebase over time, right? Like maybe it will get codebase and understands it more. the same way that a person would have an
break things for a codebase they understand really well versus if you piece of code and say fix this they might mess things up. Um so that that's if that you know combination of like trained on our codebase plus it has
spot. Curtis, how about you? What are you thinking about here? &gt;&gt; Yeah, I mean I've got questions, right? Like was was that code validated by other agents? Was it validated by other people? Was it just operating on its own
and it trusted itself? Because why wouldn't it trust itself, right? It's it's much like a person, right? I'm going to trust whatever I code because that's I'm the best that there ever was. Uh, and that's just kind of the reality
of it, I think. And we we did some testing with this and we've seen it testing with this and we've seen it early on that AI can write code. It doesn't necessarily write good code and it almost never writes secure code right
out of the gate, right? even even with the parameters and the playbooks and all the things you try to give it, it trusts itself. And so, you know, you've got to do multi- aent coding where it's validating from other agents that the
code that it wrote was secure. And then you and so at that point, you start to doing all the validating. And then we go back to the first problem we tackled on this call, which is cost and decision paralysis. And how do you balloon all of
that and not show that the AI is doing its job, right? Because if I then spend $100 million on AI and say, "But I need all of my people to still read every line of code, what what's going to happen, right?"
Like it that's the problem we're running into. We expect too much, candidly, out into. We expect too much, candidly, out of AI this early on in the game. Um, when Mythos came out and and hit the floor, everyone freaked out about
vulnerabilities and how do we patch them faster, which created the requirement for AI to now create your patches. It create it created the requirement for AI to tackle this problem that AI has created. That's not necessarily the
right approach, right? AI can't necessarily solve the problem that it created. We've got to figure out a way to use it to help us solve the problem, to its own issue. Um, and I think that that's kind of one of those things that
we're still struggling to figure out, like how do we find the endgame of that. yet. &gt;&gt; I think that that's, you know, a really nice kind of way to summarize, frankly, a lot of what we've talked about here,
which is that so much of the kind of decision paralysis and what where do I A lot of it does ladder up to this thing where it's like we're we're expecting so much out of it. And I think that some of the kind of, you know, media narratives,
really help that. You know, there are certainly people kind of exaggerating what AI can do because it's good for them to exaggerate. Um, but they'll like that I said that. But anyway, um, but I do think that there is, you know,
this sense where we kind of have to get our our expectations in proportion for like what this stuff can actually do cuz sometimes it feels like we're all sometimes it feels like we're all operating as if like AGI is already here
and the super intelligence is already active and why aren't you just using it? &gt;&gt; It reminded me of a of another analogy and I know I love analogies here, but we are in the AI age of like the third grade right now. We're expecting it to
go out and take the SATs. We haven't trained it enough for it to be very good at a lot of things. It does a lot of things well, but it doesn't do
a lot of things great yet. We're still learning on AI. AI is still learning from us. So, we need to take that mindset and kind of run with it and start being the teachers instead of being, you know, the guy who's sitting
on the sidelines trying to critique what the teachers are doing. &gt;&gt; I think that that is a perfect analogy to end this episode on, folks. That does it for us. Thank you to our panelists, Curtis and Claire and Dave. Thank you to
the viewers and the listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so you never miss an episode. Stay safe in third grade, folks. Cut it some slack.
