NVIDIA CSO David Reber on AI and Cybersecurity

Written By
James Maguire
James Maguire
Published: Mar 2, 2023
Updated: Nov 6, 2024
1 minute read

Transcription

foreign speaks we're talking about two technology sectors that are now inextricably linked that is artificial intelligence and cyber security AI is now at the very Forefront of protecting against cyber attacks even as it's used as a tool by hackers to perpetrate attacks to discuss that I'm joined by David Reber Chief security officer and have a head of product security at Nvidia David absolutely thrilled to have you with us today thanks for having me I'm looking forward to the conversation so it I think it's really fascinating in the world of cyber security it's almost like it's it's AI versus AI it's like some sort of a an escalating arms race can you talk about how AI is shaping the cyber security sector these days yeah so when we look at it there is a ton of offense and defense Evolutions always going on Cyber has always been a cat and mouse game where the Defenders are always having to be right every time where the offense always has to be right once one of the fundamental limiters of the offense traditionally has been scale how can I uniquely scale and customize my exploits my phishing my attacks to every Enterprise in the world generally scale is what has limited them to being as efficient when with what they really really want to be able to do now with AI they're able to generate phishing emails that look just like your CEO or your executive sent you custom tailored to you as an individual for what you did that afternoon so that scale Dynamic is really changing the pace and making that evolution of adversarial and adversarial AI at machine scale additionally cyber defense has always been a data problem we've we've tried to make it look like oh we can just write these rules these filters but really at the end of the day it is a data problem it is a machine learning or AI problem but the challenge we have to look at is how do we enable the machines do what the machines are best at and what the enable the humans to do what the humans are best at and create this defensive ecosystem that allows to take over that machine scale offensive adversary do you think as as AI has played a more Central role in cyber security that it is current is it currently favoring the good guys or the bad guys it's it's a tool in both toolboxes I would say that it's easier to see the adversarial wins than the defensive wins right now right but there's a lot of research that's going into to both sides um I mean you see AI in Pockets with different solutions and sets across the industry um one one phrase that I I like to I've heard before and I like to to say or it is it's it's AI until you trust it and then it's just automation as we look to use AI to help us automate the rules and capabilities faster um you can see those wins so it really just depends on how you look at the problem and where the space is sometimes it's better for the offense and clearer sometimes it's better for the defense I I want to make sure I understand that Fraser is really interesting it's like it's AI until you trust it otherwise it's automation am I getting that right yes and we see that a lot is it's like when you don't know or understand how it's working or don't know if it's working you talk about it as machine learning you talk about as AI then it's especially in the Cyber defense what Austin often happens is once we understand it it becomes a repeat pattern it's just automation within our Network that we trust even though it is still using machine learning techniques it's still using the same fundamentals it just becomes automation within our networks and our systems and it's it's there today in many many cases all right so if if both sides have ai how can companies get the better hand in protecting themselves which what's your recommendation in this sense one of the things I often see companies think is AI is going to solve their foundational problems that they've been skipping for years as an industry right we've tons of Cyber Solutions that will help you solve your lack of asset management or your lack of pardoned and centralized identity management but in reality AI is most effective when you lay those foundations correct whether it's zero trust strategies whether it's data Centric security models um by keeping and involving that Foundation automating your infrastructure and your deployments getting that solid is going to enable AI to be successful in defense because I can't automate rapid defense if I don't know the infrastructure that I have so you still have to solve those foundations understand those skill sets and start investing some time energy and understanding in your new hires or into your sock into use it as an additional capability and just keep learning as the industry evolves if I if I'm understood your current you're answering correctly it sounds like it's along the lines of make sure everything makes sense before you get to the AI am I am I understanding that correctly or is there something I'm missing there it's something people can do now yes however it shouldn't prohibit from getting started with AI today because what AI can help you do is prioritize those foundations that you may not have have gotten right in the past it can help you prioritize and accelerate doing those those aspects well let's let's drill down to nvidia's offerings I mean how does nvidia's AI offerings serve the cyber security Market well we like to we're not specifically a cyber solution we want to be the platform and we're an enabling platform for every cyber solution to to operate on we have a developer ecosystem we have what we call Morpheus our Morpheus sdks and what it enables developers and cyber Defenders to do is really truly take advantage of the machine learning techniques with reference models getting getting started um both guides models data sets in order to help accelerate the uniqueness of the problems that you're solving so with those platforms and our our jet just general AI pipelines and platforms that's where we want to enable all cyber Defenders and companies to build their uniquely tailored Solutions on top of that common ecosystem and machine learning capability you know one piece of that I think is interesting uh is the idea that the AI solution or AI support is going to get better with time not necessarily always with human with human assistance they will the model will learn uh I'm not sure what my question is I just think it's interesting that the companies are using these solutions for cyber security in theory they're going to get better with time is it you think it's correct or is that too optimistic what I think that the trend is we're gonna we're gonna learn through the Journey right I don't think we can definitely say this is where it's going to work 100 of the time what we do know is the data is out passing our ability of our human capacity the human capacity available to us to do cyber defense and we need to do something that's often we'll set out on a journey to say how do I look for identity of abnormalities but we'll actually end up finding some not human identity but machine abnormalities as we use Ai and as we use those techniques and tactics to look at that massive amount of data to be able to find the needle in the stack of needles is what we're really trying to do as a cyber defense and so I think to your point over time it it will right the more that we learn the more that we come together as a collective Community to share that knowledge share of this is where it's working this is where it's not that Collective defense is what's going to enable us to be successful in the future here you know what one point there that really resonated we you talked about how the data has outstripped you know our human capacity to really you know understand it and mine it and fully manage it so we need artificial intelligence we have gotten to the point where AI is really it's not just a nice thing to have or an extra fancy Sports Car Tool it's actually a necessary part of the foundation without which I think you need to be kind of afraid of what's going on yes and one thing that we will talk to a lot of like sock analysts and teams it's how do you truly enable to better optimize the human capacity that you have it is not a replacement of the human decision making apparatus in fact it's how do you accelerate the human to make those decisions for the decisions only the human can make uh all right speaking of that that AI human relationship let's look to the future of that the future of that I think it's going to really determine the things what is your idea of the the years ahead for AI and cyber security I mean and how can companies get ready for it now so the future that I see is at the end of the day it's a feedback loop everybody in the organization every human being in the organization is responsible for some aspect of cyber defense for that organization the goal of us as cyber experts is to get as much information to them as possible at the time they need to make decisions should they click on that phishing that email should they click on that link should they configure multi-factor on their email account right how do we use that in everyday life to give them as their writing code nope that's that has a high potential for exploitation this is why this this is an article that tells you why how do we get that information to them so we can be more proactive in everything and that's in addition to the standard cyber defense tools detecting malware exploitation but that's where I see the future is how do you get the knowledge the security expert knowledge to those who are not Security Experts and to your second part of that question what can you be doing doing now with that I think as one is starting to to learn what is capable what is not as I mentioned before get your your foundations in place so that you can build upon AI start getting access to all of your data to make those decisions and have your security teams working hand in hand with your developer Community understand where are they making the biggest mistakes where are the biggest hurdles that you can start injecting of how can we leverage Ai and generative AI to give them those answers a quicker faster and enable that aspect of the community it used to phrase generative AI which you do get 5000 bonus points David for using that phrase it's a very sorry but yeah you want you won the game you get a free game for using that phrase um it's a lot of good stuff anything else you'd like to add in closing about AI cyber security or or generative AI what you know how how is that all gonna shake out I I think it's to summarize it and I said it in in the beginning right it's how do we enable the machines to do what the machines are good at and the humans to do what the humans are good at the generative AI is it's starting to demonstrate of how you can use it to accelerate both offensive and defensive learnings and I think more people everybody within the organization starts putting into that putting into the discussions to figure out how can they use it to learn things that they don't know but they need to know to be successful is what's just going to make a better defensive organization how do you enable everybody in your company to be a cyber Defender because they are the front line interesting and and important too companies do need to be thinking about that uh David I think you studied a lot of fascinating stuff um very much appreciate you sharing your your thoughts today and please come back and talk with us again sometime thanks for having me I was looking forward to a future discussion

This transcript was generated automatically from the video's captions and may contain errors.

eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

I spoke with David Reber, CSO of Nvidia, about how the modern cybersecurity sector is defined by “AI vs. AI.”

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.