In this episode, Prabh Nair and Ross dive deep into the security implications of Generative AI in software development. As AI tools like ChatGPT transform developers into prompt engineers, new cybersecurity, compliance, and data privacy risks emerge.
Ross Yong
https://www.linkedin.com/in/mrrossyoung/
https://owasp.org/www-project-threat-and-safeguard-matrix/
00:00 – 01:05 – Introduction and Welcome Ross Young and his career journey
01:05 – 04:12 – Securing Generative AI
04:12 – 08:36 – How generative AI important from a CISO perspective
08:36 – 11:50 – MCP (Model Context Protocol)
11:50 – 17:43 – Threat and safeguard matrix (TSM/TASM)
17:43 – 20:00 – LLM threats step by step
20:00 – 21:42 – Integrate security controls
21:42 – 23:52 – Security Vs functionality
23:52 – 25:56 – AI-specific checks into CI/CD pipelines
25:56 – 26:42 – Recommend any generic controls for CI/CD pipeline
26:42 – 27:04 – Open-source tool for detecting the AI issues
27:04 – 30:20 – TASM aligned with the NIST AI RMF and EU AI act?
30:20 – 37:03 – Challenges faced with this framework (TSM)
37:03 – 40:00 – Single KPI
40:00 – 43:35 – One walkthrough for CISO’s to build KPI
43:35 – 45:40 – Career Advise – Upscale for CISOs
45:40 – 47:37 – Last important point
47:37 – End of the conversation by thanking Ross Young and looking forward to doing more Podcast.
We discuss:
https://owasp.org/www-project-threat-and-safeguard-matrix/
AI code security challenges – vulnerabilities in unvalidated AI-generated code
Defense-in-depth strategies for secure AI adoption
OWASP Threat & Safeguard Matrix (TSM/TASM) and its role in threat modeling
Balancing productivity vs security in AI-enabled DevSecOps pipelines
CISO challenges – shadow AI, data security posture management, and data loss prevention
AI governance frameworks – NIST AI RMF, EU AI Act, security-by-design and privacy-by-design practices
💡 Key Takeaways:
✔ Why organizations must scan and validate AI-generated code for vulnerabilities
✔ How CISOs can embed AI security controls into CI/CD pipelines
✔ The role of KPIs and business impact analysis in proving AI risk reduction to executive leadership
✔ Best practices for integrating TASM into enterprise-wide threat modeling
✔ Emerging tools like Encrypt AI for compliance scanning
This is a must-watch for CISOs, security architects, developers, and AI governance professionals preparing for the next wave of AI-powered cybersecurity risks.
AI Governance
Practical ai governance
AI Security
#genai #genaisecurity #infosec #cybersecurity
source





Leave a Reply