How Can Cyber Defenders Adapt Faster to AI?

TL;DR
Cyber defenders should measure how quickly they can change architectures and controls relative to attackers, not merely how quickly they respond. AI accelerates vulnerability discovery and exploitation, while legacy perimeter devices and weak SaaS integration models remain slow to change. Enterprises can improve resilience by demanding secure products, increasing infrastructure visibility, and adopting stronger authorization models.
Transcript
And now, a keynote that has been one year in the making, and I'll explain that in just a l- little bit in our discussion to come up. But I'd like to welcome to join me on stage Global Chief Information Security Officer of JPMorgan Chase, Mr. Pat O'Pet. Wow. Dude. What's up, dude? You got a fan base out there, man. That's right. Yeah. Come on, have ... Read More
Key Insights
- Mean time to adapt is a measure of how quickly defenders can change architectures or controls compared with the pace at which attackers iterate. Opet argues that buying speed is necessary but insufficient because cybersecurity teams must optimize their environments for continuing technological and adversarial change.
- AI creates an economy of exploration by giving attackers powerful capabilities for identifying software weaknesses. This reduces the time between vulnerability disclosure and exploitation, making traditional remediation schedules increasingly mismatched with attackers that can refine their methods on daily or even shorter cycles.
- A published patch can function like an exploit blueprint because attackers can compare changed code and work backward to the underlying weakness. JPMorgan Chase therefore treats patches as exploits, reasoning that defenders may already be running out of time as soon as a patch becomes available.
- Perimeter devices can become enterprise weaknesses despite being deployed as the front line between the untrusted internet and trusted environments. State actors have placed implants on these systems, gaining footholds from which they can pivot deeper into organizations that depend on the devices for protection.
- Legacy perimeter architecture is difficult to adapt because it can combine poorly maintained Linux versions, memory-unsafe code, weak internal trust models, limited instrumentation, and restricted opportunities for customer-driven changes. These characteristics reduce visibility and make rapid defensive improvement difficult for enterprise network teams.
- Perimeter exploitation is rising sharply, with the four most exploited vulnerabilities affecting perimeter devices and the trend growing 800 percent year over year. Opet also says half of the critical vulnerabilities JPMorgan Chase addressed in the previous year involved perimeter devices.
- SaaS is a form of outsourcing because an external provider may hold enterprise data or perform operations for the customer. JPMorgan Chase expects providers supporting systemically critical functions to apply comparable diligence, and it will not purchase solutions that cannot demonstrate the required security.
- Purchasing power can influence software security when large enterprises make protection a condition of procurement. Opet argues that providers currently favor features and functionality when market forces do not demand security, so major buyers must clearly communicate and enforce stronger expectations.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is mean time to adapt in cybersecurity?
Mean time to adapt measures how quickly a defender can change its architecture or controls in response to evolving attacks and technologies. It can be compared with the rate at which attackers iterate their attack cycles. Pat Opet presents this as a crucial cybersecurity metric because responding faster is helpful, but insufficient when underlying systems remain difficult to change.
Q: Why does AI make vulnerability exploitation faster?
AI gives attackers powerful capabilities for exploring software and identifying flaws, creating what Opet calls an economy of exploration. As those capabilities improve, the time required to discover and exploit weaknesses falls. Attackers can also target systems that defenders previously considered difficult or esoteric, including Linux-based environments, with small implants designed to discover credentials.
Q: Why does JPMorgan Chase treat patches as exploits?
JPMorgan Chase treats patches as exploits because attackers can compare patched and unpatched software to identify the weakness that the update corrected. Once a patch is published, the defensive clock is effectively running, and an organization may already be late if attackers have independently found a zero-day exploit. This makes delayed patching especially dangerous.
Q: Why are perimeter devices a major cybersecurity risk?
Perimeter devices sit between the untrusted internet and enterprise systems, but attackers have repeatedly abused them to establish footholds and pivot into organizations. Their security problems can include poorly maintained Linux versions, memory-unsafe code, weak trust architecture, limited instrumentation, and restricted customer control. These limitations make weaknesses difficult to detect, mitigate, and eliminate quickly.
Q: How large is the perimeter-device exploitation problem?
Opet says the four most exploited vulnerabilities affect perimeter devices, representing a trend that grew 800 percent year over year. He also reports that half of the critical vulnerabilities JPMorgan Chase responded to during the previous year involved perimeter devices. The firm had reached the point of contacting a supplier twice daily about a perimeter-device problem requiring correction.
Q: Why is changing legacy security infrastructure so difficult?
Legacy security infrastructure can operate on an adaptation timescale approaching a decade, while attackers may evolve on a daily timescale. Opaque vendor-controlled devices may prevent enterprises from adding instrumentation, gaining adequate visibility, or directly implementing changes. Attackers recognize these sticky ecosystems and can concentrate on embedded weaknesses that defenders cannot quickly remove through architectural improvements.
Q: What security standards should enterprises require from SaaS providers?
Enterprises should require SaaS providers to demonstrate security diligence appropriate to the operations and data entrusted to them. SaaS is effectively outsourcing because an external provider either holds customer data or performs an operation for the customer. JPMorgan Chase says it will not buy services for systemically critical operations when providers cannot demonstrate the security it expects.
Q: How can enterprise purchasing power improve software security?
Large enterprises can make security a purchasing requirement and refuse products that prioritize features and functions without demonstrating adequate protection. Opet argues that market forces have not consistently demanded secure software, so providers respond by emphasizing other priorities. A major buyer can help change that outcome by defining its expectations clearly and enforcing them through procurement decisions.
Summary & Key Takeaways
-
Pat Opet argues that mean time to adapt is becoming cybersecurity's most important metric. AI gives attackers powerful tools for finding software flaws, shortening exploitation cycles. Defenders must therefore optimize architectures for continuous change, allowing them to mitigate entire threat classes and safely adopt new technologies faster than adversaries can evolve their methods.
-
Perimeter devices illustrate the adaptation gap. These products separate the untrusted internet from enterprise environments, yet state actors have used implants on them as footholds. Legacy Linux, memory-unsafe code, poor trust architecture, limited visibility, and restricted configurability can leave defenders dependent on devices that may take years to fundamentally modernize.
-
Opet's security-first message also targets SaaS providers and third-party integrations. JPMorgan Chase expects suppliers handling its data or operations to demonstrate comparable diligence. The firm intends to use purchasing power to reject insecure services while questioning integration patterns that grant internet-based third parties access to first-party resources through simple OAuth connections.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator