Overview of AI cybersecurity is a cat and mouse game
In this live episode of the Stack Overflow Podcast from AI4, host Ryan Donovan speaks with Sam Curry, CISO at Zscaler, about how AI is reshaping cybersecurity. The conversation centers on the new “cat and mouse” dynamic between attackers and defenders, how AI changes software development and security operations, and why organizations should focus less on hype and more on reducing attack surface, improving resilience, and building security into systems by design.
Main themes and takeaways
-
AI is changing both engineering and security work
- Some tasks will become more efficient or “compressible,” while others will require more human oversight and deeper architectural thinking.
- In engineering, AI coding tools raise the bar for speed and quality.
- In security, AI increases both the volume of threats and the speed at which defenders need to detect and respond.
-
Security is becoming more asymmetric
- Attackers can use AI to generate noise, hide activity, and move faster.
- Defenders need better signal extraction, better telemetry, and more automation to keep pace.
- Curry describes this as a true cat-and-mouse game, not just a simple whack-a-mole problem.
-
The focus should be on reducing attack surface
- Rather than only “piling on” more detection and response, organizations should:
- eliminate unnecessary features and listeners,
- minimize API calls,
- reduce lateral movement opportunities,
- encrypt or tokenize sensitive data,
- and make systems harder to enumerate or probe.
- Rather than only “piling on” more detection and response, organizations should:
-
AI can improve security operations
- AI can help with:
- vulnerability discovery,
- chaining bugs into exploitable paths,
- continuous red teaming,
- risk scoring,
- deception and honeypot/honeynet strategies,
- and more realistic decoy environments.
- Curry argues this could eventually lead to major gains in vulnerability management and secure development.
- AI can help with:
Security strategies discussed
Shift-right security and runtime protection
Curry emphasizes shift-right security: embedding protections in production systems so vulnerabilities are harder to enumerate or exploit in the first place.
Examples include:
- runtime virtual patching,
- application shielding,
- blocking common exploit techniques,
- and limiting what an attacker can do even if they reach the application.
Zero trust beyond “least privilege”
He expands zero trust to include more than access control:
- least privilege
- least function
- least data sprawl
- maximize entropy in the environment
- reduce opportunities for living off the land and lateral movement
Deception as a defensive tool
Curry suggests that defenders should increasingly use:
- honeypots,
- honeynets,
- virtualized decoys,
- and realistic bait environments
The goal is to waste attacker time, generate better signals, and separate real threats from background noise.
AI, secure coding, and future-proofing
AI may improve code quality
The conversation touches on frontier models that can:
- find bugs,
- generate exploit chains,
- and improve vulnerability assessment.
Curry notes that AI may make it possible to ship more secure, better-structured code than was practical before.
Language and architecture choices matter
He argues that some languages and patterns are inherently safer:
- Rust, Go, Swift: fewer memory-safety issues
- C#: generally stronger than C/C++ in this context
- More modular, better-commented, and better-architected systems are easier to secure
Prepare for more than just AI
Curry frames AI as one of several upcoming disruptions alongside:
- quantum computing,
- robotics,
- nanotechnology,
- synthetic manufacturing,
- and synthetic biology
His advice: build systems and practices that are resilient across multiple future threats, not just the current AI wave.
Governance, privacy, and architecture
Security depends on architecture
Curry strongly argues that you can’t do a proper security review without understanding the architecture. For AI applications, that includes:
- browser-based access,
- thick clients,
- transit inspection,
- cloud hosting platforms,
- SaaS back ends,
- and provisioning controls.
Privacy and compliance matter
He also highlights:
- TLS inspection and tenant-level policy control,
- regional privacy requirements,
- data sovereignty,
- auditability,
- and the need for architectures that can support future regulatory requirements.
Industry standards are still emerging
Curry mentions work through groups like the Open Security AI Alliance to define:
- isolation best practices,
- harnesses,
- measurement standards,
- and shared guidelines for safe AI deployment.
Practical recommendations
-
Do third-party risk management now
- Don’t wait for a major AI model release to start readiness work.
-
Test rollback, backup, and recovery
- Availability and resilience matter as much as traditional cyber controls.
-
Identify single points of failure
- Build redundancy and failover into critical dependencies.
-
Review your architecture before adopting AI tools
- Especially for browser-based workflows, SaaS AI tools, and systems with CLI or provisioning access.
-
Treat security as a business function
- Curry stresses that CISOs are ultimately risk managers first, not just technical specialists.
Notable insight
“We should be thinking about how to reduce the attack surface and provide less opportunity for attackers to have purchase.”
This sums up the episode’s core message: AI may accelerate both offense and defense, but the best response is to make systems harder to attack, easier to recover, and more resilient overall.
