"You really have to balance the academic side of what I say is security with what's the pragmatic side to enable the business. Otherwise, if you don't embrace innovation, you'll be left behind"
Eran Leib (00:01.276)
So hello, everyone. My name is Eran Leib. I’m one of the co-founders of Backline AI. I have with me Ayelet, our VP product. And we have a special guest today, Ellen Mitchell from Celanese. I’m going to hand it over to Ellen to introduce himself.
Alan Mitchell (00:14.059)
Hey, good morning. Thanks for having me. My name is Alan Mitchell. I’m the global CISO for Celanese and I’ve been now with Celanese for three years and prior to that, I’ve held multiple CISO positions and spent 20 something years at IBM as well doing information security. So pleasure to be here today chatting with you.
Ayelet (00:16.834)
you
Eran Leib (00:37.92)
Amazing. So, Alan, we’re really excited to have you here. You’ve been operating, you know, like a crossroads of security, IT transformations, executive leadership for a long time. I’ve known you for quite a few years and the timing of this conversation couldn’t be better. Today, we want to explore two themes that we feel especially are important for modern CISOs. And hopefully you can share some of your wisdom with us.
So today we want to look at the first thing that we’re going to talk about is the evolution of the role itself. The CISO is no longer just the risk manager or the compliance owner. In many companies, you kind of become, as the CISO, the catalyst of a real change, helping the business move faster and more securely and to modernize the infrastructure. And adopting new technologies, yet keeping control.
So we’d to get your take on how that shift is playing out, where you see the role of the CISO heading. And the second topic is about the trust problem and the AI that is kind of gearing, you know, like that trust problem. The technology is accelerating very fast. I don’t think I’ve ever seen anything move as fast as the AI revolution. But we have a lot of issues around trust, governance, validation, oversight, and like we’ve been talking about it for quite a bit.
Ayelet (01:55.041)
Thank
Eran Leib (02:03.871)
is still limiting organizations from adopting this. So as we start giving AI more responsibilities gradually, we need to get people to incorporate human decisions into the process. And there’s a big question around how do CISOs verify, guide, ultimately, how do we trust these systems? So we’ll dig into both these topics. And so let’s…
start with your perspective on the role of how do you see the modern seesaw playing today.
Alan Mitchell (02:38.391)
Yeah, so the modern CSO or the CSO roles change immensely over the past just few years, much less the last decade, right? So it’s moved from the role of, as you pointed out, of being the person who implements the controls and enforces the controls to more of a advisor.
you know, the CISO is required to advise the business, they’re required to advise the board, and they’re required to really drive enablement of technologies versus, you know, the typical enforcer of the gates, right? So, you know, I like to say that the old CISO used to be the CISO of no, and the new CISO needs to the CISO of how do we do that securely, right? And…
you really have to balance the academic side of what I say is security with what’s the pragmatic side to enable the business. Otherwise, if you don’t embrace innovation, you’ll be left behind. So AI is a perfect example of that. It’s a technology, it’s here to stay, it’s growing faster than anything I’ve seen. I may be stating my age now, but even during the dot-com era.
There were some great innovations there, but it didn’t move at the pace that things are moving today. So really the modern CISO has to be the advisor. They have to be the cheerleader for the technology. They have to enable the technology and they have to be the solution introduction person for the technology as well as making sure that technology is safe, secure and trustworthy.
Ayelet (04:30.186)
And you know, sorry, we’re talking about, you’ve talking about, you know, needing to balance, you know, between, you know, the protecting of your business and your customers and, you know, allowing it to rapidly innovate what like changed in your day to day in your process and maybe even in your organization, you know, to allow that.
Alan Mitchell (04:53.324)
I think one of the things that we’re currently looking at today is, with the AI revolution, how do you use AI to secure AI? It’s kind of an interesting paradigm, because we’re talking about things that move, just trying to keep up with the technology. We actually have an AI board, technology board that we’ve conveyed, and their whole
Eran Leib (05:21.413)
wow.
Alan Mitchell (05:23.272)
role is to try and keep up with the day-to-day things that are changing in the AI space. And then really to separate out the hype from the reality. Because at the end of the day, it’s not about, for us at least, it’s not about all the productivity and things that you can, which is great, but it’s really where you can bring the value to the corporation. So things may look good,
from on paper, but you have to look at it from the standpoint of how will it affect the business? How will it enable the business and frankly, how will it drive top line and bottom line at that moving?
Eran Leib (06:07.623)
Are you trying to push the organization and other leaders in the organization to utilize AI more? Do feel like it’s going to help them or are you like, they’ll introduce it, I’ll have to secure it. There’s a difference between helping and securing things and making sure that the business can use it versus also promoting it because…
It’s more of, it might be a CIO thing, but also CISO sometimes says, you know, like, you can use that, it’s safe, and I want you to use it because it will help us.
Alan Mitchell (06:44.692)
Yeah, I think that’s a great point, Aaron. The thing is, if as a CISO and a modern day CISO, you almost have to encourage people to use the technology, but within certain guidelines and guardrails, right? I like to say technology is like water, right? You can’t get in the way of it. It’ll find its path, right? So I’d rather be in a situation where I say, okay.
we encourage you to use the technology, but we want you to use the technology within these guidelines. Otherwise, people will find ways to do it on their own. And if they do it on their own, they may not do so in a manner that’s as secure, right? Or secure at all. So AI and any technology, right? It’s that, it’s just a technology, but at end of the day, the fundamentals are the same, right? You have to protect your data, you have to do…
the appropriate data management and data governance. And then you have to have the appropriate level of access and authorization to that data. Then today, the generative AI phase today is really just bringing all of those components together in a more efficient manner. And it’s making it easier for the end consumer. And it’s kind of taking out the IT portion in the middle a little bit, right? Because years ago,
If you wanted to get data, you had to put it in a database where there wasn’t really a way to look at unstructured data. And it required someone who had the technical expertise to do joins and do searches and queries and things like that. And now with generative AI, once it’s trained or has access to the data, even unstructured data, it can search it with someone just using normal day-to-day terms and provide you with help.
Eran Leib (08:23.131)
Mm-hmm.
Alan Mitchell (08:37.484)
Whether it’s right or wrong is a separate question. It all depends on the data that it has access to. And we’ll probably talk about that a little bit more in the trustworthiness of AI.
Ayelet (08:55.562)
I’m wondering and I’m curious, know, we’re talking about the CISO role shifting, you know, to be more, you know, strategic and you’re talking about allowing innovation to happen, having a more strategic, you know, responsibility instead of the day-to-day enforcement. Do you think AI is helping in this, you know, domain or is it?
creating more noise that you just now need to create more guardrails to protect.
Alan Mitchell (09:31.713)
I think it’s a little bit of both, right? So I think it does help a little bit from the standpoint of people realize that technology is an enabler. And I think it kind of goes back to the question that Aran asked earlier, which is, does the business want to use AI or do they understand it? And I think, you know, they know about it, right? So you can’t turn on the TV or read an article anymore and not.
see an AI, generative AI article out there. The one thing I’ll say, remind people of AI is not new, right? It’s been around for years, right? The generative AI side of it obviously is a little bit newer. Obviously came into light, you know, December of what, 2022 with open AI and became a big deal. But I think one of the things that the modern
CISO must do and from a strategy standpoint is really be that conduit to separate out the hype, drive the value, and then really help the business understand what are the appropriate use cases for AI. In many cases, I think the business says, well, we have this problem statement, right? And the IT function and the CISO function has to be the person who consults with them and says, okay, this is a good…
use case for AI, this may not be a good use for AI, or even identify if the problem is something that needs to be fine tuned from a process standpoint first before you go and make it agentic or try to do an AI use case with it, right? Because it comes down to if the data, it’s the same old adage, if the data is bad, and if the process is bad, it doesn’t make sense to agentify it.
or use AI to improve that or try to improve the process. You’ll get some improvements from a proficiency, efficiency standpoint, but have you really improved the process, right? And that’s the question that you need to be asking.
Eran Leib (11:47.083)
Alan, you’re in a, it’s kind of like a different angle to this, but you’re in a production type of a company and you’ve been in those kinds of companies in your history, at least for the time I know you. And that’s like a couple of years now. How is that different? And also do you feel like AI coming later in this case for a CISO? it even, you know, like…
Because you’re much more grounded in the real world, I want to say. You have actually things that you produce. It’s not software. There is software naturally involved, but how is that affecting you as the CISO of such an organization versus CISOs that are 90 % of the time focused on the software?
Alan Mitchell (12:37.226)
Yeah, I think that’s a good point. And we have to be very thoughtful and strategic and, you know, surgical about how do we utilize AI, especially in the manufacturing space, right? Because there’s a lot of safety concerns. Those networks and systems typically aren’t accessed or have to have limited access due to the safety concerns and the segmentation concerns. So
We’ve actually adopted the technology to drive our digital plant. So we use very specific AI use cases to look at certain things like predict downtime, look at help with maintenance rounds, things of that nature. And it’s been very targeted, but it’s been very value-add and value-driven. And then on the other side from the sales and lead generation,
There’s definitely some opportunities and we’ve worked in that space to enable AI to aid our customers in doing grade selection and things of that nature to understand what products may fit their specific needs and wants. So I think we have to be very selective and targeted about that. And then of course, since we’re in the manufacturing space, we have to be very thoughtful about how do we…
utilize agentic and some of the new agentic frameworks within the business itself.
Eran Leib (14:11.736)
Makes total sense. So let’s, know, like shift gears a bit and let’s talk about the trust and AI and automation. So systems often say today that, you know, like we trust, but verify and we talked about it just now. What does that mean when you look at decisions that are made or executed by AI systems versus, you know, like what it used to be and
Ayelet (14:19.828)
Thank you.
Eran Leib (14:41.729)
How are we gonna take this forward?
Alan Mitchell (14:45.644)
Yeah, I think it’s more of verify and trust now versus trust and verify. So the world has shifted quite a bit. So as we look at how AI is adopted, we’re always going to see in some way, or form, at least in the near future, where a human is involved to validate or least initially validate.
the outputs and the actions of the AI. I think in certain use cases, there may be some opportunities where it’s very high fidelity. You know that the AI is trained and you can quickly validate that to where you can, know, offloads or shift left as we used to say, some of that workload to AI.
Ayelet (15:34.446)
and we’re going have a a
Alan Mitchell (15:41.569)
I think for more complicated things, we’ll continue to see a human be involved, at least in the beginning of the process to validate and then at some point through the process to do spot checks and so forth on the AI. Once we establish that trust, I think we’ll see more more agentic and more more AI being utilized in an autonomous or semi-autonomous kind of
Roll.
Ayelet (16:13.454)
Yeah, I agree, but there’s a lot to talk about, you know, when talking about autonomous remediation. And again, I completely agree. Confidence, you know, is still, you know, I think the biggest hurdle. And in your mind, like, what needs to be proven, if ever, that you will allow, you know, to say, okay, I trust the system. Let’s let it, you know.
let’s close the loop completely without any human intervention.
Eran Leib (16:47.816)
Or in plain English, when do you say, see no hands?
Alan Mitchell (16:48.042)
Yes.
Ayelet (16:50.248)
See no hands.
Alan Mitchell (16:51.424)
Yeah. So I think that’s an interesting question from the standpoint of, I don’t think there’s ever going to be a hundred percent trust, right? Or there’s this number where you can put a KPI around that, right? I like to think about it a little bit more pragmatically. Can the AI do it just as good or equally as well as a human? And I think, you know, if you can do that,
Humans make mistakes, right? But if you can have the AI do the work just as good as a human and base your measurements on that or better, then that’s probably the litmus test for us. That’ll be the measuring stick, I think, moving forward in the future.
Eran Leib (17:39.914)
maybe less mistakes per number of operations.
Alan Mitchell (17:43.892)
Yeah, and.
Ayelet (17:44.116)
Do you think that?
Alan Mitchell (17:47.168)
Okay.
Ayelet (17:47.756)
I was wondering if you think that product or security metric will change over time, you know, just to measure this, you know, how can we reassure that we got to this confident level that we can say, okay, it’s as good as a human, you know, with the percentage of mistake that we expected to have.
Alan Mitchell (18:09.056)
Yeah, I think we’re going to have to rely heavily on data-driven metrics, right, to prove that out. And I think there’ll be a barrier to entry where we’re going to have to have that data be very, very good in the beginning. And then as people gather that trust, then that’ll decline slightly. But you’re definitely going to have to use data in order to…
validate that trust, right? And the metrics will change over time. And then I think they’ll shift from, there’ll be always a trustworthy metric, and then there’ll be the value metric that’ll be very, very important. We tend to, in the security space, focus on volume metrics, and we fixed these many vulnerabilities we did.
We did this much avoidance and rest things of that nature, but it’s really going to have to shift to, what have we been able to do to shift from a value standpoint and a resiliency standpoint? And I think we’re seeing that already in the industry with some of the more mature companies and leaders out there, but it’s a matter of time. And I think AI will help us with that as well as well as be a consumer of those metrics.
Eran Leib (19:31.189)
Almost sounds like, you know, like it will, AI will help us, you know, like focus on what matters in a way. Like sift the noise. Not about, you know, like not thinking partization, but more like taking the miniscule work and just getting that done, letting us take care of the important things. And we actually talked about it in a
with a mutual friend of ours, Paul Trulove, a couple of episodes away about the changes in metrics that AI kind of introduces into the industry. We’re changing, like you said, from quantity, how many did I do, versus, well, how well do I do? And how can I get even better?
Alan Mitchell (20:17.447)
Exactly.
Absolutely. And then I think we’re going to see a shift too of AI being used to police or secure AI. So as I said, I think earlier, so that’s going to be an interesting paradigm shift as well. And it may sound cliche to say it, but we talked earlier about the technology moving so fast, right? And AI being able to process information at speeds that a human cannot, right?
And like one measure of how well do you do things, right, will be, you know, if it took three weeks to do it before and it now takes a day, right, that shows value, right? So that’s the kind of metrics we’re going to be looking at in the future. But with that said, if you’re trying to secure AI, you’re not going to be able to do it just with people. You’re going to have to use AI to secure AI. So I think that’s a…
very interesting use case and we’re starting to see that come to fruition today even as we speak.
Eran Leib (21:29.961)
Yeah, I agree.
Eran Leib (21:34.545)
going to say before that
You have a lot of know-how in the company on the stuff that you build and you produce. Do you allow, probably maybe with a private model to get all that information and actually see, you know, like that everything works together and utilize that? Because I don’t think that Zelenits, for example, will ever allow that. I mean, probably trade secrets and stuff like that to go out on a public model.
in any way, right?
Alan Mitchell (22:14.965)
Yeah, correct. think, so we do internally in our private models train with the data and telemetry data from our plants, for instance, right? So, and this is something that others on our digital plant team have shared publicly, so I’m not sharing anything, but we do protect that information, but we use it internally.
to really help us back to the value statement of providing decision support around operations in the plan. And it’s been a huge enabler for us from the standpoint of cutting down on maintenance, improving safety, things of that nature. you know, having that data and utilizing it, but it comes back to, you know, some of the guardrails and oversight that you need to be trustworthy, right?
we have to ensure that that data and we have a good data governance process in place for that. Because if we don’t have that, it’s just like anything else, garbage in, garbage out. So if you train your AI model based on bad information, you’ll get bad information out. So there’s no magic wand there. So that governance, that validation needs to take place. You can’t just blindly point to data.
Eran Leib (23:30.461)
That was exactly the reason why I asked.
Alan Mitchell (23:42.325)
assume that the output is going to be valuable.
Eran Leib (23:47.508)
So that’s exactly the reason why I asked that because if that’s your model and it’s geared exactly to your needs and you train it with the data that you feel is sanitized and it’s good and it’s not like you trust your own data, would you trust that kind of AI, I’m assuming much more, and allow it to go autonomously faster versus AI which is a generalist?
Ayelet (24:11.278)
you
Alan Mitchell (24:15.615)
Yeah, I think…
Eran Leib (24:16.339)
As a general question, not specifically in the company, right?
Alan Mitchell (24:20.585)
Yeah, I think where the use cases make sense. And I think people are going to have to be very selective about that. But there’s definitely opportunities in select areas based on what we just talked about, establishing the trust and having good data and so forth to where the real value will be in that autonomy that takes place. Once again,
that it does as good or better a job as a human, right? Because that’ll be the measuring stick. Because if I’m already trusting a human to make a decision, and the AI, we validate and verify that it’s doing just as good as job or maybe better than a human. That’s where the true value is going to be, right? So, you know, like I said, I used a term earlier in the conversation, the shift left, right? At this time, it’s a shift left using technology.
to do some of the tasks and work that needs to take place on a day-to-day basis. And that’s where the real value is going to come from with agentic and automated, even semi-automated AI, generative AI in that space.
Eran Leib (25:39.411)
Would you flip that equation? Would you let human do and let AI verify that?
Alan Mitchell (25:45.997)
I think there are use cases for that as well. We spend, if you think about it, even just from a process standpoint, we do have checkers that check the checkers. So there’s an opportunity, especially where the AI is indiscriminate. It’s trained on the data, it knows what to look for.
Humans, tend to get into our, we know what we know, right? And I think there’s opportunities for things to be missed. So I think for AI to check the humans, think that’s a good thing. I mean, it already happens today in some way, or form, even before we got into generative AI, right? We’ve been using AI models and so forth to check data and validate data.
So I see it as no different. It’ll just be probably more efficient and it’ll be easier to do based on some of the models that are being developed today.
Ayelet (27:00.078)
Looking like fast forward, I don’t I to say three years, it sounds like a lot of time, especially in this, know, extreme rapid changes that we see. Do you think that the traditional processes that we have today with the validation and, you know, the change control and everything that we do today will dramatically change or we still have those, you know, guardrails and processes stay?
Alan Mitchell (27:29.086)
I think fundamentally those controls and processes will have to stay in place. But I think the level at which we enforce those processes will evolve with the technology and the AI space. I think it’ll help drive probably more efficiency. Because as we just talked about,
Ayelet (27:29.602)
relevant.
Alan Mitchell (27:58.761)
AI checking the people, right? I mean, a lot of controls are right as checking conditions, right? So once again, it kind of goes back to my point about AI being used to secure AI. So I think the fundamental processes will still remain the same. Who or what performs that role will definitely evolve over, I’d say the next few months, much less next few years, right?
Ayelet (28:25.496)
Yeah.
Alan Mitchell (28:26.732)
In AI space, I don’t know what at the end of all this, know, during .com, right? We had the, you know, at the speed of .com and, you know, that equated to some amount of time. It’s going to be interesting to see what the time condensation or collapse becomes with AI.
Eran Leib (28:49.625)
Yep, 100 % agree. So I’m actually going to, before we wrap up, I wanted to kind of introduce a question to you that you’ve been through. I want to say this is kind of the third revolution you’re going through. You’re like you had .com, you had cloud. Let’s not forget that, right? Because cloud
Alan Mitchell (29:13.835)
Yes.
Eran Leib (29:16.625)
took us about 10 years to adopt.com was about, you know, like, I want to say almost 20, 15, 20. The cloud went to 10. This seems to be moving way faster. What kind of advice do you have, you know, like for someone who, who starts, you know, like in the security world or, you know, like aiming to become, you know, like a young CISO that eventually, you know, like
Alan Mitchell (29:30.623)
Absolutely.
Eran Leib (29:44.473)
And I’ve heard before, don’t do that. So let’s not give that advice. And Xanax also is not a good advice. So let’s move to other types of advice.
Alan Mitchell (29:47.594)
Yeah.
Alan Mitchell (29:57.418)
Yeah, so I’ve actually been through four evolutions, if you count moving from mainframe to… So yeah, now I’m telling my age a little bit. I think the biggest evolution for someone that’s becoming a new CISO is that contrary to the way that the job posts and people are articulating the role, you can’t be the master of all anymore.
Eran Leib (30:03.898)
Fair enough. I’ve been there too, which tells my age.
Alan Mitchell (30:26.567)
It’s just not humanly possible, right? So you have to make sure that you train yourself in the things that are relevant and make sense, ground yourself in the processes and the methodologies that have proved themselves throughout different technology changes, and then surround yourself with people that can help you.
navigate all the different technologies that are out there, right? You just can’t be an expert in everything these days because there’s so much out there and there’s more and more that’s expected of the CISO. So, you you have to have your breath and you have to choose where you have your depth and you can’t do it all. So that would be my advice to the young CISO or to new CISO is that, you know,
find out what your strengths are, focus on those, and then surround yourself with people that can help you in the other areas because we’re expecting more and more CISOs. And I think it’s one of those roles, unlike some of the other C-level execs, right? A CFO, for instance, has to keep up with the financials and to keep up with the regulatory compliance and things of that nature, right?
Ayelet (31:49.006)
you
Alan Mitchell (31:53.843)
So it’s still very focused. And I just use that for illustrative purposes, but the CISO or Chief Security Officers asked to maintain this whole breadth of things, including technologies. And then of course, because there’s technology debt, you have to remember all of the past historical stuff. our plate gets bigger, you know, every day.
and it’s not going to get any less. So that would be my advice.
Eran Leib (32:27.579)
That’s actually a very good advice. Also, by the way, I feel like it’s a very good advice also for CIOs. Because I feel like CIOs and CISOs, I never thought about it, but those are the two that continuously evolve unlike other C levels.
Alan Mitchell (32:33.193)
Yes.
Alan Mitchell (32:41.589)
Yes, exactly. mean, market conditions change, structural conditions change, things like that for other C levels. for CIOs and CISOs, we really have to keep up with the technology and with what’s current. Otherwise, we’ll get left behind.
Eran Leib (33:05.049)
Great. So thank you everyone for joining us and thank you, Alan. Thank you, Ayelet. And that’s a wrap.
Ayelet (33:10.456)
Thank you.
Alan Mitchell (33:10.485)
Thank you.