This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

What is the Future of AI in Security?

Download resources

About this session

Samer Faour, a solutions architect at Exabeam, gives a broad tour of AI in security rather than a product pitch. He opens with a taxonomy (reactive, limited-memory, theory-of-mind, self-aware AI) and shows that machine learning and pattern recognition have quietly powered UEBA, SOAR, EDR and XDR for over a decade, well before generative AI made the term fashionable. He contrasts manual, signature-based SOC work before AI with AI-assisted alert enrichment, natural-language search query building, and threat-explainer summaries after AI, using a Lapsus-style intrusion timeline to show how UEBA can flag a first-time login as anomalous minutes before signature tools catch lateral movement or data loss. A long section on challenges covers black-box opacity, accountability (citing the Air Canada chatbot ruling), bias, privacy, legal exposure and unreliable, unrepeatable outputs. He closes with predictions: vendor consolidation, industry- and product-specific AI models replacing general-purpose ones, and a shortage of AI talent. The extended Q&A covers how Exabeam differs from black-box UEBA competitors and what generative-AI features it has shipped, including its Security Copilot and stateful user tracking.

Key takeaways

  • Remember that machine learning and pattern recognition already power UEBA, SOAR, EDR and XDR; generative AI is a new layer, not the starting point of AI in security.
  • Use behavioral baselining (per user, per asset, per peer group) to catch insider-style intrusions, since first-time or off-baseline events surface anomalies before signature-based detections trigger.
  • Plan for accountability, not just capability: your organization is legally responsible for what a deployed AI tool says or does, as the Air Canada chatbot ruling showed.
  • Do not trust AI output as repeatable or auditable if you cannot see how it reasons; treat black-box models as a governance risk to disclose and manage, not just a technical limitation.
  • Expect general-purpose AI to lose ground to industry- and product-specific models, since accuracy in cyber detection needs to be far higher than casual consumer use tolerates.

Speakers

Samer Faour
Samer Faour
Solutions Architect · Exabeam
Samer Faur is a Solutions Architect at Exabeam with over 14 years of experience in information security. His diverse background includes roles at security vendors, consulting firms, system integrators, and end-users, where he has worked with over… Read moreRead less

Samer Faur is a Solutions Architect at Exabeam with over 14 years of experience in information security. His diverse background includes roles at security vendors, consulting firms, system integrators, and end-users, where he has worked with over 100 customers across various industries. Samer specializes in SIEM, UEBA, SOAR, and Threat Intel, overseeing all stages of the deployment lifecycle from requirements gathering to operationalization.

Resources

Tags

More from GoSec 2024

Also from Samer Faour

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.