
Is a closed or an open AI model more trustworthy?
Morgan Adamski: I think that's what we're trying to get people to understand, is there is no silver bullet. There's not one thing that -- capability that you're going to be able to use to do all of these things. AI is not going to solve all of your problems. Not that to say it's not phenomenal, but it's not. You're going to have to think of the problem in different types of pillars, and you're going to have to layer them in a way that makes sense for a comprehensive cybersecurity program. [ Music ]
Johnny Hand: Welcome to AI Security Brief, where we're unpacking emerging AI threats, vulnerability research, and the strategic decisions that security leaders are making right now. I'm Johnny Hand.
Dustin Childs: And I'm Dustin Childs. When adopting AI, you usually have to make a decision between frontier models and open-weight models, but it's not a binary choice. The right model depends on the use case, risk, and the balance between flexibility control in your organization. And responsible adoption really depends on your organization's architecture and governance.
Johnny Hand: That's right. This was a perfect conversation for Morgan Adamski, who leads Cyber, Data & Technology Risk Practices at PwC. The great thing about Morgan is she's working every day with the boards, with CISOs, and security teams that are navigating AI adoption right now. One of the key things she talks about is how, right now, we're all getting paralysis by analysis, but we have to shift to focus on building for flexibility, understanding our data, and getting the fundamentals right.
Dustin Childs: Yeah. It was a great conversation with Morgan, and she really talked about how people often focus on using AI to improve security, but we need to secure AI itself. She also covers identity, access recovery, and the human oversight as agents enter the enterprise. It was a really great conversation. We had a lot of fun with it. So let's just go ahead and jump in.
Johnny Hand: Morgan, welcome to the AI Security Brief. We're excited to have you with us.
Morgan Adamski: I'm very excited to be here.
Dustin Childs: So I'm curious, when you talk to CISOs today, is the AI model conversation still mostly about capability, or has it become about security and governance first?
Morgan Adamski: Yeah. So different -- there's a bunch of different conversations happening at the CISO level, especially right now with a lot of incidents that are happening in the news. There's a conversation on whether or not they're using closed models or open-weight models. There's a conversation if they should commit to only one model. And one of the things that we're really trying to tell a lot of companies is that they should be looking at multiple different types of models, right? Because being able to use different types of models, they're going to find different types of things. And there's different pros and cons associated with both closed models as well as open-weight models. You know, a lot of companies are trying to figure out from a cost-efficiency perspective. Are they going to be able to afford to only leverage closed models in their environment and for the work that they're trying to do? Maybe they need to be able to have open-weight models in play because there's cost efficiencies. There's also an ability to have more agility in what they're doing to be able to swap out different types of models depending on what's evolved and what's come out that week. So we try to also emphasize. You really got to focus on the architecture that you're building to be able to leverage these different types of models and how quickly you can bring them on board. And so it's a multi-model conversation with a lot of CISOs right now on, like, there's a lot of good technology out there. There's a lot of different types of models. You should be looking at all potential ones depending on what your needs are. And when we talk about needs, to your point on security, a lot of that conversation is around, like, data security, data protection, governance. What type of risk tolerance do you have within the company? Where are you leveraging these models within your enterprise? Are they going to have access to information that maybe you don't want necessarily an open weight model to have? Those are all legitimate questions. So it does come a little bit back to security and governance, but, like, we don't want people to feel so paralyzed that they're like, "I'm going to use one model, and that's the only model that's going to be helpful." And then recognize that they've potentially put themselves in a corner where they don't have the same type of agility that they require with how fast this technology is moving.
Johnny Hand: With most organizations, they don't have a lot of that practical skill set to be able to distill models and bring them down into their workflows and get highly specialized. So how do you -- how are you navigating that? Because I think what I've seen from a lot of folks that just don't have a lot of maturity and talent around AI, they're heavily dependent on these models, but they're also hitting that cost wall. So what are you seeing there in terms of that two approaches between the frontier and the open-weight models?
Morgan Adamski: Yeah. So, to your point, you're absolutely right. Like, every company is in a different part of this journey, especially based on their technical expertise and capacity inside their company, trying to figure out, okay, what can we do ourselves? Where do we need to hire and augment, leveraging technical expertise outside of the organization and bring people in? And I do think that's a very thoughtful conversation for a lot of people, determining what they can use and what they can't use and what they'll be able to build. I think that's what we're trying to get people to understand, is there is no silver bullet. There's not one thing that -- capability that you're going to be able to use to do all of these things. AI is not going to solve all of your problems. Not that to say it's not phenomenal, but it's not. You're going to have to think of the problem in different types of pillars, and you're going to have to layer them in a way that makes sense for a comprehensive cybersecurity program.
Dustin Childs: I actually wanted to back up a little bit and bring this up a little bit higher level for some of our listeners, because we've been talking about closed models and open-weight models. And, Morgan, how do you define a closed or frontier model versus an open-weight model? And where do those categories overlap? Because I think that's an important distinction that not everyone understands.
Morgan Adamski: Yeah. That's a great question. I'm not sure I'm going to answer it that well, Dustin, so I'm going to do my best here.
Dustin Childs: Okay. That's fine.
Morgan Adamski: So when I think of closed models, I think of things like Claude. I think of things like -- I wouldn't say Mythos because I don't want to directly drop into that one. ChatGPT 5.6, various things, Opus, things that people can get access to. I think with open-source models, more so in the DeepSeek Chinese, like, type -- I tend to affiliate with that, that people could have access to that have a little less constraints on them. They have a little less of the liability protections, the things that it can access information. From an overlap perspective -- I don't know. How would you describe the overlap?
Dustin Childs: I don't know that there is so much of an overlap, just as there is --
Morgan Adamski: Yeah. Sorry, I was like --
Dustin Childs: Yeah. There might not be. That's kind of why I was asking the question, is I see them as two separate yet equal entities. But in a way, the open weights, you're removing so many guardrails, but at the same time, you might want to remove some of those guardrails if you're risk-tolerant enough, whereas the frontier models, the closed models are going to institute some of those things. I know, from our perspective, some of our analysts have had to go back a few versions to be able to do their work in fuzzing and their research because the new guardrails say, "Oh, no. We're not going to let you do that." That might be hacking, and the hacking is bad. So it's kind of interesting. I think the open-weight models will also look away a little bit more when it comes to that.
Morgan Adamski: Yeah. I mean, I think when I think of guardrails, like, guardrails are great because they're supposed to keep you in the lanes of the road. They say, "Don't go here. Don't go there." But you're absolutely right. If they're in place and they're not actually allowing you to do the legitimate work that you're trying to do, they almost become ineffective. I just think of it as being a little -- having a little bit more agility built into the system to allow people to figure out what is left and right. And it's not necessarily just a free flow of things or a free world or what people are trying to determine that are potentially out of scope, but it's just a different type of approach.
Dustin Childs: Yeah.
Johnny Hand: I think that's what's driving so much of the division, right, is the capabilities of the frontier models are really phenomenal, but then they have to be leveraged in a way that makes sense for your -- so they're good on one level and very capable, and they fit a good need. But then when you do need to do defensive and more specific actions, you have to lean on those open-weight because you can't do them with the frontier models. And it's a really hard balance for defenders. But I do like that you called out attention to some of the entry-level folks that are coming in with a bit of experience that a lot of -- just to be transparent -- a lot of, you know, more seasoned security defenders are more risk-averse to. They weren't leaning in in the last, you know, five or six years to a lot of this and -- so it's a good call-out because that is the deskilling of a really, you know, capable force, cyber defense force is happening. And then we need to do an upskilling of those incoming analysts that are coming in to use these technologies in a way that's important. So very good call out.
Morgan Adamski: We both -- all of us know, though, that technology is constantly changing. And so you've got to build a program, a governance structure, a process, an approval process that moves at the speed that technology is changing. And I think that is something that companies really struggle with because, from a risk perspective, they just -- you're trying to accept a technology that you may not fully understand or appreciate, and you're saying, "Yes, I want to give it to you, but I have no idea if I can because I don't know how to integrate into the fabrics, my architecture, my enterprise." And so it, that is the constant battle. It's a good tension, by the way, to have, because you always want to have people ask the right questions to make sure you have the right security controls in place. But if that timeline is too slow, you're almost like -- you're almost way behind everybody else.
Dustin Childs: You're. Yeah. It's paralysis by analysis. Where do you see organizations making the most progress?
Morgan Adamski: I definitely see a lot of organizations. So, by the way, I think about it in two different buckets right now when we talk about AI and cybersecurity. I think about AI-driven security, which is essentially how are cyber defenders leveraging AI from a security perspective. And in that bucket, we see a lot of companies, a lot of CISOs or cyber defense organizations already integrating AI into things like ticket triage, writing signatures, being able to determine anomalous behavior, being able to leverage it in terms of their incident response, being able to quickly determine whether or not the adversary -- it is truly an adversary or not. So already integrating it into essentially their security operations workflows that they're using every single day, which I think is phenomenal. We also see a lot of people in this place looking at it from, like, an exposure management and a patch management perspective. We all know that the patch counts have significantly grown over the last couple months. And so, helping companies prioritize where they should be focusing their patch management based on criticality or active exploitation, or if there's a PoC out there that they need to know about. I think a lot of companies are doing that right now too, which is good, which they're using AI also to determine the visibility of their network. So all good things. So, like, basic cyber foundations that we've talked about for years, using AI to do it better and at scale. I think the other part we see companies investing in, which is what we refer to as AI security or trust AI, is actually how they are securing AI, whether it be things from LLMs to agents to APIs or MCPs, something along those lines. The agent identity security discussion is fascinating, right? For NHIs, for non-human identities, like, how are you going to think about securing that from identity access management program? That's a huge conversation. I'm not entirely sure we have all figured out the solution for that, by the way. I think that's a hard one for aided identity. But when we talk about securing AI, I try to talk about a couple of foundational things with companies that I see them investing in. First, it comes from a data protection, in terms of, do the agents have access? Do you know what data the agents have access to, what they're able to do with it, how, you know, what their privileges are? Is the next one identity access management? Like, do they have the least allowed privileges? Are you able to revoke their privileges, put them on the bench, to make sure that they're not doing things that they shouldn't be doing? The governance piece overarching in terms of the agents. And then, quite honestly, the last piece is recovery. So do you have the ability to contain agents if they are acting out in a way they are not? Do you have ability to revert back to what they did so you can take away and recover what they did that they shouldn't be doing? So a lot of investments in this space, but the agent piece is really what people are trying to wrap their head around.
Dustin Childs: So you just said something that kind of spurred a thought in my mind that I wanted to ask, is, for security leaders who are just beginning this journey, what should they prioritize first, and how should they frame that conversation with the board and the executive team?
Morgan Adamski: I think one of the most important things they do first is better understand their data. And they've got to be able to structure it and ensure they understand, like, it's all uniform and commonplace because data is such a critical component of leveraging AI in an effective manner. And I have found that most companies don't necessarily always have that uniform approach to data structure just because it's multiple years and different types of platforms, different types of technology, which is understandable.
Dustin Childs: Yeah.
Morgan Adamski: Oh, yes. And it resides in different places, right? They don't technically usually always have it in a common place or a common location to be able to make it uniform. So that's the first part of it, is understanding data. For security professionals also, as you can imagine, like, it's still some of the basics of, like, do you understand your architecture and how many technology providers and different types of programs and components and capabilities you have existing within your environment? Tech debt, but also, you know, the Frankenstein problem of, like, of years I've just, like, piled and bolted on anything that I thought that might be helpful for me to be successful. And now I've got all these different types of capabilities, all these different types of technology. We talked about the fact that the data resides in all these different types of programs. And so you got to have a common baseline. And a lot of companies struggle right now because they want to, as I mentioned earlier, let me do one thing. Let me focus on one thing as it relates to AI, trying to make progress. But the problem is, with that approach, if you don't have a larger roadmap and take a step back, all you're doing is building on that Frankenstein architecture you already have. You got to step back and think about what are the various programs that I want to put in place, everywhere from having an agentic SOC to having a robust identity access management program to thinking about how you're approaching zero trust from a network segmentation or micro-segmentation process, because that's a security aspect of it to protect. You know that potential breach is coming, and then how do I recover? And so, like, all of those pieces have to be thought about.
Dustin Childs: You know, I live in a world of vulnerabilities and exploits, and it's funny, people ask me what's changed in the last thing -- over the last 10 years. Like, absolutely nothing. The top exploit, you know, 10 years ago was a stack-based buffer overflow, and the top thing that we see today is, guess what? A stack-based buffer overflow. So it's just AI finding them now instead of HD Moore or some other researcher.
Morgan Adamski: Right.
Dustin Childs: But yeah, so I --
Morgan Adamski: And AI is going to keep getting better, right? We know in previous, like, now people, when we see these cases that adversaries or models, like, leveraging AI, yeah, they're loud, they're noisy. That's how we saw original cyber actors act when they were still trying to figure out their tradecraft. It gets better. It gets refined. They learn over time. That's coming as well, where it's going to be even harder to detect. And so, it's all the same discussion.
Johnny Hand: So, Morgan, I'm curious. Based on -- we've talked a lot -- covered a lot of areas around, you know, AI security and governance and what do these open-weight and these frontier models look like, how organizations are using them. But what's one thing that you want our audience to think about or maybe hear from this conversation that's important for you?
Morgan Adamski: Yes, focus on the basics. Yes, the adversary is getting faster. But there is so much opportunity in this space to really transform your organization and how you're doing cybersecurity that it should excite you what's happening, no matter what headlines you see every single day, because there's just a lot going on, but a lot of opportunity to be successful. So I want people to feel, like, excited about the opportunity versus potentially deflated and a heavy weight on their shoulders because there's just so much to take on.
Dustin Childs: And, Morgan, we always ask our guests one last question. We talked about a lot today. Is there something that we missed? Is there a question that we should have asked you that we didn't?
Morgan Adamski: I wouldn't say it's something that you missed. One area -- there are two areas, actually, that I would emphasize people to continue to talk about and think about in this space. I really always want to drive home the conversation around AI, the vulnerabilities, the concern about patches, the fact that there won't be a patch for everything, but the implications that it has on operational technology, OT. I think the OT conversation is always one that we've -- a lot of us have tried to bring to the forefront to get people to pay attention to, just because of the complexities of it. But how AI is going to be applied and leveraged by cyber defenders on OT, especially when you're talking about patch management on a manufacturing floor, is a really important conversation for us to have because we know that adversaries and nation-state actors target OT.
Johnny Hand: Yeah. No. I love that you bring up OT. It's this problem that we've been trying to solve for many, many years, and it's so different than other industries, right? We just -- the approach to it, the facade of an air-gapped system that's not really air-gapped, the necessity of not, you know, even upgrading or changing out equipment. Like, all of these makes that a very challenging environment. And then you couple that with AI as something that they do not want to talk about in that industry. So I'm curious, are you -- from your perspective and your role, are you seeing an appetite that's changing around the technology that's being supplanted inside OT?
Morgan Adamski: I see a lot of people recognize and confirm the importance of OT and the fact that they need to think about how to leverage AI from a security perspective to help them manage just the vulnerabilities that exist. But to your point, I also still see a huge reluctancy from a lot of these OT owners on -- I just -- I can't go offline. I can't go offline for patch management. I can't go offline for cycles. From a visibility perspective, all of my data actually resides locally. It's not aggregated in any way that would enable you to be able to discover these vulnerabilities at scale or to deploy patches at scale. So I'm not really sure how you want me to solve this problem. So I think if we keep -- I'm hoping that if we keep driving the conversation and making people recognize the significance of this and think about some creative solutions on how we could help them get through it, that we'll see more positive outcomes in the near future. I also really just want to encourage companies that, like, every board conversation, every CISO should be really thinking about how robust is their OT program, especially if it impacts them directly. There's a lot of sectors that it does. And do we have the right level of investment? If we don't, we need to probably expedite that as quickly as possible.
Dustin Childs: Do you think it'll take an incident, like, let's say, a Log4j in the OT world to really get some movement in that area?
Morgan Adamski: Well, I mean, you know, it's always hard, Dustin, being like, I want an incident to get attention, but we are cybersecurity professionals where sometimes we're like, we're going to take advantage of this incident because we need investment. We need people to pay attention and why it matters to them. My only concern with that is that we just saw cyberattacks on water facilities.
Dustin Childs: Yes, we did.
Morgan Adamski: Right? So if that didn't draw enough attention to people, to the fact of, like, this is a target of nation-state actors. Look what occurred. And people are not recognizing that of, like, "Oh, that could be so simple for me to be targeted," that I just -- I'm a little concerned on what we really need. And maybe you do need a big flash-to-bang type scenario, but, like, I hope we don't have to come to that to get the level of attention that's required to be able to fix this. But, you know, I think there's enough of us that care about it.
Dustin Childs: Let's hope not, because boiling water is boring.
Morgan Adamski: Yeah. I, you know, I mean, these are daily lives. It's just like we talk about the -- how important the narrative is for cybersecurity professionals when they're talking to the board. You can't talk to them about the cyber implications and what it means to them. You have to tell them why it impacts their individual businesses and why it's going to overall hurt the company. The same thing applies to OT and some of the things that are public utilities. It's going to impact your daily lives, and here's why you should care. And that's the narrative we need to start really driving home.
Johnny Hand: Great. I'll do a callout because we had a great episode with Jason Cradit, who is a VPN leader. He's been doing OT security for 20-plus years, and it was really, I would say, encouraging because he's tackling this problem head-on. And, you know, he went from an organization that says no to all AI to starting to showcase where AI can win for them. And there is that challenge of the legacy kind of mentality that we can't take these systems down. We can't patch them. We can't drop these things. But I think he's optimistic about the future and wanting to change the perspectives and bring in AI in a way that's meaningful, that can actually help us solve some of these really tough and quite honest old problems in OT.
Dustin Childs: So, Morgan, thanks again for such a great conversation today. We really appreciate you sharing your insights on frontier versus open-weight AI models, and so the problems with AI adoption in IT and OT, and how security leaders should really approach that choice. And I can't wait for you to join us again on a future episode.
Morgan Adamski: Thanks again, Dustin and Johnny. It was great to be here.
Johnny Hand: Dustin, what a great episode with Morgan. Just digging into the need for multiple models and not just digging into one specific model is a big deal. We know that flexibility in the model selection, focusing on different jobs, all of that is critical. But organizations feel like they need to select that one thing that's going to do the job the best for them. So we know that architecture is a big importance. We got to have the right models, and we have to be able to change course as the technology evolves.
Dustin Childs: Yeah. I also liked how she pointed out that, you know, it really only works regardless of model with a true security foundation in place. You have to understand where your data lives and who or what, in this case, can access it. And you need to be sure that you can revoke privileges at a moment's notice, and you can contain or reverse an agent's actions. And it's, you know, really it's the familiar security disciplines that we've been talking about for the last 10 years, and now they just have a little bit of an increased urgency due to AI.
Johnny Hand: Yeah. The other thing is that we're splitting this up when we talk about the distinction between AI-driven security, you know, what's protecting us, and actually securing your AI, because AI-driven security can help teams triage alerts better. They can analyze behavior, helps you prioritize vulnerabilities, and respond faster. But you still have to have compensating controls and security around the models, the agents, the APIs, and those non-human identities. So that governance has to move with you at the speed of your technology rather than just becoming a bottleneck that's slowing everything in the business down.
Dustin Childs: Yeah. I also liked how Morgan was really optimistic about stuff. And not -- this is not a story just about faster adversaries, but about faster defenders. I mean, AI gives the defenders the opportunity to improve the quality, speed, and scale of their work. And that's really necessary in this new world that we live in. I also really liked how she just emphasized on being brilliant at the basics. What worked 10 years ago is what's working today. It's just being done with a little bit more urgency because of AI. And we do encourage you to move with urgency, but there's no one model or tool that's going to solve everything. There is no silver bullet.
Johnny Hand: And that does it for another episode of the AI Security Brief. We want to thank you for joining us, and our goal is always to host conversations that get you thinking differently about security. And if this does, consider subscribing so you don't miss what's next.
Dustin Childs: AI Security Brief is mixed and produced by Elliot Peltzman, with original music by Amneajynx. Our executive producer is Jennifer Eiben, with content strategy by Ma'ayan Plaut and Melanie Gallant. Additional production help by Liz Stokes. Video editing by Sarelle Joppy and Brigitte Criqui Wild.
Johnny Hand: Thank you so much for listening. We'll see you next time on the AI Security Brief. [ Music ]


