Loading…
ChiBrrCon 2027
Type: Risk clear filter
Friday, October 9
 

1:15pm PDT

Bridging the Gap: Unifying AI Risk Management with NIST CSF 2.0
FILLING
Friday October 9, 2026 1:15pm - 2:00pm PDT
Limited Capacity filling up
We've all seen the explosion of AI, but the security risks often feel abstract and overwhelming. My talk, 'Bridging the Gap: Unifying AI Risk Management with NIST CSF 2.0,' is about cutting through the noise. (and it can be really loud!)  I'll show you how to stop managing AI risk with a patchwork of solutions and start using a cohesive, practical approach. I'll take two powerful tools—NIST's CSF 2.0 and the AI RMF—and provide a clear, actionable blueprint for unifying them.
You'll leave with a simplified, repeatable process for managing AI risk that you can implement in your organization immediately. Forget the theory; this is about actionable strategy and real-world implementation
The Pain & The Promise: The AI Risk Gap: The explosion of AI has created a critical governance problem: security and risk teams are managing highly abstract AI risks—from algorithmic bias to data poisoning—outside the established controls of the enterprise. This disconnect is chaotic, paralyzing innovation and rendering compliance efforts ineffective. This session provides the solution: a practical, repeatable methodology to finally bridge this gap.
The Bridge-Building Process: Establishing the FoundationIntroduction to the core concept of using the CSF as the enterprise container and the AI RMF as the specialist's tool.
The Bridge-Building Process: We establish a unified framework where the NIST CSF 2.0 provides the overarching Cybersecurity Management System (the Outer Frame), and the NIST AI RMF serves as the Specialized AI Risk Engine (the Inner Core). Our approach focuses on developing a Cyber-AI Profile—a focused set of CSF outcomes tailored specifically to your AI systems and MLOps (a set of practices, tools, and collaborative platforms designed to automate and streamline the entire machine learning lifecycle) environment.

The Blueprint ->   The Integration ->  The Workflow
The What!             The So What!          The How! 
The Foundation    The Bridge              The Application

The Blueprint: Mapping the AI Lifecycle , The Integration and  A Simple Workflow: We will detail a clear, actionable workflow, 4 Steps- showing how AI RMF activities map across the six CSF functions:an example of the first 3
  • GOVERN (The Policy Layer): How AI RMF's Govern function defines the AI Risk Appetite and assigns accountability for the model (GV.RM).
  • IDENTIFY (The Assessment Layer): Using AI RMF's Map and Measure functions to perform Threat Modeling and quantify non-cyber risks (like unacceptable bias) for the CSF risk register (ID.RA)
  • PROTECT (The Control Layer): Implementing MLOps controls for Training Data Integrity and securing the model artifact against tampering (PR.DS, PR.PS).


Speakers
avatar for Jeanine Baisi

Jeanine Baisi

Product Security Consultant, Motorola Solutions Inc.
Jeanine Baisi brings over 20 years of experience in cybersecurity standards, frameworks, and cross-technology practices. A veteran of Motorola Solutions (MSI) for the past decade, Jeanine has navigated pivotal roles ranging from Security Field Services to her current position as a... Read More →
Friday October 9, 2026 1:15pm - 2:00pm PDT
⏪️ 3. Despair (Ballroom)

3:15pm PDT

The Risky Business, of AI Illiteracy
FILLING
Friday October 9, 2026 3:15pm - 4:00pm PDT
Limited Capacity filling up
Introduction: Myself and how my experience building vulnerability management programs altered my views on risks.


Seeing the Forest: I discuss the common focuses of security programs, and how headlines can influence reactions and prioritizations. Then introduce some of the largest breaches of the past few years and highlight how AI actually played into those breaches. 


Building Blocks: Before I can get to risk modeling I introduce the tools needed to understand your own risks: inventories, topologies, data flow diagrams, and relationships with the teams that own the above. However this is a ‘trick’ and I reveal that building those blocks causes you to threat model without even realizing it which is why I harp on documenting everything you find throughout building those blocks.


Prioritization: To properly prioritize what risks you accept, first you need to understand the feasibility and likelihood of AI being exploited. As well as what impact its use would have on the business: can revenue still be generated, what services go offline, can an attacker pivot and make things worse, how long would it take to recover, ect. Understanding how your business operates, and what's interconnected is key to building your priorities.


Mitigation: It’s not always possible to eliminate all of your risks which is why we mitigate them as best as we can. I explain how mitigation can come from two forms: making a AI harder to exploit, or decreasing the likelihood of a threat taking place. 


Acceptance: Security staff cannot accept risks, oftentimes executives insist that we do or insist on mitigations that are unsatisfactory to security teams. When executives are presented with a risk acceptance document outlining the potential impacts and potential better mitigations that can be implemented. That way we can CYA.


AI Inventoring: Just inventorying what AI tools you have isn’t enough, they can be used in so many different ways in different configurations, how do you document how they are used while preventing too much disruption and upset from the executive suite?


Wrap up: recap that there are always new threats, vulnerabilities, and AIs that someone might want to onboard, so don’t get derailed from your priorities.
Speakers
avatar for Sean Juroviesky

Sean Juroviesky

Senior Security Engineer, SoundCloud
Sean Juroviesky is a dedicated cybersecurity, risk management, and privacy advocate; speaking on those topics at conferences across the world including DEF CON, CypherCon, CornCon, BSides Rochester, SecretCon, Sec-T, and more. Sean also acts as a cybersecurity architect for a large... Read More →
Friday October 9, 2026 3:15pm - 4:00pm PDT
⏪️ 3. Despair (Ballroom)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.