Detection at Scale

Cisco Meraki's Stephen Gubenia on How to Crawl-Walk-Run to AI-Powered SecOps


Listen Later

Stephen Gubenia, Head of Detection Engineering for Threat Response for Cisco Meraki, shares his evolution from managing overwhelming alert volumes as a one-person security team to architecting sophisticated automated systems that handle everything from enrichment to containment. 

Stephen discusses the organizational changes needed for successful AI adoption, including top-down buy-in and proper training programs that help team members understand AI as a productivity multiplier rather than a job threat. 

The conversation also explores Stephen’s practical "crawl, walk, run" methodology for responsibly implementing AI agents, the critical importance of maintaining human oversight through auditable workflows, and how security teams can transition from reactive alert management to strategic agent supervision. 

Topics discussed:

  • Evolution from manual security operations to AI-powered agentic workflows that eliminate repetitive tasks and enable strategic focus.
  • Implementation of the "crawl, walk, run" methodology for gradually introducing AI agents with proper human oversight and validation.
  • Building enrichment agents that automatically gather threat intelligence and OSINT data instead of manual investigations.
  • Development of reasoning models that can dynamically triage alerts, run additional queries, and recommend investigation steps.
  • Automated containment workflows that can perform endpoint isolation and other response actions while maintaining appropriate guardrails.
  • Essential foundations including proper logging pipelines, alerting systems, and detection logic required before implementing AI automation.
  • Human-in-the-loop strategies that transition from per-alert review to periodic auditing and agent management oversight.
  • Organizational change management including top-down buy-in, training programs, and addressing fears about AI replacing jobs.
  • Future of detection engineering with AI-assisted rule development, gap analysis, and customized detection libraries.
  • Learning recommendations for cybersecurity professionals to develop AI literacy through reputable sources and consistent daily practice.
  • Listen to more episodes: 

    Apple 

    Spotify 

    YouTube

    Website

    ...more
    View all episodesView all episodes
    Download on the App Store

    Detection at ScaleBy Panther Labs

    • 5
    • 5
    • 5
    • 5
    • 5

    5

    11 ratings


    More shows like Detection at Scale

    View all
    Risky Business by Patrick Gray

    Risky Business

    374 Listeners

    SpyCast by SpyCast

    SpyCast

    1,535 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    653 Listeners

    The Defender's Advantage Podcast by Mandiant

    The Defender's Advantage Podcast

    33 Listeners

    Science Vs by Spotify Studios

    Science Vs

    12,225 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    318 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    8,039 Listeners

    All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

    All-In with Chamath, Jason, Sacks & Friedberg

    9,927 Listeners

    Dwarkesh Podcast by Dwarkesh Patel

    Dwarkesh Podcast

    511 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    138 Listeners

    Cloud Security Podcast by Google by Anton Chuvakin

    Cloud Security Podcast by Google

    40 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    44 Listeners

    The Economics of Everyday Things by Freakonomics Network & Zachary Crockett

    The Economics of Everyday Things

    1,654 Listeners

    Prof G Markets by Vox Media Podcast Network

    Prof G Markets

    1,427 Listeners

    Sources & Methods by NPR

    Sources & Methods

    798 Listeners