Uploaded May 2026 | Updated September 2026, 40 minutes ago
Jonathan Spring (CISA, US)
Several processes around AI systems are new or at least updated. We spend a lot of time talking about what's new, but not a lot of talking about what stays the same. In this talk, Dr. Spring provides a thorough review of all the various vulnerability management norms and processes that actually work pretty well for AI-related cybersecurity vulnerabilities. These items span asset management (such as SBOM), secure software development (such as the SSDF), coordinated vulnerability disclosure (for example CVE-2024-3660), and vulnerability triage systems. There are some practices that are not new to vulnerability management but have new names in AI systems. For example, "download arbitrary code from the internet and execute it" has always been an unpatchable security vulnerability. AI systems just happen to make it extraordinarily easy to configure a system that will download and run arbitrary code from the internet. We will just need to help our AI engineer colleagues manage that risk. The best way we can help our AI colleagues is to be clear about what cybersecurity norms and processes still work and that we expect the AI folks should integrate into, rather than make a parallel process that duplicates existing cybersecurity processes.
---
Dr. Jonathan Spring is a cybersecurity specialist in the Cybersecurity and Infrastructure Security Agency. Working within the Cybersecurity Division’s Vulnerability Management Office, his area of focus includes researching and producing reliable evidence to support effective cybersecurity policies at various levels of vulnerability management, machine learning, and threat intelligence.
Jonathan Spring (CISA, US)
Several processes around AI systems are new or at least updated. We spend a lot of time talking about what's new, but not a lot of talking about what stays the same. In this talk, Dr. Spring provides a thorough review of all the various vulnerability management norms and processes that actually work pretty well for AI-related cybersecurity vulnerabilities. These items span asset management (such as SBOM), secure software development (such as the SSDF), coordinated vulnerability disclosure (for example CVE-2024-3660), and vulnerability triage systems. There are some practices that are not new to vulnerability management but have new names in AI systems. For example, "download arbitrary code from the internet and execute it" has always been an unpatchable security vulnerability. AI systems just happen to make it extraordinarily easy to configure a system that will download and run arbitrary code from the internet. We will just need to help our AI engineer colleagues manage that risk. The best way we can help our AI colleagues is to be clear about what cybersecurity norms and processes still work and that we expect the AI folks should integrate into, rather than make a parallel process that duplicates existing cybersecurity processes.
---
Dr. Jonathan Spring is a cybersecurity specialist in the Cybersecurity and Infrastructure Security Agency. Working within the Cybersecurity Division’s Vulnerability Management Office, his area of focus includes researching and producing reliable evidence to support effective cybersecurity policies at various levels of vulnerability management, machine learning, and threat intelligence.










