
*Cloud Security Podcast* Features Expert on AI's Impact on Vulnerability Management
The Cloud Security Podcast welcomes Sapna Paul, Senior Director of Vulnerability Management at Day Force, to discuss the impact of AI on vulnerability management. She explains that assets are no longer static (such as servers or containers) but dynamic, like neural network models, requiring a continuous approach of observation, anomaly detection, and retraining rather than one-time patches. Three layers of vulnerabilities are identified: the model (adversarial attacks), data (poisoning, bias), and behavior (technically correct results but ethically problematic). Cited frameworks include the NIST AI Risk Management Framework (AI RML) and the EU AI Act, with tools like Counterfit (Microsoft) or SHAP for explainability. Sapna emphasizes the importance of AI adoption through cloud platforms (AWS Bedrock, Azure AI) and team training, while integrating risk management into business language. The discussion also covers the evolving skill sets required for cybersecurity professionals, combining traditional expertise with an understanding of AI lifecycle management.