|
During the COVID lockdowns, I decided to learn about cybersecurity as a way to fill in the time. I even signed up to sit the notorious 24-hour OSCP exam, although I never actually sat it, as I soon discovered cybersecurity wasn't for me. One thing I did take from the experience, however, was the concept of offensive and defensive security. Offensive (or red team) cybersecurity experts spend their days finding vulnerabilities in systems before hackers can exploit them. Defensive (or blue team) experts monitor for threats and respond when they arise. I was reminded of this recently when a client asked me to review the statistical content of a slide deck he was preparing for a pitch to his own stakeholders. Working through it, I found myself completing both an offensive and a defensive pass. In the offensive pass, I read the slides the way a hostile stakeholder would. Several things stood out immediately - places where my client had been vague about sample size requirements, for instance, that were practically begging for difficult questions. Left unaddressed, those gaps would have undermined his credibility at exactly the wrong moment. In the defensive pass, I looked for issues my client hadn't yet considered. The most significant was this: because the model was predicting rare events, false positives would inevitably outnumber true positives. If that's not flagged upfront, stakeholders will eventually notice, and when they do, the credibility damage is far worse than if you'd simply named it from the start. Both passes are worth doing every time you present analytical work to stakeholders. The offensive pass forces you to find the weaknesses a hostile critic would exploit. The defensive pass forces you to think through the implications of your own work before your stakeholders do. The goal isn't to make your work look perfect. It's to demonstrate that you've thought harder about it than anyone else in the room. Talk again soon, Dr Genevieve Hayes |
Twice weekly, I share proven strategies to help data scientists get noticed, promoted, and valued. No theory — just practical steps to transform your technical expertise into business impact and the freedom to call your own shots.
While visiting my parents recently, I had a conversation with my (non-technical) 80-year-old dad that went something like this: Dad: The problem with AI is that it makes mistakes. If you don’t know if it’s right or wrong, then it’s useless. Me: But you use (OCR tool) Abbyy all the time. That’s AI. Is that useless? Dad: No. Because of Abbyy, I get stuff done in a fraction of the time it would otherwise take me. But I still have to review everything it does because it makes mistakes. What this...
There’s a meme that’s been doing the rounds recently that shows a text message from someone’s significant other, who has noticed a $15k withdrawal from their joint bank account and assumes it’s for an engagement ring. Below that is the punchline - a screenshot of an Anthropic bill for $15k. Some people are now spending so much on AI that their “oh crap” billing moments have become a running joke. But if you think things are bad now, it’s only going to get worse. We are currently living...
I spend a lot of time talking to data professionals about AI, and one thing I’ve noticed is that attitudes typically fall into one of two extremes: AI boom or AI doom. At one extreme are those who are excited about the new opportunities AI will create - the chance to do more interesting work or finally launch the business they’ve always dreamed about. These people are always eager to share what they’ve used AI to create, and the results invariably amaze. But at the other end are those who lie...