Machine learning has become indispensable in modern cybersecurity, but knowledge of how to build security machine learning systems that go beyond proof-of-concept is not widely available. In this talk, I’ll break the ice on discussing best practices for bringing machine learning into the domain of actual security practice, discussing how to research, develop, build, deploy, and operate security machine learning systems effectively in real-world environments. Based on seven years of experience deploying machine learning systems to hundreds of thousands of organizations, the talk will start with a discussion of what capabilities machine learning affords and where machine learning can help within cybersecurity ecosystems. I’ll then discuss a representative set of real-world machine learning operationalization case studies, including alert prioritization, mobile malware detection, malicious web content detection, and phishing detection. In each example, I will go beyond simple proofs of concept to describe a fully fleshed out and deployable system in which machine learning co-exists within a larger ecosystem of allowlists, blocklists, and signatures. Finally, I’ll give pointers to how you can learn more, and references to papers my colleagues and I have authored describing the machine learning models covered in the talk.