Trending Topics

Merlin Gillespie, CTO at Cybanetix: “AI tools represent the fastest growing, least-protected entry point in the enterprise”
Artificial Intelligence (AI) tools such as copilot, coding agents, and LLM-powered workflows are now intrinsically embedded across every business function, promising efficiency and productivity gains. But they also significantly elevate risk levels as well as introducing new threats, one notable example being indirect prompt injection where missives to the LLM are hidden in documents and files. It’s a whole new paradigm and one which CISOs are having to adapt to.
As far as Merlin Gillespie, CTO at Cybanetix, is concerned, we are fast reaching crisis point as the technology outstrips the capabilities of the organisation and its leaders. With more than twenty years’ experience of scaling and securing dynamic infrastructures in high pressure environments at the likes of Sky and Capita, he is familiar with the pressures large companies experience when they attempt to innovate at speed.
In this exclusive interview, Merlin reflects on the state of AI security today, where gaps are emerging, and how CISOs can equip themselves to move with the times without becoming encumbered by an armoury of AI solutions.
CISOs are struggling to keep pace as AI innovation cycles shorten. Where have you seen the knowledge gaps appearing?
Adoption has been so rapid that many CISOs cannot answer some fundamental questions about their AI estate right now, such as how many AI agents are running in their environment and what data they have access to. They’ve been firefighting on multiple fronts while at the same time trying to keep up to speed with developments. We’ve spoken to business leaders who have no idea what Model Context Protocol (MCP) is, for example, even though the open standard form of communication which allows AI to easily connect to tools, databases and file systems has transformed AI infrastructure over the past year.
Now they’re having to get to grips with the autonomous nature of agentic AI which can carry out tasks without a human-in-the-loop, so the speed of change in AI is undoubtedly a problem. That’s backed up by the AI Safety Institute (AISI), which has been tracking AI development since 2023, and recently stated that frontier model capabilities are doubling every four months, down from eight previously, so the evolutionary timeframe has effectively doubled.
You’ve described three AI domains in the enterprise. What do those look like and how do they elevate risk?
The first is the user behaviour. This can see individual employees upload sensitive data into public large language models (LLMs) which can largely be controlled through Data Loss Prevention (DLP). However, users can also choose to use unsanctioned models resulting in Shadow AI and that creates an invisible layer that the business can’t then monitor and secure.
The second domain is governance and under that umbrella comes model provenance, the AI bill of materials (AI-BOM) and ownership of AI assets across the business. All those elements then determine the AI posture of the business and its cyber maturity.
The third is embedded AI, where agents and tools are wired into business processes, which can often lead to excessive privileges being assigned to agents, particularly if they are allowed to act as individuals, and no clear inventory.
Are security vendors also falling behind the curve in providing solutions to address these risks?
Vendors are reacting to combat these risks and there are some trail blazing technologies out there. But each domain has different controls, vendors and specialists serving that space. That then compels the organisation to buy numerous point solutions which inevitably creates gaps in the security posture. So it’s not that the market is slow or that the solutions to these problems aren’t available; it’s that the market is fragmented and CISOs are left wondering where to turn. The last thing they want is to add to the complexity by creating a bloated AI stack. And then there’s the issue of futureproofing. AI is moving so fast that there’s a danger that the CISO could get saddled with solutions are rapidly outpaced by developments, so investing in that technology is in itself a risk.
How can CISOs tip the balance and regain control over their AI infrastructure?
They need to obtain a 360-degree view of the AI security ecosystem that includes observability and exposure mapping, behavioural monitoring of AI activity across the estate, runtime protection at both the infrastructure and application layers, and synthetic and adversarial testing of the models themselves.
That can be achieved by harnessing together best-of-breed technology solutions with a strategic approach. Technically, the business needs to apply user-level controls, AI discovery, access control, red teaming, and detection and response, as well as agent behaviour analytics to monitor AI behaviour. But to get the most out of those, you need to be able to devise an AI security policy and strategy, plan deployment and integration, and analyse the security posture in order to harden systems. Plus you need to be able use that telemetry, so require AI observability and real-time threat detection for AI specific risks such as prompt abuse, model manipulation or anomalous AI behaviour.
By combining technical solutions, strategic implementation and threat detection and response, it becomes possible to build a capability that can map to established standards such as ISO 42001, the EU AI Act, and the NIST AI RMF.
What elements should they be looking to address when constructing a credible AI security programme?
There are six key areas. To begin with, they’ll need to conduct an AI risk assessment. That will entail discovering and building an inventory of every AI component in use, mapping agent-to-agent relationships and constructing a visual agentic risk map detailing the blast radius of each integration. That then allows the business to identify and address control gaps. Technological solutions can then be stood up to triage and prioritise risks and to enforce policies such as across no/low-code and custom-built AI environments to protect internally developed AI and safeguard training data from misuse or compromise. Those in turn should be integrated with the Security Operations Centre (SOC) and Continuous Exposure Management (CEM) dashboards.
In the SOC, that security telemetry can be combined with other threat intel such as from identity and Endpoint Detection and Response (EDR) solutions to gain a full understanding of the threat and assist with escalation. Automatic containment options from blocking to intercepting traffic or notifications sent to the end customer can then be applied, with the option for human-led response when needed.
These elements then facilitate continuous AI risk reporting, with risks and exposures used to track AI posture improvements and assess and demonstrate AI usage against security, compliance and governance requirements. Finally, rigorous tests then ensure the AI security programme is functioning effectively by carrying out real-time detection of prompt injection, anomalous behaviours and data exfiltration as well as AI red teaming to continuously surface exploitable weaknesses.
Are you advocating that CISOs adopt a managed service and if so, what are the advantages of taking that approach over a build-your-own security solution for AI?
To me it seems obvious that investing in a series of dedicated point solutions not to mention inhouse AI-specialist personnel is both costly and risky. In contrast, a managed AI service reduces exposure through the continuous discovery and control of AI tools, agents and models. They gain operational assurance through expert-led oversight and response and can achieve faster detection and response through integrated workflows and automation. But, crucially, they’re also not tied in to those vendors, so their security posture can evolve as new AI capabilities, models and attack techniques emerge. It’s a no-brainer.
If you could give one piece of advice to CISOs and IT leaders with respect to securing AI, what would it be?
Concentrate on establishing AI observability and runtime protection irrespective of the path you choose to secure your AI. Implemented well, that’s all you need to safely enable AI adoption, prevent data exposure, protect AI development internally, enforce policy, and deal with AI-specific threats.
