In the space of three sentences, Nicole Carignan, SVP Security and AI Strategy at Darktrace, manages to sum up a huge part of the problem – and opportunity – facing CISOs. “Boards and executive teams are under pressure to adopt AI because it promises productivity, speed and growth,” she told us.
“But the same tools also create new risks around data exposure, shadow AI, agentic systems and regulatory compliance. Also, AI poses the worst insider threat risk to date as well as an expanded attack surface where adversaries can attempt to attack, manipulate and use in order to proceed with their attack.”
She goes on to explain that teams are left confused about what tools they should be using, and we should at this point say that Darktrace has skin in this game. This British company, with an HQ in Cambridge, describes itself as “a global leader in cybersecurity AI, delivering the essential cybersecurity platform to protect organizations today and for an ever-changing future”.
Why listen to what Nicole has to say? We could point to many reasons, but one is that her adult life has been steeped in AI – starting with her time at Texas A&M University, where she set “up a maps application using graph theory in order to facilitate the best navigation”.
Since then, Nicole has spent 20 years working in the US federal government with a focus on cyber threat intelligence, data science, machine learning and network security. Now, Nicole advises Darktrace customers on the ever-evolving threat from AI, including how to respond.
Read on to discover what that advice involves…
Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?
Iโm Nicole Carignan, SVP Security & AI Strategy at Darktrace, and I work with customers on how AI is changing the threat landscape and how organisations should respond. A lot of my work sits at the intersection of cybersecurity, artificial intelligence and business risk. That means helping security leaders understand not just what attackers are doing with AI, but also how the use of AI inside their own organisations is changing what they need to defend.
I have spent around 25 years working across cybersecurity, networks, computer science and AI, including 20 years with the US federal government. My background covers cyber threat intelligence, data science, machine learning, artificial intelligence, network security, operations engineering and defence-in-depth approaches.
I came into cybersecurity through the technical side, but what has kept me in the field is the fact that it never stands still. Every major technology shift changes the problem. Cloud changed it. Remote work changed it. Now AI is changing it again, and in a much deeper way because it affects both sides of the equation. Attackers can use AI to move faster and scale their work, while defenders can use it to detect threats, understand behaviour and respond more quickly.
That is why this moment is so important. AI is not just another tool in the security stack. It is becoming part of how businesses operate. That means security teams need to understand and secure AI itself, not just use AI to defend everything else.
What are the biggest cybersecurity challenges those in leadership roles are facing?
The hardest challenge for leaders is that cyber risk is now moving faster than governance. That is especially clear with AI. Boards and executive teams are under pressure to adopt AI because it promises productivity, speed and growth. But the same tools also create new risks around data exposure, shadow AI, agentic systems and regulatory compliance. Also, AI poses the worst insider threat risk to date as well as an expanded attack surface where adversaries can attempt to attack, manipulate and use in order to proceed with their attack.
Most leaders are still struggling to answer basic questions. Which AI tools are being used? Who is using them? What data is being uploaded? Which agents have access to which systems? Are those agents acting within their intended purpose? If you cannot answer those questions, you cannot manage the risk.
Employees are typically just trying to move faster, with AI tools helping them summarise a document, write code or automate a task. If that tool is unsanctioned, unmonitored, ungoverned or connected to sensitive data, however, the organisation may have created a substantial risk without knowing it.
The rapid adoption of agentic AI makes this more serious. These systems can access data, trigger workflows and act on behalf of people. In practice, they can look operationally like digital employees, but without human judgement, ethics or accountability.
Leaders need to quickly understand how they can adopt AI technology safely, without stifling it. That means visibility, clear ownership, strong governance and the ability to intervene when behaviour moves outside what is normal or acceptable.
In order to mitigate the risk of AI adoption, defense in depth is required to include finite identity access management, strong controls, and monitoring, behavior analytics, anomaly detection, risk and intent evaluation of anomalies, autonomous investigation and autonomous containment. Layered security with advanced detection and response is crucial to securing non-deterministic AI systems.
What is your take on ethical hackers and their role in cybersecurity?
Ethical hackers help organisations see themselves through an attackerโs eyes, a perspective that is hard to create from inside the business. Security teams are often busy managing alerts, supporting users, handling incidents and keeping systems running. A good ethical hacker can step back and ask: if I wanted to break this, where would I start?
Their role is becoming even more important as AI becomes embedded in the enterprise. Traditional penetration testing focused on networks, applications and infrastructure. Now we also need to test AI systems, prompts, every AI interface/connector/protocol, agent permissions, model/agent behaviour, data flows and the ways attackers might manipulate autonomous systems.
At the same time, AI is changing the speed at which vulnerabilities can be discovered and exploited. Models like Claude Mythos demonstrate how AI can rapidly identify weaknesses in software and systems. That capability can strengthen defensive research and testing, but it can also accelerate attackersโ ability to find exploitable gaps. The result is that the window between vulnerability discovery and exploitation is becoming much shorter.
So ethical hacking cannot be treated as a once-a-year exercise. It needs to be part of a wider security model that includes continuous testing, evaluation, validation and verification as well as fast remediation and real-time detection of abnormal behaviour. Finding the weakness matters. But organisations also need to know what happens if the weakness is exploited before the vulnerability is disclosed and a patch is available.
The best ethical hackers are not just technically strong. They are good communicators. They can explain all the different attack vectors an organization needs to defend against to a developer, a CISO or a legal team. And they can help the business prioritise what security and risk mitigation efforts.
AI will make their work more powerful, but it also raises the bar. In an AI-shaped threat environment, the goal is not just to find flaws. It is to help organisations become resilient when attackers find them first. But, also to help organizations defend against social engineering, identity compromise, adversarial machine learning (attacking AI systems themselves), insider threat, as well as misuse, abuse and risky drift of AI systems.
What are some prevention strategies you believe every business should adopt?
Every business should start with the fundamentals, but they need to be treated as ongoing disciplines, not one-off projects. Multi-factor authentication, least privilege, threat vulnerability management, tested backups, network segmentation, secure-by-design, governance, advanced detection and response, and strong email security still matter. These principles detect an event early, stop the spread, mitigate the risk and damage of an incident.
The problem is that environments do not stay still. Employees change roles, cloud services expand, SaaS tools are added, new suppliers are connected, AI assistants and agents are introduced. So prevention and building a resilient program needs to be continuous. What was secure six months ago may not be secure today.
I would put identity at the centre of prevention. Attackers increasingly want valid access. If they can use a real account, a legitimate tool or an over-permissioned system, their activity is much harder to spot. Businesses need to understand who and what has access to sensitive data. That now includes non-human identities such as service accounts, APIs and AI agents.
AI governance is the place where strategies are least developed today. For those, security teams should start with a few practical questions. Can we see what AI is being asked, told and allowed to do? Which agents are acting inside the business, what can they access, and can we trust what they are doing? What agents are teams building, and where are the risks being introduced before they go live? And where is unapproved AI hiding? Those questions matter because a prompt can now trigger an action, an agent can be over-permissioned, and an employee can move sensitive data into an unapproved tool without meaning to create risk.
Finally, organisations should rehearse. Run tabletop exercises for ransomware, deepfake fraud, AI data leakage and agent misuse. Prevention is not only about stopping every attack. It is about reducing risk early and making sure that, when something does go wrong, the business can respond quickly and clearly.
What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good (in cybersecurity)?
Generative AI is powerful because it works through natural language. That is also what makes it vulnerable. People can ask it to summarise, reason, code, plan and act. But attackers can also try to manipulate those same interactions.
The natural language interface is why adoption scaled so quickly because it democratized access to powerful language models without subject matter expertise.
The natural language interface also makes it very difficult to secure. Many organizations are attempting to secure this with static filters, but behavioral semantic analysis to understand intent, risk and context is the only way to secure such an open-ended interface. This open-ended interface is why threat actors have been able to jailbreak, poison, and facilitate access to sensitive data.
Also, in an agentic environment, the risk is heightened, as a prompt becomes an instruction that triggers action. It may cause an AI assistant to retrieve a document, call a tool, update a record, create code, summarise customer data or start a workflow. If that instruction is careless, hidden or malicious, the risk moves to a real business impact.
Generative AI also changes the speed of attack. Models like Claude Mythos show how AI can rapidly identify weaknesses in software and systems. That capability can help defenders test and strengthen their environments, as we’re seeing, but it can also help attackers find exploitable gaps much faster. The result is that organisations have to assume their software is vulnerable. In assuming compromise, this highlights the need for visibility, monitoring, behavior analytics and autonomous investigation and containment in order to detect and contain adversaries within an enterprise.
But AI is also one of the strongest tools defenders have. Generative AI can help security teams investigate incidents faster by being used to aggregate intelligence across products, summarise activity and reduce manual workload. But, Generative AI is only one type of model, probabilistic model of natural language. This should not be the only AI that is adopted by security operations. Behavioural AI sits alongside it focusing on understanding what is normal across users, systems, devices and AI agents, then identifying subtle changes that may indicate compromise and autonomously stopping threats. Together they put defenders onto a whole new, more proactive footing.
As generative AI becomes more agentic across the enterprise, that behavioural approach becomes increasingly important. Organisations are introducing systems that can access data, interact with tools and take action with limited human oversight. In that environment, security teams cannot rely only on known indicators or static rules. They need to understand what normal behaviour looks like across users, systems and AI agents, then identify when something begins to act outside its expected purpose. Used well, defensive AI helps humans keep pace with this changing environment. This was recently highlighted in the guidance from UK/US/CA/AU/NZ governments in order to carefully adopt AI.
Which cybersecurity best practices are being adopted with the most success by companies?
First, organizations that are investing in security while they are investing in AI adoption or innovation will be most successful. Introducing this amount of risk without a plan to mitigate that risk over time will leave an organization quite exposed.
Next, the companies doing this best are the ones that have stopped treating security as a list of isolated controls. Those controls still matter, of course. Strong authentication, privilege management, backups, patching and incident response planning are all essential. But they only get you so far if you cannot understand what is actually happening across the business.
One of the biggest shifts is that modern attacks often do not look obviously malicious at first. An attacker might use a real account. They might move through a legitimate tool. An AI agent might access data it is technically allowed to access, but in a way that does not fit its role. A user might paste sensitive information into an AI tool because they are trying to work faster, not because they mean to create risk. These trends make understanding what’s happening with your business, not just at the perimeter, an increasingly vital task.
In this context, behavioural AI has become the most effective foundation for security strategies. It gives security teams a way to understand normal patterns across users, systems, devices, data and AI agents, then spot when something starts to drift, which it will inevitably do.
I think that is where the best companies are heading. They are not just adding more tools or more alerts. They are implementing autonomous containment and trying to give analysts better context intelligence so they can act earlier and with more confidence.
The same applies to AI governance. The answer is not to ban AI. The answer is to see where it is being used, understand what it can access, set and enforce security policies, and control risky behaviour without slowing the business down unnecessarily.
Whatโs something that has drastically changed about cybersecurity since you first got started in the field?
The biggest change is that cybersecurity used to be defending a finite environment that was on-premise and completely controlled by the organization.
That world has gone. Businesses now run across cloud, SaaS platforms, remote work, suppliers, personal devices, networks, data centers, email, messaging and collaboration tools, APIs and AI systems. There is no clean edge anymore. The attack surface is spread across the whole business.
More importantly, many attacks no longer look like attacks at first. The security industryโs dependance on cyber threat intelligence of previously reported attacks is becoming antiquated. With threat actors having access to AI or frontier models, they are able to cater their attacks, use different ingress vectors, manipulate trusted tooling or adopted AI to evade traditional security detections. Attacks will increasingly seem novel. They can look like a real user logging in, a normal tool being used, a file being shared, or a workflow being triggered. With AI agents, that becomes even more complex. An agent may access data it is technically allowed to access, but in a way that does not fit its role or purpose.
This means organizations need to change their security detections and workflows to be behavioral-intelligence centric. Also, autonomous containment at machine speed becomes vital to defend, mitigate risk and reduce damage.
It is not enough to know whether an action is allowed. You need to know whether it makes sense. Is this normal for this user? Is this normal for this system? Is this agent acting within its expected boundaries? Are a series of ordinary-looking actions becoming risky when viewed together? What is the risk associated with this action? And, with that context and risk understanding, taking containment actions autonomously.
For me, that is the defining change. Security is no longer just about blocking known bad things. It is about understanding how the business normally behaves, then spotting when something begins to drift. That is why Behavioural AI has become so important. It gives defenders the context they need in environments that are too complex and too fast-moving for static rules alone.
Also from our Interviews section