What Security Programs Need Before Deploying AI?

Category :

AI

Posted On :

Share This :

Enterprise CISOs are under pressure to buy AI-powered security technologies, but it can be hard to tell which tools will reduce risk and which will increase costs because vendors increasingly market their products as AI. Additionally, AI can worsen holes in network visibility, poorly classified data, and lax access controls.

 

While 87% of CEOs believe AI-related vulnerabilities are the fastest-growing cyber risk, the World Economic Forum found that almost one-third of firms lack a process to evaluate the security of AI technologies before adopting them.

 

According to the National Institute of Standards and Technology (NIST), depending on the data and systems they may access, third-party generative AI technologies may pose privacy and information-security vulnerabilities. According to a Cloud Security Alliance (CSA) report, 47% of firms had a security issue involving an AI agent in the previous year, and 53% of enterprises had AI agents exceed their authorized rights.

 

56% of digital trust experts, according to ISACA, are unsure of how fast they could stop an AI system during a security crisis.

 

These results imply that many security leaders are using AI more quickly than they are able to assess what they are purchasing or manage its access.

 

On the AI in Business podcast, Yolandi de Weerdt spoke with Mark Alvarado, CISO at Academy Sports + Outdoors, about how security leaders can distinguish true AI value from vendor claims and how AI can exacerbate pre-existing flaws in identity management, data governance, network security, and employee technology practices.

 

To help leaders determine where AI fits into a security program, this paper looks at three insights:

  • Determine the issue, potential fixes, and actual cost of ownership before allowing an AI tool access to company identities, data, or systems to prevent needless AI exposure.

 

  • Identity, information, and network visibility as the cornerstones of deployment: To help teams limit exposure and maintain the capacity to intervene, map the accounts, data, permissions, and connections involved in each use case.

 

  • Reaction thresholds associated with significant business risk: Before enabling AI-assisted detection to initiate operational action, determine which behavioral deviations need to be reviewed or immediately contained.
    The entire episode can be heard below:

 

Mark Alvarado, CISO at Academy Sports + Outdoors, is the guest.

Expertise: Identity and Access Management, IT Compliance, Enterprise Risk Management, and Cybersecurity Strategy.

 

Brief Recognition: As the Executive Director of IT Security & Compliance at Academy Sports + Outdoors, Mark Alvarado has developed and overseen the organization’s security program, enhancing its capacity to identify and safeguard commercial data. Having held security positions at Ovintiv and Norton Rose Fulbright, he has over 20 years of experience in cybersecurity, risk, and compliance. He created an incident response structure at Academy Sports + Outdoors that helped the company’s cyber program grow and cut recovery times by 90%. Alvarado has an M.S. in Cybersecurity and Information Assurance from Western Governors University and a Master of Legal Studies in Cyber Law from Texas A&M University School of Law.

 

Evaluation Based On Problems To Avoid Needless Exposure To AI

Although a vendor may assert that their product employs artificial intelligence (AI) to detect vulnerabilities more quickly, this does not prove that the product is appropriate for a certain security context. According to Mark Alvarado, buyers have a deeper understanding of a company’s systems and operational procedures than vendors have. It is the buyer’s job to comprehend its own needs and make the appropriate inquiries.

 

Alvarado’s training in business analysis is the source of this discipline. Before investigating solutions and gaining support from stakeholders, he described the existing workflow, the intended state, and the technical requirements when a department asked for a solution.

 

When it comes to security investments, he follows the same process: start with a written problem statement, determine potential solutions and their actual cost of ownership, and utilize that work as the foundation for a project charter. Alvarado claims that this effort either convinces him of a solution or dissuades him from asking for funding, regardless of whether AI is involved.

 

Additionally, both buyers and sellers may use the phrase to indicate multiple roles; Alvarado advises creating a common definition of “AI” during purchase conversations. Both parties should clarify their meanings before a discussion becomes technical, financial, or legal.

 

An additional readiness test is created by employee behavior. Alvarado suggests an AI governance tool that provides workers with precise instructions on when and how to use AI, as well as questions to ask before doing so:

 

What they hope to do with it, what will happen to the data, whether the connection is one-way or two-way, and whether the tool is open or closed?

He cautions that without employee support, people will figure out how to get around the controls.

 

“Your home can have the strongest locks. However, it doesn’t matter how pricey the lock is if someone in your home just leaves it open, gets around it, or jimmies it. Someone will enter.

— Academy Sports + Outdoors’ CISO, Mark Alvarado

 

Network Visibility, Data, And Identity As Deployment Pillars

According to Alvarado, AI “has only made your program exponentially worse” if a security program wasn’t already “buttoned up.” He starts by figuring out how the business is organized, where its important data is located, and where the edge actually is. From there, he works backward.

 

Based on it, he determines which three foundations should come first before implementing AI. These programs don’t have to be perfect at the start. He claims that getting them “buttoned up really tight” is a trip with its own expenses. Before an AI system goes live, a team should be able to respond to the following questions from each foundation:

 

  • Identity: what or who will take action? Without a user ID, nothing can communicate with another system, and AI frequently utilizes a particular identity to accomplish this. Teams must be able to swiftly disable the user ID and identify whose account it uses.

 

  • Data: What information is involved? Knowing where data is located and how it is classified helps a team decide whether to stand down or escalate because critical data might land a company in hot water with authorities while generic data might not.

 

  • Where may data go in a network? Teams must monitor data while it’s in transit, check it for malicious payloads, and terminate the connection as soon as feasible if something goes wrong.
    Alvarado does not wish to downplay the importance of the other cybersecurity domains. However, he believes that these three areas will be crucial to AI and the basis for businesses to “fight AI with AI” as more businesses go to the cloud and attacks become more frequent and sophisticated. He claims that teams utilizing AI-based tools have a chance once such issues are resolved.

 

Reaction Thresholds Associated With Significant Business Risk

Alvarado believes that utilizing AI to examine massive amounts of activity for deviations from predefined patterns is beneficial as identity, data, and network activity are all accessible. He likens credentials to the keys, the network to a road, a gadget to a car, and an identity to its driver. Unexpected changes to the device, route, destination, or data accessed could be a sign that the account is not being used by the authorized user.

 

The system may assess an identity’s typical activities and highlight variations for evaluation because most people are creatures of habit. Since business needs change, a departure does not necessarily indicate nefarious action.

 

Alvarado makes a distinction between removing the “keys” by disabling an identity or cutting off a network connection and requiring a user to verify anomalous conduct. He takes action before conducting an investigation when a trend is so unusual, or an action is so heinous, that the organization cannot afford to make a mistake. He bases his choice on what a CISO is truly in charge of:

 

Essentially, your role as a CISO is not to prevent every minor incident. You can, which is fantastic. There is a price for it. It is your responsibility to prevent the occurrence from becoming significant. Every business has a different material threshold, and each one should establish its own. Because your program will cost money, that’s how you make sure you’re using it wisely.

— Academy Sports + Outdoor’s CISO, Mark Alvarado

 

He continues by saying that each firm should establish its own materiality criterion because it varies from company to company.

 

Since a false positive might disrupt real work, Alvarado recognizes the cost of responding before an inquiry is finished. In his experience, nobody is upset about erring on the cautious side, so if that occurs, the car returns to the road. He claims that although AI-based tools are slightly more expensive, once the three foundations are established, the expense is justified.

 

These ideas work together to support Alvarado’s main point, which is to begin with a well-defined business challenge and then provide the controls necessary to transform an AI-generated signal into a security choice that can be justified.