Image Credit: Pexels

Three security leaders speak about the overlooked vulnerabilities, such as unmanaged AI, poor cyber hygiene, and lack of defenses, that leave organizations exposed.

As AI changes how employees work, cybersecurity has become increasingly complicated. AI may make some processes more efficient, but it also creates new opportunities for cyberattacks. To respond to the threats, businesses now have more security tool options as well as regulations and compliance requirements. 

A problem, according to experts, is that many organizations struggle with basic cybersecurity problems, and mistakes can be devastating. Several persistent blind spots cause serious issues in cybersecurity. Companies often ignore shadow AI risks, don’t understand their own vulnerabilities, and chase after compliance certificates instead of engaging real protection. 

Effective cybersecurity requires an organization to understand which systems and assets are most important, along with the risks and behavior that can open them to attack. 

Compliance Doesn’t Guarantee Security

When a company’s computer system is in “compliance”, it means it is fulfilling a specific set of regulations or requirements. The system should have cybersecurity to protect it from the possibility or impact of an attack. An organization can meet required standards, but still have weaknesses in its system that cyberattacks can exploit to access its data. 

Netragard was founded in 2006 and focuses on providing offensive security to organizations. Real cybersecurity, according to the company’s founder and CEO, Adriel Desautels, requires more than passing a compliance audit by ticking boxes. 

“Every organization is unique. Every person in an organization is unique. The path to compromise is different. The only way you’re going to build effective defenses is if you first suffer a breach at the hands of real threat actors, and you can do that either by hiring a team like ours, or at the hands of a bad guy,” says Desautels.

Desautels built his company after he witnessed the failure of a cybersecurity system to spot a critical vulnerability he was able to exploit in four minutes. He asserts that “compliance-driven security theater” leaves companies open to attacks that can bypass every certified control. Effective cybersecurity is based on what he calls contextualized threat intelligence. 

“Specifically, how does a threat align with your people, culture, and opportunities to get at your specific data? You take that intelligence to build threat-informed defenses, save money by not wasting it on what doesn’t matter, and build something with a 12,000% ROI if it prevents a single breach,” says Desautels.

Recent cybersecurity discussions have revolved around AI hacking, but Desautels believes this threat is overhyped and that these attacks only succeed against targets with inadequate security. 

“OpenAI’s model generated over 17,000 events to attack Hugging Face. That’s not a crafty attack. That’s not advanced. That’s not even script kiddie level: it’s hyper automation, and it’s super easy to defeat. AI did not do anything novel,” says Desautels.

When an organization is focused heavily on passing audits, security systems end up tailored to satisfying requirements and producing reports. If an organization’s asset doesn’t fit into a compliance checklist, it may be ignored or not receive the attention it needs. 

Many Organizations Don’t Know What They Need To Protect Most

Real-world cybersecurity resilience happens when businesses understand what assets they actually need to protect and the threats against them. Many organizations aren’t even aware of all the assets they own, let alone how to keep them secure. 

“Understanding what you have, scanning for vulnerabilities, patching them: that’s cyber hygiene. It’s not glamorous, but without that foundation, everything else is built on sand,” says Roselle Safran, CEO and founder of KeyCaliber.

KeyCaliber is a cybersecurity company that helps organizations find and prioritize their digital assets, identifying what they call the “crown jewels.” Cybersecurity teams often have to manage a large number of devices, applications, cloud services, employee accounts, databases, and other digital assets. All of them produce a large number of alerts and vulnerabilities, but not all of them carry the same risk. If there is a problem in a minor system, it may be less urgent than a weakness in a critical business asset. 

“We founded KeyCaliber to identify which computer systems in the environment are the most important: the crown jewels. Once you know that, you have your North Star. If there’s a vulnerability on a critical asset, that’s what you jump on, instead of just tackling whatever came in most recently,” says Safran.

A lack of cyber hygiene is a serious issue with many organizations, and they fail to have appropriate protections. They often overlook applying patches and updates and don’t monitor assets for vulnerabilities. These tasks, which form the foundation of cybersecurity, are important even if they seem mundane. 

“Frontier AI models can identify vulnerabilities that have never been seen before — and then form a plan where they daisy chain them together to get in and go further. With agentic AI, you can spin up hundreds of agents doing this simultaneously. It’s a very big concern for the cybersecurity industry,” Safran says.

As employees continue to introduce new AI tools into their work, it is being implemented faster than organizations can create guardrails. 

Shadow AI Is Creating A New Security And Compliance Problem

Shadow AI, which refers to unapproved tools, is a major risk to systems. It’s part of the double-edged sword of AI: it can help automate defense, but it can also open the door to attackers. 

“There’s no product you can buy off the shelf that gives you security or compliance when it comes to AI. Security is not a product; it is not a set of tools; it’s people doing procedures and processes. The companies that have people whose job it is to think about these things are the ones that put these processes in place,” says Amir Tarighat, the co-founder and CEO of the Agency. 

Agency is a cybersecurity company that helps organizations address security and governance challenges that are related to the emergence of AI. Tarighat asserts that AI governance starts with people and processes and that organizations need to implement policies on how AI tools are approved and used. 

“If an employee dumps customer data into a prompt without proper controls, you might be violating the compliance and security obligations you have for your customers: data retention requirements and data training requirements can cause them to fail their audits,” says Tarighat.

Many organizations have a “check-the-box” approach, focusing on passing audits and don’t understand that shadow AI may be used without the organization’s approval or oversight. Sensitive information may be entered by an employee into an external AI platform, such as customer data, confidential business information, and more.  Establishing how AI is being used is essential for business relationships.

“The impetus for taking action is usually a third party: insurance companies, customers, or auditors. ISO 42001, the international AI standard, is already gaining traction. Companies that need to meet those requirements will have to prove how AI is managed inside their organization,” says Tarighat.

Cybersecurity Is More Than Passing An Audit

Compliance has value to a business, but it is not the same as being secure. Ticking the boxes for rules, regulations, and requirements is important, but doesn’t prepare an organization for a cyberattack. Businesses need to stop making fundamental security mistakes and learn about their “crown jewel” assets. By understanding what can go wrong in their system, they can reduce the opportunities for cyberattacks.