As enterprises face AI-driven cyberattacks, AI security governance must control autonomous systems that can reach data, connect applications and act on users’ behalf. That makes human accountability a core security requirement.
Traditional controls remain necessary, but security teams must also understand the data flows and processes agents create. People, therefore, need a new role in supervising consequential actions, according to Brennan Baybeck (pictured), senior vice president and chief information security officer of Oracle Customer Success at Oracle Corp.
“Humans have never been more critical to help control these robots, as we call them,” he said. “We used to say humans are the weakest link. But now what I’m saying is that robots are the most powerful and potentially dangerous link, and humans are now an essential link.”
Baybeck talked with theCUBE Research’s Dave Vellante at Oracle’s “AI Cyberattacks Are Escalating: How to Secure Your Data Now” event, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed human oversight of AI agents, AI security governance and the shared responsibility between customers and technology providers. (* Disclosure below.)
AI security governance returns to first principles
That oversight must rest on basic controls, including least privilege, authorization, network segmentation and monitoring. Yet Baybeck sees three recurring gaps as organizations put AI into production.
“There’s definitely some patterns that we’re seeing, and there’s three of them that I want to highlight,” he said. “The first one is a lack of a solid foundational governance program for AI. The second one is not having the security basics in place to start with, especially in their Oracle ecosystems. And then not understanding the shared security responsibility model when it comes to AI services with service providers.”
The shared model assigns security duties to both providers and customers. At the same time, AI can help security teams produce policies, standards and assessment tools faster, Baybeck added.
“Security professionals can leverage AI and actually create a governance program, associated policies, standards, processes and best practices in a matter of hours,” he said. “There is no excuse anymore of why we don’t have a governance program in place at any company because you can literally use AI services to create that and have a very well-thought-out and deployable governance program.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE Research’s coverage of Oracle’s “AI Cyberattacks Are Escalating: How to Secure Your Data Now” event:
(* Disclosure: TheCUBE is a paid media partner for Oracle’s “AI Cyberattacks Are Escalating: How to Secure Your Data Now” event. Neither Oracle, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
