Whereas it would appear to be AI is throwing a wrench into cybersecurity methods by rushing up the specter of system vulnerabilities, CISOs are additionally utilizing AI to strengthen their very own safety posture. However with out guardrails in place, the proliferation of AI brokers inside organizations can create complications round identification administration and go away “orphaned” AI brokers with unfettered entry to personal knowledge.
CISOs face a posh identification administration problem involving not simply human customers, but additionally the AI brokers they create and, at instances, go away once they transfer on to different organizations.
“The danger is individuals begin proliferating a variety of [AI agents] across the enterprise, after which they get orphaned, after which they grow to be an assault vector,” mentioned Atticus Tysen, CIO and CISO at Intuit.
Tysen reviewed the 4 areas the place AI is affecting enterprise safety. The primary three are acquainted territory: AI can be utilized to reinforce assaults towards corporations; it creates new assault surfaces as corporations deploy it, and it offers defenders new instruments to counter these threats. The fourth, AI governance, is the place the proliferation of AI brokers creates completely different issues.
“That is much less about controlling using [AI], however extra about ‘how do you allow correct MCP utilization and allow individuals to supply brokers that they share with others?'” Tysen mentioned.
Atticus Tysen, CIO and CISO, Intuit
The rise of AI brokers challenges identification administration
One side of sturdy AI governance is identification administration for AI brokers inside the enterprise.
Whereas an worker might need good intentions in launching a brand new AI agent, unfastened entry controls can shortly grow to be an issue, Tysen mentioned. If “they themselves have overbroad permissions, that then give the agent overbroad permissions, then the agent can then do issues sudden with these permissions. That is not a nasty actor. That is a very good actor simply not realizing the right way to management what they’re constructing,” he mentioned.
Wally Dalyrymple, CISO at tutorial testing corporations ETS and PSI, mentioned one of many greatest dangers from AI is identification administration.
“How are you going to handle machine-to-machine identities if you had been by no means constructed to handle machine-to-machine identities? We weren’t structured that approach. Identification is the brand new perimeter,” he mentioned.
Dalyrymple defined that AI brokers are actually utilizing organizational identities to entry service accounts that are not all the time assigned to an individual. An identification may be assigned to a crew inside the IT or safety division, and “now these service accounts are interacting with brokers, and it is occurring so quick behind the scenes, and at such giant quantity and scale,” he mentioned. An AI agent would possibly use a bunch’s identification to finish a process or share identities with different brokers, for instance.
“Identities get entry to knowledge — it might be PII, healthcare or HR knowledge. What entry does an agent have, and extra importantly, who owns that agent?” he mentioned.
Additional complicating the matter, an worker would possibly go away a corporation after making a dozen brokers, leaving the group to disable each the previous worker’s account and the accounts of each agent that particular person created, Dalyrymple defined. Conventional identification and entry administration instruments do not know the right way to handle AI brokers, he mentioned.
Wally Dalyrymple, CISO, ETS and PSI
Managing agent sprawl
When Dalyrymple and his crew conduct threat assessments for brand spanking new enterprise tasks, a part of that course of entails making a plan to handle agent sprawl.
“We have now to deal with every agent as its personal identification,” Dalyrymple mentioned. This is not a one-and-done course of — his crew regularly checks in with mission groups to see if the mission scope has modified and to evaluate how that may have an effect on the administration of latest brokers.
A method Dalyrymple’s crew manages AI agent identities is with AI agent attestation, a cryptographic technique of proving an agent’s identification, combating drift, controlling autonomy and securing collaboration between brokers.
In response to Raghavaiah Avula, engineering chief and architect at safety firm Palo Alto Networks, AI attestation is a vital course of for validating that AI brokers will be trusted of their present state, as they evolve over time. Attestation assesses “agent identification and position, mannequin and configuration model, integrity of reminiscence and context, belief rating and conduct indicators, and atmosphere and dependency well being,” he mentioned.
Till just lately , the standard definition of cybersecurity resilience was whether or not CISOs might detect a breach and recuperate from it shortly sufficient with out main injury to the group, mentioned Ravi Soin, CIO and CISO at Smartsheet.
“Resilience now has to reply a second query, which isn’t simply can we recuperate, however can we even know what’s leaving or really occurring inside our surroundings proper now, beneath what permissions and why?” Soin mentioned.
Ravi Soin, CIO and CISO, Smartsheet
Smartsheet’s method to the AI agent problem is Good Hub, a central management panel for managing AI instruments, the place “each AI agent within the atmosphere will get configured, owned and monitored … with visibility into each agent in a single place,” he mentioned.
“We’re doing agent identification as a repository inside the company warehouse, the place you’ve a listing of each agent that exists, each MCP that runs inside the firm is recognized, and we now have that topology,” Soin mentioned.
Organizations want to have the ability to reply three major questions on AI brokers: what actions are they taking inside a corporation, throughout which methods, and beneath what circumstances. “If you cannot reply that, you are not resilient,” he mentioned.
How is your group dealing with identification administration of AI brokers? Tell us at [email protected].
