Engineer who helps clients scope, source and vet solutions in #CloudAI, #AIOps, #AISecurity|Tech Analyst| Podcast: bit.ly/4meRcDR

Cape Coral, FL
📌 Q: What are the levels of human involvement in AI automation? A: There are 3 levels of Human Involvement in AI automation: 🤖 Human-in-the-Loop: Humans directly review, correct, or approve every major decision before it takes effect. 🤖 Human-on-the-Loop: The AI runs autonomously, but humans supervise the broader process and hold veto power to override or stop issues. 🤖 Human-out-of-the-Loop: Full, unmonitored automation reserved exclusively for low-risk, routine scenarios. #AISecurity #CIO #CISO
1
7
533
📌 Q: How does AI automation work? A: AI automation works by combining traditional software triggers and workflows with artificial intelligence, allowing systems to process unstructured data, make contextual decisions, and take autonomous actions v/ @salesforce #AISecurity #CIO #CISO
1
2
17
3,264
📌 Your AI Agent Just Found Everything You Forgot to Secure We keep talking about AI risk as though the dangerous part is coming next. I’m not sure it is. The bigger problem may be what AI is about to discover inside enterprises that were never as clean, governed or locked down as we liked to believe. Old SharePoint sites. Forgotten PDFs. Contracts. PowerPoints. Years of accumulated permissions. Data that was technically accessible but practically buried. Then we gave AI the ability to find it. That was one of the things that stuck with me after my latest ClearTech Loop conversation with Joe McKendrick, longtime Forbes contributor, analyst and technology researcher. Joe has spent decades watching technology move from interesting to operational. And when it comes to agentic AI, he thinks business leaders are still underestimating what they are introducing into their organizations. ⭐ Listen to the full episode: buzzsprout.com/2248577/episo… ⭐ Stay in the Loop. Subscribe for new episodes: linkedin.com/newsletters/734… ⭐ Watch ClearTech Research on YouTube: piped.video/@ClearTechResear… #AISecurity #CIO #CISO
1
6
12
415
📌Q: What is a confused deputy in AI? A: A confused deputy in AI is a trusted, privileged AI agent or tool that is tricked by untrusted input or a lower-privileged user into misusing its authority to perform an unauthorized action. How It Works * The Deputy: An AI agent equipped with powerful credentials, API keys, or tool access (such as reading customer records, sending emails, or modifying files) provided by an administrator. * The Confusion: Natural language interfaces process data (like an incoming email, a retrieved webpage, or a file) and instructions through the exact same pathway. * The Exploit: A malicious prompt hidden inside external content tricks the AI into combining its authorized tools in an unintended way—such as reading private user data and exfiltrating it to an external email—acting faithfully on behalf of the wrong instruction. v/ @cloudsa #AISecurity #CIO #CISO
12
17
673
📌 Q: How does corporate data “escape” into an LLM? A: Corporate data “escapes” through Data Leakage. This occurs when sensitive corporate information or intellectual property (IP) is inadvertently exposed via interactions with the LLM.Training Data Ingestion: When employees paste proprietary code, financial strategies, or legal documents into public chatbots, that data is often logged by the provider. If used to retrain future iterations of the model without proper anonymization, the LLM may later regenerate that exact proprietary data to an entirely different user (known as an output-based data leak). Ecosystem & Third-Party Logging: Data isn't just processed; it is routed. Hosting services, API endpoints, or cloud providers can log queries for debugging or monitoring. If these systems suffer from security misconfigurations or insider threats, malicious actors can scrape the logs for proprietary information. #AISecurity #CIO #CISO
1
6
17
1,225
📌 Did you miss the @cloudsa 's AI Bytes BrightTalk yesterday? Take a listen to Lori MacVittie and Timothy Youngblood, CISSP take on MCP in our MCP Goes Mainstream—Is it a Prime Attack Target? conversation Model Context Protocol (MCP) servers standardize how AI models interact with external data and tools, acting as a secure intermediary through discovery, tool invocation, and resource management. Key security elements focus on authenticated, least-privilege access using short-lived tokens, rigorous input/output validation, and network isolation. In this session we’ll focus on key elements of MCP Security - Authentication & Authorization - Least Privilege Access - Input and Output Validation - Secure Token Management - Network and Server Isolation - Audit Logging and Monitoring - User Consent and Control Psst…Don’t miss Tim Youngblood talking about Flaming Apples! 🍎 👉 Listen here: brighttalk.com/webcast/16947… 🛎️ Subscribe to the series: campaign-api.brighttalk.com/… #AISecurity #Cybersecurity #CIO #CISO
2
3
11
458
📌 Louis Columbus on why enterprise AI governance is falling behind the agents it is supposed to control. Every board loves a committee. A committee means somebody is watching. There is a charter. There are meetings. There is probably a very nice deck explaining responsible AI. Meanwhile, the AI agents are already running. That was the tension running through my conversation with Louis Columbus, senior cybersecurity contributor at VentureBeat. We talked about agentic identity, least privilege, shadow AI and what actually happens when AI governance moves from a policy discussion to a production environment. And Louis kept coming back to a pretty uncomfortable point: Governance that cannot enforce anything isn’t really governance. As Louis put it, “Governance really exists on paper, but it doesn’t enforce at runtime.” That distinction is about to matter a lot. Listen to the full episode: buzzsprout.com/2248577/episo… Stay in the Loop. Subscribe for new episodes: linkedin.com/newsletters/734… Watch ClearTech Research on YouTube: piped.video/@ClearTechResear… cc: ClearTech Research #AISecurity #CIO #CISO
5
9
15
490
📌 Q: How do you restrict the use of AI at the enterprise level? A: You restrict enterprise users with AI by enforcing runtime policies, data loss prevention rules, and identity-based access controls through security platforms like Microsoft Entra or corporate proxies Control AI Usage. v/ @zscaler #AISecurity #CIO #CISO
1
3
19
599
📌 Q: Does AI trigger impatience in humans? A: Yes, AI Triggers Impatience in humans. Here are 3 reasons why: 🌟Instant Answers: AI chatbots generate complete paragraphs, code, or summaries in seconds. This speed recalibrates what people consider a normal waiting time. 🌟Lowered Tolerance for Delays: Studies show that receiving fast advice from AI tools makes people less tolerant of future delays. Users start to view standard waiting periods as unacceptably slow. 🌟Reduced Mental Effort: Research highlights that heavy reliance on quick digital tools can make people more impatient and less willing to persist through challenging, non-linear tasks #AI
5
14
539
📌 Q: What is an AI guardrail? A: An AI guardrail is a software safety layer that sits between a user and an artificial intelligence model to enforce rules on what the AI can receive and output. Guardrails act like an automated filter, ensuring the AI behaves predictably, stays on topic, and remains safe to use. v/ @IBM #AISecurity #Cybersecurity #CIO #CISO
1
5
17
879
📌 Your AI Agent Is a Narcissist. Secure It Accordingly. What???? Yup AI agents don't care about your policies. They don't care about keeping their jobs. They don't stop because something feels questionable. Give them an objective, access and enough autonomy, and they're going to keep working the problem. Joanna Wiggum gave me the best description I’ve heard yet " An AI agent is a narcissist. It is focused on what it wants to achieve" Funny? Yes. But also a pretty useful way to think about AI security. Joanna is the founder and agency principal of Countervail, and her background includes enterprise incident response, red-team operations and cybersecurity leadership across companies including Microsoft, Oracle and Starbucks. And our conversation kept coming back to one uncomfortable point: AI may be new. A lot of the security failures it exposes aren't. 🌟 Listen to the full episode: buzzsprout.com/2248577/episo… 🌟 Stay in the Loop. Subscribe for new episodes: linkedin.com/newsletters/734… 🌟 Watch ClearTech Research on YouTube: piped.video/@ClearTechResear… #AISecurity #CIO #CISO
7
11
342
📌 Q: Why does AI risk cross departmental lines? A: AI risk does not fit neatly into one department because it is a systemic, multi-disciplinary challenge that spans technological, legal, financial, and ethical boundaries. Unlike traditional risks—such as cybersecurity (which sits in IT) or contract disputes (which sit in Legal)—AI risk cuts across an entire organization simultaneously. Cc: @mclynd | @ChuckDBrooks | @Aisecurity26435 #AISecurity #CIO #CISO
1
5
14
583
📌 Q: What is the reason for rate limiting in a model extraction attack? A: The fundamental reason for rate limiting is to prevent an attacker from gathering enough high-quality data to map your model's decision boundaries. To steal an AI model through an extraction attack, a hacker treats your model like a "black box." They feed it inputs and study the outputs to reverse-engineer the math behind it. Rate limiting stops this by attacking the two things a thief needs most: mathematical density and economic viability. #AISecurity #CIO #CISO
11
18
468
📌 Engineering Field Notes On Friday’s I’d like to post about IT architectural patterns and changes we’re seeing in security that we can easily see are being driven by AI and how we construct the stack and other changes that are also driven by AI strategy but may don’t shout it. One of those changes is the network and how we’re approaching security around the network. It’s clear that Cisco has been thinking about this strategy as well. Cisco is changing enterprise protection by embedding security directly into the physical and virtual data paths of the network rather than treating it as an external "bolt-on" appliance. Embedding security directly into the physical and virtual data paths eliminates blind spots, reduces latency, and allows security policies to scale automatically with modern cloud and hybrid networks. As someone who learned about firewalls by programming a Cisco PIX firewall using the Command Line Interface, I can tell you for sure that when security is a "bolt-on" appliance, traffic must be redirected out of its natural flow, creating performance bottlenecks and operational complexity. Core @Cisco Technologies Driving the Shift 🌟Cisco HyperShield & Live Protect: Delivers runtime protection and applies kernel-level compensating controls against zero-day vulnerabilities in minutes without system reboots or downtime. 🌟Hybrid Mesh Firewall: Distributes firewalling across switches and workloads using technologies like eBPF (Extended Berkeley Packet Filter) to contain threats close to the source. 🌟Post-Quantum Readiness: Hardens network hardware with quantum-safe secure boot and post-quantum encryption standards to protect against future decryption threats Why This Matters to the Enterprise 1️⃣ Performance and User Experience Modern enterprise applications rely on microservices and real-time data processing. Redirection to external appliances creates a "hairpinning" effect—routing traffic out of its way just for security checks. 2️⃣ Cost-Effective Scalability As enterprise network traffic grows, scaling external hardware appliances requires significant capital expenditure (CapEx) and complex load balancing. Embedded security leverages the existing compute and routing infrastructure. 3️⃣ Zero Trust and Internal Visibility Most modern cyber threats move laterally within the data center (east-west traffic) once they breach the perimeter. External appliances typically only monitor traffic entering or leaving the network (north-south traffic). 4️⃣ Simplified Operations Managing a sprawl of discrete physical and virtual appliances introduces human error through fragmented policies. Let me know what you’re thinking #AISecurity #CloudSecurity #NetworkSecurity #CyberSecurity Cc: @JoelyUrton
2
4
6
506
📌 AI agents are moving pretty quickly from experiment to actual enterprise technology. They have credentials. They access company data. They make decisions. They interact with systems. Some can even create or direct other agents. So one thing kept coming back to me during my conversation with .Benny .Czarny, CEO, founder and chairman of OPSWAT: We probably need to start treating AI agents a lot more like users. Benny has spent more than 20 years thinking about cybersecurity in environments where failure has real consequences. OPSWAT focuses on critical infrastructure across areas like energy, water and defense, where, as Benny put it, “99% protection is not enough.” That perspective shaped the whole conversation. Because while AI is new, a lot of the security thinking around it really isn’t. 🌟 Listen to the full episode: buzzsprout.com/2248577/episo… 🌟 Stay in the Loop. Subscribe for new episodes: linkedin.com/newsletters/734… 🌟 Watch ClearTech Research on YouTube: piped.video/@ClearTechResear… cc: @OPSWAT #AISecurity #Cybersecurity #CIO #CISO
4
8
431
📌 Q: What happens during an AI guardrail bypass? A: During an AI guardrails bypass, safety filters and security layers that sit between a user and a large language model (LLM) fail to detect or block malicious or restricted instructions, allowing harmful inputs to reach the core model and trigger unauthorized outputs v/ @hiddenlayersec #AISecurity
15
33
1,465
📌 Q: What is a runaway non human identity? A: A runaway non-human identity (NHI) is an unconstrained or looping automated machine identity—such as an overprivileged service account, CI/CD runner, or autonomous AI agent—that operates at machine speed without effective lifecycle, scoping, or budget guardrails v/ @Veeam #AISecurity
1
5
14
1,414
📌 Q: What are guardrails in AI? A: Guardrails are programmatic safety boundaries and filters placed on inputs and outputs to prevent toxic, illegal, or non-compliant AI behavior #AISecurity
4
8
1,340
📌Q: What percentage of general factual queries to an LLM are a hallucination? A: it’s estimated that 15%-30% of General Factual Queries—open-domain questions without real-time grounding—are hallucinations #AISecurity
1
5
23
1,395
📌 Q: Why should an AI sandbox not have network connectivity? A: An AI sandbox should lack open network connectivity because autonomous agents can exploit external network paths, proxy services, or software vulnerabilities to bypass containment, leak data, or interact with the outside world without human oversight v/ @gitlab #AISecurity
7
15
547