13 national cyber agencies from around the world, led by #ACSC, have collaborated on a guide for secure use of a range of "AI" technologies, and it is definitely worth a read! "Engaging with Artificial Intelligence" was written with collaboration from Australian Cyber Security Centre, along with the Cybersecurity and Infrastructure Security Agency (#CISA), FBI, NSA, NCSC-UK, CCCS, NCSC-NZ, CERT NZ, BSI, INCD, NISC, NCSC-NO, CSA, and SNCC, so you would expect this to be a tome, but it's only 15 pages! It is refreshing to see that the article is not solely focused on LLMs (eg. ChatGPT), but defines Artificial Intelligence to include Machine Learning, Natural Language Processing, and Generative AI (LLMs), while acknowledging there are other sub-fields as well. The challenges identified (with actual real-world examples!) are: 🚩 Data Poisoning of an AI Model: manipulating an AI model's training data, leading to incorrect, biased, or malicious outputs 🚩 Input Manipulation Attacks: includes prompt injection and adversarial examples, where malicious inputs are used to hijack AI model outputs or cause misclassifications 🚩 Generative AI Hallucinations: generating inaccurate or factually incorrect information 🚩 Privacy and Intellectual Property Concerns: challenges in ensuring the security of sensitive data, including personal and intellectual property, within AI systems 🚩 Model Stealing Attack: creating replicas of AI models using the outputs of existing systems, raising intellectual property and privacy issues The suggested mitigations include generic (but useful!) cybersecurity advice as well as AI-specific advice: 🔐 Implement cyber security frameworks 🔐 Assess privacy and data protection impact 🔐 Enforce phishing-resistant multi-factor authentication 🔐 Manage privileged access on a need-to-know basis 🔐 Maintain backups of AI models and training data 🔐 Conduct trials for AI systems 🔐 Use secure-by-design principles and evaluate supply chains 🔐 Understand AI system limitations 🔐 Ensure qualified staff manage AI systems 🔐 Perform regular health checks and manage data drift 🔐 Implement logging and monitoring for AI systems 🔐 Develop an incident response plan for AI systems This guide is a great practical resource for users of AI systems. I would interested to know if there are any incident response plans specifically written for AI systems - are there any available from a reputable source?
How to Manage Cybersecurity in AI
Explore top LinkedIn content from expert professionals.
Summary
Managing cybersecurity in artificial intelligence (AI) means protecting AI systems from threats like malicious data manipulation, unauthorized access, and privacy risks as these technologies become more widely used. AI cybersecurity involves both traditional IT defenses and AI-specific strategies, ensuring safe deployment, operation, and ongoing monitoring of intelligent systems.
- Secure deployment: Build AI on robust IT infrastructure, use threat models for risk analysis, and regularly update software and hardware to guard against attacks.
- Monitor and control: Continuously track AI activities, enforce strict access controls, and log interactions to quickly detect and address suspicious behavior.
- Establish governance: Set clear policies for who can deploy and manage AI agents, maintain human oversight for critical actions, and review permissions to prevent unauthorized use.
-
-
At Dallas Ignite last week, we walked Palo Alto Networks clients through what we call a unified approach to securing AI. One mandate. Two halves. Sharing here how each half maps to what we cover in our Defender's Guide to the Frontier AI Impact on Cybersecurity. Mandate One: Defending against frontier models being weaponized against your architecture. The familiar half. Adversaries with AI capability are accelerating everything. Faster recon. Faster exploitation. Faster lateral movement once they're in. Four actions that matter right now: 1️⃣ Find and fix vulnerabilities before adversaries do. Frontier AI has become the primary source of vulnerability discovery. Target a 72-hour patch cycle for criticals, with automated deployment where change risk allows. Start by scanning your own code and supply chain. 2️⃣ Aggressively reduce your attack surface. Run an external assessment now. Eliminate internet-reachable assets that shouldn't be reachable. Harden the ones that need to stay up. 3️⃣ Deploy unified protection across every layer. Endpoint, network, identity, cloud, application. Patchwork architectures (the average enterprise runs 80-plus tools) cannot operate at AI speed. Full stop. 4️⃣ Modernize security operations to detect and respond at machine speed. Single-digit minute MTTR is the target. That requires consolidated tooling and AI-assisted triage, not more analysts. Mandate Two: Securing the rapid deployment of AI apps and agents inside your own enterprise. The half most organizations are behind on. AI is showing up in four places: browser agents executing workflows, endpoint copilots and GenAI assistants, AI baked into vendor and internal apps, and enterprise agents taking autonomous actions across systems. Same four actions. Different operational specifics. 1️⃣ Find and inventory what's actually running. Do a structured discovery across all four areas. Most exercises surface years of accumulated deployments nobody centrally tracked, including AI shipped quietly through software updates. 2️⃣ Reduce the unauthorized AI footprint. Shut down deployments that bypassed governance. Then build the policy that prevents it from happening again. 3️⃣ Deploy governance across AI permissions and decision authority. Who can stand up an agent. Who approves what permissions. Who reviews what actions the agent has taken. This is the layer most enterprises have not built yet. 4️⃣ Modernize incident response for AI-specific failure modes. Compromised agents. Unauthorized actions. Permission escalation. Run a tabletop this quarter that includes at least one AI-agent scenario. Both mandates follow the same sequence: visibility first, then assessment, then protection. At PANW we frame this as Discover, Assess, Protect. The framework is consistent. The specifics are not. Where to start: if you haven't run a structured discovery across those four areas in the last six months, that's your first move. You cannot secure what you cannot see.
-
Yesterday, the National Security Agency Artificial Intelligence Security Center published the joint Cybersecurity Information Sheet Deploying AI Systems Securely in collaboration with the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation (FBI), the Australian Signals Directorate’s Australian Cyber Security Centre, the Canadian Centre for Cyber Security, the New Zealand National Cyber Security Centre, and the United Kingdom’s National Cyber Security Centre. Deploying AI securely demands a strategy that tackles AI-specific and traditional IT vulnerabilities, especially in high-risk environments like on-premises or private clouds. Authored by international security experts, the guidelines stress the need for ongoing updates and tailored mitigation strategies to meet unique organizational needs. 🔒 Secure Deployment Environment: * Establish robust IT infrastructure. * Align governance with organizational standards. * Use threat models to enhance security. 🏗️ Robust Architecture: * Protect AI-IT interfaces. * Guard against data poisoning. * Implement Zero Trust architectures. 🔧 Hardened Configurations: * Apply sandboxing and secure settings. * Regularly update hardware and software. 🛡️ Network Protection: * Anticipate breaches; focus on detection and quick response. * Use advanced cybersecurity solutions. 🔍 AI System Protection: * Regularly validate and test AI models. * Encrypt and control access to AI data. 👮 Operation and Maintenance: * Enforce strict access controls. * Continuously educate users and monitor systems. 🔄 Updates and Testing: * Conduct security audits and penetration tests. * Regularly update systems to address new threats. 🚨 Emergency Preparedness: * Develop disaster recovery plans and immutable backups. 🔐 API Security: * Secure exposed APIs with strong authentication and encryption. This framework helps reduce risks and protect sensitive data, ensuring the success and security of AI systems in a dynamic digital ecosystem. #cybersecurity #CISO #leadership
-
The Cybersecurity and Infrastructure Security Agency, National Security Agency, and other cybersecurity agencies Published “Careful Adoption of Agentic AI Services” providing a detailed framework for securely deploying, operating, and governing agentic AI systems. This joint guidance focuses on the unique risks introduced by AI systems capable of autonomously making decisions, using tools, and taking actions with limited human intervention, and recommends a “secure by default” approach. Some of the recommendations include: • Adopt a phased deployment approach by starting with low-risk use cases, limiting permissions and autonomy initially, and progressively expanding capabilities based on ongoing evaluation and oversight. • Implement strong guardrails and constraints, including explicit “do-not-do” rules, deny lists, safety policies, sandboxing, and layered controls to reduce the risk of harmful or unintended actions. • Maintain meaningful human oversight as a central control mechanism for high-impact or irreversible actions. The document recommends clear human approval checkpoints , defined accountability structures, and escalation procedures for sensitive operations. • Apply strict privilege and authentication controls by limiting agents to the minimum access required, using just-in-time credentials, continuously validating authorization, and preventing agents from modifying their own privileges. • Use continuous monitoring and comprehensive logging to track agent reasoning, tool usage, decisions, identity changes, and anomalous behavior in real time. The guidance stresses that monitoring should extend beyond inputs and outputs to include internal agent processes. • Conduct red teaming and scenario-based testing before and after deployment to identify prompt injection risks, emergent behaviors, attempts to evade safeguards, and other unexpected system interactions. • Strengthen resilience through fail-safe defaults, rollback capabilities, segmentation, and containment mechanisms designed to reduce the operational impact of compromised or malfunctioning agents. • Manage third-party and tool-integration risks by verifying external components, restricting tool usage to approved allow lists, monitoring inter-agent interactions, and applying supply chain risk management practices. • Integrate governance and accountability structures that define risk ownership, establish AI-specific policies, and align agentic AI oversight with existing cybersecurity and risk management frameworks. • Use system-level security analysis rather than evaluating components in isolation. The document highlights that risks in agentic AI environments often emerge from interactions between models, tools, humans, datasets, and infrastructure. The document presents agentic AI security as an ongoing operational discipline focused on resilience, containment, observability, and controlled autonomy across the full lifecycle of deployment and use.
-
Most people don’t realize the DoD already published a full roadmap on how to manage cybersecurity risk in AI systems. It’s called the AI Cybersecurity Risk Management Tailoring Guide (July 2025). This guide quietly set the tone for how RMF will evolve with artificial intelligence. It breaks down exactly how AI fits into every step of the RMF process, from design and development to deployment, monitoring, and decommissioning. Here’s what stood out to me: • AI models don’t go through a full ATO; they follow an “Assess Only” process that ties into the main system’s package. • Data integrity and provenance are now key cybersecurity priorities, not side notes. • Continuous ATO (cATO) is the direction DoD is heading for AI-enabled systems. • The guide maps CNSSI 1253 controls directly to each phase of the AI lifecycle, which is huge for ISSOs. • RMF isn’t being replaced; it’s being modernized to align with AI, cloud, and automation. If you work in RMF, GRC, or federal compliance, study this document. It’s the blueprint for how AI and cybersecurity will intersect across the DoD and government in the years ahead. Need RMF Training: https://lnkd.in/eYHfeN-b
-
🚨 AI security cannot be managed with informal rules. It needs a real policy. I reviewed this AI Security Policy Template based on ISO 42001, and it is a strong reminder that secure AI adoption requires governance, ownership, and continuous control. A good AI security policy should define: 🔹 Governance & Risk Management AI governance committee, risk assessments, compliance tracking, and AI risk register. 🔹 Data Protection & Privacy Data minimization, encryption, retention, deletion, consent, and privacy impact assessments. 🔹 AI Model Security Secure development, trusted datasets, model inventory, deployment controls, drift monitoring, and rollback procedures. 🔹 Access Control RBAC, least privilege, MFA, JIT access, API security, and regular access reviews. 🔹 Monitoring & Incident Response Real-time monitoring, tamper-evident logs, AI-specific IR plans, drills, and post-incident reviews. 🔹 Responsible AI Bias mitigation, transparency, explainability, ethics review, and human oversight. 🔹 Vendor Management Third-party AI assessments, contract requirements, right-to-audit clauses, and continuous vendor monitoring. 💡 My biggest takeaway: AI policy is not paperwork. It is the operating model for safe AI. Because every AI system needs clear answers to: • who owns it? • what data does it use? • who can access it? • how is it monitored? • how are incidents handled? • how are vendors controlled? • when should humans intervene? 🚨 Without policy, AI scales faster than governance. And that is where risk grows. 💬 Does your organization already have an AI security policy? #AISecurity #AIGovernance #ISO42001 #ResponsibleAI #CyberSecurity #RiskManagement #DataPrivacy #LLMSecurity #AICompliance #GRC
-
The OWASP® Foundation Threat and Safeguard Matrix (TaSM) is designed to provide a structured, action-oriented approach to cybersecurity planning. This work on the OWASP website by Ross Young explains how to use the OWASP TaSM and as it relates to GenAI risks: https://lnkd.in/g3ZRypWw These new risks require organizations to think beyond traditional cybersecurity threats and focus on new vulnerabilities specific to AI systems. * * * How to use the TaSM in general: 1) Identify Major Threats - Begin by listing your organization’s key risks. Include common threats like web application attacks, phishing, third-party data breaches, supply chain attacks, and DoS attacks and unique threats, such as insider risks or fraud. - Use frameworks like STRIDE-LM or NIST 800-30 to explore detailed scenarios. 2) Map Threats to NIST Cybersecurity Functions Align each threat with the NIST functions: Identify, Protect, Detect, Respond, and Recover. 3) Define Safeguards Mitigate threats by implementing safeguards in 3 areas: - People: Training and awareness programs. - Processes: Policies and operational procedures. - Technology: Tools like firewalls, encryption, and antivirus. 4) Add Metrics to Track Progress - Attach measurable goals to safeguards. - Summarize metrics into a report for leadership. Include KPIs to show successes, challenges, and next steps. 5) Monitor and Adjust Regularly review metrics, identify gaps, and adjust strategies. Use trends to prioritize improvements and investments. 6) Communicate Results Present a concise summary of progress, gaps, and actionable next steps to leadership, ensuring alignment with organizational goals. * * * The TaSM can be expanded for Risk Committees by adding a column to list each department’s top 3-5 threats. This allows the committee to evaluate risks across the company and ensure they are mitigated in a collaborative way. E.g., Cyber can work with HR to train employees and with Legal to ensure compliance when addressing phishing attacks that harm the brand. * * * How the TaSM connects to GenAI risks: The TaSM can be used to address AI-related risks by systematically mapping specific GenAI threats - such as sensitive data leaks, malicious AI supply chains, hallucinated promises, data overexposure, AI misuse, unethical recommendations, and bias-fueled liability - to appropriate safeguards. Focus on the top 3-4 AI threats most critical to your business and use the TaSM to outline safeguards for these high-priority risks, e.g.: - Identify: Audit systems and data usage to understand vulnerabilities. - Protect: Enforce policies, restrict access, and train employees on safe AI usage. - Detect: Monitor for unauthorized data uploads or unusual AI behavior. - Respond: Define incident response plans for managing AI-related breaches or misuse. - Recover: Develop plans to retrain models, address bias, or mitigate legal fallout.
-
The 𝗔𝗜 𝗗𝗮𝘁𝗮 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 guidance from 𝗗𝗛𝗦/𝗡𝗦𝗔/𝗙𝗕𝗜 outlines best practices for securing data used in AI systems. Federal CISOs should focus on implementing a comprehensive data security framework that aligns with these recommendations. Below are the suggested steps to take, along with a schedule for implementation. 𝗠𝗮𝗷𝗼𝗿 𝗦𝘁𝗲𝗽𝘀 𝗳𝗼𝗿 𝗜𝗺𝗽𝗹𝗲𝗺𝗲𝗻𝘁𝗮𝘁𝗶𝗼𝗻 1. Establish Governance Framework - Define AI security policies based on DHS/CISA guidance. - Assign roles for AI data governance and conduct risk assessments. 2. Enhance Data Integrity - Track data provenance using cryptographically signed logs. - Verify AI training and operational data sources. - Implement quantum-resistant digital signatures for authentication. 3. Secure Storage & Transmission - Apply AES-256 encryption for data security. - Ensure compliance with NIST FIPS 140-3 standards. - Implement Zero Trust architecture for access control. 4. Mitigate Data Poisoning Risks - Require certification from data providers and audit datasets. - Deploy anomaly detection to identify adversarial threats. 5. Monitor Data Drift & Security Validation - Establish automated monitoring systems. - Conduct ongoing AI risk assessments. - Implement retraining processes to counter data drift. 𝗦𝗰𝗵𝗲𝗱𝘂𝗹𝗲 𝗳𝗼𝗿 𝗜𝗺𝗽𝗹𝗲𝗺𝗲𝗻𝘁𝗮𝘁𝗶𝗼𝗻 Phase 1 (Month 1-3): Governance & Risk Assessment • Define policies, assign roles, and initiate compliance tracking. Phase 2 (Month 4-6): Secure Infrastructure • Deploy encryption and access controls. • Conduct security audits on AI models. Phase 3 (Month 7-9): Active Threat Monitoring • Implement continuous monitoring for AI data integrity. • Set up automated alerts for security breaches. Phase 4 (Month 10-12): Ongoing Assessment & Compliance • Conduct quarterly audits and risk assessments. • Validate security effectiveness using industry frameworks. 𝗞𝗲𝘆 𝗦𝘂𝗰𝗰𝗲𝘀𝘀 𝗙𝗮𝗰𝘁𝗼𝗿𝘀 • Collaboration: Align with Federal AI security teams. • Training: Conduct AI cybersecurity education. • Incident Response: Develop breach handling protocols. • Regulatory Compliance: Adapt security measures to evolving policies.
-
The latest joint cybersecurity guidance from the NSA, CISA, FBI, and international partners outlines critical best practices for securing data used to train and operate AI systems recognizing data integrity as foundational to AI reliability. Key highlights include: • Mapping data-specific risks across all 6 NIST AI lifecycle stages: Plan and Design, Collect and Process, Build and Use, Verify and Validate, Deploy and Use, Operate and Monitor • Identifying three core AI data risks: poisoned data, compromised supply chain, and data drift for each with tailored mitigations • Outlining 10 concrete data security practices, including digital signatures, trusted computing, encryption with AES 256, and secure provenance tracking • Exposing real-world poisoning techniques like split-view attacks (costing as little as 60 dollars) and frontrunning poisoning against Wikipedia snapshots • Emphasizing cryptographically signed, append-only datasets and certification requirements for foundation model providers • Recommending anomaly detection, deduplication, differential privacy, and federated learning to combat adversarial and duplicate data threats • Integrating risk frameworks including NIST AI RMF, FIPS 204 and 205, and Zero Trust architecture for continuous protection Who should take note: • Developers and MLOps teams curating datasets, fine-tuning models, or building data pipelines • CISOs, data owners, and AI risk officers assessing third-party model integrity • Leaders in national security, healthcare, and finance tasked with AI assurance and governance • Policymakers shaping standards for secure, resilient AI deployment Noteworthy aspects: • Mitigations tailored to curated, collected, and web-crawled datasets and each with unique attack vectors and remediation strategies • Concrete protections against adversarial machine learning threats including model inversion and statistical bias • Emphasis on human-in-the-loop testing, secure model retraining, and auditability to maintain trust over time Actionable step: Build data-centric security into every phase of your AI lifecycle by following the 10 best practices, conducting ongoing assessments, and enforcing cryptographic protections. Consideration: AI security does not start at the model but rather it starts at the dataset. If you are not securing your data pipeline, you are not securing your AI.
-
Dear AI and Cybersecurity Auditors, AI changes how risk enters your environment and expands your attack surface. Traditional cybersecurity controls no longer cover model behavior, training data, prompts, agents, and AI-driven decisions. This draft extends NIST CSF 2.0 into AI systems. It treats models, data, prompts, agents, and AI decisions as real cyber assets. It also addresses how attackers already use AI to scale speed, deception, and impact. Here is why this framework matters for security, risk, and audit leaders. 📌 AI expands the attack surface beyond infrastructure into training data, models, prompts, agents, and third-party AI services 📌 Governance shifts from IT ownership to enterprise accountability with clear risk ownership, oversight, and decision authority 📌 Traditional controls still apply, but AI requires added focus on model integrity, data provenance, output reliability, and human oversight 📌 The framework maps AI risk directly to CSF functions so teams avoid parallel AI security programs 📌 Defensive teams use AI to reduce alert fatigue, improve detection accuracy, and support faster incident response 📌 Adversaries already use AI for phishing, malware generation, social engineering, and automated attack orchestration 📌 Continuous monitoring extends beyond systems into model drift, hallucinations, and unexpected behavior 📌 Risk tolerance must account for AI failure modes, not only system outages or data loss 📌 Audit and assurance teams gain a structured way to test AI controls across Secure, Defend, and Thwart focus areas 📌 The profile supports assessment, control design, and executive reporting without adding unnecessary complexity AI security fails when teams treat AI as software. NIST IR 8596 reframes AI as a risk domain inside cybersecurity. If your organization builds, buys, or relies on AI, this profile gives you a practical path to govern, secure, and defend it with intent. #NIST #Cybersecurity #AIGovernance #AIRisk #AIControls #ITAudit #CyberRisk #AISecurity #GRC #CSF #CyberVerge ♻️ Share this with your team or repost so more professionals. 👉Follow Nathaniel Alagbe for more.