Agentic AI and the New Cybersecurity Risk Model | Security Boulevard Ep. 12
In this episode of the Security Boulevard Podcast, Tom Hollingsworth, Alan Shimel, and Mitch Ashley take a close look at how agentic AI is changing the cybersecurity threat landscape. As AI systems gain autonomy, traditional security models struggle to keep pace with how decisions are made, actions are taken, and risks propagate across environments.
The discussion focuses on the need for stronger security measures around AI agents, the growing responsibility vendors carry in delivering secure platforms, and why observability is now essential for understanding AI-driven workloads. The panel also addresses the shared accountability of developers and security professionals in designing, deploying, and maintaining trustworthy AI systems.
Reflecting on past challenges in AI security, the conversation balances realism with cautious optimism, outlining what meaningful progress could look like as the industry matures. The episode closes with updates on upcoming events and a call for continued community engagement around AI security best practices.
Hosts
-
Tom Hollingsworth
-
Alan Shimel
-
Mitch Ashley
Listen to the full episode and explore future conversations at SecurityBoulevard.com.
Transcript
Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube channel, tech Strong tv, and all of your favorite podcast platforms.
Before we jump into today's topic, let's meet the panel starting with Alan. Alan, it's good to see you again. Tom, it's nice to see you.
I've, I've been, I've been on the road a lot. It's conference season, so happy to be here in the office and able to jump on today. Well, we're very happy to have you.
And, uh, joining us is also someone who's been on the road quite a bit recently. Uh, Mitch, it's good to see you again as well. I'm back in Guitar Central where I belong.
Exactly. You know what? I think I like your decor better than the hotel rooms in Las Vegas.
Uh, you definitely have an eye for, uh, you know, things that are interesting. I'm in, I'm in my, my, my man cave, and I got my stuff around me. Oh, well, that's awesome.
I, of course, am in the formalist void of my office because let's be fair, you guys are more interesting than me. But let's jump into today's topic because it is something that's actually very interesting. And I think that, you know, Mitch, uh, you highlighted something I think that we all should be keeping an eye on.
We've been talking about AG agentic AI a lot recently. We've had several episodes about it here We've been covering in a lot of other areas, but of course, you know, the s and AG agentic stands for security. So one of the things we've gotta figure out is how are we going to secure agentic ai?
Now, before we even got started on this, we, we had to make sure that we were clear on this. We're not talking about using agents to do security on this episode. That's an entirely different conversation to have.
We wanna talk about how we're going to secure the agents themselves, because as we know, with all things related to ai, those particular pieces of code have a lot of access. And if something were to figure out a way to confuse them or jailbreak them, or potentially turn them against us, we could have a big problem on our hands. Mitch, I'm gonna let you kinda lay things out since you brought this topic up.
What is it about AG agentic security, meaning securing those agents that kind of has piqued your interest? Well, I, the, the main thing is that we have been seeing announcements from vendors, you know, the large vendors, the Microsofts and Googles, uh, GitHub's even, uh, and even folks that are kind of farther down the food chain around doing some different kinds of security with agents while they're rolling out agents. And while that's notable to me, you know, Alan and I have been preaching the gospel of, uh, DevSecOps and shifting left or whatever, however, you get software secure and always questioning like, are we making progress?
Are we ever gonna get there? And of course, I think beginning of the year, I would say we're in the hope mode. Well, we hope we do it right this time.
Well appears that something. I'm not saying we're, we're fixing everything, but there are a lot of products that are coming out for agent identity, security guardrails, um, control some oversight. There's even talk around behavior and compliance.
Uh, a little bit of that coming out. I mean, I've got a whole list of rash of vendor announcements. Again, none of this is complete solving all the problems, but I have to believe that in the interest of, we wanna be part of AI too, the security and other companies security part of these product companies are saying, we better get our act together now and start working on security of AI and agents.
Let's get products out the door. You know, Mitch, not to disagree with you, but I, I gotta disagree with you. I, I think right now, just like every other tech company out here, security executive security vendors are under tremendous amount of pressure from their board, their investors, the VCs, to say, what are you doing with ai?
What's your AI story? And for most of them, for most of them, what they're doing, what's their AI story is how they're using ai, how they're using AI to be, to provide better security, to do better AppSec, to do better endpoint, to do better data. DLP or what cloud security or what have you.
It's how do they use security? It's just a subset of these vendors who are gonna say, well, how do we defend, how do we secure an AI future? And there's gonna be a lot of them whose lips move.
But I think you gotta watch for the ones who, who are putting their hands in their pocket and, and coming out with it. I, I've seen a lot of talk about it, but it pals in comparison to the companies who are saying, we're going to use AI to give you better security. And, and this is an old story.
There's where you and I would, would differ. Yes. I think the, the market's very large for using AI for security, the market for wanting to get AI into production.
Meaning I want my agents to go into, go into production. Enterprises are not gonna let AI into production. You're gonna be super cautious.
'cause the data issues that market is, you know, pick a, pick a multiple that's much bigger than the security market using ai. Both of 'em are important, but I think that's, I think the enterprise is what's driving. If you really want these deployed into production, you have to secure ai.
Mitch, I appreciate your point of view. When has that ever actually been the truth? I was waiting, waiting.
Do open. Wait, wait. Lemme take you back on a little trip down memory lake.
Let, let's go to thousand war 2002. We don't use open source in the enterprise. It's not secure.
Who, who throat are we gonna choke? Everyone was using open source. We don't use white wifi in the enterprise.
It's not secure. It's wide open as people, you and I were, as people are tossing the WAPs under their desk when their bosses work, work by, we don't use the cloud. It's insecure cloud.
The biggest inhibitor to cloud adoption is cloud security. As every developer and their mother whipped out a credit card and spun up instances. What makes you think this time's any different?
It's, it's not different in the, in what you're saying in that way. I agree with what you're saying. What's different is we see companies coming out with security solutions earlier in the maturation of AI and agents in the cycle I see is different.
And I'm, I'm not claiming any, uh, any clairvoyant that suddenly we're all gonna get religions and secure all of our ai. But I do think the market, everyone wanting it, it's happening in observability too. You see companies like, okay, I want, uh, I want the observability of my agents.
How do we Dynatrace, Datadog, new Relic be part of the Microsoft announcement, right? Um, for DevOps agent, the other companies that aren't AI companies that want to be part of the AI era are moving, some of them are moving in a fast mover way. Not all of them.
There's a lot that aren't. But so, so you are gonna have some security products for some of this ai. Maybe we're gonna see some better security.
Not, not, not the kind of, you know, what was the Eden was the Star Trek episode when they're all all headed to Eden. Mm-hmm. You know, we're probably not gonna go there because that turned out not to be a good place anyway.
Yeah. Well, if I remember correctly, the guy with the ears, Tom, you gonna, I I think, uh, Mitch, you kind of stumbled across something that I think blends what Alan was saying. The reason why I feel like people are moving a hundred miles an hour is not because there's any hesitancy on their part to implement ai.
Like they know that there are risks associated with it, but the bigger risk is the board and the investors coming down from on high saying, you have to have a strategy. You have to adopt something. You have to do something now.
Or we're gonna unseat you. We're gonna, would've put somebody in that can do that. But the observability piece, I think is maybe kind of the, the trick to get this in here, because what's the one thing that they want to know above and beyond?
We have an AI strategy. They wanna see the data points proving that it's actually happening, right? How much, um, ag agentic workload have you deployed?
How utilized are these agents? And maybe by selling this as an observability platform and saying, oh, well, you know, we can tell that we're using these agents in their max to 85% capacity or whatever. Oh, by the way, we can also see what workloads they're doing.
We can see if something jail breaks that we can see if things are, are doing behavioral stuff that they shouldn't. I feel like that's a way to back into the security conversation as kind of an afterthought that will also allow you to bring that up to the board in three more months when it becomes relevant. Oh, by the way, we, we prevented like all of the board, uh, members, uh, salaries from being leaked through an AI prompt injection attack.
Oh, I didn't know that that was possible. Well, good thing that I was thinking about this while you guys were worried about whether or not we had enough agents deployed. I think that's a very good point.
And especially if the vendor you're already using for observability or security or both are moving, uh, making moves to introduce those products. Now, I think you're in a better position. Y you know, again, experience leads me to say we will have security for agentic AI when customers put their foot down and demand security for ai.
Yeah, for sure. Mm-hmm. But to Tom's point, when you've got the board and the C level, what's your AI story?
What's your AI story? How fast can we get this? How fast can we, can we, can we lay some people off and replace them with ai?
Right? That kind of pressure doesn't bode well for, for it. But here's an interesting thing too, Mitch, ultimately, who's responsible for the security of the ent ai for these agents?
Is it the people designing the agents? Are we, in other words, are we gonna have a secure by design sort of standard for, uh, uh, agents, for AI agents? Or are we gonna see the rise of a, at first the cottage industry, hopefully growing into a, you know, big part of the, not a big part, but a significant industry of security companies or, you know, cyber companies that secure agent ais, maybe even robotic AI as well.
But, you know, so in other words, ultimately who's the, who's responsible here? Is it a security company that's solely focused on the security of your agents? Or is it the developers of the agents themselves who have security as part of their mission?
I think it's, at least right now, what we're seeing is the pu the companies that are creating the platforms for agents to operate within. So the, uh, agent hq, Microsoft, the agent hub at, at, um, at GitHub, that what they're building in the framework for, you heard at AWS last week, Alan, about their A AWS security agent, their a WS DevOps agent, and coupled right in that announcement and is, and here's the vendors who are integrating with that agent so they can connect into it. So the framework of security and observability are starting to be put in place, at least in those cases.
Uh, um, it certainly isn't across the board. Will there be a, a whiz or a somebody that, you know, pops up as the agent security company or AI security company? Probably.
I think, we'll, we'll see some of those come up, but the other folks are not gonna miss out. They're, they're gonna go after this market and they, and some of 'em already are. So the framework one sounded very much to me, like the early cloud security.
Remember we built it into the platform, right? We don't have to show you everything, but AWS was pretty good about giving, uh, vendors a, a window in into the security of that foundation, if you will. And, and I think that what we saw at AWS last week and what we've heard from Microsoft very much kind of fits that cloud security mm-hmm.
Model where, Hey, we're responsible for the, for the platform and, and we're gonna partner with you. We're gonna do some of that security, and then we're gonna make APIs or, or MCP servers or whatever available for you to supplement that with more. But I do think you're right.
I think we're gonna have a category buster, like a wiz or, or, you know, in the last cycle that, and I don't know what Futurum or Gartner or whoever will name it, but it's gonna be a category of security companies that secure agent ai, wherever it may be. And, and there will be some winners there. Very much like we, I think on a much bigger scale, like we saw with microservices in Kubernetes, right?
We see a C app rise as a product category. And there's some that's exactly what I'm referring to. Like, see now, right?
And, and you know, the funny thing is usually the analysts come up with a name for it after it's, they saw it in the wild, you know what I mean? And now, okay, we gotta name that, but I, I do think we're gonna see in the wild a security, as I said, it'll start as a cottage industry and grow, but a, uh, uh, another silo in the cyber market for companies that specialize in, in securing, uh, uh, gentech or agents, AI agents that doesn't let the AI agent developers off the hook though. No.
We need some sort of best practices to about you, you wanna call it the law of AI or something, right? These are the three rules and the zero law of how an agent behaves or should behave from a security point of view. I agree with you, Alan, But here's the problem.
We don't know how agents behave until we see them in the wild. And that's one of the things that we're, we're running into right now, is the, just the absolute sheer amount of creativity that people are throwing at these problems to try to bust them up. I mean, last week we saw the Icaro Labs paper where you can gelb break an LLM by writing your prompt injection in poetry, because someone somewhere was like, why would anybody ever wanna write hacking instructions in poetry?
Well, Before that, you could do it with calculus, right? You could do your prompts in math and, and break it as well. Um, yes.
But you also gotta remember, Tom, right now we're in a Cambrian explosion era of AI where we're making all kinds of funky animals with six eyes, eight legs, 12 guts, and, and, you know, and everything else at, at some point, I I, I'm hoping we're gonna have, and, and some point soon we'll have standardization and best practices come out, right? We, we don't have best practices yet. We don't need, We, we don't have best practices because we haven't seen a best solution yet.
Like, like you said, why, why does an animal have four legs and not five or 12? Because we found out that through trial and error, through evolution, 12 legs doesn't work there. There's Evolution's slow.
We can't afford, we can't afford e you know, we've gotta, evolution Can be slow, but there's also this theory of punctuated evolution where you have a rapid number of changes that quickly fall out, and then we iterate on the best model. And we're seeing that now with a lot of companies who are like, no, no, no, no, that's not gonna work. We need to move on and do something different over here because that doesn't scale the way we want it to.
But the problem is, is that when we jump to that next, uh, shift, if you will, it's almost like, just like a neural learning model. We've forgotten all the lessons we learned over here. We're starting fresh.
Well, what if we do it this way? Or what if we have it that way? And unfortunately, from my perspective, developers don't do themselves any favors because they're so focused on doing the job that they forget what happens when people try to do the job wrong, right?
Like, think about anyone who like used to check for cross site scripting. It's like, well, what happens if I type the wrong thing into this dialogue box or causing an overflow condition or something like that? Well, why would you do that?
Well, why wouldn't you think about that? Like, I, I think about any, any number of like software development things like, you know, uh, video games are actually a really good example. If you look at the people, it's like, okay, we deployed this patch, but there's a bug in it.
If you wanna know if there's a bug, make it something that's useful to the users. Like if it's a way to get infinite money or something like that, they'll find ways to, to test it quickly and get the outcome that they want. And then you'll have to go back and go, oh yeah, we probably should patch that out.
'cause that's not an, an intended side effect. And I think that we've gotta get to a point where we can do that rapidly. Because unfortunately, as much as I would like to say that I would love that the value of adding security happens before the thing is released until you release it.
You won't know what kind of attacks you're gonna face against it. Well, it's like, this is very much where, again, back to microservices, right? When we first started working with microservices, like, how many, are we gonna have a a dozen or two dozen, uh, hundreds, may thousands.
Really? How am I gonna manage that? How am I gonna know what they're all doing And if they're doing what they're supposed to be doing?
You say the same thing for agents, right? And that's where, you know, Kubernetes came from. That's where OpenTelemetry really took off from.
Um, and this, we're seeing the same things start to happen here where, uh, vendors are coming out with pictured product name, but it's an agent control plane someplace where you have some observability or a place to manage what agents are running, what tasks that they're doing. We don't know what the best framework of the best model. I think it looks like a, a video game or a PC game like StarCraft, that that's what I hope the interface looks like someday.
But that aside, you know, it, it's being defined or will be defined. I don't think the solution is there yet. com, I feel it, I feel compelled to say, this isn't the developer's problem.
Let's not throw this on the shoulders of developers and say, oh, the developer has to think this way. The developer has to do these things. Developers have a bid on their plate, right?
We need this is, this is all of our, this is the whole stack. The whole team's problem. It's the DevOps engineers problem.
It's the security guy's problem. It's the tester's problem. It's the AI's problem.
It's the platform engineers problem. And it's the SREs problem. It's all of our problem, right?
Don't, don't throw it on the developer that he should be, you know, because that's a recipe for failure. The developer's not a security professional developer may not have written the code. AI wrote it.
AI might have written the code, but here's, here's where I think there's good news. I think using AI technology, we could do things like digital twinning and, and, and, and stuff like this where we can see kinda what's out there and fuzzing and everything else. And you know, I, what I, and I've seen this just in the last year or two, what I used to think of is after the event horizon security, in other words, post-deployment deployment, security measures being deployed, pre-deployment, right?
We, we've seen, uh, what we used to consider vulnerability management move into AppSec, right? And, and, and things like this. So I, I think given the, the, uh, capabilities of ai, we can have higher confidence in the software we release in our software supply chain, which will result in hopefully fewer, not eliminating, but fewer security issues post-deployment.
And, and that's why I think we do need to spend a lot of effort and a lot of resources in harnessing AI to make our security better. You know, the, I think this also ties into things like, uh, the announcement within with anthropic buying bun, the job JavaScript runtime environment of yes, I can imagine that for production use. I can also imagine that for setting up sandboxes and testing ai, doing those tasks and actually running it as maybe part, even part of the code generation process before it says, here's your code.
I've got your code for you it, doing some testing, doing it, running it in an environment, at least for that particular programming language. You know, we're, we can do things a bit differently in how we create software. It doesn't mean we're changing all of it, but I think folks are kind of thinking out of the box now with ai.
I think so what, lemme lemme, lemme switch gears a little bit. Um, also one of the early questions about agents was, well, what, what permissions does it have? And the first company that I ran into that had made a decision about that, and may may not have been, probably weren't the first company to do it, was to treat a AI agents as a teammate, as a user in the system to give them their own id, their own, uh, credentials if you will, security, but also their own permission structure and set up and actually show up in the list of kind of users you can select to, uh, perform tasks and things like that.
And that te seems to be what the approach people are taking is build on our identity, our IM systems for agents. Now, is that enough where we need more? I don't know, but that seems to be the prevailing wind.
You guys think that's, is that gonna solve the problem long enough for us to get AI into production or we got some more hills to climb for Hamburger Hill there, Alan, We're not there yet. Because the problem with limiting the agent's horizon as far as what it can do is what happens if those controls are breached? And, and we've seen that time and again with your average user, right?
Well, I'm not gonna give them admin rights. Okay, that's great. What happens if they get them?
Oh, crap, now they have visibility into the entire infrastructure and they can do whatever. Like, like how many times have we seen like backup operators get breached and oh look, it can read everything. I think you're gonna have to take an agentic AI approach with a combination of zero trust, where even if the agent itself is limited, I have a se a separate set of controls on top of it that hides things that it doesn't need to see.
So even if someone does manage to break out of the security controls, they are basically in a, in a prison cell. And, and we've learned that over the years with users, right? Like, like even the most well-meaning user can accidentally do things without realizing it.
I go all the way back to my internship when I was at IBM and someone obliterated about 50 gigs worth of backup data in 2001 off of a tape robot because he accidentally removed the wrong directory. Because when he, when he, uh, changed users, he didn't do PWD to figure out he was on the tape robot and not an attempt directory. And to this day, 25 years later, I still do PWD anytime I change user focus at all because of that.
Because I don't want to be in an area where I can cause a massive amount of damage. And that's the whole heart behind zero trust, right? If, if I can't control what the users do, I'm gonna control what the users can see.
And I think we have to have that, we have to put an extra set of guardrails above the agents to prevent the kinds of attacks that could potentially cause them to do harm. Yes. Um, so the, the, the, the thing about this though is we've got, at some point we're gonna start thinking of these agents and, and we've seen this written already, digital coworkers, digital workforce.
Yep. It's a digital workforce and they're your digital coworkers. And again, you know, we're gonna need best practices to emerge, but these digital coworkers are gonna have, I I I hesitate to use the word identity.
They're gonna have an identity and access management, right? An IAM for your digital workforce, right? And I, I, I bet you some of the IAM vendors are already working on this and, and included in that, I I think zero, you know, zero, don't leave your zero trust at the door when you're dealing with agen, right?
All of the policies and best practices we've developed around IAM should, should apply to our agents. Now you've got MCP servers and, and, and, uh, you know, these kinds of things. Very similar.
Mitch and Tom, if you remember just three or four years ago, there was this whole move towards, uh, AI security. There was a whole bunch of AI security companies mm-hmm. Api you mean traceable, right?
Yeah. API, yeah. Yep.
A, I'm sorry, API security. And um, and now all of a sudden it kind of got subsumed. It went away pretty quick.
I I think we're gonna see a similar thing around MPC, excuse me, ccp. Yeah, no, I do that too. Get my initials mixed up.
MCP servers and, and the security built around those kinds of interactions. But they all fall within the broader category of IAM for agents. That's my, I think that's the likely outcome here.
No, I was just gonna kind of wrap with, I think one of the things that is happening is we are building on some good things that we've done. Because you see policy as code. Now that's policy guardrails, right?
You see, even see behavior behavioral because of the unpredictable nature of generative ai, uh, behavioral and outcome based. There's different names people have for this, for the output to make sure that it's accurate. Um, the others, I spent some time the, with a company that's taking the output of AI and then putting into, into structured languages, traditional languages for further execution.
So you aren't using the same resources, but also getting more predictable results. Kind of a hybrid approach of AI plus structured code. We're we're building on things we've, we've done including identity management.
Not saying it's solving the problem, but we're, but we're not starting from scratch either. Like how are we gonna secure those APIs? I don't know, maybe we should like put a, put an account on there, et cetera.
So I'm, I'm, uh, cautiously optimistic, mostly hopeful that we'll do better this time. Even if it's marginal, it's better. I love the hope, Mitch.
I, I appreciate it, but I also appreciate having Alan here to remind me that we've had hope before. Yeah, keep hope alive. Keep hope alive.
Alright, I think we'll go ahead and wrap up the episode today. On that note, um, you know, we've got a lot of things in the air right now. I know it's the end of the year for most everyone listening to this podcast.
I'm sure you probably hopefully have implemented change freeze December so that you're not dealing with any other craziness, but we've got a lot of stuff coming out. Uh, Mitch, what's something you've got coming up that people definitely wanna be checking out? I definitely want folks to check out the agent of Cha, agent of dev podcast that I'm doing with Brad Shiman.
It's all about sort of what's real and what's happening in AI agent and agentic development, you know, across the SDLC. So that, and both of us are coming at it as analyst and folks that have a practitioner background. And I, and I've got a number of reports.
We just did our AWS report, uh, combined with a bunch of analysts. Uh, right now we're kind of tuning the practices, so there'll be some information coming out about what I'm gonna be doing with the software lifecycle engineering. So keep watching, watch LinkedIn, 'cause that's, that's where I post everything.
Great. Alan, what have you got coming up? 'cause I know you've been a really busy man.
Yeah, I mean, you can keep up with me on LinkedIn or text junk tv, but what I really would like to call the people's attention is coming up after the first of the year. I think it's January the week of January 9th, something like that is our annual virtual event called Predict. This year, of course, it's Predict 2026 starring our FUTURUM analyst team.
And each one of the analysts will be doing sessions on, uh, what they think is the big story, what they think you need to know for 2026. And, uh, it's always a great event. I think this year with the FU team it's gonna be even better.
com and look up Predict. But it's free to register and attend and ask questions and it's gonna be a great event and I'm really looking forward to that. And We thank you all for listening to this episode of Security Boulevard podcast.
Remember, if you enjoyed this conversation, we would love it if you would subscribe on YouTube, make sure you hit the notification bell and, uh, get all those updates. Or you can also subscribe to us in your favorite podcast application choice because we don't want you to miss any of these episodes. Do us a favor, leave a rating and a review and a comment.
All of those things really help us get noticed by a lot of other people out there. And if you have somebody that really needs to understand security, this is the best place to do it. So send it to a friend.
com and the Futureum Group. com. The Techstrong TV website or the techron TV app, which runs on Apple tv, Roku, any kind of smart device that has a screen, that app runs on it and you're gonna want to check it out.
We also want you to check out our socials because we are on x, Twitter and LinkedIn as security BLVD. And there's a lot more content out there that you're gonna wanna check out. We thank you very much for tuning in for this episode.
We'll see everybody next week.