Agentic AI Management Challenges with Oasis Security’s Marta Dern Simon
In this interview, Marta Dern Simon, senior product marketing manager at Oasis Security, discusses the emerging challenges of managing AI agents, particularly around permissions and security. She highlights the complexities of securing these agents as they expand organizational attack surfaces, emphasizing the need for proper oversight and the potential risks if security lags behind innovation.
Transcript
ai video series Army host Mike Ard. Today we're with Marta Dern Simon, senior product marketing manager for Oasis Security. We're talking about AI agents and how many of them they're gonna be and they all suddenly need to have permissions and well, it might be like adding thousands of employees to the environment overnight.
Mara, welcome to the show. Welcome Mike. Thank you for having me.
So walk us through here. What are we not really thinking through well enough when it comes to all these AI agents? 'cause um, I've lost count how many of them there might be and even in a small organization.
Yeah, so first of all we, there is a big discussion now and I think it's very interesting if we should treat them as humans or as non-humans, right? So are they really employees? Are they really very similar to your, to another employee in your organization?
For sure, yes, but at the same time, we cannot treat them as humans. 'cause for AI agents, who are they and who is the owner and how do we authenticate them so we can use MFA really? So that's why A always is, at least we are pushing to, towards leaning into AI as non-human.
So as workloads because at the end an AI agent, it is really like a human, but they can, they decide, they, they are independently deciding to like how to work and how to accomplish a task. And sometimes that doesn't work as, as similar as humans, right? So we need to be careful on how we treat them as humans or non-humans.
Do we need a new category that's somewhere in between? Could be, yeah. I think, I think that's a, an interesting approach, especially as how they evolve.
I think it'll be interesting to see what companies decide to do for sure. Now won't these agents also have privileges and won't that make them kind of primary targets for somebody who's gonna try to hack in and either a try to get them to do something or pretend to be them and escalate their privileges? Absolutely, absolutely.
I completely agree with you. I mean, AI agents, at the end, what they're doing is expanding the perimeter again. So they are expanding the attack surface, right?
So if you don't have, if you don't know what you have in your organization and you have an AI agent doing certain tasks and this one is not properly secured, someone could hack in and then they are in the organization and that's, there is a name for that already. It's LLM jacking. So it is there, companies are started paying attention to it, I'm sorry to say, but every time I've seen any new innovation, it usually takes the security question to kind of catch up by about, eh, a year, year and a half, sometimes two years behind.
Are we gonna get any better this time? I mean that's my hope. I I think so.
Um, I think we are already in a good position, right? I think we are already trying to catch up. It's not like all the cases that it has taken a couple of years.
I think in this case a lot of companies are already pushing towards securing AI and not only using AI in their companies to secure, but also how to secure this ai, right? It's like two different approaches and it's very confusing. So do you think the bad guys are sitting around looking at all of this and kinda laughing to themselves going, you know, thanks guys for the larger attack surface.
Um, I think, I mean I'm, I hope they are not laughing at this. I cope we are putting some barriers to them also, I think that sometimes we think of AI as, oh it's easier for me and I can just look at cha GDP and find like, I dunno, uh, quote code using cha gb. That's easier for me.
But at the same times, like the bad guys also have cha g dp, right? Or they have any other AI tool that they can leverage. So we need to be careful because AI can be like a, so like it can be a pro and a con at the same time.
Who's in charge of this? And I'm asking that question because finding cybersecurity people was hard enough. Finding cybersecurity people who understand AI is even harder.
And so I'm kind of looking for a unicorn and um, where would I find the talent? First of all, I think that for at least maybe that's the first innovation my age has lived through, right? Because we were, I was like, I was young, very young with the internet.
I, I kind of grew up with internet. For me, the mobile and devices, it was also in the growing up experience. That's the first time I'm in the edge, in the edge of the technology.
Like we are learning at the, at the pace of the technology, it's not that we are outpaced is we are really really learning on it, right? So I think security specialists, they are already using AI in their advantage. So in Oasis we are already like our security people are not only security, they all, they all know about ai, they are all learning about ai.
So I think that's a little bit my faith that security people will also lean towards ai. You also seem to be implying that there might be a new generation of folks that we would call AI native who grew up with the technologies and kind of understand it, um, as more of a natural extension of everything they do. I I that's, that's my vision 100%.
I mean we are seeing it with Google for example. People are not longer looking terms, right? When we search, we not only search for something, we just, myself, I just go to wherever LLM model I'm using and I ask for the question like, Hey, do you know this?
How do I look for this? And I expect the answer, right? So we are already seeing the change in the search.
Do you think as we have AI agents and they're assigned a specific task, we'll have AI agents for security and they will monitor the other AI agents to see what they're up to and provide some governance and you know, the AI agents will kind of look after each other. I think that's, that's a bit metrics, at least in my head. It's a bit far away.
What I do believe is that we'll have AI agents to like pursue some tasks and then we'll need some humans to oversee everything, right? So it won't be like an ai an AI agent controlling another one. At some point you will have someone overseeing the complete process.
How many of these AI agents are gonna be, do you think, packaged in an application that I'm gonna buy that I'm hoping somebody else may be responsible for? And how many of them are gonna be more of these kind of custom agents that I built to manage a process? And I guess I'm trying to figure out if different agents will require different levels of security and governance.
Absolutely. And I think that's, I mean at the end when I think of AI agent, I also think of the supply. For me it's like a relationship also to the supply chain, like security, right?
So you are as vulnerable as the most third party vulnerable in your organization is. In this case, AI agents will be the same. Um, I I, I'm not thinking about numbers right now, but I do believe that we'll need to classify AI agents with the most privilege, with more security as we do with identities, right?
As you, we do with humans. Like your user account is not as privileged as a, uh, an account controlled by your pm. So I think we'll need to establish the same type of relationships to make sure each AI agent is as secure as it needs to be, but not more than that, right?
So we don't want to um, slow down innovation. We don't want to slow down the process. We just need to make sure the innovation goes in within security, right?
So it's an a secure innovation. So what is your best advice to folks about how to get ready for all this? What should they be doing?
I mean, in some places, I'm sure employees are already using AI agents, they just don't know about it. But, um, how do I kind of get in front of all this? Yeah, so I think I, I had this conversation with a customer the other day 'cause they were already like, they were asking the same question you are right now.
And I think it was interesting because what, for example, their approach was like, let's first clean up everything I have, right? So what we see in companies that even before ai, AI agents, they already have a lot of accounts that they don't know they have and they already have a lot of like, mess from the bus, right? So I think the first step is clean up your environments, making sure you only know you, you know, all the accounts that you have, you know everything that is in there.
And then once you start using AI and you start using AI agents, make sure you know what are these AI agents doing and what, what up to what up to what things can they do, right? So up to what permissions they have to do stuff to make sure they don't do certain things you don't wanna do, you don't want them to do or they don't want, you don't want them to access certain information, you don't want them to access, right? So just make sure everything is clean and make sure you rightsize them so nothing unexpected happens.
And then of course monitor them, right? Because if in the hypothetical case that something bad happens, you cut it early. So if you cut it early you can like modify whatever needs to be modified.
So I think it's a three step approach where you say, okay, let's clean everything. Let's make sure we rightsize the permissions and in case that doesn't happen, let's monitor to fix whatever needs to be fixed. What are the odds that something will go wrong?
Because we've been talking about hallucinations for a while now with gen AI and prompts, but now we have AI agents that I don't know, are they more narrowly trained and maybe are a little more reliable? What, what's the difference? Up to this point, what we were doing is we were using AI but from a workflow perspective, right?
So we were automating a task and the AI was just doing the task. We, it was supposed to do the one that we told him. Now with agents, we are just giving the agent the capacity, like the objective, right?
We are saying hey, I want to accomplish this task and then AI agent will do whatever it takes to make sure they accomplish the task. So that's the difference. In the past it was okay, it's a certain number of steps and they will repeat it and they will do it every time the same way.
In this case the AI agent will do the task and if it can be like it will learn from it and even opt optimize it from it, right? So that's a little bit how it difference like the new generation And am I gonna get confronted with, you know, a hundred agents for each app or will there be kinda like one super agent that talks to all the other agents? And I might not see those agents, but I still gotta figure out how to secure them.
I would, I I hope it's the first one. So you have one agent per each task as you do with any service accounts in the past, in your active directory that you had one per task. I hope it's the same way, right?
Because then you can like assign the least privilege access possible. If you have one super agent, that one will need to be like a domain admin, right? And we don't want that.
We still want to follow the principles that were like, that are already running the world. We don't need something new. We don't need a super agent, we just need to make sure that the, the agent is capable of doing the task with the least privilege possible.
So unfortunately people don't usually pay attention until something really catastrophic happens. So how long will it be before we see that first catastrophic AI agent security incident that makes everybody kind of wake up and do something about this? I, I hope it's little than sooner to be honest, but I think we are not that far away.
'cause many companies are implementing AI and maybe they were not ready for it and maybe they are not taking the enough precautions, right? And sometimes there is already like um, shadow it and there is a lot of possibilities to like these AI agents are a lot of times out out of no go tools. So more people are like, they are being democratized, like democratized.
So more people can get to them and can implement them, right? Even if they don't have that much knowledge on security or security is not even top of mind. So I hope it's not that soon, but I would not be surprised Folks.
Well you heard in here they say to be forewarned is to be forearmed. Hopefully that will play out again in the age of AI agents, but I got a feeling that we might have to learn this the hard way. Hey Marta, thanks for being on the show.
Thanks you so much. Take care And thank you all for watching the latest episode of the Techstrong AI series. You can find this episode and others on our website.
We invite you to check them all out. Until then, we'll see you next.