Atera CISO Warns of Rising Cybersecurity Risks from Shadow AI
Atera CISO Noam Vander dives into why usage of shadow artificial intelligence (AI) services is going to wind up being a much bigger cybersecurity issue than most organizations currently appreciate.
Transcript
Hey guys, thanks for the throwaway here with Noam Vander who's CSO for a and we're gonna have a little chat about what's going on with shadow AI from a cybersecurity perspective, because, well, it's rampant, so no, welcome to show. Thank you. Thank you, Mike.
Uh, thanks for having me. Just about, everybody's using some form of AI at this point, and a lot of people are copy and pasting data into these things without thinking about it too much. And a lot of the usage of these things is not even being tracked.
If you're a CISO at this point, what are you supposed to do about all this? 'cause it's not like you can just run around and wave your hands and say no. Yeah, yeah.
If you're a ciso, that's definitely a current problem. Uh, if you haven't discovered it already, then, then, then you have it. Um, the, the, the main plan with shadow ai, just like shadow it, um, is really to try and discover what you have, um, assess the risk, and then, uh, try to govern it, try to govern, uh, uh, all that you've found.
That's the, the basic plan. There's a lot to do in order to achieve it, but, uh, but that's the plan. Are there certain, uh, services for AI or maybe even on premises approaches or whatever that are inherently more secure than others?
Or is it just a matter of figuring out which ones to use and putting the right controls in place? Um, yes, you can definitely, during the vetting of new AI tools, look for services which are inherently secure. Um, starting from, you know, that, that's what I ask when I vet, uh, ai, uh, tools.
On, on what models, uh, are, are the, the, is the AI based on, in inera or based on Microsoft? Uh, open, uh, OpenAI, uh, on Azure. That's a really robust, uh, AI platform, and it gives us, you know, uh, enterprise grade security.
So it's really important to see that these tools are based on, on, on, on an enterprise grade, uh, company. Uh, you gotta make sure the companies, uh, incorporate, you know, AI security tools, understand what they do with your data, who can see it, if the customers can see it, if they're, if they train, uh, um, um, based on your data, there's a lot you can check to make sure if an AI tool is secure. Mm-hmm.
Do we need to educate the end users? Because most end users that I know didn't read page 400 of the licensing agreement, so they have no idea what's going on with the data. Yes, definitely, definitely.
Um, achieving, uh, a security goes through working with people. Uh, you have to educate, uh, on your policies, on the risks of the usage with ai. Uh, you have to educate 'em.
If we're talking about shadow AI to, to, to come to you before they use any tools, a lot of that, that's the main reason shadow AI is created. Uh, employees don't come to it or security before they start, they start working with ai. So we have to educating you, you have to have a good process.
Uh, you have to incorporate it in your general security awareness trainings. Definitely without it, it's, it's, you can put in all the technology you want, but you have to work with the people. I think for a lot of folks, the threat is theoretical because they're entering data and they're not realizing that the LLM that's underneath whatever it is they just entered, is gonna use that to train a future iteration of that AI model.
So we may not actually see that data show up somewhere where it's not supposed to be for, um, months even, maybe even years. So, um, do we just not have a sense of urgency because there isn't at this point anybody who we point to as the victim? Um, yes.
Maybe that, that's a, that's a good observation. I mean, for us, it's definitely an issue and, and we do have a sense of urgency and we make sure to opt out of any model training and, and to work only with ais that allow you to opt out of model training or promise you that they don't do training. Um, but it's definitely a problem.
I don't think, think it's, it's theoretical. I mean, each shooter today have as 4, 5, 6 AI tools. Definitely some of them, usually the small ones, the free ones, uh, they, they train their, their, their models based on your data.
And it's a problem. And I believe that in the future we'll start seeing data leakage and, and security incidents that, that they're derived from it, from, from training of customers data. The other thing that comes to mind is that, um, not everybody seems to be equally embracing ai.
And I bring this up because we'll have 20% of the company who are hardcore advocates and 20% are probably over my dead body, and the other 40% don't wanna admit that they're using it. So how do I have like a conversation that says, um, you know, it's okay there for everybody to kinda maybe come clean about what they're using AI for so we can have a more intelligent conversation about governance and security? Um, yeah, that's a good question.
I mean, it, it depends. First of all, it depends on your company's risk appetite. I mean, there are companies that, that, that can't afford use ai, but, but most companies, uh, especially competitive sales driven companies, they, they have to use AI today.
You have to, to stay ahead of the, of the, of the market, um, and, and security teams, you know, it's a cliche, but they, they, they should be enablers and they, they should work with stakeholders and find ways to make that work. And there are ways, I mean, saying no to ai I is, is not a good practice. You have to understand the need and find ways to secure it and, and enable it to, to, to your employees.
Mm-hmm. I also feel like maybe it'll get harder to detect. 'cause today there's still this notion of that I'm gonna go use an AI tool when there's chat GPT or whatever.
But going forward, it seems to me all this stuff is gonna be embedded inside of another application. And I might not even be aware that, uh, or care that I'm actually using a Gen AI LLM somewhere that's external to me. 'cause it's all hidden inside the application.
But then I don't know what happened to the data 'cause it was a SaaS app. So do we need to be a little more cognizant of how these, um, models are gonna be embedded into everything? Yeah, this is, this is where, yeah, that's a good question.
This is where vendors have to step, step up and, and, and, and embrace transparency towards their customers and, and be transparent about the usage of ai, whether in the UI or the backend and, and, and, and, and how they use it. This is something that, that we atera have identified early on and we're very transparent about how, how, uh, uh, we use the data, what, what AI does, and this is something that's really all vendors should embrace. Mm-hmm.
What do you think the regulatory climate's gonna be like as it applies to the usage of these tools? 'cause well, you know, maybe here in the United States we're gonna be a little, uh, freewheeling and then Europe seems to be a little stricter. Is it gonna be different by country and region?
And I gotta think through different regulations. Um, there's always a difference. I mean, there's a difference now with, with regular data privacy, GDPR and, and different state laws in the us and, and, and each country has different laws and, and it's, I'm guessing it'll be the same with ai.
We have the, the, the Uua A U act right now, which is kind of the, the beacon. Uh, and there are a few other, uh, regulations and they're different. But at the end of the day, it's, it's based on the same best practices with, uh, certain changes.
Uh, but yeah. Yeah, I'm, I'm guessing there will be difference and, and it, it, it's sometimes tough as a, a product company to maintain all of them, but, but this is what, what what you have to do to, to make, uh, your, uh, customers feel safe. Mm-hmm.
I can't help but wonder if maybe security people should be at their forefront of usage of these tools. 'cause the best way to understand what the issues are is to be an end user in the first Definitely, definitely, uh, security version. Not different from any other, uh, company, uh, employee stakeholders.
Um, AI is affecting cyberspace immensely. Uh, whether you're an attacker or a defender and you have to start leveraging ai, we're seeing more and more security vendors leverage ai. We're seeing a lot more tax that leverage ai.
Um, so definitely security practitioners, it must start, uh, uh, leveraging AI in everything they do. Mm-hmm. Also, it seems to me, with the rise of AI agents, which are kind of like the next level of ai, yeah.
Um, we're essentially creating, uh, an entity, for lack of a better phrase, that manages a process. It's autonomous. Doesn't that become like one of the juiciest targets in the world?
Because now I can take over that entire process by targeting that agent, and all I need to do is compromise the agent's credentials and away we go. Yeah. Agent agent AI is, is, is a great thing.
It's incorporated in, in, in terra it autopilot and it's wonderful. But yes, it also, uh, brings new risks and new security concerns. Uh, you really have to put a lot of guardrails around your AI agents, uh, which is something that we have done.
Uh, and you have to put boundaries around what it can and cannot do. Uh, and I expect, and I, and I, and I've seen some, I expect more and more security tools, uh, to focus gent AI security, uh, and this is where the industry has to step up and provide us, uh, with the tools to, to, to, to guard ourself from, from agents. Mm-hmm.
And of course, we're gonna have shadow AI agents, just like we have shadow AI tools. And so will that be the thing that kind of breaks the camel's back and creates that level of urgency that we need? Because in, you know, I'm suddenly thinking about this.
There could be hundreds of thousands of AI agents running around out there, and we don't know exactly what they're all up to. Yeah, that's right. I think, uh, OpenAI just announced, uh, they're a new public AI agency.
Everyone could use their agent to do whatever he wants. Uh, yes. It, it, it will be problem much like it's, it's another subset of shadow ai.
Are you using unapproved, uh, uh, AI agents? Um, but in the end of the day, if you do follow, you know, the people process technology, you educate the people, you have good processes and you embed the technology that that can detect it. I mean, if, if you use, uh, uh, sass E or CA sb that that, uh, uh, you, you have pretty much full visibility of, of, of whatever your users do in the cloud, including, uh, uh, work with the AI agent, uh, then, then, then you should have the ability to control and, and know about these, uh, type of actions as well.
Mm-hmm. So how granular is my level of control gonna get? I mean, am I gonna be able to detect individual end user's usage of a unsanctioned tool and then what, send them an alert or a message that says, you know, we can see what you're up to and we recommend you use this tool over here to go do that?
Definitely. That, that's my expectation. Expectation.
If you combine CASB capability with DLPs, either traditional or AI focused DLPs, then you should have, and, and there are some tools already in the market are usually startups, uh, that that can do it. Yeah. They can control which AI tools you're using.
I mean, the, the basic level is control, which AI tools you're using. You can use that, but not this tool. Another level is, okay, you can use chat GPT, but, but you can't use your own private chat GPT, only our corporate JGPT and another level could be a really DLP, which you can enter certain data into your chat, but data that we have classified as sensitive is, is going to get blocked or replaced by fake data.
This is, this is something that, uh, there are a few startups today that, that actually do it via either, uh, something on your endpoint or browser extension. Mm-hmm. Is it your sense that we'll be able to extend the tools we have to deal with these issues?
Or do we need to add yet another layer of security in another layer of defense, which, uh, everybody kind of bristles that because, you know, that's another layer of cost. Um, if you'd asked me that like six months ago, then I would say, yeah, you, you're gonna see a lot more AI security dedicated tools. Uh, um, but I think once the big vendors are going to get into it, and we saw this week Sentinel One purchasing, uh, from security, which is an AI security tool, uh, I'm guessing that more and more AI security will go into, uh, the current tools and it'll be like a, a specific area.
Uh, and it'll be incorporated in your usual tools. I mean, your EDR will now also protect you from certain endpoint AI security risks. Your CASB will have an AI security, uh, pain or a filter.
Um, so yeah, I think the bigger vendors are getting into it and, and it'll be incorporated in them. Hmm. So what is your best advice to your fellow CISOs then about how to go approach all this stuff?
And, um, is there some way of thinking about this that is maybe not intuitively obvious that folks should kind of just take a minute or take a breath and come up with a plan? Yeah, it's, it's, it's a tough issue. So yeah, really, first of all, if you're not doing something about shadow ai, you're, you're missing it.
You gotta, you gotta do something about it. You gotta acknowledge it, you gotta incorporate it in your work plan. Uh, you, you can start small.
You don't have to violate the tools and stuff like that. Work with the people, uh, with the stakeholders, uh, come up with some policy, uh, communicate with your management about the risks, uh, understand the risk appetite and, uh, really be, be an enabler of this, uh, come from a positive way that, that, that you think, you know, this AI is great, it's a great tool for, for every company, but, but you wanna make it secure, uh, and, and really put it into your work plan. That's that.
Do something that's, that's the tip. I mean, a lot of companies are still tackling the, the, the old risks or the, the, the major common risks and, and putting that aside, but the, the, it's, it's, the risk is now. It's not theoretical.
Alright, well folks, you heard it here. The AI and Genie is out of the bottle not going back in, so we gotta figure out a way to live with it. Hey, no, thanks for being on the show.
Thank you. Thank you very much for having me mind. It was a great conversation.
Uh, thank you. All right. And back to you guys in the student.