AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
Season 2 of ClearTech Loop is built around three questions:
How is AI changing the way organizations think about risk?
What does stronger cybersecurity leadership look like right now?
How should leaders rethink cloud strategy as business and technology keep shifting?
Hosted by Jo Peterson, Chief Analyst at ClearTech Research, ClearTech Loop is a fast, focused podcast covering AI, cybersecurity, and cloud risk through a business leadership lens.
Each 10-15 minute episode explores the issues shaping modern technology strategy and the decisions leaders cannot afford to ignore.
From governance and resilience to infrastructure change and emerging risk, ClearTech Loop helps leaders make sense of what is shifting, what matters most, and what comes next.
AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
AI Agent Governance: Who Owns the Risk? with Benny Czarny of OPSWAT
•ClearTech Research / Jo Peterson•Season 4•Episode 1
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
0:00
|
14:50
Guest
Benny Czarny CEO, Founder & Chairman of the Board OPSWAT
Host
Jo Peterson CIO, Clarify360 Chief Analyst, ClearTech Research
AI agents have credentials. They access enterprise data. They make decisions. And increasingly, they can act without waiting for a human.
So who actually owns the risk?
Jo Peterson sits down with Benny Czarny, CEO, Founder & Chairman of the Board at OPSWAT, to talk about what AI agent governance needs to look like as autonomous AI moves deeper into the enterprise.
They discuss why every AI agent needs its own identity and a human owner, how least privilege should apply to agents and sub-agents, and why understanding what data an agent can access may be just as important as securing the model itself.
Benny also shares where CISOs should start if they don’t yet have an AI agent inventory or governance framework in place.
In This Episode
Why every AI agent needs a human owner
Least privilege for AI agents and sub-agents
The growing risk around AI data access
Why AI governance needs real authority
The first step CISOs should take in the next 30 days
Chapter Markers
00:00 Meet Benny Czarny of OPSWAT 01:40 Protecting critical infrastructure 02:05 Least privilege for AI agents 03:58 Permanent credentials and autonomous agents 05:15 Does AI governance actually work? 07:23 Where CISOs should start 09:29 Protecting the AI data lake 12:34 What AI can learn from OT security 13:12 Cloud, on-prem and air-gapped AI 13:54 OPSWAT’s own AI journey
Hey everyone! Thank you so much for joining this week's edition of Clear Tech Loop. I'm Jo Peterson. I'm the CIO of Clarify 360 and the Chief Analyst at Clear Tech Research. I am here with mr. Benny Charney, CEO, founder, and chairman of the board of Opswat. Hi, Benny.
Benny Czarny:
Hi, hi, Jo. Thanks for having me.
Jo Peterson:
Thank you for coming. In case folks are not familiar with Opswat, why did you create it, and what problem is it trying to solve for enterprises?
Benny Czarny:
So, for Opswat, we protect the world critical infrastructure. So we have a platform, we have technologies, and also we have a training academy. So many critical infrastructure. You know, pretty much a way of life, water, energy, defense. You know, they have a very very complex network. You have to protect them pretty much their entirety. You know, 99% protection is not enough, so you need to build purposely build technologies to protect them, and also they are lacking specific training to leverage this platform and to train the IT and cybersecurity professional within this critical infrastructure to protect organizations. So this is what we do. We are very global company. We have we we have more than 2000 customers globally. We have more than 1000 employees. We operate in more. Although we focus only on like 12 countries, we operate in more than 80, and we work with really really cool and exciting and amazing organizations.
Jo Peterson:
I love that. I love the training aspect. And in case folks want to find you, what's your URL?
Benny Czarny:
It's www.opswat.com, and the academy is www.opswatacademy.com. Actually, opswatamy.com exceeded 288,000 certified students, which is think about-it's almost the population of Iceland. Actually, we are only 50,000 short or so.
Jo Peterson:
That's awesome. Now I'm going to have to go check it out, of course, because I never met a cert I didn't like. So there's that, right? As everybody knows, this is an AI security podcast, and we do three questions. So let me just start. Many AI agents hold delegated credentials. They make authorization decisions in real time, and they can spawn sub-agents with their own permission sets. So traditional IM and Pam tools weren't built for this. What does a realistic path to least privilege access for AI agents actually look like for a large enterprise today?
Benny Czarny:
So see every agent it sends its own identity and and also limited permission. My biggest concern and one of the things that we deal with is the data flow to and from this AI agent, and also what's the data, what's the data lake that this AI agent is accessing, because you know, an AI agent without with the wrong permission and the wrong access to the wrong data could create a cybersecurity issue, a privacy issue, a privacy violation. So the so whenever you think about it, the sub agent should never receive more authority than the parent agent, and everything here should be limited by the data flow, the data lake, and also the actions that requires the human approval here. Sorry about that. I'm going to slide in my phone here.
Jo Peterson:
No, that's great. What you're saying is so important. The human in the loop is such a large, important part of things. And you're right. When you set the permissions, you can't be given the the sub agents more credentials than the primary agent.
Benny Czarny:
Now, there's one key aspect here that anybody dealing with building their AI agent, you need to be very, very, very careful here of creating permanent credentials, and and also autonomous agents. We all see what happened kind of last week with OpenAI. Are this is a very, very dangerous combination. So you can't really get it. And on top of that, at least my big big concern, things that I'm dealing with on a day to day, is the data flow to the data lake of these specific agents, and how to segregate this data lake from a specific AI agent, and also segregating different AI like different AI agents to to have access to different data lakes, and sometimes you want to get the sub agents also to further segregate their data lakes into other micro labs. So think about you want to truly control. Okay, think about every agent like a human being, and you want to truly kind of limit. Everything they have credentials and you know segregate that to a point that you control how the agents communicate and you know exactly how the agents are communicating and what access what data they access.
Jo Peterson:
I love the idea of further micro segmentation and and of course you're touching on the topic of zero trust, right? So, really important, particularly in this scenario. And I like the way you're thinking about it about creating almost separate data lakes, right? So that maybe that incident that happened last week doesn't happen again, right? So that's really important. Let me get to the second question here. So, 50% of large enterprises now have dedicated AI governance committees. Is that structure actually working, or is it creating the appearance of governance without the substance?
Benny Czarny:
It can walk. Seriously, it can work, but and I really think that we are like, how do you call it? We are pretty much at the early stages of governors of AI agents. We're early stage of AI agents, and we are very much kind of just trying to figure out how to govern, how to create compliance for that, how to create a good segmentation and segregation for that, and so it can work only when when we truly have a governance power. So what's the point? I mean, it's going to be because everything works so fast. I mean, by the time that you can react, it might be too late. So I do believe in that, and I do believe that the governance should be done, and also believing in AI agents to to to commit that. Though you need to also further kind of like you are programming a police officer, and then the committee it also should maintain a very clear inventory of everything. And also, if you program it right, then you need to also assign the ownership. You need to improve the control. Sometimes you need to maybe classify the risk before you do that, and and also you need to have the the power and the authority to stop any unsafe deployment. And that's it's a very delicate balance.
Jo Peterson:
Yeah, I mean, back in the day we had shadow IT, and it feels like now we have shadow AI. Of course, we have
right? So, last question:
You get to speak to a lot of IT leaders, I'm sure. Give us your advice if a CISO in this audience is starting from zero on AI agent governance, meaning some of the things you pointed out: no inventory, no agent-specific controls, no monitoring. What is the single most important thing they should do in the next 30 days?
Benny Czarny:
So that's a very loaded question. I would say number one, I would first build an inventory of all of the AI agents, and and by the way, you have already tools for that. I mean, we are using built-in tool for that. I'm also looking for external tools for that to get inventory of every agent, and and also make sure every AI agent have also a human behind it. So there needs to be an owner, and the owner needs to be like a human that very much controlling that. And then you also want to document and create a full metrics of responsibility where these agents are, you know, what are their permissions, what they can access, what's the data lake they can access, and then another key thing I would do, I would truly protect the data lake, because think about that. I mean, there was a there was a breach in acropic like four months ago, it was that hackers leveraged malware. They uploaded to Anthropic, and and then Anthropic accelerates the permutation of this malware. Why? Because and so think and this is Anthropic with all of these safeguards and all of these kind of person which exist. So think about other LLMs that you deploy at your organizations of all other agents. So the data lake needs to be super protected, kind of. So first, you cannot have a virus. You cannot afford to have a virus there. So you know, I just I just authored my first book, Cybersecurity Upside Down. It's about cybersecurity prevention through file regeneration, which is it is, but. by the way, it was bestseller. I also need to send you a copy, Jo.
Jo Peterson:
Congratulations! I love that.
Benny Czarny:
I got bestseller on honored by USA Today, so it's it's also going really well. So it's it's all about cybersecurity prevention through file regeneration, very effective to prevent AI born threat, so and and and I keep going to CISOs and convincing them, hey, anything, any data flow to your data lake should be regenerated. So you know that if there was kind of any AI born malware, it would be eliminated. It's a very it's a very deterministic. It's not in I'm not leveraging AI to detect AI. Simply assuming that there is a threat, and by file regeneration, assuming the data lake that AI agents will use is going to be clean. So I'm not trying to make a sales pitch right now. Maybe I just
Jo Peterson:
I love your thinking because you're really talking about going back to basics and defense in depth, and then you're applying things from other parts of security, like OT security is where we see air gap systems, right? We see that in OT a lot, and you're taking some really important thinking from OT security and bringing it mainstream. So I like the leveling up aspect of thinking about AI in a different way because it is unlike traditional cybersecurity. AI doesn't behave in a binary fashion.
Benny Czarny:
Yeah. So again, I'm bringing it from the cloud back to the super kind of era. I mean, like I would say, third, Third, third, third, third cloud, third on-prem, on-prem cloud connect, and third air gap completely disconnected.
Jo Peterson:
Right, and you're talking about the idea of changing the environment or bifurcating the environment as well, so that all your eggs are not in one basket, which is also very important, right? People get goofed up when all the eggs are in one basket because that's just a single point of failure. So, yeah. So,
Benny Czarny:
yeah, it's it's it's it's a journey. I mean, I'm seeing that. I'm in the midst of all of that with with obstacle. We have our own kind of IT challenges, right? We we just build our own CRM system using generative AI. We build our own portal and channel application using that. So we are dealing with customer data. So we see it. However, I find it way more predictable and way more secure than using any SaaS application.
Jo Peterson:
That's interesting. I like your take on it. I mean, it's we're all learning together, and I appreciate the insight. So it's really good. Well, it's been lovely having you here today. Thank you for making time to visit, everyone. I hope you learned something from Benny. I sure did. So Benny, we'll have to have you back. Great, great interview.