AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
Season 2 of ClearTech Loop is built around three questions:
How is AI changing the way organizations think about risk?
What does stronger cybersecurity leadership look like right now?
How should leaders rethink cloud strategy as business and technology keep shifting?
Hosted by Jo Peterson, Chief Analyst at ClearTech Research, ClearTech Loop is a fast, focused podcast covering AI, cybersecurity, and cloud risk through a business leadership lens.
Each 10-15 minute episode explores the issues shaping modern technology strategy and the decisions leaders cannot afford to ignore.
From governance and resilience to infrastructure change and emerging risk, ClearTech Loop helps leaders make sense of what is shifting, what matters most, and what comes next.
AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
Your AI Agent Just Found Everything You Forgot to Secure
•ClearTech Research / Jo Peterson•Season 4•Episode 3
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
0:00
|
13:35
AI agents are gaining credentials, permissions and the ability to act across enterprise systems. But what happens when they discover years of forgotten files, excessive permissions and data that was never secured with AI access in mind?
In this episode of ClearTech Loop, Jo Peterson talks with longtime technology analyst and Forbes contributor Joe McKendrick about the security implications of the agentic workforce.
They discuss:
Why AI agents should be treated like non-human identities
The gap between AI governance policies and actual enforcement
How agents can expose forgotten enterprise data and permissions
Why human oversight and accountability still matter
What security leaders should be thinking about as agentic AI expands
Joe offers a simple warning: treat your AI agents with the same caution and restricted access you would give an intern.
Because AI may not create your security debt.
It may simply be the thing that finally exposes it.
Hey everyone! Thank you so much for joining this session of Clear Tech Loop. I'm Jo Peterson. I'm the CIO of Clarify 360 and the Chief Analyst at ClearTech Research, and I'm here today with mr. Joe McKendrick. Hi, Joe.
Joe McKendrick:
Hi, Joe.
Jo Peterson:
hi Joe, two Joes in the house, two Joes,
Joe McKendrick:
yeah, two Joes, yeah, three Joes, two Joes.
Jo Peterson:
In case you're not familiar with his work, go check it out. He's a senior contributor for Forbes, CNET, and Information Today, and has been for years, and he's a respected tech analyst and author. So, let's dig right into the questions. Jo, AI agents hold delegated credentials. They make authorization decisions in real time, and they can spawn subagents with their own permission sets. Do you think the non-technical C-suite has a grasp of the organizational security concerns that come along with this agentic workforce?A
Joe McKendrick:
Wow, Joe, you know it's a really big topic. You know, and and and frankly, we're just only starting to understand the implications of having an agentic workforce. You know, digital workforce or whatever you want to call it. And frankly, I don't think the non-technical business leaders really have a grasp of these implications yet? You know, yeah, they see the potential cost savings. You know, that's that's been the the big deal. You know, replacing people with AI agents, which is which is really wrong-headed thinking, in my opinion, and the subject of a whole different conversation, right? A whole different webcast. But these leaders need to look beyond the temporary cost savings being dangled in front of them, and and think about the long term implications of of an agentic workforce of bringing in these AI agents. And I'll attempt to drill down on a couple issues that aren't necessarily at the forefront of corporate thinking. But you know, let's see if we can, you know, get the conversation started around there, and you know, just to start with the external risk, you know, the external risk coming from the outside. You know, you have an agentic workforce, but unfortunately, so do the bad guys on the outside now, and they're likely way ahead of us with the technology as well. You know, remember the show Breaking Bad with Walter White's fictional meth enterprise, you know it may have been a pretty nefarious, but you know it provided viewers of the show a lesson in what a highly efficient business model should look like. Right, extremely tightly enforced production, very tightly enforced. You know distribution partnership. repeat business, all that stuff, and today's bad guys-they they run on the you know similarly really efficient business models. Unfortunately, for the rest of the world, that leverage the latest technologies, including AI, and are are light years ahead of legitimate businesses, you know, and and they tend to be the earliest adopters. Unfortunately, for the rest of us, you know, those phone calls from top executives to employees. You know, employee gets a phone call from someone in the C-suite. You know, police transfer $200,000 in corporate funds to such and such an account. You know, that's you know deepfake. You know, that's coming out of the AI world. You know, and it's all automated, so the bad guys don't even have to work for a living anymore. You know, and you know businesses aren't ready, quite ready to handle all this AR, this AI born tsunami of external security, cyber security threats coming their way. In fact, a survey I just saw a survey that finds 56% of security managers in the survey say they saw an increase in AI-driven attacks over the past year. So the bad guys are on the loose. They're using these agents for their nefarious purposes, and not good news for the rest of us.
Jo Peterson:
That's a true story, you know. And I like the word tsunami Because unfortunately, we're just starting to see that stuff kind of tease out, right?
Joe McKendrick:
Exactly.
Jo Peterson:
So we are. So another percentage here: 50% of large enterprises now have dedicated AI governance committees. Is that structure actually working, in your opinion, or is it more about creating the appearance of governance without some real substance behind
Joe McKendrick:
not relegated to the IT department. You know, they're not they they're not to be used or seen as technical committees. They need to. As diverse across the business as possible, you know. I just read that a lot of organizations are actually hiring philosophy majors to help them sort through the rights and wrongs of AI decisioning. You may not have philosophers or ethicists on your staff, but it certainly helps to make a broad to have a broad representation of your business, you know the the C suites executives, the marketers, operations people, production people, even salespeople, right, and so on. So you need you need that you need to have that committee, and you need to have the the organization well represented and different points of view, different points of ways of looking at AI to really make it effective.
Jo Peterson:
Who would have thought we would put philosophy and AI together? But if you think about it, it makes a lot of sense because you know you're trying to teach someone that's not a human being right and wrong.
Joe McKendrick:
Yeah, exactly, exactly. Yeah, when it comes to agents, agent accountability-you know-similar to human accountability, it needs to be part of the equation. You know, you need to treat your AI agents with the same levels of caution and restricted access as as you would an intern. You know, you wouldn't give an intern access to your corporate accounting system, for example, or your corporate payment system. You know, you need to audit your agents' activities frequently understand what what they're doing. You know, implement the human in the loop. Keep a human in the loop. Loop. You know, assign very specific responsibilities around agents and monitor them closely. You know, you you need to have. You know, most companies have existing cybersecurity policies. You know, going way back and have developed. You know, through the digital era and so forth, and they need to be extended to cover these these these these agents, these non-human identities that are emerging. You know, and agents are getting smarter. You know, they're developing more capabilities. They're acting more like humans, and you know, when it in terms of interacting with systems, but they're still a different class of employee, and you need that transparency. Transparency, you need to understand what are they doing behind the scenes. You know, you know, and and you need to understand. You know what what happened when an action was taken against a certain system. You know, was it human that took the action? The service account. You know, was it an agent? You know, what's going on with that? And odds are, you know, your team probably doesn't know the answers to these questions with 100 certainty. You know, more and more to our systems, agents look like humans and have a lot of permissions. You need those guardrails, and at the same time, you need to strike a balance. You know, you want your agents to be creative. You know, in terms of how creative an algorithm could be, but you want to have have them. You want them to to be able to contribute at least to that sense of creativity, but you need to have those guardrails to to keep them in line as well. You don't want them going rogue. And in fact, I just saw a survey from EY that that shows that 75% of enterprises actually lack such guardrails. So it's a it's a it's a it's a wild west frontier, and we need to start really regulating what's going on within your agent workforce.
Jo Peterson:
Yeah, that's that's interesting, and you know you make such a good point about them being interns. They are, they just are. All right, last question. I'm the new CISO in town. It's the wild, wild west. I've walked in and realized that you know it's the wild, wild west town that I've walked into, and like that phrase. And I I know that I'm already behind, and so I've got 30 days to put some things in place. And when I say I'm behind, I mean I've got no inventory. I've got no agent-specific controls that you just talked about. I'm not monitoring. What do I do first?
Joe McKendrick:
Okay, Jo. The key is trust. You know, trust is everything. You know, it's trust in the data, trust in the AI models you're using, trust in the viability of your governance model, and there's if there's one thing a security leader should do as they as they step into the job is to take a really good look at what's going on across the industry, what the industry is doing in terms of securing agentic AI. You know, pay attention to the standards, the protocols that are being developed to build greater trust in AI, and I'll give you a couple examples. You know, Thomson Reuters, for example, recently formed a group called the Trust and AI Alliance. It's it's got Anthropic, AWS, Google Cloud, OpenAI. It's again, it's the Trust and AI Alliance, and and they're dedicated to engineering more trust into agentic systems. Another group that's been around for a while, the Data and Trusted AI Alliance. You know, it's formed by enterprise CEOs and CIOs. You know, to build cross-industry data provenance provenance standards and AI vendor assessment frameworks. Nvidia has just been active in in. Group called the Open AI, the Open Secure AI Alliance. Rather, they've got Microsoft, IBM, Cisco, Adobe, some of the big players. You know, and they're devoted to building open tools and secure models. So you got some groups that really take to look at and understand what they're doing to you know to to move these things forward. Just a couple weeks back, I actually had the opportunity to sit down with the Secretary General of the IEC. That's Felipe Mesker, an important standards group, and he talked about what the standards, the International Standards Group, is doing to secure AI more concretely. For example, they just launched standards for a range of AI trust concerns, including industrial automation, cyber security, and industrial industrial processes, you know, it's kind of building on. There's an existing 27,000 standard they call, which deals with IT security, information security, and their goal, their what they're doing now is building on that to ensure that AI works within this security framework. You know, they're adding AI, if you will, to what they already have in terms of security for for a lot of systems. So there's a lot of activity in there, and the advice is, you know, you want to build trust, you want to come in, you want to build trust in what your company's doing with AI and with agentic AI. Look what's happening across the industry to ensure that.
Jo Peterson:
That's that's some good advice, and you're right. There are some great places and resources that people can go go to and take a look and read about what others are doing. We're in a better spot that way than we were a year ago, right? So that's kind of good that folks are getting together and applying some thinking and helping, you know, the collective about some of this. So that's that's kind of good. So one thing's for sure, it's gonna keep moving forward, and it's gonna keep moving forward fast. So you know, maybe next time next year when we talk again, we'll we'll have even better frameworks to talk about.
Joe McKendrick:
Yeah, and Joe, if I can if I can talk about one other
Jo Peterson:
yeah
Joe McKendrick:
one other thing, I'm aware of there's there's companies out there that have rolled out agentic AI, generative AI, whatever whatever the the you might want to call it, and they've discovered that they've had to shut the systems down because they've discovered that these systems, these agents, are basically crawling across the entire enterprise, pulling in everything that's been out there in the enterprise in SharePoint repositories, PDFs, PowerPoints, contracts, whatever you name it, pulling it all into their AI systems. You know, and the the information out there, this information has never been vetted for security. You know, it's stuff that's been sitting out there for years,
Jo Peterson:
right?
Joe McKendrick:
Many cases, and all of a sudden, here's AI. You know, with a prompt, bringing this all in, exposing all this. You know, in this case, in the cases I've heard about with internal employees, which may or may not be good for the security of that or that that that information, so that's another issue that's that's out there that needs to be addressed.
Jo Peterson:
I think that's fair, and you make a really good point, right? So I'd love to have you back another time, and we can talk further.
Joe McKendrick:
Yeah, yeah, it's it's a fast changing market. It
Jo Peterson:
is all right. Well, thank you again, and thank you everyone for joining. And we'll talk to you next time.