
News last month that one of OpenAI’s advanced AI models had escaped a controlled testing environment and hacked a start-up has sent shockwaves through the technology industry and alarmed policymakers. But it also underlined something cybersecurity experts have warned about for some time.
As organisations race to adopt artificial intelligence, a whole new class of security vulnerabilities has emerged, posing significant risks to businesses and forcing organisations to rethink how they deploy this transformational technology.
Chief information security officers (CISOs) find themselves on the frontline of this transition and must now strike a delicate balance: safeguarding the business while still enabling innovation at a time of dizzying technological change.
Boards are demanding change at speed, employees are experimenting with new AI tools and organisations can no longer afford security to operate as a barrier to progress.
CISOs must embrace evolution if they are to help their organisations unlock significant gains in productivity, innovation and competitive advantage – even if this means trying to reconcile the seemingly competing priorities of reducing risk while enabling safe AI deployment at scale.
From ‘no’ to ‘yes’
James Robinson believes the answer lies in a fundamental shift in the CISO’s role. Currently CISO at Netskope, the cloud-native cybersecurity and networking platform, he has spent the past 20 years helping organisations navigate an evolving threat landscape.
“There’s an old caricature of our role as the ‘department of no’, or the person who shows up to kill the project,” says Robinson.
However, in reality, Robinson says that the CISO’s role has been evolving for years – from one focused primarily on mitigating risk to one that enables the wider business to achieve its goals. But it is being tested more than ever in the age of AI, as CEOs push for adoption across the business and every department scrambles to adjust.
The result at many organisations has been a fragmented approach. Employees are using unapproved tools as part of “shadow IT”, often with the approval of senior leadership; best practice is not being shared; and security gaps are emerging across the business.
According to Netskope research, AI is now deployed in 73% of organisations, yet only 7% have governance that enforces security policy in real time.
Robinson says it would be easy for CISOs to retreat to old habits, but that would ultimately slow innovation. Instead, security leaders must adopt a “yes, if…” mindset – finding ways to deploy AI securely rather than simply blocking it.
“It needs to be a ‘yes, we can do this but how do we get you there and how do we do so in a secure way?’” he explains.
“What you don’t want to be is the person that holds up the company instead of getting it to that next level. If you look at every major breakthrough we’ve ever had, there were people saying you can’t do this, and guess what? We did it and made a breakthrough.”
Governance, guardrails and data protection
Deploying AI securely in the current technological environment is far from straightforward, however. CISOs must ensure they are protecting the business from all the traditional cyber risks, from phishing scams to malware. But they must also contend with an entirely new category of threats, as AI applications expand the attack surface, identify new weaknesses and enable increasingly sophisticated cyber-attacks.
It’s putting huge pressure on teams to keep up with bad actors, says Robinson. While 90% of cybersecurity professionals have increased their AI security budgets this year, 29% feel less secure than they did twelve months ago, according to Netskope’s research.
Robinson believes security leaders must focus on three key pillars to get the job done: governance, guardrails and data protection.
Regarding the first, businesses must establish the “right foundations”, he says, giving CISOs visibility, control and enforcement over AI use. This requires taking a more consultative approach in an environment where departments often circumnavigate security teams.
The CISO needs to be a visible partner rather than waiting until something goes wrong, then reacting
“The CISO needs to be a visible partner rather than waiting until something goes wrong, then reacting,” suggests Robinson.
The aim, he says, is to help employees make more informed decisions about the emerging opportunities and risks and to preclude AI applications that present higher security or compliance risks.
“As technology and security leaders we should be a voice of reason,” says Robinson. “We need to be able to help the business achieve what it needs to – but explain that to do so means using specific systems and partners that we may already have a relationship with.’”
Stronger defences
Governance alone, however, is not enough. Organisations also need technical controls that can enforce policy in real time without slowing the business down. That’s where Robinson believes modern security platforms have an increasingly important role to play.
Netskope’s platforms, which are used by blue-chip clients around the world, offer a range of technical defences designed for this purpose. One is real-time visibility, enabling organisations to detect risky AI activity as it happens, assess AI risk with dynamic and continuously updated risk scores, and apply controls and user coaching immediately.
“This helps tackle the shadow IT problem, giving CISOs oversight of AI usage before they even begin to enforce policies,” says Robinson.
Netskope’s AI Guardrails sit between users and large language models, understanding intent, inspecting prompts and responses in real time to detect inappropriate usage, as well as new threats including prompt injection and jailbreak attacks, and attempts to steal sensitive data.
It also integrates with data loss prevention controls to stop users from sharing confidential information, including intellectual property, customer records and regulated personal data, without approval. Every interaction is logged, providing organisations with the audit trail needed to demonstrate compliance and investigate incidents.
Success breeds success
The most common mistake CISOs make when it comes to AI is failing to put the right security foundations in place, believes Robinson: “Without this, the process of deploying AI becomes inefficient and the business cannot move as quickly as it needs to.”
He also advises CISOs to share best practice to create a healthier AI culture across the business, so teams aren’t so dependent on a centralised security team. “Success breeds success, so share how teams are getting on through the processes that you’ve created and others can learn from it.”
He accepts CISOs are under greater pressure than ever, but adds that with the right tools and processes, they can achieve their objectives and become more trusted partners within the wider business, playing a greater strategic role.
That matters, because to succeed in the AI era, organisations must view security not as a constraint but as an enabler.
“Security leaders need to support conversations about new business, new revenue and new products. If you can, you’re going to have a far stronger perception and better approval rating within your business.”
News last month that one of OpenAI's advanced AI models had escaped a controlled testing environment and hacked a start-up has sent shockwaves through the technology industry and alarmed policymakers. But it also underlined something cybersecurity experts have warned about for some time.
As organisations race to adopt artificial intelligence, a whole new class of security vulnerabilities has emerged, posing significant risks to businesses and forcing organisations to rethink how they deploy this transformational technology.
Chief information security officers (CISOs) find themselves on the frontline of this transition and must now strike a delicate balance: safeguarding the business while still enabling innovation at a time of dizzying technological change.