Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On

Treasury reveals $6B in debt buybacks, triple the normal level – but markets slump

September 9, 2026

Apple unveils $1,999 foldable ‘iPhone Duo’ as new CEO John Ternus takes reins

September 9, 2026

Why Your Security Stack Was Never Built For This

September 9, 2026

Why that Elizabeth Holmes Netflix clip is so excruciating, according to expert

September 9, 2026

Work Has A Supply Chain Problem. AI Just Made That Problem Urgent

September 9, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » Why Your Security Stack Was Never Built For This

Why Your Security Stack Was Never Built For This

By News RoomSeptember 9, 2026No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
Share
Facebook Twitter LinkedIn Pinterest Email

Etay Maor is Vice President of Threat Intelligence for Cato Networks, a leader of advanced cloud-native cybersecurity technologies.

AI has upended thinking behind the traditional security framework in more ways than one. The conventional security framework, which is trusted by most CISOs, is rooted in the simple idea that risk travels through visible assets, including files, networks and applications. Accordingly, cybersecurity posture is underpinned by (but not limited to) firewalls inspecting traffic, data loss prevention (DLP) scanning files and email, and cloud access security brokers (CASB) governing SaaS activity.

AI is breaking this model. It doesn’t move through a file; it moves through a prompt, the model’s response to this prompt, and a chain of actions that the AI agent has agency to take on its own. The boundaries that the security arsenal had to defend earlier were very clear, but not so much now with the rise of AI. This is a whole new attack surface.

Governance Not Keeping Up With Adoption

AI agents are already widely used, with 43% of organizations reporting that more than half of their employees use them regularly. But there are significant control gaps. Fifty-three percent said agents occasionally or sometimes exceed their intended permissions, while 44% had little or no confidence in detecting agent-specific threats. Yet only 31% had formally adopted a policy governing AI agent use.

That combination of widespread adoption, limited oversight and weak threat detection makes for a scenario with serious business repercussions. AI security, therefore, cannot be seen purely from a technical prism, but has to move up the ladder and become a leadership issue.

The pressure is coming from multiple directions. Boards are looking for more accountability, and regulators want stronger controls. There is also internal pressure from business leaders who want to adopt AI but need more evidence that autonomous systems don’t disrupt operations or make unauthorized decisions.

Your customers also want clear and concrete assurance that their data remains protected in the age of AI. You therefore need to stop asking whether AI poses a risk, but whether your organization can manage AI without the associated risk.

Four Areas Where Traditional Controls Fall Short

1. Unsanctioned AI Use

You might have an AI governance policy implementation timeline in place, after which you will allow the use of authorized tools. But employees are not waiting for approval. They are already looking for AI tools to speed up tasks and improve efficiency. In fact, Gartner research reveals that 69% of enterprises already suspect or have concrete proof that staff members are using banned public AI tools.

Imagine a sales executive pasting customer data into a public chatbot or a software developer giving an AI coding assistant access to the company’s private code repository. None of these actions are either logged or approved. With one in five organizations experiencing a breach linked to shadow AI in 2025, there is no doubt that such actions increase AI risk.

2. Sensitive Data Leakage

Developers can knowingly or unknowingly share API keys and credentials while chatting with AI coding assistants. This action can put production environments in danger. AI tools can even summarize documents containing sensitive information and share them onward, without users realizing it has done so. Per reporting from TechTarget, analysis from Gartner projects that at least 80% of unauthorized AI activity will stem from internal policy violations rather than external attackers. The problem is that traditional DLP is not built to inspect the AI interaction layer.

3. AI Failing In Ways Testing Can’t Catch

AI is making its way into co-pilots, internal tools and customer-facing apps. These applications can access company systems, use sensitive data and take actions on a user’s behalf. But this means two problems rear their heads again and again:

• Prompt Injection: The model treats an attacker’s text as a trusted instruction.

• Jailbreaking: Clever framing gets the model to ignore its own safety rules.​

In a now real-world case, a car dealership’s chatbot was pranked by users who asked it to write code (it did) or agree to sell a car for one dollar (it didn’t). And while the chatbot generally handlded these requests well, it’s important to note that even without being hacked, models are trained to follow whatever instructions it receives.

4. A Lack Of A Human Safety Net

AI agents with agency do not wait for your next message. They call APIs, chain actions together and move across systems on their own to deliver an output. Zero trust verifies each request against a fixed identity and scope, but it doesn’t reason for the sequence of actions an agent takes, or what that sequence adds up to across systems. A recent study found that 91% of organizations have no way to step in before an AI agent executes a harmful action.

What You Need To Do

Traditional tools monitor data at rest or in transit. But AI risk emerges in interactions, model behavior and autonomous decisions. CASB and DLP still matter, but we must add a security layer for AI risk.

Find out where AI is used, by whom, and with what data. Then, build governance covering employee tools, custom applications and independent agents.

Crucially, we must move to AI anomaly detection. It is no longer enough to authenticate an agent or a session; security now requires assessing specific actions as high risk to allow or block them. This ensures you implement AI with confidence, reducing risk while improving ROI.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Etay Maor
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

Work Has A Supply Chain Problem. AI Just Made That Problem Urgent

September 9, 2026

Enterprise AI Doesn’t Need A Bigger Brain; It Needs A Confidence Gate

September 9, 2026

The First Trillion-Dollar Spend Without A Mature Measurement Layer

September 9, 2026

Why Your AI Guardrails Are Only As Real As Your Runtime Visibility

September 9, 2026

Why Payment Speed Alone Won’t Differentiate Your Business

September 9, 2026

How We Feel About AI And What That Means For Your Company

September 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Apple unveils $1,999 foldable ‘iPhone Duo’ as new CEO John Ternus takes reins

Business September 9, 2026

Apple unveiled its first-ever foldable iPhone at a splashy event Wednesday as new CEO John…

Why Your Security Stack Was Never Built For This

September 9, 2026

Why that Elizabeth Holmes Netflix clip is so excruciating, according to expert

September 9, 2026

Work Has A Supply Chain Problem. AI Just Made That Problem Urgent

September 9, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

All-you-can-eat Good Time Country Buffet comes to NYC’s East Village

September 9, 2026

Enterprise AI Doesn’t Need A Bigger Brain; It Needs A Confidence Gate

September 9, 2026

The First Trillion-Dollar Spend Without A Mature Measurement Layer

September 9, 2026

Dow falls 350 points as oil jumps above $100 for first time since July

September 9, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.