Understand how autonomous agents, emerging standards, and connected AI tools are reshaping the security landscape—and how to respond.
This session examines security frameworks including NIST and the EU AI Act, the risks created by autonomous agents with reasoning and tool access, and the Model Context Protocol as a potential standard for connecting AI systems safely.
Presented by: Jamal Khan, Chief Growth and Innovation Officer and Head of CNXN Helix, and James Hilliard, Event Host at Connection.
Auto-generated captions, merged into readable paragraphs. Jump to any moment via the timestamps.
We never give up to fight is a must. We going in, in, we bringing the fire. We about to combust. We ready and willing to do what we gotta do. You cannot stop. We put in the time we
Well, hello everyone and welcome James Hilliard here. Thank you for joining us for this conversation where we will focus all about AI security. As you all know, shifting very, very fast these days with the rise of a agentic AI and systems that are reasoning and remembering and taking action. The security playbook definitely has to evolve. And we're gonna talk about that today with Jamal Kahn,
our Chief Growth and Innovation Officer here at Connection. He's been out there working with a lot of clients, talking about securing AI system and, and how to really be in compliance and build resilience systems, et cetera. So thank you, my friend, for being here. Um, I mean security, is it really all that hard? Can't we just put in a little antivirus here and there and just, you know, move on with our days? It's pretty hard. Yes. And it's always been hard.
It's always been hard. Um, there was a, what we would, I would consider a simpler time because just the threats didn't come at us as quickly. But as you and I both know, over the many, many years, those threats keep coming quicker and quicker. Our systems are under more attack, more robust attacks and everything. But, um, bottom line is that with AI
being such a transformative time period, we've had these major transformations. First it was the pc, then it was the web, now it's ai. Mm-hmm. And we've had many transformations between those, but this is a major one. Is it time high level question that we'll dive into? Is it time that we really have to rethink how are we going to secure this new future?
Absolutely. I mean, it goes without saying, right? Yeah. It's, it's a function, uh, of adoption. Um, and, and I think I, given the fact that we wanna talk about frameworks in general, we we're clearly seeing that artificial intelligence is outpacing policy frameworks. Absolutely. Yeah. Right. It's, there's, there's no question about it. Um, are, Are the folks that you talk to now mm-hmm. Ready to, to make the mental shift, which we'll talk about,
there's a, a, a technical shift of security as well. Are they ready to make the mental shift to where we need to be, to look at all these different vectors that maybe haven't been on our radar to secure ai? Yes. They, they are. They absolutely are. Okay. Uh, and, but there's a function of the approach, right? So in some cases, they will be willing to make the mental shift while at the same time provide an
environment where their organization and the resources within that organization are then still given a landscape or a sandbox where they can operate. Or the mental shift is, yes. Again, I understand the risks are immense. Let's clamp everything down. So I think it's what they do. Step two, the, the mental belief or, or sense that AI inherently brings a greater set
of risks, uh, exists. But how they react to that is, is usually quite diverse. And, and we're gonna go through, uh, kind of a series kinda lay things out, uh, in a, hopefully a logical order for you all to understand how it might look for your organization to, to go through thinking about, uh, here, we'll talk about some of these frameworks and everything before we really dive deep into that.
As we, what, what should the ultimate end goal in terms of a, uh, a security mindset be for organizations? Meaning, are we going to be able to be 100% secure? We were never a hundred percent secure on our PCs, as we said, as antivirus. We were never a hundred percent secure on the web.
What are we looking at in this AI world? Uh, I Think it's very similar to where the legacy infrastructure or the legacy security approach sits as well. Um, as a security practitioner, I, I think, and you'll hear this consistently across that ecosystem, there's no such thing as a hundred percent. So that's not the end goal. The end goal is can you build in a, a mechanism, uh,
a process that can help you mitigate your risk? And what that essentially means is, you know, fastest means of detecting a challenge. And then the ability to respond to that in the shortest amount of time is generally speaking, the goal that we're looking for both in the classic cybersecurity space as well as in DI space. And then the last, again, kind of set up here, and then we'll dive into some of these frameworks and things like that.
My observation, having covered the tech industry for 20 plus years, security was, oh yeah, we've had our conversation now. What about security? We saw that change where security really did lead the way. Mm-hmm. Um, is that ingrained in what we're thinking about now? I am seeing more of the companies are focused on AI now.
They are trying to be proactive on the security front. They know that they have to be secure. Mm-hmm. Is that your observation? As his Know, I think as you move up the maturity cycle of artificial intelligence, the number one gating issue becomes, um, orchestration policy control and security. And we hear that from some of our mature customers where they come and ask us these questions, which is,
I've got a, a pretty significant challenge. Uh, the adoption is outpacing any of the policies mm-hmm. That we have. Any of the internal frameworks, the risks are becoming non-deterministic. If you think about it in the historical or the classic sense, the risks that existed prior to artificial intelligence were very much deterministic. If you did this, you'd have this output. If you put in this input, you'd have that output.
And if you saw an anomaly in that, you would immediately be able to ascertain that. There's some inherent challenge in that proposition. With ai, it's non-deterministic, especially with gen ai. So that lends to this level of immeasurability. That becomes a pretty significant, uh, challenge. Um, I think you are also seeing governance gaps as AI is getting more and more deployed out there.
How you govern that creates these sets of areas that we would call the governance gaps. And where wherever you have governance gaps, you have attack surfaces, you have the ability for attackers, uh, to sort of, uh, move in. And last but not least, regulators, um, are catching up and they're asking questions. They're saying, we want your responses to our, uh, asks, be more evidence based than intent based.
So yes, if you had the intention of, of securing something, uh, that's great. We wanna see the evidence behind how you are securing things. So I think No more just intention, No more. You have to show us hard line evidence. So I think you combine the adoption velocity. You combine, uh, gaps in governance. You combine the ask of the regulators and the boards.
Uh, you're clearly starting to see this question around AI risk being, um, brought up. More often than not. Why should the folks that are listening today be talking about risk? Be making sure that their executives are thinking about the risks that AI is exposing. Why now? Today is the time, if you haven't been focusing there, do you need to? I, I think it's similar to what I just expressed, which is,
um, adoption, uh, is certainly outpacing, uh, any regulation law Policy and growing faster and growing faster, Faster. So you're seeing that, that acceleration. Um, you are also seeing now this, initially there was this security for AI and AI for security sort of conversation almost converging. So they're becoming one in the same. And as I mentioned earlier, the, the governance gaps are lending
to potentially new attack surfaces being developed. Uh, and then again, the ask from the boards and the regulators on, I, I need your responses or your infrastructure or your approach being more evidence-based as opposed to intent base. All of those three things, and, and other reasons are, are compounding the need on why this conversation's becoming front and center.
I'm going to assume, and I know that folks out there listening, they know about the security frameworks that are out there. But as part of this event, we do want people to continue to learn. And it's just worth reiterating and, and drilling home what the frameworks are, who are the ones that we need to prioritize and really be looking to for that leadership? And then what is different from them.
So let's lay out what are a couple of the major frameworks that do need to be top of mind and we need to be thinking about today? Right. So you, you've got, and this is less a framework, uh, the EU AI Act, uh, it is, um, a legally binding piece of legislation. Um, it's has, you know, what are called risk tiered obligations. Uh, there are certain notification bodies, um,
their conformity assessments, you know, high risk use cases should approach a certain way, uh, and so on and so forth. Uh, and that's, that's almost the, the gold standard for legislation that exists out there. And I know the folks in, in the European Union, um, you know, took the, the first plunge, The lead on It Yeah. On the defense, uh, of that, uh, that legislation. And then you've got the NIST frameworks, right?
So the NIST RMF frameworks, the risk management frameworks, um, they are not, um, uh, obligatory. I mean, they, they're voluntary More suggestion Yeah. Suggestions Than best practice required. And I think what they do, what NIST does a really good job of is by bringing this, these frameworks, uh, they sort of set up the baseline and they establish what we call the governance spine, right?
So most government entities will look at the NIST as the north star around how they are going to, um, develop their, set Their legislation. Yeah. You know, set their policies and, and governance and, and risk management frameworks. And, and what the NIST RMF does is it, it approaches it through this concept called map measure, um, manage and, um, uh, and govern.
So that, those are those four step mechanisms that they've defined. Um, I think the ISO standards bodies have come up with some interesting, um, standards. The 23 8 94, I think that's the, uh, AI risk management framework. And then you've got the 40 2001, uh, which is the AI management system, uh, framework. And those are good standards. And, um, I got into recent conversations
with the folks at Forrester, and they've come up with a new, uh, risk management framework for AI called the Aegis, uh, uh, system. And it's an acronym that stands, uh, for something. Um, so I, I think you're beginning to see that early, um, build out of these different frameworks, all sort of fit and, and conform to certain needs and, um, requirements somehow on the legislative side,
some on the policy governance, internal enterprise control side. So you're seeing a big mix of These, and I would argue, don't know if you would as well, but a little sooner to coming up with these for AI than we did in the past when we had other growth within. I think that's tech Space. Yeah. Think that's fair. That's, that's a fair, fair observation. You're right. Hopefully it's because we learned that sometimes that was a little too far behind. But how often do they need to go back and review these?
Are these constantly changing, or is the EU like what they've done? Is that kind of set in stone and they're thinking set and forget it? Or are they realizing that's going to have to continually evolve and be managed on a regular basis because the change in AI are so Right. I think when you're looking at frameworks that are non legislative, you have the ability to have a, a quicker cadence of validation and valuation, reassessment, resetting, even the,
So especially with NIST and, and I sound And ISO standards, right? And, and you know, one would hope that they would constantly come up with revisions, uh, who would hope so and so forth. But from a legislative perspective, those do take end up taking a little bit longer. Yeah. But, but I think within ai, given its velocity, its change, we're still sort of in the early stages of really understanding its impact. Its adaptability and adaptability. Uh, then it's, you know, um, shifting, uh, risk, uh, um,
uh, challenges. I think it would behoove us as an industry to do constant reevaluation and, and resetting of these frameworks. Are these ideas that we've just talked on this and ISO and, and, and the EU standard, were they welcomed with open arms? Are people taking these recommendations to heart and saying, actually, these aren't a bad starting point,
or is there any, we still aren't quite sure. We kinda wanna do it our own, let us explore more. Do we really need this right now? No, it's, it's absolutely welcomed. Okay. Um, it's an area that brings some structure to an otherwise unstructured space. Very, uh, I think whether it's from a security industry perspective, whether it's from AI practitioners
or just folks who are trying to adopt this technology, having those swim lanes where you can sort of truly say, okay, if I were to follow this baseline, um, uh, that, that at least gets me off of step one. Having said that, I, I think we cannot overstate the value of these ecosystems either. Um, they, they provide at best a floor level construct upon which now you've gotta build
other elements as well. So, you know, in, in many ways, these frameworks, uh, you know, help create roles, identify the right roles, helps you identify the type of documentation and, and processes that you may need, you know, risk registered, you might have impact assessments that you wanna put in play, um, playbooks that in the classic cybersecurity sense, you want to have mm-hmm. Mm-hmm. X happens.
What's my playbook to, to execute against that X. Um, it also encourages, uh, the creation of artifacts. And that's very important. And in ai, I think more important than sort of in the classic sense, uh, you know, you're looking at your data lineage, you're looking at your evaluation, uh, mechanisms or results. You're looking at your models and, uh, and, and the model cards that exist. Uh, and last but not least, your, your procurement clauses are also reasonably well defined in
these frameworks where you've gotta build that AI bill of materials, you've gotta have that provenance. That's very important. So I think, uh, it does a really good job, um, uh, these frameworks essentially in helping us, you know, codify these three or four things that I think are Important. And is that the value that they bring right now is that what they're actually helping companies with is setting that this is our starting point. That's it. That's it. That's exactly it.
It's, it's that, that basement ground foundation that is that starting point and, and they help in those three areas that I, that I just Explained. Is that enough right now? Or is there a little more that is desired from these frameworks that you might like to see pushed further? Um, shortcomings? Yeah. No, I, I think it's a good start,
but it's certainly not enough. And, and I think it's, that was almost a rhetorical question. Um, there's still a lot of challenges with these frameworks. Um, one is, as I mentioned earlier on, is this contextual nature of risk within ai. Uh, AI's risk is very amorphous, it's very difficult, but given its non-deterministic nature, um,
so you may have an input that you put in and you get an output, and that output could theoretically be poisoned, and it's giving you an output that sounds perfectly legitimate. And that could be the basis upon which you do subsequent actions. Given the non-deterministic nature of those outputs could be, it's very difficult to identify whether something happened, right? So that context or that contextual risk, you know, uh, is, is a challenge.
Um, and by the way, that risk sort of straddles what may be low risk in one domain, maybe high risk in another domain. Um, and so there's no single sort of definition. Uh, then frameworks in general are very static snapshots, you know, the at they are at a moment in time. And, and AI is constantly sort of mutating and shifting and, and adjusting.
And, and, and at runtime, it can, again, given its non-deterministic nature, uh, have a, a, a challenge. Um, you know, then there's black boxes, right? So there's a lot of IP that's black box, whether it's these frontier model ecosystems, how do you go through an auditability process so frameworks don't address address that. Um, so there are these, should They, and you, you think they should,
will they evolve to that? I, I think it's a difficult ask for frameworks to do that, to be honest with you, because I think frameworks by the very nature wanna set a baseline, uh, and, And give you some freedom to grow and find those nuances. Yeah. Um, I, I think there, there's a completely different sort of dynamic control plane that we need to, as an industry talk about, is what is that cybersecurity or that security dynamic control plane that sits on top
of these frameworks that enable us to do some of those, uh, further validations. But, um, you know, asking this of frameworks is, I think asking a little bit too much. Okay. So frameworks are important. They set our baseline, that's our foundation, some shortcomings, but that doesn't mean that we don't still start there and we don't support these, and we don't have to still pay attention to how they evolve.
Um, the frameworks that are in place. Is there anything on the horizon that are, uh, frameworks that we should be keeping an eye out for? Or would it just be modifications of what we've seen come to the lead, iso, nist, et cetera? Um, no, I, I think as the frameworks stand today, I, short of the ISO standards, 'cause I think I, I would be looking more towards the ISO
standards to give us that level of property and detail orientation that, that I'm talking about. But even there, I I, I do not see any one of these frameworks or legal, um, structures to give us that dynamic control pain function. And so what you'll likely to see that the industry itself, uh, will come out with certain mechanisms, you know, one being the MCP protocols, uh,
those are the model control protocols, um, and other certain mechanisms that are more dynamic that address these challenges that I'm talking about. The constant mutation of ai, the velocity of ai, it's changing non-deterministic nature. I, I don't expect the frameworks addressing that, that particular challenge, The idea of AI being so adaptive and things changing so much. Let's talk a little bit about, uh,
what an adaptive runtime control plane can, can look like. You brought that up a little bit earlier. Kind of define that force. What's that look like? What does that bring to the table? Yeah, so First and foremost, this is not codified in stoned. This is something that, um, I think we're going through the process as an industry to sort of look at, um, and, and address and frame. But I, I think there's a good sense of, you know,
what would those baselines be that one would look for from an adaptive controlled perspective. Um, you know, one would be the constant evaluation need. You know, how are you consistently evaluating the overall ecosystem, uh, of a, an ai, uh, um, you know, proposition? And that includes everything from pre and post-deployment mechanisms. It will require some level of what's called red teaming.
Um, so this constant evaluation, I think is, is something that's relatively new, uh, and important. Uh, then this notion of policy as a code, it's a very difficult challenge even within the classic cybersecurity set sense. Mm-hmm. We always had cybersecurity policies, but the ability to translate that into something that's, um, that's executable from a almost a coding perspective,
using a level of orchestration layers and tooling, that's a big challenge. But I think that is something a dynamic control plane, uh, needs to, needs to have and, and, and enable, you know, allow lists. What are the different tooling mechanisms that we should allow? Um, you know, what are some of the approval mechanisms? Uh, are they kill switches when something goes wrong with ai? It just goes crazy. You've got an AI
that's running an agent framework, that AI is using a bunch of different models If it fundamentally breaks and you start seeing poor decisions, how do you monitor that? Can you stop that? How do you stop that? How do you roll back all of those playbooks, those, that's again, part of your dynamic, uh, control plane. Um, you know, one thing that I'm really a big proponent on is, is this provenance notion, which is gonna be important
for even auditability and downstream validation when you do have these challenges, is that AI bill of materials, the provenance, uh, you know, what's your, um, what are the sign artifacts? What's your data lineage? Uh, what are your model lineages? Having that available, you know, certified is a, a critically important thing. And, and last but not least, something that I've always talked about is this whole notion of drift
and anomaly detection models tend to drift. Uh, and they, they can drift based upon environmental considerations that have changed. They can drift based upon the models just performing poorly. Um, they work really well in the lab ecosystem. The minute you bring them out in, in the production environment, they start drifting. Yeah. So imagine now the challenge of building this dynamic control plane. And at Helix, we're actually working on that,
and that's a function that we bring to bear through an orchestration of different tool sets and toolkits. But there's also a lot of r and d that's going into the proposition, uh, that folks like Jeff and Ryan and others are working on. And, and, and so we are building out that dynamic, uh, orchestration policy and security control plane, which I think is gonna be fundamentally important. What I don't see happening, I'm go back, get back
to the old playbooks of Dave from security. They used to be binders. Mm-hmm. Right? You would do so, and then you would pull out and you would go through paper and say, this is what we're gonna do because this happened to this server, this happened. And, and they'd run through that people, the fleshy orbs, we can't do that. Doesn't this require AI to watch over itself and help give us those insights to see where these are?
And then isn't that dangerous? You know, I, I had a really interesting conversation yesterday, uh, with, uh, uh, the principal analyst at Forest, uh, uh, Ali Mellon. And, and she, she was also sort of pushing back on this notion about AI sort of managing and helping police ai. And isn't that sort of the fox guarding the henhouse? And, and the answer is yes, in some ways it is.
But there are methods of implementing that in a way that mitigate that, uh, that that risk. Look, there's a fundamental problem that exists, and that's the speed problem. Hmm. I, I, if someone can come up with a better proposition that the velocity with which artificial intelligence works today and is likely to work in, in the next three years with agents running multiple models
Interesting. Yeah. Interacting, resulting in actions being called those actions resulting in real decisions being made that impact businesses and people. If someone has the ability to show me a mechanism where you can do that in a manual process, you can do that through these frameworks. I'll be more than happy. But I just don't see that. Yeah. So I, I think we've, we've gotta come to this conclusion
that we are going to have to build these dynamic control planes that are, in some ways, may, may way, shape or form, will have contact space AI driving, uh, their efficacy and value. And, and, and there is no avoiding that at scale and at runtime. And don't we have to do that because those that are trying to get at our data, those that are trying to exploit us, the bad actors,
they're not gonna say, ah, well, we just won't use AI for that. They're gonna be using Sure. Their own set of tools to try and, Right. And, and that is a slightly different challenge, which is now you're saying, okay, how are adversaries leveraging artificial intelligence to make them faster and smarter to attack our systems? And that certainly lends, now having said that, I think it's important to say, look, we're not going to necessarily see tomorrow the SOC turn into a
completely automated AI system. That's not gonna happen. Sure. We're, we're still gonna have playbooks. We'll still have, you know, rollback policies. There'll still be some level of what we call separation of duties. We would still want to have humans in the loop before those actions are actually taken, uh, human auditors and so on and so forth. So I, I think there still will be involvement in the medium to near term of human beings being involved in
that overall process. But this notion that we cannot use artificial intelligence to police artificial intelligence, I think it's, it, for me, it's just, it's, it's no notion we've gotta be more embracing of leveraging AI and AI tools to address AI challenges. But we've gotta certainly separate those duties, separate their functions. Um, so there's no overlap. Can you imagine time where it's so complex that it has
to be that it is absolutely A hundred percent AI only? Absolutely. Yeah. It is. I can imagine that You said not three years, but I, I, I'm, I'm usually, it's speculation The ball here, I'm usually pretty off by my, my timelines. I'm usually not off in terms of what likely is gonna happen, what the outcome is. I'm usually, I'm, I'm usually more aggressive. I think the windows are, are shorter, but, you know, even if I add a couple
of years within the next five years, the ecosystem's gonna become so complex. Yeah. Um, you know, there's, there's an, another insidious challenge with AI is AI decision making is often not explainable, especially when you get into deep neural networks and, and, and things that are a little bit more complex. Um, so I, It just says, here's your outcome. Here's, here's, here's what I say Outcome. So now how do you validate that? How do you check that? How do you secure that? How do you, uh,
how do you make certain that certain, and now again, as you're gonna see a prevalence of agent frameworks and what agents are, you've got these smaller semi independent systems that are making decisions that are actually calling tools that have some level of context in how they're making those decisions. 'cause they remember what decisions were made by me Before. Right. By the way, they, they adjust. Yeah. And so they, depending on the varying input, they will make that decision. Then they will execute an action.
That speed of velocity of decision making. You know, you, you, you require a dynamic control plane that can control and manage that. Yeah. And how different from the human world that we've been in, where things can get s slowed down by meeting after meeting, after meeting after meeting. And you might still come to the right decision, but it took forever. These agents can immediately get right to that. Right. And that's where, Though, I, I can, I can say this with a high level
of short, I'm sure there's certain corporate cultures out there that will put meetings between agents, and we will still have that, that level of Ation. I don't wanna be in that meeting. I don't wanna be anywhere near that. Um, let's go back to something that, that, that you brought up earlier. These CPS MO model control protocols. Uh, I know folks have have heard those. It's starting to come out as something that people are getting more familiar with.
But define it for us. Where does that fit into the current, now let's bring it back from instead of, you know, when everything's run AI and five years from now, bring it back to now. Right. So I, the, the analogy I use, and by the way, this was a mechanism that, you know, within our team, we had talked about from many years prior. I mean, I think five, six years ago, we said, at some point, there's gonna have to be this, this plane of
engageable protocols. And, and where that thought process came from was from your, uh, networking protocol concepts said, when you're, when you're doing, um, when you're going into the web, and by the way, this was the first question that was asked me on my first job interview ever. Uh, the gentleman who was interviewing me, I was going in for a software development position to build internet based applications. And he asked me this very simple question.
He said, okay, help me understand how when you type in http, www.whatevercnn.com, what happens? And you know, I I, I you said magic. I, yeah. You know, and I, I was, I started, started to stumble that question. He helped me, he helped my hand and helped me through that question. He said, no, no, no, no. What happens on the browser?
And so one of the things that happens is this what's called, uh, uh, name re resolution, right? The domain name, uh, resolution that occurs where you do a DNS lookup for www.cnn.com, it translates into an ip. And that's a protocols very simple protocol. It's always working. They're very established rules and, and principles. Uh, you've got these root servers that act as this,
you know, top level directory and everything flows down from that root server architecture. So in similar ways, we're looking at CPS is providing us with some of that baseline benchmark where when we are running our models, or we are running something within this overall ecosystem of ai, we can check that against these protocol validators. Uh, and so imagine that these MCP
or maybe MCP today, which, you know, helps, you know, establish cap capability gates, it helps, um, establish Tampa or, uh, proof, uh, logging or, or, or, or, you know, tamper evident logging and so on and so forth. Imagine this, this set of protocols that are out there that allow us in a trusted fashion, validate some of these
mechanics within this overall AI ecosystem. And that's what MCP sort of promises us to do over the longer arc of time as it evolves. And so I think I'm super excited about that because I think we need that sort of standards based approach to make this thing work. Are they helping to do that now? Are they functional? Um, we're in the early stage of it. Um, I don't think it's helping us do that now
as an industry. Uh, but those, those approaches are small, small enough approaches. Yeah. Those approaches are being taken, um, in, in some of, certainly the, the frontier model ecosystem that's out there. Uh, you had mentioned the idea of artifacts and the idea that, uh, organizations need to, uh, have a certain level of, uh, artifacts out there that are available regardless
of whatever frameworks they're following. And I'll expand upon that. Right. So I think this is almost, um, you know, I would classify this as sort of your cheat sheet or your cheat code on what are some of the baseline things. Uh, you want to have, you know, one thing, as I mentioned, the providence, uh, component. You, you certainly want to have this AI builds of material.
Um, you know, this lineage, uh, how you capture that, you know, it's, it's open to everyone's own, uh, view on it. But, you know, what are your data sets that you're using? Uh, what's the lineage on that data set? Um, what are the weights? If you've gone into this proposition of fine tuning your models, um, you know, how are you sort of adjusting those weights, uh, and, and what are called edges within those models
that make those models be more tuned to your, uh, use function? Um, you know, your prompts, uh, you know, what are the prompts that you, uh, authorize? Maybe you want to have a, a a library of prompts that you want to give. How have you validated those prompts? Um, then your tooling that you're using, how are you actually validating the provenance and the efficacy and, and the reliability of those tools?
And then the versioning that exists across this entire ecosystem. I mean, that's your almost step one lineage AI bill of materials. You've gotta have a very robust, uh, mechanism to control that. Uh, then you want to have certainly an evaluation sort of dossier of sorts, right? So as you are going through the process of running these mechanisms, you've gotta start looking at the results and making judgment calls on, you know,
what's the robustness? Were there any grounding results that we can sort of base our output against to validate whether, you know, in this evaluation process, are systems are performing the way they, uh, ought to be performing, and then doing adversarial testing, and also called edge case testing. That's very important to sort of see, uh, whether again, the model has drifted or, or is, uh, is in the process of drifting. Mm-hmm.
What teams are owning that? Who should be owning that? Who should be overlooking that? Who should be double checking it? Who should be triple checking it? Yeah. So that, that's a million dollar question. In many ways, that's not yet fully rationalized. Okay. So it would again, be a function of new teams or existing teams that have added responsibility. I certain think the CISOs would. So I was gonna say under the CISO stack in,
in some manner there, The CSO stack would come into play. You've got the EC chief AI officer and their teams. That would certainly come into play because the skillsets very unique and and quite complex. You certainly have the CIO and their set of teams. So I think it's a shared responsibility. Uh, but I wasn't done with, with those sets of, uh, requirements. Yeah. It's the operational playbook, right? In, in classic cybersecurity, when you have a set challenge,
what are your steps B, C, and D in order to sort of, you know, measure and mitigate and remediate, um, similar situations. If you've got AI that goes haywire, what's your kill switch? What's your rollback process? You really wanna build those playbooks early enough so you don't find yourself in a situation where you're, you're, you're trying to handle, uh, these incidences that are likely to happen. Uh, and then procurement terms, I think it's very important
for any organization to define within the procurement contracts with vendors and partners and providers that, you know, simple things like, you know, no training on on our data in any of their products. Um, you've gotta look at, you know, what's called, um, uh, you know, encryption key residency, if there's encryption being involved, who actually owns the CMAC process, right?
Right. That's very important. You, you don't want the ability to have, let's say if you're using a hyperscaler to have your data in the cloud somewhere, but your CMAC controls are with the cloud provider. No. Your data at rest should have, uh, your, your managed encryption key standards controlled by yourself. So your data Address, that's responsibility. Yeah, Absolutely. And so your data at rest is, is under your, your control
and that audits and logging, and then any sort of version change notice notices for your procurement suppliers as well. They're constantly upgrading their products. You want to have the ability to get notified that aversion has changed, an underlying model has changed. And what does that represent in terms of down downstream cascading impact on your agent frameworks and your other, uh, applications out there.
So there's a lot there. Yes. Uh, that needs to be unpacked, but I think that's, uh, the minimum set of artifacts that are needed. Everything we've talked about so far, does a company's industry have a major impact on, on how things are prioritized? I'm thinking healthcare versus manufacturing versus retail versus, uh, financial service and everything.
How much does that play? Or is it not that it's just, it's something that everybody, every company in every vertical just needs to still apply these basic standards we have now and, and, and grow them. Yeah. I, I think the lazy answer would be, yeah. No, it kind of applies to everyone. And I think in some levels that may the case where,
you know, your baseline policy, building out some of your, um, you know, lineage dossier information and your AI bill of materials, I think some of that is sort of just good housekeeping. Mm-hmm. So almost cross applicable. Uh, but I think you, you highlight, uh, an added layer of complexity in the proposition. Highly regulated industries have a different risk threshold with non-regulated industries.
Right? And so you have a little bit more give in, let's say, a retail ecosystem, even though there you've got PII, and you've got GDPR compliance and some of those other regulatory aspects that come in play. But now, when you're looking at the healthcare ecosystem, you're looking at the financial ecosystem, and you're looking certainly at the more restricted ecosystems. It's a completely different ballgame. Uh, and even their deployment strategies are very distinct.
For example, in the DOD ecosystem, a lot of the asks are air gapped ecosystems, right? These are systems at the edge. As we start moving AI more towards the edge, these could be AI systems that are on a ship in a base on the front line. What does that mean? How do you secure that environment? It's very different from just an e-commerce website that's doing predictive analytics. Sure. Um, so I, I think there's a tremendous variance
in complexity that comes from that. Do you think that there will be industry specific frameworks in groups that will evolve out of this? That will, there should be focus, there should be No, there should be anything now. Um, Nothing now. Um, I mean, I think the, the federal ecosystem does try and set up certain standards. The NIST standard would be one. Uh, then there's certain, you know, certain standards
around FedRAMP compliance and what that means. So they do try and set the basic hygiene that's required. But I think within the AI consumption, by the way, the Fed is not a monolith, right? The Fed is the civilian agencies versus the, the Department of Energy is very unique r and d, you've got the national labs, you've got the do OD ecosystem. And within the do OD ecosystem, you've got a whole broad set of considerations.
You've got the analysis work, you've got the edge kinetic work, and then you look at the IC community, which is the intelligence community. It's a complete, so even that's not a monolith. Uh, and I, I think that comes from the experts within that space that have to sort of look at all the tool sets and mechanisms that they have, its applicability within their own ecosystem, and then create the dynamic control plane on
top of that, baseline that, And pick and choose those best, best ones for all. Right? Um, one of the issues with security has always been the idea of if we're gonna kind of be secure, we gotta lock everything down and can't let anybody have any fun, right? That was always a balance that, that we had. So these days with ai, it's all about innovation. It's at innovation at speed,
and the speed we've never seen before. How do we make sure that the security controls that we're looking to implement don't hold that innovation back? Where's the balance? Who thinks about that balance? Where do you see that balance now? Right. So I, I think it varies. Like I said, it depends on the culture, the risk appetite,
the regulated or non-regulated nature of the business. And also down to individual CISOs, right? So in some cases you'll have CISOs that will, um, you know, unequivocally say, because I don't understand, or I don't have the ability to manage, I've gotta sort of pause this thing Now that's at the expense of, uh, velocity of innovation and which is a significant, you know, competitive disadvantage if you,
if you're not evolving fast enough. So there are ways and mechanisms to sort of manage that or help those CSOs, uh, manage those challenges. You know, one of the things is, you know, building, you know, time timebox sandboxes that allow, um, their developers or their, you know, business line owners to, to play around with these technologies. So timebox sandboxes, um, that, that give you
that, that, that, that ability to sort of, uh, uh, you know, innovate in that space. Uh, there's also graduating your scopes. You, you don't wanna sort of come in with the notion and say, we're gonna boil the ocean. So I think, again, the CSOs will look at, can we sort of graduate the scope? So maybe we start off with highly curated dataset, conversational access through LLMs, and then we graduate to maybe, you know, low blast impact,
uh, AI agents that do, can do very simple things like, uh, support shift, uh, or average whole time reduction. There are a whole bunch of these use cases that are really, you know, reasonably well matured and, and have a very narrow blast radius, uh, challenge that exists. Uh, and then setting up measurable evaluation gates. So if you set up measure measurable evaluation mechanisms
that give the CISOs or the organization this sense of calmness that yes, we're constantly evaluating it. We're seeing we've got a good sense of where our risk is and all of that, that hygiene that I talked about, then I think you can strike a good balance. If you don't have those mechanisms, then you're going to usually have, um, often a knee-jerk reaction in terms of how policies made within organizations. Either you completely open everything up,
now you're opening yourself up to immense risk. Yes. Or you're completely clamping down and now you've at a Disadvantage stifling innovation, And then you're stifling innovation. Yeah. Yeah. Uh, I wrote down the word graduate 'cause you said that a couple times and it made me think about our kids. Jamal, we have college age kids, and I want to kind of pose this question, follow me here. I think it's gonna work,
Hopefully, hopefully. Who knows? It's always a, a, a risk here. Um, I'm thinking about trying to give folks out in the audience kind of an idea of where do they stand in terms of how they're approaching security and would that be appealing to a young graduate, someone
that is evaluating companies to go work for. Mm-hmm. And so it's kind of to say, and and again, I hope this works maybe as feedback. So maybe we pretend, I pretend that you are, uh, a college grad. You are interested in, uh, the cybersecurity area. You're interested in ai. What questions might you be asking for? What would you be looking for at companies that you are interviewing at?
Right. To really see if that's an excellent, okay, this is an on this company, I can get engaged where I won't touch that company for nothing 'cause they don't know what they're doing. That type of thing. And, and I think it gives the folks out there an idea to evaluate, okay, are we appealing? Are we on that cutting edge? Are we following the right frameworks? Are we doing those things? What, what are your thoughts? I think that's, that's an excellent question. And but out my response will have a few caveats.
One, you know, on a personal level, I tend to be very analytic in you. Yeah. In, in looking at those sets of elements. I don't think all fresh, fresh graduates, given where the job market is today, will, will be that discriminating. Sure, sure, sure. But, but right off the bat, if, if I were sort of in the early stages of my career, I, the questions I would ask is exactly that.
What sort of tooling are you preparing or enabling me to have within this AI ecosystem that allows me to do my job better in a less toiling fashion? And that's a very important consideration. Every job has this component of toil. Sure. With ai, toil is becoming less and less necessary. If your processes are archaic and your tooling
and digital dexterity is archaic, then you will continually have toil within our daily work life. And so the argument that all CIOs and all leaders and organization ought to be looking at is identify the toil work and can we automate that work and can we enable our resources with those tools that, that sort of extricate that. Because once that happens, now I am truly trying
to impress upon those new hires that we're, we hired you for your mind and for your intellect, and that's where we're gonna apply your, your, uh, your agency. And, and that's what I would be looking at. And so that sort of straddles everything from, you know, co-pilots and GPTs and, and the ability to create low-code, no-code agents that automate some of the mundane toil tasks. So if you've not built them for me, give me the tools
that allow me to do that. And any organization that does that would would certainly be one that I would wanna work in more so, uh, than not. Also, the way work works today is very different. And I think organizations need to sort of understand, especially with how the, the newer generation or the, uh, the, the millennial generation work is no longer structured.
And, and the funny thing is, as a, as an exec in a company, I've always expressed that notion, but now for the first time, someone's saying, okay, prove me that you believe, prove me. Yeah. That you believe in that notion, because I always used to express, I really don't care how you work, as long as you give me the output and the outcomes that I'm looking for. And I use the analogy, you can hold your nose from your right hand, your left hand, I don't care as long as you get
what I, what we need as a company done. Mm-hmm. And I think now the, the, the newer sort of entrance into the workforce is saying, okay, fine. We, we buy that. Prove that you actually believe that. Yeah. And so that changes how work gets done. And organizations in many ways need to unshackle themselves from, from some of that classic way of operating. And, and I think they will get better talent
and they'll become more efficient. Uh, and, and certainly that's where, where the ecosystem's going. Last word, how do folks that have been watching today, what is it that they do tomorrow, next week, next month, that gets them to a more secure posture, gets them more aligned with where the world is evolving?
What's something that you, is a tangible that they can do to get a little more secure, you know, tomorrow than they were yesterday, right? So that, that classic 30, 60, 90 day sort of cheat sheet, um, you know, let's, let's say within the next 30 days, step one, which is the most basic step, which is establish your AI inventory. You will be surprised how much shadow AI exists within the organization.
You know, people working off of credit cards and working off, off just their own even accounts. Uh, establish that AI use inventory very quickly. Okay. And then, and then codify and publish a policy. You know, I think a lot of organizations are still sort of grappling with this notion we can help in helping organizations publish their AI policies, because I think those guardrails are, are fundamentally important.
And then I think if you are in the early stage in the next 30 days, and you are one of those organizations that want to innovate fast, look at those one or two lighthouse low blast radius AI projects, conversational access to curated data copilots that are, you know, fine tuned in certain ways. Maybe one or two agents that are removing the toil. That's your 30 day strategy. I think it's very easy to sort of go down that path
and execute that 60, 60. Now you are starting to say, okay, I would've done all of these things in 30 days, so now I need to build some sort of a harness, an ecosystem that brings a higher level of controls management orchestration policy. So you're looking at your evaluation harness. Remember I said evaluations are gonna become very important. Now, are the outputs the right thing?
'cause the last thing you wanna do is in that 30 day, create a bunch of agents that give poor results, right? And now all of a sudden everyone's gonna be skeptical. And you, you've basically killed that, that that notion of automation and bringing intelligence. Um, so, so evaluation harnesses become important. Um, but doing so within the construct of PII and DLP controls are important. 'cause you wanna mitigate and manage
your, your risk as well. And then also capture your AI bill of materials. You can begin during that process. Uh, and then start that early process of building your playbooks, right? Start defining your playbooks. If something goes south, what do I do? If something goes here, what do I do? Start creating those playbooks. Um, and then there's the, the 90, uh, 90 day, the longer term, now you're seeing what is my source strategy, my security orchestration,
automation and, and response strategy. And how do I take my AI efforts and projects and plug that into my source strategy? I think that is your 90 plus day, uh, effort. Um, and, and then starting to enforce, you know, policy as a code, uh, across both your tools and the approval mechanisms you're doing. Your red teaming, as I mentioned, the red teaming process becomes very important.
Uh, and then last but not least, what I already explained is your procurement process. Yeah. Uh, on, as you're bringing this tooling and this, this, this scaffolding of AI build outs, how, you know, what are your procurement, uh, processes? I, I think that is a good 30, 60, 90 day, um, cheat Sheet. And again, folks, it's just that easy. So you can just follow that, get out there, get it done 30, 60, 90 days. Or if you do feel that you need a little more conversation,
then we encourage you to reach out to the Helix team. If you already have someone connection in place, reach out to those team members. We'll get you in touch. If you wanna head online to cn xn helix.com, that'll get you more information. And again, you can connect with the team. Jamal, appreciate the time. Thank you sir. Folks, really do appreciate you all taking time to join us. Hopefully you got some answers and maybe even some more questions that'll help you on your
journey in terms of everything tied to AI and security. Uh, we do look forward to working with you down the road as you need our support. We're gonna be there for you. And again, thank you for joining us.
Book a call with our team to map applied AI to your operations — no pitch, just a working conversation about what’s possible.
A candid conversation on turning AI investment into measurable revenue — soft vs. hard dollars, and where the money is actually made.
How applied AI cuts through alert fatigue — turning a flood of security signals into clear, prioritized answers your team can act on.
Turning everyday camera feeds into operational insight with computer vision — from detection on the floor to decisions that move the business.