Amir Boldo, CPTO & Co-Founder, Above Security joins Michael Novinson at the #ISMGStudio at #BHUSA2026. They are discussing insider risk and why the same behavioral lens has to cover humans and AI agents alike. They deep dive into 'The Synthetic Insider' and why #AI agents need Identity, Governance, and Investigation. AI agents have credentials, read email, touch source code, and act inside business systems - and the insider risk program can't see any of it. Full interview going live soon on the #ISMGMediaNetwork #ISMGStudio #Cybersecurity #ISMGatBHUSA #InsiderThreat
Information Security Media Group (ISMG)’s Post
More Relevant Posts
-
AI agents are multiplying fast, and so are the machine identities that come with them. The real risk is not just more identities. It’s the quiet buildup of access that stays in place long after the task is done. That’s why zero standing privilege matters more than ever: give access only when it’s needed, and remove it when it’s not. How is your team managing AI-driven privilege sprawl? #AI #AgenticAI #permissions #sprawl #cybersecurity
To view or add a comment, sign in
-
Sean Duca is back on KBKast, now as co-founder and CEO of getsoteria.ai, bringing 25+ years in cybersecurity and a blunt take. The industry has spent the whole AI race confusing what a model can do with what it's allowed to do. 👇 Sean sits down with Karissa to work through why confidence and permission are two separate gates that most vendors treat as one, what governed autonomy actually looks like once the agents are live, and why a smarter model won't fix the problem when the authority to act still sits inside the reasoning itself. 🔐 🎧 Listen to their full conversation here: https://lnkd.in/gfgEVkkq In partnership with Vanta 🦙 #Cybersecurity #AI #CISO #SecurityOperations #AIGovernance #AgenticAI #KBKast #Vanta #InfoSec
To view or add a comment, sign in
-
-
Cyera has launched Agent Guardian and Cyera Endpoint at Black Hat 2026 to secure the autonomous workforce with visibility, governance, and runtime control for AI agents. "AI agents have become a new class of enterprise identity. But the fundamental shift isn't that organizations have more identities; it's that the gap between permission and execution has disappeared," said Tamar Bar-Ilan, cofounder and CTO of Cyera. More in the comment section #AgentGuardian #AISecurity #AgenticAI #NonHumanIdentities #Cybersecurity #AI #TechIntelPro
To view or add a comment, sign in
-
-
If one AI agent gets compromised, what else does it have access to? Most organizations can't answer that today not because the information doesn't exist, but because it's scattered. Which systems a given #agent touches, what data it can reach, and what it's permitted to do usually live in separate records nobody has connected. Without that connection, "#compromised" is a vague word. With it, it's a specific, boundable question: exactly what could this one identity reach, and what would it mean if it did. This is why #AIgovernance increasingly starts with a graph, not a spreadsheet mapping every AI asset, identity, and its relationships, so blast radius is something you can see before an incident forces you to reconstruct it. If one #AIagent in your organization were compromised right now, could you name what it can reach? Follow HARBA. #AISecurity #AIGovernance #ShadowAI #EnterpriseAI #CyberSecurity #CISO #RiskManagement
To view or add a comment, sign in
-
-
The biggest insider threat may no longer be human. In this keynote, Lalit Choda, Founder of the Non-Human Identity Management Group, shares a real-world story from a global financial institution that reveals how the misuse of a non-human identity led to a major business-impacting incident—and why AI agents are fundamentally changing the insider threat model. Learn why traditional security assumptions are breaking down and what organizations must do to govern non-human identities, Shadow AI, and Agentic AI before these risks scale. Watch now → https://ow.ly/EwEB50ZuvBt #InsiderThreat #NonHumanIdentity #CyberSecurity
To view or add a comment, sign in
-
Sharing a keynote talk I gave at Cloud Security Alliance Agentic AI Summit recently, on the NHI Internal Threat Amplified with AI
The biggest insider threat may no longer be human. In this keynote, Lalit Choda, Founder of the Non-Human Identity Management Group, shares a real-world story from a global financial institution that reveals how the misuse of a non-human identity led to a major business-impacting incident—and why AI agents are fundamentally changing the insider threat model. Learn why traditional security assumptions are breaking down and what organizations must do to govern non-human identities, Shadow AI, and Agentic AI before these risks scale. Watch now → https://ow.ly/EwEB50ZuvBt #InsiderThreat #NonHumanIdentity #CyberSecurity
To view or add a comment, sign in
-
One of the most useful ways to think about agentic attacks is through non-AI indicators, the behavioral signals that tell blue teams something is off, even if the attacker is using AI. What is clear is that these attacks often don’t look “complex” in the classic sense. They look fast, adaptive, and unusually efficient, such as short bursts of recon, rapid pivots, unexpected identity use, and access patterns that don’t fit the normal role of the account. That makes timing, sequence, and identity context far more important than waiting for a perfect AI-specific signature. For defenders then, the lesson is practical. Focus on the shape of the attack, not the label. Watch for unusual behavior in service accounts, API keys, legacy auth paths, and other non-human identities, and reinforce controls with continuous verification and runtime identity enforcement. This is a timely topic for infosec and blue teams because it pushes detection beyond static rules and toward behavior-based defense that can keep up with machine-speed threats. #Infosec #BlueTeam #IdentitySecurity #ZeroTrust #NonHumanIdentity #ThreatDetection #SOC #AIsecurity #CyberSecurity #MFA #PAM
To view or add a comment, sign in
-
-
AI rollouts usually stall for one reason: nobody can say what data an agent reached after something goes wrong, so the whole program pauses until someone can. Bedrock Data CEO and co-founder Bruno Kurtic explains why in a new video below. Bruno and the Bedrock Data team will be at Black Hat this week talking with security teams who are working through that same problem. Reserve a 1:1 with our exec team to discuss how to keep your AI rollout from stalling: https://luma.com/2jxedlln #BHUSA #BlackHat #Cybersecurity #AgentDLP #AIGovernance #DataSecurity
To view or add a comment, sign in
-
AI Can See Everything. It Still Doesn't Know What Matters. AI can see everything. It still doesn't know what matters. It can process 1,248 alerts without fatigue and flag every anomaly, but seeing more was never the real problem in security. Knowing which of those things actually matters, in this context, at this moment, still needs real judgement. That's why the analysts who thrive don't compete with the machine on speed. They let AI clear the noise, then bring what it can't replicate, judgement earned from understanding what's actually at risk. #CyberSecurity #InfoSec #SOC #ArtificialIntelligence #ThreatDetection #CynuxEra #BlueTeam #IncidentResponse #MachineLearning #CyberSecurityCareers
To view or add a comment, sign in
-
-
AI agents are showing up across organizations faster than most security teams can keep track of. Without visibility, permissions, or guardrails, it’s the AI wild west. In this 30-second walkthrough, Andrew Plesman Plesman shows how Agen.co helps IT and security teams discover every AI agent, control what it can access, and enforce the policies that keep autonomous work secure. How is your organization governing AI agents today? #AI #AIAgents #AgentSecurity #CyberSecurity #IdentitySecurity #EnterpriseAI #AgenCo
To view or add a comment, sign in
More from this author
-
Inside Black Hat USA 2026 With ISMG.Studio | Edition 179
Information Security Media Group (ISMG) 3d -
AI-Powered Threats and Emerging Risks Shaping Cybersecurity This Week | 178 Edition
Information Security Media Group (ISMG) 1w -
From Black Hat USA 2025 to What's Next | 177 Edition
Information Security Media Group (ISMG) 2w
Explore related topics
- AI Agents and Enterprise Security Risks
- The Role of AI Agents in Cybersecurity
- Risks of Using AI Agents
- Risks of AI in Identity Theft
- How AI Agents Are Changing Vulnerability Analysis
- Using synthetic agents in insurance
- How Agentic AI Improves Security Operations
- How to Foster Transparency in AI Agent Operations
- Understanding Security Risks of AI Coding Assistants
Explore content categories
- Career
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Hospitality & Tourism
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development
Thank you, Michael Novinson and the Information Security Media Group (ISMG) team. It was a pleasure discussing the future of insider risk