Zero trust

For Cybersecurity Awareness Month, it’s time to rethink zero-trust for the AI era

COMMENTARY: Today starts Cybersecurity Awareness Month, and while much of the discussion this October will rightfully focus on AI, we need to make sure those concerns don’t lead us to lose focus on the cybersecurity fundamentals.

AI has increased the speed and scale of cyberattacks exponentially. Historically, organizations often failed to implement best practices, but avoided compromise because attackers didn’t have the resources to target them.

AI changed that.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

In the past, organizations often failed to change default administrative credentials on hardware, a problem that has persisted for decades. Today, AI can find and exploit those mistakes faster, leaving organizations less time to correct them.

We don't need to speculate the consequences of basic security failures. Recent attacks on U.S. water systems exploited internet-facing operational technology, while earlier attacks succeeded against equipment using default or no passwords.

That’s why the debate over fully-autonomous AI attacks can obscure a more immediate problem. Autonomous attacks succeed today because organizations have not secured themselves against conventional attacks.

The FBI has emphasized that defenses against traditional attacks can also help protect against AI-enabled threats. Jason Bilnoski, deputy assistant director of the FBI's Cyber Division, put it succinctly: “The adversaries are still [exploiting] basic principles or basic cyber hygiene principles that we are not following.”

Organizations need to audit and test their systems to ensure the basics are right: we need to close unnecessary internet-facing ports, promptly patch systems for known vulnerabilities, reset default passwords, and prevent the execution of untrusted software. These controls can help defend against AI-enabled attacks and have long protected organizations from traditional threats.

One of these fundamentals is zero-trust. It has become a widely-recognized security model. For starters, zero-trust assumes no implicit trust based solely on a user’s or application’s network location or ownership. Authorization gets continuously evaluated for both users and applications. Users and applications should only have access to the resources needed to perform their function, a concept called least privilege. It also embraces deny by default; an action gets blocked unless it has been explicitly allowed.

Many organizations have made zero-trust a goal, but its principles are not being enforced uniformly across artificial intelligence. An AI agent can act on a user’s behalf, so the same zero-trust controls on software apply. Yet AI systems are often granted broad permissions to access data, interact with applications, communicate with other systems, use APIs, execute commands, and in some cases, make operational decisions.

We can safely adopt AI if fundamental controls are correctly implemented. A prompt or built-in guardrail can tell an AI system what it should do, but it cannot replace hard technical controls that block prohibited actions.

Applying zero-trust to AI should start with three practical steps:

  • Block installation of unapproved AI agents and applications by default.
  • Use web controls to block unapproved browser-based AI services while allowing those the organization approves.
  • Apply the same principle of least privilege used for applications and users to AI. Agents should only have access to the minimum data, applications, APIs, and networks required for their intended purpose.  Limit their actions within those resources to what is explicitly allowed.

This Cybersecurity Awareness Month, organizations should focus on the controls they already know work. AI can make basic security mistakes easier to find and exploit, often at greater scale. Applying these fundamentals helps protect against both AI-enabled and traditional attacks, creating a resilient baseline that mitigates risks regardless of the threat vector.

Danny Jenkins, co-founder and CEO, ThreatLocker

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Asymmetric Warfare

You can skip this ad in 5 seconds