Cloud Security Today

Matthew Chiodi

The Cloud Security Today podcast features expert commentary and personal stories on the “how” side of cybersecurity. This is not a news program but rather a podcast that focuses on cyber leadership and understanding the threats most impacting organizations today.

  1. há 3 dias

    The AI harness

    AI security has a hype problem. Every week brings a new headline about agents escaping sandboxes, AI replacing security teams, or models becoming “too smart” to control. But the more useful question for CISOs is much more practical: where do the actual security controls belong? In this episode, I sit down with Diana Kelley, CISO at Noma Security and one of the clearest voices in AI security, to separate AI mythology from operational reality. Diana explains why the LLM itself is not the security boundary, why the “harness” around the model matters, and how security teams should think about contamination, consequence, and runtime control as agentic AI moves into the enterprise. This conversation is not about AI hype. It is about what CISOs, security architects, and technical leaders need to understand before AI systems start taking autonomous action at machine speed. What You’ll LearnWhy AI security is different from traditional AppSecWhat an AI “harness” is and why it mattersWhy the LLM should not be treated as a security controlHow prompt injection relates to trust boundaries and context windowsWhy agentic AI increases both speed and consequenceKey TakeawaysThe model is not the control point. The LLM is powerful, but it is not deterministic enough to serve as the primary security boundary. Security controls need to live before and after inference — in the harness, surrounding software, workflow, and runtime environment. Think in terms of contamination and consequence. Contamination is what enters the context window. Consequence is what the system does after inference. Both need controls, especially when AI agents can act repeatedly and autonomously. Agentic AI changes the scale problem. A single bad prompt is one thing. Hundreds or thousands of agents looping through tasks at machine speed is another. The risk is not just bad output. It is autonomous action without adequate guardrails.

4,9
de 5
16 avaliações

Sobre

The Cloud Security Today podcast features expert commentary and personal stories on the “how” side of cybersecurity. This is not a news program but rather a podcast that focuses on cyber leadership and understanding the threats most impacting organizations today.

Você também pode gostar de