By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Integrating Holistic AI Security: From AI Adoption to AI Governance

Your organization may already run more AI than you realize. Brian O’Donnell of Carahsoft on closing the gap between adoption and accountability.

Artificial Intelligence (AI) has become a valuable cybersecurity tool in both the public and private sectors. Analysts use AI to detect anomalous patterns, identify threats, analyze large volumes of data and automate responses and remediation efforts in defense against malicious activity. Common use cases include:

  • Identifying phishing attempts and other fraudulent activity
  • Uncovering uncommon network and user patterns
  • Enabling real-time threat detection

The faster the threat is contained, the less room it has to cause lasting damage, such as significant data loss. Organizations are investing more and more in AI cybersecurity solutions and automated detection and containment methods, reducing the overall cost of remediation and the impact of security breaches.

Understanding the AI Threat Environment

Just as private sector cybersecurity methods are changing with AI, so are the methods of malicious actors. These methods vary, but include:

  • Deepfake impersonation: Malicious actors can use AI-created identities to obtain sensitive information, including AI-generated voices, videos or synthetic identities. Last year alone, the Federal Bureau of Investigation (FBI) reported that AI fraud cost Americans over $893 million. 
  • Malware and exploit support: As companies use AI to assist with code generation, troubleshooting malicious scripts and identifying weak configurations, malicious actors can take advantage of those opportunities by masquerading their AI agents as patchwork solutions.
  • Credential attacks and social engineering: AI can help cyberattackers craft tailored lures based on publicly available company data, roles, industry and other factors.

In addition to encountering new techniques, companies are facing an increased volume of AI-driven cyberattacks. It has become a race to adopt the most sophisticated AI methods first. However, implementation without governance can lead to its own pitfalls. Employees may engage in shadow AI or input sensitive data into unauthorized AI tools. Without defined ownership, no one may be responsible for assessing AI risk, model performance, vendor oversight or incident response. This can lead to compliance gaps and data leakage.


 AI Governance: Best Practices and Where to Start

Adopting AI solutions is only the first step in full integration in your cybersecurity technology stack; the ability to maintain, control and observe AI Agents, or “AI governance,” is a crucial component of ensuring longevity in a cybersecurity strategy. Commercial organizations should treat AI governance as an extension of cybersecurity, privacy, risk management, compliance and enterprise architecture, rather than as a standalone innovation project. This holistic approach to AI governance pulls companies away from systems that require patch methods or require manual change processes.

Executives looking to implement or strengthen AI governance can start with the following steps:

  • Create an AI Inventory: Identify all the AI solutions used across the organization and classify the use cases by risk.
  • Define Ownership and Accountability: Assign roles for all AI systems, including business or technical owners, security or privacy reviewers and an executive overseer.
  • Create AI Usage Policies: Establish rules and consequences for sensitive data, approved tools and acceptable prompts. 
  • Build Governance into Procurement: Require AI vendors to disclose security controls before incorporating the solutions into the organization’s technology stack.

Ultimately, AI governance comes down to a company knowing and understanding how their AI tools operate. AI governance is not a single, passive action or policy; organizations must consistently implement best practices to maintain governance over their AI solutions. These include:

  • Establishing an enterprise AI governance policy program that defines approved use cases, ownership and a risk review process.
  • Applying strong security controls to AI systems, such as access management, data loss prevention, prompt and output filtering, red teaming and more.
  • Setting strict data management policies, including limiting what data AI tools can access, prohibiting the use of unauthorized AI platforms and validating vendor practices for data retention, model training, deletion and privacy compliance.
  • Requiring human review for high-impact AI outputs, especially when those outputs influence cybersecurity response, customer decisions, financial analysis, legal interpretation and more.
  • Updating incident response plans to address AI-specific issues such as prompt injection, model manipulation, data leakage, agent misuse and compromised AI integrations. 

Strengthen AI Governance with Carahsoft

Carahsoft is uniquely positioned to help organizations strengthen their AI governance posture. As the Master Aggregator™ for our vendor, reseller and integrator partners, we have a vast AI portfolio that includes:

  • AI Governance and Compliance Tools: These solutions help organize and inventory AI systems, manage policies and document risk.
  • Secure AI and AI Control Planes: These tools enforce guardrails, manage model access, prevent data leakage and monitor prompts and outputs.
  • AI Agent Security: Companies can use these to monitor what AI agents can access and enforce policies.
  • Cybersecurity Modernization: These focus on AI-enabled threat detection, endpoint protection, identity security and vulnerability management.

Carahsoft is dedicated to connecting organizations with the most strategic vendors, reseller partners and system integrators best suited for addressing their respective challenges. 

As cybersecurity techniques continue to adapt to a rapidly evolving AI threat landscape, organizations must integrate practices, policies and solutions that strengthen their AI governance. By ensuring security controls are in place from procurement to deployment, organizations can ensure their sensitive data is secure and their AI cybersecurity tools are working as intended. With Carahsoft acting as the glue, organizations can easily find the right AI governance solutions for their network.

About the Author

Brian O’Donnell is Vice President at Carahsoft Technology Corp. He has been a member of the executive management team since the company’s inception in 2004. Brian is responsible for the strategic growth and development of partnerships with industry-leading cybersecurity companies focused on the federal, state and local government, as well as education and healthcare markets. Prior to joining Carahsoft, Brian served as Director, Sales at DLT Solutions, an award-winning value-added reseller focused on the public sector. 

Previous Post

Why Operational Resilience is the Foundation of OT Cybersecurity

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.