By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Cybersecurity Fundamentals Still Win. But the Floor Has Moved.

Dana Kilcrease, CISO at Berkeley College, explores how AI is challenging long-standing cybersecurity assumptions. The fundamentals haven’t changed—but as systems gain greater autonomy, the meaning of concepts like least privilege, identity, zero trust, and resilience may need to change with them.

Dana Kilcrease

Berkley College | CISO

Every few years, the technology world experiences a new shift, and with it, a new class of risk.  The internet brought remote exploitation at scale.  Mobile created new channels for corporate data leakage.  Cloud magnified the consequences of misconfiguration.  Now AI has emerged, introducing threats such as prompt injection and excessive agency, which in turn has created new vendors, conference tracks, and heightened board-level anxiety.  

Some of this is genuinely new.  The security fundamentals, thankfully, have not suddenly stopped working.  Whether it is SaaS or AI, organizations still need to know what they are protecting and how they plan to recover from disruptions.

Cybersecurity fundamentals remain the foundation of any effective security program.  Yet the application of those principles cannot remain frozen in time.  The latest AI shift is exposing a trap in simply sticking to static fundamentals, where a principle can remain correct even when the assumptions beneath its implementation have changed.

The question is whether we have interpreted these principles broadly enough for systems that can act with increasing independence.

Beyond Least Privilege

Least privilege is perhaps the most recognized foundational principle of all.  The idea of only provisioning access to the essential resources needed for a given task has been a cornerstone of even the earliest security programs.  With the advent of agentic operations, we must now look at this through a new lens, where privilege alone is not sufficient and agency itself becomes a new floor.  Least agency requires us to not only look at what we will allow an agent to access, but also at what autonomy and transactional authority it needs to conduct its task.  Establishing an agent’s identity and delegated authority should not amount to blanket approval for every subsequent action.  Rather, consequential operations must be evaluated in context based on actions and decisions, not just data and systems.

Identity Must Follow Delegation

Nonhuman identities are nothing new, despite what you may hear on conference floors.  Service accounts and other machine identities have existed for decades, and the industry has developed mature patterns for delegated authority.  What has changed is the dynamism and complexity of that delegation.  Organizations must ensure that each agent is uniquely identifiable and that its chain of delegation remains traceable as it interacts with other agents and systems.

Default Deny for Agent Capabilities

Default deny has traditionally meant prohibiting access unless it is explicitly granted.  Agentic systems should similarly be deployed with tools, connectors, persistent memory, and external communication disabled unless required.   Any AI implementation should deliberately enable only the capabilities necessary for its desired purpose and provide enforceable boundaries around their use.

Zero Trust for Objectives and Actions

Zero trust rejects implicit trust based on network location or a previous authentication event.  By the same principle, we must reevaluate authorization whenever an agent’s objective or proposed action changes.  New threats like poisoned context or manipulated memory can redirect an otherwise legitimate system and we must avoid assuming that an agent is pursuing its authorized intent simply because it was initially authorized.

When Data Becomes Instruction

The idea that all external input should be treated as untrusted has been around for decades (I’m sure we can all recite the definitions of SQL injection and cross-site scripting ad nauseam).  AI has complicated this as natural language can be treated as both data and instruction.  Any text from a webpage, email, or other retrieved text may contain content designed to influence the model, rather than simply inform it.  Because models cannot reliably distinguish instructions from untrusted content on their own, systems must treat retrieved content as untrusted and validate consequential operations outside the model. 

The New Boundaries of Data Minimization

Many organizations have spent decades accumulating ungoverned data and permission sprawl.  AI did not create this underlying problem, but its ability to discover and aggregate across disparate systems has made the consequences of this debt far easier to realize.  Strong entitlement governance can reduce this, but many organizations still lack visibility into what they retain and who can access it.  Agentic systems introduce new retention surfaces, including conversation history, outputs, retrieved context, and persistent memory.  Data minimization programs must therefore include properly scoping agent access and establishing retention policies for stored context and memory.

Resilience at Machine Speed

Security is imperfect and resilience has traditionally focused on maintaining operations and enabling recovery when prevention fails.  This core premise has not changed, although the tempo has.  Agentic systems can execute a chain of actions faster than a human can intervene, potentially turning a small error into a material event.  Resilience must now begin by bounding the scope and irreversibility of autonomous actions through transaction limits, approval gates, circuit breakers, and immediate revocation of authority.  When failure can propagate at machine speed, containment and reversibility become essential parts of recovery.

The Foundations Remain, but Their Scope Has Expanded

There is no doubt that AI has changed how organizations act on information.  The coming years will certainly produce new frameworks and products.  Some will be valuable, many will not.  Nevertheless, simply creating a separate security universe around AI while foundational weaknesses remain unsolved will likely prove to be a mistake.

Across each technology shift, the enduring principles still win.  Verify explicitly, authorize narrowly, minimize exposure, design for recovery.  What has changed is the underlying subject of these fundamentals.  Identity must account for autonomous agents, while authorization must govern delegated action.  Data extends to context and memory, and the attack surface now encompasses tools and models.  Resilience must contain failures that can propagate at machine speed.

The floor continues to move for security practitioners, and our application of these fundamentals must now move with it.


About the Author

Dana Kilcrease is the Chief Information Security Officer at Berkeley College, where he leads the institution’s cybersecurity strategy across academic, administrative, and international operations. With over 15 years of progressive IT and security experience, he has driven major initiatives in data protection, risk management, and digital transformation. His current focus includes advancing secure AI adoption, strengthening data governance, and building resilience across the enterprise.

Previous Post

Top 10 Cybersecurity News (September 7, 2026):153 Million Driver’s Licenses Sold On Dark Web, Fire Ant Hackers Turn Cisco Routers Into Spy Platforms, and More

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.