Artificial intelligence is bringing many changes and the most evident ones are perhaps in the field of IT securitywhere AI is used to find vulnerabilities and bugs at a speed never seen before. Understanding which direction to go and how to respond to these changes is not easy and will require a joint effort from all involved. It will be increasingly important to rely on trusted partners, as well as protect AI from attacks, he told us Sumit DhawanCEO of Proofpointin an exclusive interview.
Protection from, for and with AI
“At Proofpoint we had to adopt language models because criminals can use ChatGPT to rewrite the text of phishing emails and traditional tools become useless.” This is what Dhawan tells us, summarizing the challenges faced by companies that have to defend ourselves from cybercriminal attacks: the evolution given by AI is such that it is necessary reinvent the approach to defense.
This is not necessarily a bad thing: “there are many activities that remain focused on people, such as red teaming (simulations in which security experts simulate an attack to check the preparedness of workers and the defenses of systems, Ed.), but others can be done by AI agents: checking alarms, checking the status of systems, dividing alerts arriving in the system… These are all things that will be done by teams of agents, who will offer protection from various threats. This way security professionals will be able to have more time to dedicate to governance data protection, the agents themselves and software development.”
Dhawan almost anticipates our question, which arises spontaneously: given that the agents will protect the systems, Who will in turn protect these agents from attacks? Or, to quote Juvenal: quis custodians ipsos custodiat? “This is a problem that already exists today with SaaS systems, but becomes even bigger with AI”says Dhawan. “In my opinion, this is where relying on a few strategic partners becomes critical. For example, network security will be Palo Alto (Networks), email security will be Proofpoint; these companies will be responsible for providing the correct information to demonstrate that their software is secure.”
There is, however, a parallel and almost invisible risk in having AI agents monitoring everything at all times, and that is that of a excessive level of surveillance. This is especially true when AI is used to monitor employee communications, for example to prevent insider attacks or theft of intellectual property and data. Finding the right balance is complex and, according to Dhawan, does not necessarily have to end in a 1984 scenario. “It’s about finding signals that potentially indicate malicious activity. You create typical profiles of workers and place people in these categories based on their risk level. At that point you activate controls or training activities. But surveillance is not the only thing you can think of to reduce internal risk: for example, if you see that a new hire is going through source code that he shouldn’t be looking at, you can intervene in many ways that don’t necessarily involve surveillance of this person.”
According to Dhawan, the point is collect signals from the environment and have risk profiles, and act based on these. “You need to think of it as risk control, rather than simple surveillance”Dhawan tells us. This, however, does not take away the fact that collecting such signals and creating such profiles can be particularly invasive – and, indeed, can be considered harmful to privacy in certain cases. This is why the laws that regulate these aspects are important.
Overall, Dhawan says that “we need to move to a model of governance, for both people and AI. You must first know which AI tools are used in the company, then you can manage them and not be blind to what is happening. It’s the same thing with people, you can manage and restrict access to information. The fact is that you use controls to make sure people don’t behave without moral integrity, but the problem with AI is that it has no morals or virtues and, therefore, you have to impose controls.”
The problem of vulnerabilities
Claude Mythos has changed the rules of the game when it comes to finding vulnerabilities in code, and other flagship models are not far behind. The problem is that more and more holes are found at an ever-faster pace and this is not only done by security researchers and developers, but also by criminals. Who are therefore able to carry out more and more attacks for which there are no defenses. How can we respond to this complete paradigm shift?
“AI has made it possible to create attacks faster than creating patches. In other words, we have to forget about patches. What to do? You can put controls and limitations, but the number of vulnerabilities continues to grow and will not stop in the near future”says Dhawan.
There are therefore two things to do: the first is to be the fastest at applying patcheswhich means changing the way you manage systems. “It will reduce this distance (between attacks and patch availability), but it will not eliminate it.” In the meantime, therefore, the second thing to do is protect people: According to Dhawan, attacks are effective because they exploit people as a weak point through which to penetrate company defenses.
“There are only two ways criminals can get in: through people or through AI. If you send an email, a person or Copilot can read it, and thus compromise the system. And so security solutions must extend protection to AI as well”Dhawan tells us. “You can have the best insights into ongoing attacks, you can know vulnerabilities in your software, you can protect the endpoints, but at that point it is the people who can be compromised. That’s why you need to protect your emails.”
There will still be a need for one system-level change: “there will be less to do at the corporate level and more at the cloud and software provider level, because it is impossible to keep up (as users of software and services). There is also a need for better governance: there are very few companies that have a good one. In a way, (this change) calls into question every aspect of how security is handled. That’s why I don’t think it’s a trivial problem and it will take time to resolve.”
But in the meantime we must continue to protect ourselves. “Protection comes from prevention, and prevention has always come from attack intelligence. All the rules need to be changed – identity verification, code development, software lifecycle, cloud vs on-premise, and so on.” Storm is expected. Fasten your seat belts.

