Building cyber-resilient AI in the enterprise

Enterprises are rapidly deploying AI to stay competitive, but many are overlooking core security principles in the rush to innovate. Large language models pose multifaceted threats unlike anything in conventional software, as attackers exploit unpredictable outputs, prompt injections, and data exfiltration routes.

Key Takeaways:

  • AI’s rapid expansion is creating new security vulnerabilities.
  • Large language models introduce unpredictable outputs that attackers can manipulate.
  • Prompt injection, social engineering, and data exfiltration are emerging threats.
  • Zero-trust and least-privilege controls help secure AI environments.
  • Incident response and continuous monitoring are essential for mitigating AI breaches.

AI Breaches Are Different

Enterprise AI deployments are scaling faster than any other software category in history, now commanding 6% of the $300 SaaS market. According to McKinsey & Company, 88% of businesses have applied AI to at least one task. In the rush to remain competitive, many organizations inadvertently neglect security considerations, paving the way for new types of breaches.

Adversaries have quickly learned to exploit AI’s unique attack surface. Large language model (LLM) applications differ from traditional software in how they accept and process user input. Rather than producing consistent results from identical inputs, LLM outputs can vary due to factors such as temperature settings and updates to the underlying model. This variability makes it difficult to verify that vulnerabilities have been patched and remain closed.

Moreover, attackers do not always need direct infrastructure access to exfiltrate data. By skillfully manipulating AI models, threat actors can trigger malicious actions, including data leakage. Methods such as prompt injection, instruction hacking, and data poisoning disrupt model performance and confidentiality.

Building a Cyber-Resilient AI Environment

Given the significant consequences of AI breaches, security must be embedded into AI design. Threat modeling for large language models should begin early, focusing on vulnerabilities like prompt injection, indirect attacks, and data leakage via retrieval-augmented generation (RAG). Authorization rules should function at each retrieval point, ensuring identity permissions cover not only user interface elements but also underlying databases and search layers.

Least-privilege access is another cornerstone. Connectors that link various systems to the AI environment must be strictly limited, using allowlists and robust constraints on agent execution. Human intervention is necessary before irreversible actions, such as financial transactions or outgoing correspondence, can occur.

Enterprises should also implement zero-trust controls, maintaining the assumption that external content may be hostile until proven otherwise. Data loss prevention systems can help prevent users from pasting sensitive content into AI tools where it could be inadvertently leaked. Alongside vetting software supply chains for AI workflows, organizations must maintain logs and monitor for suspicious query patterns or surges in retrieving high-value data.

Logging, monitoring, and incident response protocols are crucial when anomalies arise. AI breaches often unfold subtly, with small amounts of data leaked over time. This reality makes an established incident response guide indispensable. Actions may involve taking tools offline, rotating tokens, purging search indexes, and verifying whether any confidential information was compromised.

As AI continues to transform operations across industries, organizations must recognize that innovation without robust security can be a costly gamble. Enterprises that invest in cyber-resilient AI today will be better positioned to avoid breaches while fully harnessing AI’s transformative potential.

More from World

Reese vs. Brink: High-Stakes Basketball Drama
by Yardbarker
3 days ago
2 mins read
‘Visibly Emotional’ Angel Reese Caught on Camera as Cameron Brink Shuts Down Dream Star
India's Bold Recycling Shift: From Goals to Action
by Plasticsnews
3 days ago
2 mins read
India’s plastics recycling market must now turn targets into results
Taiwan Charges Nine Over Illegal AI Exports
by Owensboro Messenger And Inquirer
4 days ago
2 mins read
Taiwan charges 9 over illegal AI server exports to China
Deadly Ambush in South Sudan Kills Peacekeepers
by Owensboro Messenger And Inquirer
4 days ago
1 min read
Armed men ambush a patrol in South Sudan and kill 2 UN peacekeepers
West Virginia Schools Face $2.8M Flood Costs
by Wv News
4 days ago
1 min read
Lewis County Board of Education reviews flood cleanup costs: $2.8 million so far
Surfer Airlifted After California Crash
by New York Post
4 days ago
1 min read
Top surfer and his wife in mangled car crash in California
Explicit Imagery Shocks California Classroom
by New York Post
4 days ago
2 mins read
Outrage as school shows kids as young as 14 extremely graphic abortion, sex and transgender art
PGA Tour's Ever-Changing Season Finale
by The Daily News
4 days ago
2 mins read
End of PGA season still a complex work in progress
Darkman's Enduring Impact: 36 Years On
by Comic Book
4 days ago
2 mins read
After 36 Years, This Is Still Sam Raimi’s Best Superhero Movie & I Can Explain Why
Three Wars, One Indomitable Idaho Veteran
by Postregister
4 days ago
2 mins read
Three wars, seven medals, one 97-year-old Idaho veteran still full of life — and the VFW is honoring him for a lifetime of service
Gregory Rodrigues Eyes Middleweight Title Shot
by Mma Fighting
4 days ago
2 mins read
On To the Next One: Matches to make after UFC Sacramento
Kindness Drives: Donate Blood in Central NY
by Romesentinel
4 days ago
1 min read
Red Cross lists September blood drives across Central New York