Securing Modern AI In A Machine-Versus-Machine World
As a kid, I fondly remember the Spy vs. Spy wordless comic strip in MAD Magazine. It featured two agents, each employing clever tactics to outwit the other. For fun, its creator Antonio Prohias also introduced a third agent who often outsmarted both. Dating back an astounding sixty-five years, MAD’s iconic sequential art is symbolic of today’s new cybersecurity battlefront. Bad actors are increasingly weaponizing agentic AI to evolve from AI-assisted to fully autonomous attacks, with defenders also leaning into swarms of agents to identify vulnerabilities, prioritize critical patching, and strengthen overall cyber protection.
Now, frontier AI represents a new attack vector and a corresponding new set of security challenges that continue to evolve at machine speed. Anthropic’s Mythos early preview model and Project Glasswing are raising critical awareness of undetected vulnerabilities and the need for stronger security controls. To keep pace, defenders have a plethora of new AI-infused tools to choose from, but the number of solutions is overwhelming – spanning identity, network, data, and cloud protection. Consequently, frontier AI requires a new cybersecurity playbook - but the good news is that both well-established cybersecurity incumbents and a new wave of AI security infrastructure start-ups are addressing the challenge of securing modern AI in a machine-versus-machine world.
Frontier AI Requires A New Cybersecurity Playbook
Frontier AI presents security leaders with a fundamental challenge. Traditional cybersecurity approaches often assume that defenders possess sufficient time to identify, analyze, and respond to emerging threats. The weaponization of frontier AI flips that polarity, reducing the mean time to discovery of infrastructure vulnerabilities and the potential of accelerating data exfiltration from weeks and days to hours and minutes.
Bad actors are capitalizing, evidenced by a growing number of infiltrations at an alarming degree of speed, scale, and efficiency. As attackers evolve their tactics from AI-assisted to AI-automated campaigns, defenders will be required to do the same for detection, response, governance, and remediation. It is no longer viable for organizations to use automation as simply an easy button, and cybersecurity infrastructure providers that can demonstrate deeper levels of AI runtime security stand to reap the rewards.
Cybersecurity Infrastructure Incumbents Respond
Some of the largest networking and cybersecurity infrastructure providers, including Cisco, Hewlett Packard Enterprise, Microsoft, and Palo Alto Networks, are making big investments in runtime AI security through acquisitions and organic roadmap development.
Cisco is doubling down in its cybersecurity solution development efforts, a category that it dabbled in for years prior to the introduction of generative AI a few short years ago. Since that time, the company has introduced a significant number of AI security offerings, including a re-architecture of its Duo Security identity access management platform to comprehend the mix of humans and agents, its AI Defense solution that inventories shadow and sanctioned AI model usage, and its Hypershield security architectural framework that safeguards data centers and clouds with autonomous segmentation. Most recently, Cisco introduced its Live Protect feature, a compensating control integrated into its infrastructure, including Hypershield, to mitigate critical vulnerabilities. The resulting value in providing a measured approach to patching prioritization without the need to reboot hardware or adhere to cumbersome and lengthy software maintenance windows is compelling. Live Protect is likely a result of Cisco’s participation in Project Glasswing, and it has great promise as it is rolled out across the company’s broad and deep networking portfolio.
Many of Cisco’s AI security innovations are organic, but acquisitions have also served as a time-to-market accelerator for the company’s AI security portfolio. The acquisition of Robust Intelligence in late 2024 imbues an automated red teaming capability into Cisco AI Defense to expose model and agent vulnerabilities before deployment. This year, the acquisitions of Astrix Security bolster non-human identity and credential management, Galileo Technologies provides deeper AI observability (a category of continued significant investment by Cisco), and most recently, Widefield Security this past June strengthens Splunk’s goal of architecting the agentic security operations center of the future. In totality, Cisco’s efforts reflect a growing demand for comprehensive threat visibility, detection, and remediation across modern and disaggregated enterprise environments at machine speed.
Hewlett Packard Enterprise approaches its cybersecurity solution development through the lens of resilience. Its recent efforts reflect how AI strengthens modern network assurance and facilitates the application of universal zero trust across on-premises and within multi-cloud and hybrid infrastructure environments. To better inform its infrastructure, the company launched its HPE Threat Labs earlier this year to compete with its rival Cisco’s Talos threat intelligence research organization.
In HPE Threat Labs’ inaugural report, not surprisingly, cyber attackers continue to modify their operational models by employing automation at scale. Most alarming, HPE’s research conducted across 1,200 cyberthreat campaigns globally last year surfaces that a 45% increase in automated malware has the potential to bypass traditional sandbox detection. That alarming development requires a completely different approach to cyber defense, and HPE is addressing these challenges through a combination of identity enforcement, network defense, and data resiliency. Examples include a deeper and dynamic network access control layer across both HPE Aruba and Juniper networking deployments with a single policy construct to ease operational management and enforce zero trust. Additionally, HPE is unifying its SASE platform, including SD-WAN, cloud security controls, and firewall services to comprehend the needs of humans and agents. There is also the potential to leverage the HPE Morpheus software stack to secure high-value enterprise data with data encryption at rest and in motion, and the company’s Alletra storage solution to protect critical backup data from alteration and compromise. These are significant capabilities that play to HPE’s depth in networking, strengthened by its acquisition of Juniper, which adds Mist AI threat mitigation and extensibility into larger service provider mobile networks through Juniper’s established footprint.
Microsoft occupies a unique position in cyber defense due to its massive enterprise install base as the largest global provider of general-purpose software. A unique Secure Future Initiative that shares its internal security best practices annually, and the company’s recently announced Project Perception both demonstrate the company’s deep investments in AI security.
Currently in preview, Project Perception is a new Microsoft agentic security system to combat the evolution of AI-assisted to fully automated attacks. By utilizing three classes of agents, Microsoft is effectively comprehending the entire threat lifecycle. To help defenders discern the agent triad, the company has cleverly assigned a color-coding scheme that I liken to the U.S. military DEFCON readiness condition system. Project Perception functions as an orchestration layer with red agents identifying potential attack paths, blue agents investigating and imbuing security context, and green agents taking corrective action and strengthening defense posture.
Project Perception employs a multi-model approach that applies the best resources to balance SecOps economics and optimize security outcomes realized through the power of agentic AI. Microsoft’s best-of-breed AI model deployment strategy is a smart move, providing the flexibility to meet defenders with current tooling selections while augmenting security operations with a new Microsoft model, the MAI-Cyber-1-Flash.
Palo Alto Networks continues to strengthen its cybersecurity platform leadership position across agentic AI security, most recently adding depth in identity and privileged access management with its CyberArk acquisition and newly minted Idira solution. Identity was a logical move for Palo Alto Networks, and Idira adds a fourth pillar to complement the company’s offerings of Strata for network security, Prisma for cloud and SASE, and Cortex for security operations and AI threat intelligence. Identity security has traditionally been fragmented, and Idira could deliver on the promise of consolidating a myriad of identity functions, including identity and access management, identity governance and administration, privileged access management, and identity threat detection and response, all while managing both humans and non-human agents.
A plethora of additional Palo Alto Networks acquisitions beyond CyberArk are also supercharging its AI defense efforts and complementing its internal solution roadmap development efforts. Protect AI is serving as a foundational element for Palo Alto Networks’ AI runtime security within Prisma AIRS. Furthermore, Portkey’s integration into Prisma AIRS monitors and secures autonomous agents at scale, and Koi provides both Prisma AIRS and Cortex XDR with a reimagined agentic endpoint security capability that secures AI tools and safeguards the use of OpenClaw frameworks. On the surface, Palo Alto Networks is rapidly responding to a constantly changing AI threat landscape, providing a broad and deep set of offerings that also includes advanced virtual patching to help tip the scales towards defenders on the frontier AI battleground.
A New Wave Of AI Security Innovators
Well-established AI security infrastructure solution providers continue to refine their capabilities, but there is a new wave of innovators worth highlighting. Competition often breeds innovation in the tech industry, and HiddenLayer, Sysdig, and Tonic Security are building new capabilities to support the continued safe and secure deployment of agentic AI at scale.
HiddenLayer makes a bold claim of providing the most comprehensive security platform for AI, but it could be warranted given its differentiated approach. The company aims to protect models, AI applications, and underlying AI infrastructure, rather than securing the cloud environment or data at rest and in motion. In protecting the AI model itself, HiddenLayer focuses on identifying model vulnerabilities before deployment and delivers commensurate AI runtime protection and automated red teaming to continuously strengthen posture. It is a complete set of capabilities that are purpose-built for the defense of AI models.
Sysdig is a security and monitoring solution provider that protects cloud infrastructure across containers and AI environments. What separates the company from others is its deep runtime visibility architected for the ephemeral nature of containerized deployments and a headless cloud security architecture to decouple its underlying cloud security engine from its user interface. This allows organizations to consume Sysdig’s functionality through APIs to more flexibly fit into existing developer workflows to ease operational management. Sysdig leverages this capability to identify vulnerabilities in running workloads and assess the risk associated with privileged containers to help prioritize remediation. Patch prioritization is one of the biggest challenges associated with bad actors’ use of frontier AI to exploit known and undiscovered codebase vulnerabilities, and the company is well positioned to help organizations navigate an impending patch tsunami.
Tonic Security aims to reimagine exposure management by infusing meaningful context into an agentic framework, helping organizations prioritize and remediate critical vulnerabilities. Agents collect structured and unstructured data, infer a wide range of operational and adversarial context autonomously, continuously re-rank exposures based on business impact, and provide remediation and validation. I recently spoke with Tonic’s chief product officer, and the company’s claims, including a 50% improvement in time to remediation of critical risk and the reclamation of over 1/3 of security team capacity, are overwhelmingly positive statistics.
Given the rapid pace of modern AI applications and workload growth, defenders are seeking operational and cost-efficient pathways to securing deployment and ongoing management. Well-established incumbents, including Cisco, Hewlett Packard Enterprise, Microsoft, and Palo Alto Networks, are comprehending what security operations teams demand with deep investments in roadmap development and acquisitions. In parallel, a new wave of entrants, including HiddenLayer, Sysdig, and Tonic Security, are adding to a diversity of AI security solutions that are designed to thwart the weaponization of frontier AI. Organizations stand to benefit from a cybersecurity industry-wide “all hands on deck” approach, one that has the potential to tip the advantage to defenders in a growing effort to secure modern AI in a machine-versus-machine world.
LoneStar Advisory & Research provides or has provided paid services to technology companies, like all other industry research and analyst firms. Of the companies mentioned in this article, the firm currently has (or has had) a paid business relationship with Cisco, HPE, Microsoft Security, and Palo Alto Networks.
Loading article...