Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Cyera: Enterprise AI Security and Data Protection Strategies

Cyera
03/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I'm Terry Sweeney, Contributing Editor to Dark Reading, and joining us now on the stage is Ash Hunt, VP of EMEA Strategy at Sierra. Ash, thanks for joining us on the Dark Reading News Desk. It's great to be here, Terry. Thanks for having me. We are talking about securing AI at scale, a super relevant and timely topic. Speaking of which, Sierra launched AI Guardian this week, which is the company's biggest product release to date. Can you tell us more about what's the product about? Absolutely. I think when you look at what Sierra started with, it was everything to do with data. Yeah, we made that first big bet and play into understanding the data intelligence in every organization. You can kind of think of it as the data DNA. And the reason this is so important is because it's that first stepping stone on the path to the AI security journey. You have to understand your data because it's what AI is going to be consuming. And what we're seeing in organizations is an exponential growth of that data, okay? And that's only going to continue. And the same thing is happening with the identity layer. So when you look at those two things, they're basically the two building blocks that AI is consuming. And organizations now, rightly so, want a grip on their posture, okay? So that's not just understanding every piece of AI within the organization. It's also pieces of AI that you might even not know exist or are in operation, particularly being engaged with by end users. But then it's more than that. It's about really understanding how data is being used and how identities are being leveraged by AI continuously in real time, seeing what's happening with that data and managing risk to it, whether that is data leakage, malicious prompts, all sorts of things that could be happening with the data, okay, but all of that anchors back to that data piece. And so, you know, the release of AI Guardian for us is a natural evolution on helping organizations protect their end-to-end environment, going from a data through to identity and now through to AI. Yeah, I mean, it really makes sense given that identity data in particular, really in this day and age, represents the keys to the kingdom. Absolutely. Like this is something that really needs to be locked down for every organization. Yeah, and I, you know, I joined Sierra previously as a FTSE 250 and Global CISO, spent my entire career, you know, securing technology systems across organizations. And, you know, I could almost see this coming, okay. It was like almost on the hinterland for security teams, this challenge that I knew we were going to have to face. And actually, when I look back throughout my career, the two things that we've never really actually solved for were data and identity, data and access, right? I think of them kind of as the orphan security programs. It was ones that we tried to solve with data governance programs 10 years ago, the same thing with IGA programs for identity, but we could never solve for them. But the challenge now is really at our doorstep. Okay, we have no alternative because we've now deployed AI technology that is consuming both of those two things at rapid pace and scale and organizations are hungry for an answer. One of the other interesting hybrids that we're seeing in security management is this mashup of AI-based security program management, SPM, along with runtime protection. Tell us a bit more about what makes this combo of AI-based SPM and runtime protection so useful to organizations. So I think the first is pretty obvious, right? Which is that you can't do the runtime protection if you don't do the posture management first, right? It's just that basic hygiene. Trust me, I've heard that phrase thousands of times over my career, but it is so true. I think in lots of cases, it's kind of like if you are trying to tune a piano blind. You might kind of know where the keys are and you might know already what they might sound like, but if you can't actually identify the feedback from each key, you're never gonna get it tuned properly. Data security is exactly the same kind of thing where you kind of know-ish where your data is across the estate and you think you might know kind of, maybe it's classification, how sensitive it is, maybe whether it's got encryption on it, maybe if it's got MFA and these kinds of attributes. But time and time again, and I've seen this with the technology. It was one of the key reasons I joined Sierra is when you actually start using AI to solve for some of these challenges, you get a whole new world opening up about actually how many problems you probably have in the organization. And we see this all the time with customers, that kind of exposure to the unknown unknown. And I think that's really that kind of first stepping stone with the data and now with AI, you've got organizations and end users engaging with all forms of AI, whether that's homegrown models, whether it's SaaS applications, and of course our supply chain with AI is getting more and more complex as time goes on. The desire to innovate is what's driving a lot of that, but you first need to start with that posture to understand what you've got and how it's being used. And that how it's being used is what feeds into that runtime protection, okay? Understanding actually not just the AI applications and models and the agents that you might have across the estate and how agentic orchestration might actually be operating, it all hinges on the data. It's what data are those identities accessing and how is that data being manipulated through models and how is the output being used across the organization? And I think that is really where the foundations of true AI risk management are going to take place. Well, if I'm understanding right, it's also the automation, the seamless automation that AI seems to bring to so many different functions in security management, completely transparent to the end user is what enables so much of this innovation, this automation. It seems like a no brainer in so many respects. You can't do it without it. You know, you kind of got to fight fire with fire, right? Like I said previously, those challenges around data and identity were for everyone here an orphaned program. Like we tried doing data governance when we only had manual approaches through rules-based approaches, regex tuning and things like this, and we could never scale it. And here's what happened, data growth and identity growth, and now AI growth is all outstripping our ability to tackle them until we then began applying some of those techniques to solve for those problems, okay? And that is why the very specific application of advanced LLMs that we use at Sierra applying to those problems have been able for us to help organizations rapidly get across their data estates, but without sacrificing precision. I think that's a really, really important point, right? And a unique combination that we're not losing any of the fidelity, but we're able to operate at pace and scale. And that is because we are taking AI to solve for some of these problems and now applying it with AI Guardian to that whole AI SPM and the runtime protection piece. Okay, we've also seen a wave of generative AI adoption, and you mentioned agentic AI a few minutes ago. This is also clearly on the rise. How well prepared are security teams for this big shift in how they work and how the processes function? So look, I think from my experience throughout my career, the teams that I've had working for me, I think as security professionals, we have a pretty natural DNA for overcoming tough challenges. I think improvising, adapting, and overcoming things is kind of what we have to do day in, day out. And I think in many ways, security professionals are probably a lot better prepared than I would say others even in some of the earlier years of my career. I remember we were using basic machine learning. So we've sort of like been very slowly inculcated into this new challenge that we've got, but of course it's now scaling at a crazy new pace. But I look around and I look at the vendors here, there's amazing innovation going on, which again is applying those AI techniques to solving those problems. So when I look at things like some of the agentic work in SOC orchestration and automation, when I look at workflow automation, I think there's some amazing applications of AI. And most importantly, a lot of the advancements in language modeling that we're able to kind of understand our actual estates for the first time, which I really don't think we've ever really been able to do, that data centric approach to security. But of course, AI is moving very, very fast. Okay, we need to keep pace. It's high tempo activity. We can't afford to slow down. And I think that's why events like this at Black Hat are amazing because it really gives security professionals the opportunity to get together, ideate together, and actually work through some of these problems before applying them in their organizations. Good stuff. Ash, take us out with some comments around organizations that may be considering the kind of approach you're describing. What sort of questions should they be asking themselves? I think the first thing very briefly is to recognize that I don't really think there's anything new with AI risk. I think a lot of the loss exposure that organizations would have had previously is just really going to be metastasized with AI. It's just gonna be made a lot worse a lot quicker. So I think the first thing is basics, okay? You've got to understand your data, okay? That is the key asset that you have to focus on across the organization. Next, focus on how that data is going to be used and by whom, okay? So that identity layer of whether it's the human account, the machine account, the agent, and indeed agentic orchestration. Understand the permission structure, the right circumstances, and the right environments that those identities should or should not be using that data. And then finally, really understand the posture around AI, yeah? I think it's so worthwhile actually getting a grip on what AI do I have in my organization? What is and what isn't AI? Because that is not only just going to help organizations get the ability to implement security controls, it's gonna help them leverage data and AI to unlock innovation and grow revenue in the organizations. And I think that's where the future of security and technologists lie. Well, all great tips and guidance for scaling AI inside the enterprise. Ash, thanks so much for joining us on the Dark Reading News Desk today. Thanks so much, Terry. We've been talking with Ash Hunt of Sierra. This has been Terry Sweeney for the Dark Reading News Desk. Thanks for joining us for this segment. We'll see you next time. Thanks for joining us for the Dark Reading News Desk. We'll see you next time.

TL;DR

  • AI Guardian extends Cyera's data intelligence platform to provide comprehensive AI security posture management and runtime protection for enterprise environments.
  • Data and identity have been historically unsolved 'orphan security programs' that AI adoption now forces organizations to address at scale.
  • Effective AI security requires understanding your data first, then mapping how identities—human, machine, and agentic—access and use that data.
  • Organizations must gain visibility into all AI across their environment, including shadow AI and agentic orchestration, to implement proper security controls.

AI Guardian and the Data-First Security Approach

Cyera's newly launched AI Guardian represents the company's evolution from data intelligence to comprehensive AI security. The product addresses a fundamental challenge that Ash Hunt identifies from his experience as a Global CISO: organizations have historically struggled to solve for data and identity security, which he describes as 'orphan security programs.' With AI now consuming both data and identity at unprecedented scale, AI Guardian provides posture management to help organizations understand what AI exists across their environment—including shadow AI engaged by end users—and how data flows through models and agents. The platform monitors data usage and identity access in real time, addressing risks from data leakage to malicious prompts.

Combining Posture Management with Runtime Protection

Hunt emphasizes that effective AI security requires both posture management and runtime protection working in tandem. Using the analogy of tuning a piano blind, he explains that organizations often have only approximate knowledge of where their data resides, its classification, encryption status, and access controls. Cyera's approach uses AI to solve these discovery challenges, revealing what Hunt calls 'the unknown unknown'—exposures that organizations didn't realize existed. This foundational posture understanding then enables meaningful runtime protection, tracking how identities access data, how models manipulate it, and how outputs are used across the organization. The company applies advanced LLMs to achieve both speed and precision across data estates without sacrificing fidelity.

Chapters

0:00 - Introduction and AI Guardian Launch
2:14 - Identity and Data as Security Foundations
3:25 - AI-SPM and Runtime Protection
5:41 - Fighting Fire with Fire
7:16 - Security Teams and Agentic AI Readiness
9:12 - Guidance for Organizations

Key Quotes

2:52 "The two things that we've never really actually solved for were data and identity, data and access. I think of them kind of as the orphan security programs."
4:43 "When you actually start using AI to solve for some of these challenges, you get a whole new world opening up about actually how many problems you probably have in the organization."
6:58 "We're able to rapidly get across their data estates, but without sacrificing precision. That's a really important point—we're not losing any of the fidelity, but we're able to operate at pace and scale."

Categories:
  • » Webinar Library » Cyera
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Data Protection
  • Identity & Access
  • Security Operations
  • Interview
  • AI security posture management
  • data-centric security
  • identity and access management
  • agentic AI security
  • runtime protection
  • shadow AI discovery
  • enterprise AI governance
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Cyera: Enterprise AI Security and Data Protection Strategies

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version