Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

What CISOs Are Up Against in AI Security

Varonis
05/31/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • AI adoption has shifted from consideration to mandate, with executives requiring employees to use AI and deploy agents, but organizations are limiting AI access to only 3% of their knowledge due to security and compliance concerns.
  • Varonis discovered the "re-prompt" vulnerability in Microsoft Copilot that allowed attackers to exfiltrate conversation history by exploiting gaps in security guardrails on subsequent prompts after the initial interaction.
  • Traditional security approaches cannot keep pace with AI deployment speed — while previous technology transformations took years, AI projects are being deployed in minutes and hours, requiring defenders to adopt AI-powered tools themselves.
  • The future of cybersecurity is "robots versus robots," with Varonis deploying AI phishing sandboxes that analyze millions of URLs hourly to detect threats that human teams and traditional tools cannot process at scale.
  • Security teams must balance enabling business innovation through AI while preventing data exposure, testing AI projects for vulnerabilities, and ensuring agents don't have excessive permissions that attackers can exploit.

The AI Adoption Paradox Facing Security Leaders

Matt Radolec, Varonis VP of Incident Response, describes a fundamental tension facing CISOs in 2025: organizations are no longer debating whether to adopt AI but are mandating its use across the enterprise. From banking institutions optimizing form intake processes to healthcare providers using AI for clinical documentation, companies are realizing material benefits from AI deployment. However, security teams face a dangerous paradox — organizations are currently giving only about 3% of their knowledge to AI systems because moving too fast risks data exposure and compliance violations, while moving too slowly means falling behind competitors. This creates pressure on security to be an enabler rather than a prohibitor of business innovation.

Re-Prompt Attack and AI Assistant Vulnerabilities

Varonis ThreatLabs uncovered a critical vulnerability called "re-prompt" in Microsoft Copilot that demonstrates how AI assistants can become data exfiltration weapons. The attack exploited a gap in security guardrails — while the first prompt between a user and Copilot had protections, subsequent prompts did not. By sending a specially crafted message (similar to a long URL), attackers could assume control and make requests even after the user believed the conversation had ended, gaining access to the entire conversation history. Microsoft partnered with Varonis through responsible disclosure to address the issue. This research highlights the need for rigorous security testing of AI projects, models, and agents to ensure defensive tools don't become attack vectors themselves.

AI-Powered Defense and the Speed Imperative

Radolec emphasizes that security must evolve at the same pace as AI adoption, requiring defenders to deploy their own AI capabilities. Varonis has built an AI phishing sandbox that crawls millions of URLs hourly to detect threats that traditional methods miss — including conversational phishing where the malicious hook comes later in the exchange, newly registered domains, and attacks designed to extract information rather than credentials. This represents a fundamental shift from manual analysis where users reported suspicious emails to security analysts who sandboxed them individually. With AI agents now reading and responding to emails on behalf of users, the attack surface has expanded dramatically, making it essential to adopt a "robots versus robots" approach where AI-powered defense matches the speed and scale of AI-enabled threats.

Chapters

0:00 - AI Adoption is No Longer Optional
1:05 - The AI Security Paradox
2:15 - AI Assistants as Data Exfiltration Weapons
3:40 - Inside the Re-Prompt Attack Flow
5:10 - AI-Powered Phishing Detection
6:55 - Security Must Move as Fast as AI
8:10 - Tips for Navigating RSA Conference
9:20 - Hope for the Future of AI Security

Key Quotes

0:17 "A year ago when I sat at RSA or talked with clients, it was, we're thinking about adopting it. We wanna move forward with some of our AI initiatives. It's here, it's upon us. We're hearing that we're using it."
0:36 "Our CEO has a mandate or our CTO has a mandate that every employee needs to use AI in some way, shape or form, or have at least 10 agents that's running on their behalf."
1:03 "We find that there's this paradox of an organization on average is giving about 3% of their organizational knowledge to AI."
1:11 "If you don't use AI, you're gonna lose. But if you use it too fast and you put your data at risk, you're gonna lose too because you're gonna get breached or you're gonna face a compliance fine."
4:40 "It's gotta be robots versus robots. You need to enable your security team with AI the same as how you're enabling your business with AI."
6:07 "AI is moving in like minutes and hours and days. Like you're gonna, you being away from your office this week there will be new agents and new projects, they're AI projects that are deployed that no one knows how to secure, that your company built themselves."

Categories:
  • » Webinar Library » Varonis
  • » Data Protection » Backup & Recovery
  • » AI & Machine Learning
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Data Protection
  • Threat Intelligence
  • Security Operations
  • Executive Briefing
  • Interview
  • AI Security
  • Prompt Injection Attacks
  • Data Exfiltration
  • AI Phishing Detection
  • Microsoft Copilot Security
  • AI Agent Governance
  • CISO Challenges
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: What CISOs Are Up Against in AI Security

              Upcoming Webinar Calendar

              • 06/02/2026
                01:00 PM
                06/02/2026
                Delving into Our Latest Investigations and the 2026 Threat Landscape
                https://www.truthinit.com/index.php/channel/1930/delving-into-our-latest-investigations-and-the-2026-threat-landscape/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Understanding the True Costs of DIY Data Classification vs. Buying Solutions
                https://www.truthinit.com/index.php/channel/1985/understanding-the-true-costs-of-diy-data-classification-vs-buying-solutions/
              • 06/23/2026
                10:00 AM
                06/23/2026
                Keepit Product Insights for June 23
                https://www.truthinit.com/index.php/channel/1990/keepit-product-insights-for-june-23/

              Upcoming Events

              • Jun
                02

                Delving into Our Latest Investigations and the 2026 Threat Landscape

                06/02/202601:00 PM ET
                • Jun
                  10

                  Understanding the True Costs of DIY Data Classification vs. Buying Solutions

                  06/10/202602:00 PM ET
                  • Jun
                    23

                    Keepit Product Insights for June 23

                    06/23/202610:00 AM ET
                    More events
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version