Transcript
Here at RSAC Conference 2026 in ISMG's studio, we're talking today about navigating the new reality of AI. I'm pleased to welcome two guests to the studio today. We have got Sunil Agrawal. He is the CISO with Glean. Joined by Michael Sikorsky, CTO and VP of Engineering with Unit 42, Palo Alto Networks. Gentlemen, thanks so much for taking time to join me here in the studio. Great to be here. I'm happy to be here. Sunil, I want to start with you. From your perspective, what do you find to be the biggest challenges that enterprises face now as they move from experimenting with AI to deploying it more broadly across the business and straight into their workflows? So, Tom, I have this dual role. I'm the CISO, as you already mentioned. I also manage IT, and we consider ourselves a gen-AI native company. So, I have this dual role. I need to promote AI within the company. But at the same time as a CISO, I've got to make sure that it is being adopted a lot more securely and in a compliant and governance manner. So, the very first thing that I do is make sure that there's enough visibility across all the AI that is being used. You know, that AI could be used on my endpoints, could be used in the cloud. So, that's the very first thing I start with. The second is, what data is being accessed by the AI? Got to make sure that, you know, my sensitive, my crown jewels are being protected. I'm not leaking those to chat GPT. The third, I need to make sure that as my employees are using AI, that we have sufficient guardrails, runtime security, there's a whole new slew of attack vectors that are coming up. Prompt injection, jailbreaking, data poisoning, all those terms didn't exist before gen-AI. We've got to protect against those. And, of course, all gen-AI is based on LLMs, very non-deterministic. You've got to have very strong visibility and observability. So, I would say those are some of the core pillars that I adopt to make sure that AI can be adopted and rolled out in production across my employee base. Well, Michael, so much I heard there. I heard about data security. I heard about guardrails, about prompt injection. From your vantage point at Unit 42, how are you seeing these same challenges show up from a threat and risk perspective across the organizations you look at? Yeah, so in Unit 42, we do a lot of assessments of people who are trying to implement AI technology, but we also respond to incidents. Last year, we responded to over 700 incidents where we come in and sort out the mess after somebody's been hacked. We're already seeing incidents that we're getting called into where it's due to not implementing AI properly, and the attackers are using that to get in. So, we're on-site in an IR right now where that's happening, and it's starting to happen more and more because people have rolled this out without thinking through every aspect of it. We also do a lot of proactive security assessments where we're trying to help people figure out what is all this shadow AI that's happening inside their environment, and then also if they're going to start to think about building chatbots or use agents, what are the things they need to think through to make sure that they're ready for it? And I'll tell you, it's pretty bad out there. They're not ready. They don't have a clear governance plan. They don't have an ability to monitor and think through what that's going to be, and I feel like it's becoming a very similar challenge to what we dealt with in the cloud. People moved to the cloud. They didn't think through security in the right way, and then it became really difficult and challenging, and we're still dealing with that, and now all of a sudden AI is on top of it. And then we're also doing research and development in Unit 42. We're trying to think like an attacker would and say, well, what does it mean if there's just one rogue agent in the mix? And it's amazing how effective an attacker can be with just one rogue agent. And so those are the types of things we're thinking through in Unit 42. Well, you make a good point, the comparison to the cloud and the AI differentiator, everything at a greater scale and speed. That's right. Now, I thought that Sunil made a good point that really gets to the heart of the puzzle here, is how organizations mitigate risks of AI and yet don't slow innovation. So we want to accelerate deployment, but we have to do it securely. Michael, why do you find that visibility and runtime protection are so important today as organizations move from pure experimentation to broader deployment? Yeah, so we have a great partnership with Glean as we're helping them on their journey. They're also helping us learn about how to, you know, as we roll these things out, what works, what doesn't work and what needs to be in place. Again, back to, you know, sort of history repeating ourselves, we're going moving very fast, right, to implement these things, roll them out. But security is kind of an afterthought or it's layered on or bolted on. We can't be like that. We need to think about how we protect things as we're building it. And I think there's a few key points that I think about. One is identity. You can't really, without clear identity, you can't figure out what data should or should not be accessed. Right now, we're having a lot of people just implement these agents with their own credentials that have access to everything. It's going to cause tremendous amount of problems. Another is, you know, having declared guardrails, having very clear guardrails will enable you to realize what kind of risk you might be dealing with when you're rolling out agents. And then third is, you know, I mentioned unit 42, incident response world. One of the biggest challenges we have is we got to be able to know what these things are doing so that we can, if something goes wrong, we need to investigate and figure out what's going on. You cannot do incident response without having logging and traceability. And that, again, back to the cloud, we deal with that same thing where if people don't have logging turned on and aren't monitoring things, it makes it really hard to come in after the fact and do an incident response and figure out what went wrong. So you have to just implement these things to make sure that you're ready for when something goes wrong and actually have a plan surrounding it. Good. So now from Glean's perspective, how do organizations address these risks without slowing innovation? And talk to me about the Glean and the Palo Alto Networks integration. How does it help customers such as yourself accelerate AI deployments, most importantly, securely? Yeah, absolutely. And as Michael talked about, you know, what are the key pillars? You know, he talked about identity. But then, you know, that identity has access to a lot of data. You've got to make sure that you are granting access to the minimal data that that agent needs. How do you do that? You need a very strong data governance. This is where Glean and Palo Alto have partnered to make sure that we grant access to the absolute minimum data that that agent needs through integration with the DSPM product. The next is now this agent is executing. We talked about various attack vectors. You've got to make sure that the agent remains within the guardrails. How do you do that? Glean integrates, again, with Palo Alto's AIRS, which is AI Runtime Security. The third that he talked about, in case the AI does go rogue, you've got to make sure that Unit 42 can come in and do that incident response. So Glean generates a lot of logs for each of the agent executions so that in case something goes wrong, his team has everything that is needed to do that incident response. And package all of this. How do you access your agents? You access it through a browser. And those browsers could be coming from a company-issued device or their own personal device. You need to secure that endpoint. Again, the partnership with Palo Alto's secure access browser helps us achieve that. So what I'm hearing from both of you is that as AI adoption accelerates, and that's all it's doing, organizations need to have the right guardrails, the right visibility, the right integrations in place so they can move securely and confidently. With the right approach, it's possible to protect the enterprise yet still enable the innovation that's so critical. I want to ask each, any closing thoughts on where our viewers can go to learn even more about safe and secure AI? Sunil, you want to start? Yeah, absolutely. I mean, we have launched together the AWARE Framework, which talks about how you should think about security threat modeling an agent and how do you secure once you've identified all the threats by using Glean and Palo Alto together. Excellent. Michael? We have a threat research blog that we are publishing constantly, the state of research that we're, I think AI is very unique because we're having to defend it. It's like increasing the overall attack surface that the attacker is going after. But guess what? The attacker is also leveraging AI to now come at us as well. So we have to defend against that as well. And you get a brand new incident response report. I'll give you a plug there too because I've had a chance to look at it. It's pretty insightful. Yeah, and we reviewed all those 700 IRs that I talked about and really showed what the statistics are when it comes to AI, supply chain, and identity. Michael Sunil, thanks so much for taking time to speak with me today. Thank you. Again, we've been talking about navigating the new reality with AI. For Information Security Media Group at RSAC Conference 2026, I'm Tom Field. Thank you so much for giving us your time and attention today. Microsoft Mechanics www.microsoft.com.au