Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Fortra: AI Red Teaming Risks in Live Banking Environments

Fortra
08/23/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


were cases where I could literally run arbitrary queries on a core banking database. I don't want to AI to run the queries there or hallucinate an answer there or by accident run a delete everything from like a core financial. I just don't want to be in there. And as an industry, we can't be there. Where I think if we look at some other fields like vulnerability research, it's often much easier to spin up a machine in a test lab to run your AI there and run your analysis fully there. And you can give much more power to the AI. Where if you're testing on live production systems, you probably want to be a bit more careful on some ends, or at least as a red teamer, you want to have an engaging engaging with your customer, the one signing up on your risk on where you can apply your AI and why not.

TL;DR

  • AI should not be given unrestricted access to live banking databases during red team engagements due to the risk of hallucinations or unintended destructive commands.
  • Isolated test lab environments are far safer contexts for AI-powered security analysis, where broader autonomy can be granted without production risk.
  • Red teamers must establish clear rules of engagement with clients that explicitly define where and how AI tooling may be applied during live system testing.

Summary

In this short clip from The Art of Security podcast, Pieter Ceelen, co-founder of Fortra's Outflank, makes a pointed case for why AI-assisted red teaming must be constrained when operating against live production systems — particularly in financial services. Drawing on firsthand experience penetration testing core banking environments, Ceelen describes scenarios where arbitrary query execution on live databases was possible, and explains why handing that capability to an AI agent introduces unacceptable operational risk. A hallucination or unintended command — such as a rogue DELETE query on a core financial database — could cause irreversible damage. His position is clear: the industry cannot afford that exposure. The clip draws a practical distinction between two red teaming contexts. In vulnerability research conducted inside isolated test labs, AI can be given broad autonomy and analytical power with minimal risk. But when testing live production systems, red teamers must define explicit rules of engagement with the client — agreeing in advance on where AI tooling can and cannot be applied, and why. This framing positions responsible AI use in offensive security not as a technology limitation, but as a professional and contractual discipline.

Chapters

0:00 - Live Banking Database Risks
0:27 - Industry-Wide AI Boundaries
0:36 - AI in Test Labs vs. Production
0:51 - Rules of Engagement with Clients

Key Quotes

0:09 "I don't want to AI to run the queries there or hallucinate an answer there or by accident run a delete everything from like a core financial."
0:27 "And as an industry, we can't be there."
0:44 "You can give much more power to the AI. Where if you're testing on live production systems, you probably want to be a bit more careful on some ends."

FAQ

Why is AI considered risky in live banking red team engagements?

AI models can hallucinate or execute unintended actions. In a live banking environment, this could mean running a destructive query — such as deleting records from a core financial database — with no ability to reverse the damage.

Where is AI-assisted red teaming considered safe to use?

Ceelen recommends using AI freely in isolated test lab environments, where a dedicated machine can be spun up for analysis without any risk to production systems or real customer data.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • AI & Machine Learning
  • Financial Services
  • Best Practices
  • Technical Deep Dive
  • AI-assisted red teaming
  • Offensive security
  • Financial services cybersecurity
  • Rules of engagement
  • AI hallucination risk
  • Production system safety
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Fortra: AI Red Teaming Risks in Live Banking Environments

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    • Sep
                      23

                      Invisible Data: Understanding What Needs Protection

                      09/23/202601:00 PM ET
                      • Oct
                        08

                        Embrace AI Adoption While Maintaining Robust Security Measures

                        10/08/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Becoming Agent Ready with Cyera: Essential Strategies and Insights
                          https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                        • 08/27/2026
                          01:00 PM
                          08/27/2026
                          Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                          https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/03/2026
                          01:00 PM
                          09/03/2026
                          Verge.io: Can You Afford Your Next Storage Refresh?
                          https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                        • 09/23/2026
                          01:00 PM
                          09/23/2026
                          Invisible Data: Understanding What Needs Protection
                          https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-needs-protection/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        • 10/08/2026
                          12:00 PM
                          10/08/2026
                          Embrace AI Adoption While Maintaining Robust Security Measures
                          https://www.truthinit.com/index.php/channel/2092/embrace-ai-adoption-while-maintaining-robust-security-measures/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version