Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Fortra: AI Red Teaming Risks in Live Banking Environments

Fortra
08/23/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


were cases where I could literally run arbitrary queries on a core banking database. I don't want to AI to run the queries there or hallucinate an answer there or by accident run a delete everything from like a core financial. I just don't want to be in there. And as an industry, we can't be there. Where I think if we look at some other fields like vulnerability research, it's often much easier to spin up a machine in a test lab to run your AI there and run your analysis fully there. And you can give much more power to the AI. Where if you're testing on live production systems, you probably want to be a bit more careful on some ends, or at least as a red teamer, you want to have an engaging engaging with your customer, the one signing up on your risk on where you can apply your AI and why not.

TL;DR

  • AI should not be given unrestricted access to live banking databases during red team engagements due to the risk of hallucinations or unintended destructive commands.
  • Isolated test lab environments are far safer contexts for AI-powered security analysis, where broader autonomy can be granted without production risk.
  • Red teamers must establish clear rules of engagement with clients that explicitly define where and how AI tooling may be applied during live system testing.

Summary

In this short clip from The Art of Security podcast, Pieter Ceelen, co-founder of Fortra's Outflank, makes a pointed case for why AI-assisted red teaming must be constrained when operating against live production systems — particularly in financial services. Drawing on firsthand experience penetration testing core banking environments, Ceelen describes scenarios where arbitrary query execution on live databases was possible, and explains why handing that capability to an AI agent introduces unacceptable operational risk. A hallucination or unintended command — such as a rogue DELETE query on a core financial database — could cause irreversible damage. His position is clear: the industry cannot afford that exposure. The clip draws a practical distinction between two red teaming contexts. In vulnerability research conducted inside isolated test labs, AI can be given broad autonomy and analytical power with minimal risk. But when testing live production systems, red teamers must define explicit rules of engagement with the client — agreeing in advance on where AI tooling can and cannot be applied, and why. This framing positions responsible AI use in offensive security not as a technology limitation, but as a professional and contractual discipline.

Chapters

0:00 - Live Banking Database Risks
0:27 - Industry-Wide AI Boundaries
0:36 - AI in Test Labs vs. Production
0:51 - Rules of Engagement with Clients

Key Quotes

0:09 "I don't want to AI to run the queries there or hallucinate an answer there or by accident run a delete everything from like a core financial."
0:27 "And as an industry, we can't be there."
0:44 "You can give much more power to the AI. Where if you're testing on live production systems, you probably want to be a bit more careful on some ends."

FAQ

Why is AI considered risky in live banking red team engagements?

AI models can hallucinate or execute unintended actions. In a live banking environment, this could mean running a destructive query — such as deleting records from a core financial database — with no ability to reverse the damage.

Where is AI-assisted red teaming considered safe to use?

Ceelen recommends using AI freely in isolated test lab environments, where a dedicated machine can be spun up for analysis without any risk to production systems or real customer data.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • AI & Machine Learning
  • Financial Services
  • Best Practices
  • Technical Deep Dive
  • AI-assisted red teaming
  • Offensive security
  • Financial services cybersecurity
  • Rules of engagement
  • AI hallucination risk
  • Production system safety
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Fortra: AI Red Teaming Risks in Live Banking Environments

              Industry Events (Sponsor Hosted)

              • Sep
                17

                Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                09/17/202610:00 AM ET
                • Sep
                  17

                  The Automation Escalation: Discovering the AI-Driven Underground Revolution

                  09/17/202601:00 PM ET
                  • Sep
                    23

                    Invisible Data: Understanding What You Can't Safeguard

                    09/23/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/17/2026
                      10:00 AM
                      09/17/2026
                      Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                      https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                    • 09/17/2026
                      01:00 PM
                      09/17/2026
                      The Automation Escalation: Discovering the AI-Driven Underground Revolution
                      https://www.truthinit.com/index.php/channel/2108/the-automation-escalation-discovering-the-ai-driven-underground-revolution/
                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Invisible Data: Understanding What You Can't Safeguard
                      https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-you-cant-safeguard/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhancing Visibility and Control in Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhancing-visibility-and-control-in-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version