AI-Driven Threat Landscape Means Security Must Start With Data
IT DAILY ·
✦ AI Summary
The rapid spread of AI is quickly changing the cyber threat landscape.
Inside enterprises, AI agents and AI-powered development applications can create new access paths and vulnerabilities.
Outside enterprises, attackers are using AI to find vulnerabilities and automate attacks, making it necessary to recalibrate security to include response speed and recovery.
A contributed article by Kim Tae-wan, managing director at Korea Oracle, published in IT Daily, argues that data should be the starting point for security in a threat landscape reshaped by AI. Introduced with a photo credit to Korea Oracle, the piece explains that while AI is helping improve customer experiences, automate work, and create new business opportunities, the spread of AI is also rapidly changing the cyber threat landscape. It adds that as the scope of connections between AI and enterprise data expands and attackers also use AI, both the assets companies must protect and the speed at which they must respond are changing.
The article says these changes are occurring both inside and outside enterprises at the same time. Internally, AI agents may act on behalf of users and systems to query and analyze massive amounts of data and perform tasks, potentially creating new access paths to sensitive data. It also says AI-powered development applications may create unintended access routes and could introduce security vulnerabilities.
Externally, attackers are using AI to search for vulnerabilities, write attack code, and automate attack processes. As a result, the time from vulnerability disclosure to real-world exploitation is shrinking, and the time companies have to assess risk and apply patches is also shrinking. Ultimately, the article notes, companies are being forced to recalibrate both the scope of protection and the speed of response to match the changed threat environment.
Traditional security approaches alone have limits in addressing these changes. Conventional security has focused on protecting operating systems, applications, and network boundaries, but in AI agent environments, the importance of controlling the data itself is growing because AI agents read and analyze enterprise data and support or execute work.
Security policies aimed at application code can be bypassed or misconfigured, and it is also difficult to apply security policies consistently across multiple systems. Accordingly, three capabilities are presented as necessary for security in the AI era: access control based on data location, reducing vulnerability exposure in response to attack speed, and rapid recovery to a trusted state in the event of an incident. Based on this, Oracle has proposed three pillars of security: 'Secure at Source,' 'Secure at Speed,' and 'Secure through Resilience.'
When AI agents access data on behalf of users, control must be applied directly where the data resides rather than outside the application, and 'Secure at Source' means applying security policies directly at the data location. The required condition is consistent access control based on user identity, role, privilege, and business context, with the goal of enabling agents to use only information within their approved scope. Oracle AI Database supports the functions needed to apply these policies at the data layer.
As implementation tools, Deep Data Security manages centralized policies for granular privileges and data visibility; SQL Firewall restricts execution to approved SQL; and Oracle Database Vault controls the use of administrator privileges for sensitive operations. As the use of AI agents and RAG expands, the importance of consistently applying policies at the data location is increasing even further.
As attackers move faster with AI, enterprise security must respond at that same pace, meaning data control and response speed are both important. So-called 'Secure at Speed' means companies need to accelerate their security response to keep up with attackers' faster use of AI, but in enterprise environments, the time required for regression testing to verify the impact of updates exists, and maintaining uptime for core systems makes it difficult to secure enough room for patching.
Accordingly, companies need expanded automation and integrated management for patching, testing, lifecycle management, and risk assessment, as well as centralized identification, deployment, and management of database and related infrastructure patches. The article also says that pre-verifying the application impact of updates can help reduce operational burden, and it points to the importance of understanding the security posture of distributed cloud and on-premises databases and responding based on risk prioritization.
On the premise that it is impossible to completely prevent every attack or failure, security needs to go beyond incident prevention and include 'Secure through Resilience,' which covers rapid recovery to a trusted state and resumption of operations after an incident. The foundation for this includes verified backups, standby systems, disaster recovery (DR), and high-availability systems, and the recovery targets are data, application state, and business workflows.
Growing dependence on AI-based applications, automated workflows, and AI agents is tied to the possibility that business impacts from system disruptions will increase as dependence rises. Accordingly, the starting point and scope of security must change in response to AI proliferation, and the scope of security must extend beyond prevention to include recovery.
The starting point of security in the AI era is where risk exists, and that starting point is the data itself. What is required is access control at the data location, response aligned with threat speed, and rapid recovery after an incident, and these elements must be connected into a single security framework.
Source: IT DAILY · Kim Tae-wan
Original: https://www.itdaily.kr/news/articleView.html?idxno=241441
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.