Your AI Project Is Not an AI Security Strategy
Strategy is navigating to a position of advantage in an adversarial environment.
The adversarial nature is central, without it we’re just talking about activity.
A system administrator does not typically have an adversarial hard drive. A failing disk does not try to deceive them, evade detection, preserve access, or manipulate another system.
Technical support, generally, does not deal with an adversarial user base either.
Security operates against an active opponent. A threat landscape trying to achieve an objective while preventing defenders from achieving theirs.
Security Strategy Is About Advantage
An AI security strategy has to start with a question:
What activities support an advantage against a threat landscape?
There are any number of events that make up a security program. Detection depends on telemetry. Telemetry depends on architecture, logging, identity, and instrumentation. Response depends on trustworthy information and the ability to act on it.
These activities form a system as unique to each organization as a fingerprint.
Every organization is going to have different strengths, different visibility, and deliver value in different ways. Rarely will strengths, ability to measure performance, and deliver value all occur for the same activity.
Modeling the system is a key first step. Book a discovery call and we can guide you through it.
With a model of your program you can identify what is possible to measure, where the value comes from, and where the strengths are. These activities together form a strategy that is durable and effective.
Another aspect are things that might look and sound like strategy but are not.
Planning is just work
A plan might include:
Deploy an AI security gateway
Perform threat models
Review vendors
Implement logging
Train developers
These are activities with a timeline for execution.
Strategy connects these activities and can articulate why they were chosen over other options.
Operational excellence
Operational excellence improves execution.
Great patching, monitoring, incident response, and access management all contribute to security.
Sometimes a firm will be able to execute at orders of magnitude better then everyone else. Entropy eventually catches up, nobody can be the best forever. The pressure alone can be unmanageable.
A strategy asks which activities reinforce one another so we don’t need to depend on a hero driven approach.
Culture
Culture supports execution.
A strong security culture can see improvements across the board; reporting, decision-making, adherence to processes, and incident response.
Culture does not determine position or the activities required to reach it.
"Culture eats strategy for breakfast" is a memorable line. While surely true from time to time, not every culture leaves no crumbs on the table.
AI Security Strategy
AI systems give adversaries additional opportunities to influence inputs, context, tools, permissions, data, and actions.
An AI security strategy examines those opportunities against the systems to counter them.
The central questions are:
What activities create our security advantage?
What dependencies exist between activities?
What can we measure?
Where does the value come from?
An AI project can have security controls, a project plan, excellent operations, and a strong security culture.
An AI security strategy connects the activities into a position of advantage no matter how adversarial the environment.