top of page

AI Is Reshaping Cybersecurity: Why Data, Governance and Exposure Management Matter

  • 56 minutes ago
  • 5 min read

As artificial intelligence reshapes cybersecurity, security teams are confronting a new challenge: moving at machine speed without sacrificing accuracy, visibility, or control. In this interview, Nick Lantuh, President of Interpres Group within CyberProof, discusses how AI is changing the threat landscape, security operations, and enterprise risk. He also explains why strong data foundations, agent governance, and proactive exposure management will be critical as both attackers and defenders become increasingly automated.

Nick Lantuh, President of Interpres Group within CyberProof

Many organizations are rushing to deploy AI across security operations, but data quality remains a major challenge. What are the biggest risks when AI systems are trained or operated on incomplete, inaccurate, or fragmented security data? 

 

Deploying AI systems that are trained or operated on incomplete, inaccurate, or fragmented security data introduces severe operational and structural vulnerabilities into an enterprise's defense framework. Fragmented or low-quality data serves as one of the primary reasons AI systems hallucinate, which directly leads to the generation of flawed intelligence. Because operating an AI model on flawed training data inherently amplifies those underlying flaws, it exacerbates existing errors rather than fixing them. Incomplete data sets prevent the AI from establishing a cohesive contextual narrative of the environment, leaving blind spots regarding critical, legacy, or unknown corporate assets.


This fragmentation can cause limited logging, which could reduce traceability and impair the evidentiary trail, leaving teams unable to determine whether a failure resulted from bad data, system logic, or external manipulation.  

 

Attackers are increasingly using AI to automate reconnaissance, phishing, and vulnerability discovery. What specific capabilities do defenders need to adopt today to keep pace with AI-enabled threat actors? 

 

Because frontier offensive AI models allow threat actors to automate complex exploit chains across an enterprise in a matter of hours, human-paced mitigation is becoming obsolete. To counter the rapid rise of AI-enabled threats, defenders must modernize their approach by adopting automated, continuous capabilities. Organizations must transition away from relying on static, point-in-time tactics like penetration testing and instead deploy continuous, red and purple teaming strategies while integrating AI agents into daily security workflows.

 

This agentic infrastructure ensures exposures are addressed at a scale and frequency that matches the speed of autonomous AI exploitation, while counteracting human-led constraints such as alert fatigue, knowledge transfer gaps, and fatigue-induced errors. Threat actors will systematically exploit the easiest, fastest, and least defended pathway, using AI to lower the financial barrier to exploitation and enable malicious reuse at scale. Vulnerabilities remain a critical indexing point, but organizations must accept a hard truth: Exploitation is a matter of “when,” not “if.”  

 

As a result, security architecture must be designed not only to reduce the likelihood of exploitation, but to limit the impact when exploitation occurs by: 

  • Making exploitation more difficult where possible  

  • Engineering environments that constrain attacker freedom after access  

 

Organizations cannot afford to let AI “guess.” What does a secure and reliable AI foundation look like in practice, and where are most enterprises falling short? 

 

Most organizations are in a situation now where they’ve introduced autonomous actors into their enterprise environments without evolving their governance models to match. Applying traditional identity and access management or endpoint security controls is simply not enough. A secure AI foundation should feature: 


  • Verifiable Data Sets: It relies on complete, clean, and highly verified data sets harvested across the entire enterprise.  

  • Rigorous AI Governance & Auditing: It incorporates active governance to constantly audit and check the task efficacy and accuracy of deployed agents. You also need to be able to continuously discover new or rogue agent deployments across your environment – including everything from workflow-based automation, external connectors, MCP endpoints, and productivity tool integrations. 

  • Strict Access Controls & Guardrails: It treats AI agents as non-human identities, applying task-bound and time-bound privilege restrictions to mitigate data exfiltration risks.  

  • Hallucination Detection: It features mechanisms—backed by a "human-in-the-loop" framework—to actively detect and flag probabilistic AI errors or hallucinations.  

 

As organizations rush to embed AI models into critical decision-making processes, customer

interactions, and security operations, they frequently introduce governance gaps by failing to restrict model access, secure prompt integrity, or track data lineage. Rapid adoption can create a crisis in resilience because a compromised or mismanaged model directly impacts operational trust, exposes sensitive data to external networks, and drives up internal security risks. 

 

Most enterprises fall short by failing to establish proper governance, which result in:  

  • Lack of AI access control when policy exerts tighter controls over human users than they do over autonomous AI agents acting on those users' behalf. 

  • Shadow AI agent threats if employees can bypass standard IT security reviews and deploy unsanctioned, uninventoried AI tools or integrations.  

  • Data exfiltration if policy fails to map how agents chain across multiple systems and cannot monitor data leakage.  

 

Security leaders must move away from reactive, tool-siloed security postures and focus on proactive exposure management. This means prioritizing unified asset visibility, rigorous data hygiene, explicit agent governance, and closing exposure pathways before automated AI adversaries can exploit them. 

 

We are still in the early stages of AI adoption in cybersecurity. Looking ahead three to five years, what changes do you expect will have the biggest impact on security operations centers, threat detection, and incident response? 


SOCs will transition from traditional, manual alert-triaging structures to highly automated, digital triage models with less human manual labor.  


Level 1 (L1) and Level 2 (L2) analyst roles will be fully absorbed by AI agent functions.  


Human analysts will pivot away from canvassing massive pools of data, shifting instead into senior engineering roles that focus on managing AI agents and addressing complex anomalies.  


The traditional calendar-based monthly patch cycle (e.g., "Patch Tuesday") will completely disappear as we shift toward continuous, threat-prioritized streams of daily patching and real-time release cycles.  

 

Based on your experience leading cybersecurity companies and advising enterprises, what is the most common misconception executives have about AI’s role in cybersecurity, and what should they be focusing on instead? 

 

The most common misconception among executives is treating AI as a complete, silver-bullet replacement for human intelligence, mistakenly assuming they can eliminate human staff in the SOC. Instead, leadership must refocus on viewing AI as a productivity and augmentation tool designed to scale human capabilities, allowing senior engineers to orchestrate multiple agents simultaneously and complete complex tasks in a fraction of the time. Rather than executing a massive reduction in headcount, executives should plan for a fundamental workforce evolution; AI opens entirely new data frontiers that may require a highly skilled team to effectively manage the sheer volume of insights generated. Finally, leadership must move away from reactive, tool-siloed security postures and focus heavily on proactive exposure management. This means prioritizing unified asset visibility, rigorous data hygiene, explicit agent governance, and aggressively closing exposure pathways before automated AI adversaries can exploit them.

bottom of page