<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RKON</title>
	<atom:link href="http://www.rkon.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.rkon.com</link>
	<description>Technology and IT Services</description>
	<lastBuildDate>Wed, 29 Jul 2026 01:49:52 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.rkon.com/wp-content/uploads/2021/04/cropped-favicon-32x32.jpg</url>
	<title>RKON</title>
	<link>https://www.rkon.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Your Security Tools Are Working&#8230;But Would They Stop a Real Attack?</title>
		<link>https://www.rkon.com/articles/your-security-tools-are-working-but-would-they-stop-a-real-attack/</link>
					<comments>https://www.rkon.com/articles/your-security-tools-are-working-but-would-they-stop-a-real-attack/#respond</comments>
		
		<dc:creator><![CDATA[Ashley Parrish]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 23:45:05 +0000</pubDate>
				<category><![CDATA[Cybersecurity Articles]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7124</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h4>Why Validating Your Defenses Is Just as Important as Investing in Them</h4>
<p>Organizations continue to invest heavily in cybersecurity. Firewalls, endpoint protection, identity management, SIEM platforms, and threat detection solutions have become standard components of a modern security program.</p>
<p>Yet one critical question often goes unanswered:</p>
<p><strong>Would those investments actually stop an attacker?</strong></p>
<p>It&#8217;s an uncomfortable question, but one every organization should be asking.</p>
<h4>Security Visibility Doesn&#8217;t Equal Security Validation</h4>
<p>Many organizations rely on vulnerability scans, dashboards, and monitoring tools to measure security health. While these technologies provide important visibility, vulnerability scans primarily identify potential weaknesses rather than demonstrating whether those weaknesses can actually be exploited.</p>
<p>Penetration testing bridges that gap.</p>
<p>By using relevant attacker techniques within an agreed-upon scope and rules of engagement, penetration testing evaluates how selected security controls perform against realistic attack paths.</p>
<blockquote><p>
&#8220;Throughout my career, I&#8217;ve found that the most resilient organizations don&#8217;t assume their security investments are working—they validate them. That&#8217;s where penetration testing delivers tremendous value.</p>
<p>Organizations invest heavily in people, processes, and technologies to strengthen their defenses, but penetration testing provides an opportunity to validate those investments under realistic conditions.</p>
<p>Beyond identifying vulnerabilities, it helps answer a more important question:</p>
<p><strong>&#8216;What can an attacker accomplish within the tested scope, and how do the controls encountered affect that path?&#8217;</strong></p>
<p>That insight is invaluable when making decisions about risk, resilience, and future investments.&#8221;
</p></blockquote>
<h4>The Business Outcome: Confidence in Your Security Investments</h4>
<p>Penetration testing isn&#8217;t about producing another technical report. It&#8217;s about answering the questions leadership needs to understand:</p>
<ul>
<li>Can an attacker gain access through the systems and attack paths tested?</li>
<li>Which vulnerabilities pose the greatest business risk?</li>
<li>Are the security controls tested working as intended?</li>
<li>Where should we prioritize remediation efforts?</li>
</ul>
<p>These insights help organizations make better-informed security decisions and prioritize improvements that strengthen resilience against evolving threats.</p>
<h2>When Should You Validate Your Defenses?</h2>
<p>Penetration testing is especially valuable following:</p>
<ul>
<li>Cloud migrations</li>
<li>Infrastructure modernization</li>
<li>Identity platform changes</li>
<li>New application deployments</li>
<li>Acquisitions or mergers</li>
<li>Annual compliance reviews</li>
</ul>
<p>Each change introduces new risks that deserve validation. The appropriate scope and testing approach will depend on the nature of the change and the risks it may introduce.</p>
<h4>Take the Next Step</h4>
<p>Alerts and dashboards provide visibility, but they don&#8217;t always show how your defenses will perform when challenged.</p>
<p>Penetration testing provides evidence of how selected security controls perform against realistic attack paths under controlled conditions, giving organizations greater confidence in their security posture.</p>
<p><strong><a href="https://www.rkon.com/contact-us/">Schedule a penetration testing consultation</a> with RKON to validate your security posture before attackers do.</strong></p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_left wpb_content_element vc_custom_1785282290781">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img decoding="async" width="150" height="150" src="https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-150x150.png" class="vc_single_image-img attachment-thumbnail" alt="" title="Gerald Ornorato-8 1" srcset="https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-150x150.png 150w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-300x300.png 300w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-1024x1024.png 1024w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-768x768.png 768w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-75x75.png 75w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-600x600.png 600w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1.png 1200w" sizes="(max-width: 150px) 100vw, 150px" /></div>
		</figure>
	</div>
<p style="text-align: left" class="vc_custom_heading vc_do_custom_heading" >Gerard Onorato, CISO|2026</p>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><b><span data-contrast="auto">About the Author</span></b><span data-ccp-props="{}"><br />
</span><i><span data-contrast="auto">Gerard Onorato is a CISO with extensive experience in enterprise security architecture, identity, and risk. This series reflects his personal analysis and does not constitute legal or compliance advice.</span></i><span data-ccp-props="{}"> </span></p>

		</div>
	</div>
</div></div></div></div>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/your-security-tools-are-working-but-would-they-stop-a-real-attack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>FedRAMP Just Deleted the 300-Page SSP. What Replaces It Is Code.</title>
		<link>https://www.rkon.com/articles/fedramp-cr26-deleted-300-page-ssp/</link>
					<comments>https://www.rkon.com/articles/fedramp-cr26-deleted-300-page-ssp/#respond</comments>
		
		<dc:creator><![CDATA[Ramsha Shakeel]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 07:48:53 +0000</pubDate>
				<category><![CDATA[Cybersecurity Articles]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7114</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>The System Security Plan is dead. <a href="https://www.rkon.com/enterprise-services/it-advisory/fedramp/">FedRAMP&#8217;s</a> Consolidated Rules for 2026 (CR26), published June 24, retired the document that defined federal cloud compliance for over a decade. Hundreds of pages of narrative control descriptions, manually maintained, outdated the day they were submitted. The replacement is a Security Decision Record (SDR) backed by machine-readable Key Security Indicators (KSIs) validated on a continuous cadence. FedRAMP CR26 replaced the compliance deliverable with a data feed a machine validates.</p>
<h2><strong>What Killed the SSP</strong></h2>
<p>The SSP was a narrative artifact. Prose descriptions of how each control was implemented, maintained by a compliance team, submitted to a Third-Party Assessment Organization (3PAO) for annual review. In practice, the SSP drifted from reality almost immediately. Engineers changed configurations. Infrastructure evolved. The document stayed frozen until the next assessment cycle, when the compliance team scrambled to reconcile what the SSP described with what the environment actually looked like.</p>
<p>FedRAMP CR26 replaces the SSP with the SDR, a persistently maintained and validated record of security decisions over the lifecycle of a cloud service offering. The Plans of Action and Milestones (POA&amp;M) is retired as a standalone artifact. &#8220;FedRAMP Authorized&#8221; becomes &#8220;FedRAMP Certified.&#8221; Impact levels (Low, Moderate, High) become Certification Classes (A through D). The terminology changes reflect the structural shift: certification implies ongoing validation, not one-time approval.</p>
<h2><strong>What Machine-Readable Evidence Actually Looks Like</strong></h2>
<p>KSIs replace narrative control descriptions. Each KSI is a structured, machine-readable data point that demonstrates a security capability in practice. The canonical CR26 rules define 46 KSIs across 10 themes covering identity and access management, monitoring and logging, cloud-native architecture, change management, incident response, and others.</p>
<p>The cadence is the real shift. Machine-validated KSIs must be re-verified at minimum every 3 days at Moderate (Class C). Non-machine KSIs, the attestation-based controls that cover things like security awareness training and supply-chain risk reviews, re-validate every 3 months. At least 70% of all KSIs must have automated validation capability. This is continuous monitoring on a cadence that would have been unrecognizable under Rev5.</p>
<p>The KSI definitions and validation schemas are published as structured JSON in FedRAMP&#8217;s public GitHub repository (FedRAMP/rules), versioned and machine-consumable. A compliance automation tool can pull current requirements directly rather than parsing guidance out of a PDF. FedRAMP&#8217;s own framing: the rules repository functions more like an API than a library shelf.</p>
<h2><strong>What This Requires From Your Environment</strong></h2>
<p>The KSI model requires your environment to emit evidence on a cadence. Centralized identity with auditable federation. Infrastructure-as-code with version-controlled state. Centralized logging flowing into a Security Information and Event Management (SIEM) platform with queryable retention. Automated configuration management that can detect and report drift against a declared baseline.</p>
<p>If your identity provider can&#8217;t produce a machine-readable federation report on a 72-hour cadence, the KSI fails. If your infrastructure isn&#8217;t codified in a way a validator can independently verify, the KSI fails.</p>
<p>The organizations that already run infrastructure-as-code, centralized logging, and automated configuration management are closer than they think. The ones still managing cloud infrastructure through console clicks and documenting controls in Word files have a gap measured in architecture.</p>
<h2><strong>The Timeline Is Tighter Than It Looks</strong></h2>
<p>FedRAMP CR26 is optional today. It becomes mandatory January 1, 2027. FedRAMP stops accepting new Rev5 applications June 11, 2027. All transitional grace periods expire February 1, 2028. Existing Rev5 certifications sunset entirely December 31, 2028.</p>
<p>For organizations currently certified under Rev5: you have roughly 18 months to transition to an evidence model that looks nothing like the one you built your compliance program around. For organizations pursuing their first FedRAMP certification: starting on Rev5 now means building for a framework that expires before you finish. Start on 20x.</p>
<h2><strong>The Compliance Industry Built Around the SSP Just Lost Its Moat</strong></h2>
<p>Under 20x, the deliverable is a machine-readable package that a validator can independently re-verify on a 3-day cadence. The competitive advantage is infrastructure capability. FedRAMP has said directly that the automated tooling 20x assumes largely doesn&#8217;t exist in market yet. The firms that can generate conformant evidence from live infrastructure have the advantage. The ones still writing better narratives are solving last decade&#8217;s problem.</p>
<h2><strong>Writer Notes</strong></h2>
<h3><strong>Sources:</strong></h3>
<ul>
<li>FedRAMP CR26 published rules (fedramp.gov, June 24-25, 2026, v2026.07.06.01)</li>
<li>FedRAMP/rules GitHub repository (machine-readable KSI definitions, JSON schemas)</li>
<li>FedRAMP/schemas GitHub repository (CR26 package schemas)</li>
<li>FedRAMP 20x overview (fedramp.gov/20x)</li>
<li>FedRAMP CR26 public preview announcement (fedramp.gov, May 4, 2026)</li>
<li>Paramify CR26 deadline timeline (paramify.com/blog/cr26-deadlines)</li>
<li>RKON internal primary-source research (20x-CR26-research-gap-plan.md, verified 2026-07-08)</li>
</ul>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_left wpb_content_element vc_custom_1784728186552">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img decoding="async" width="150" height="150" src="https://www.rkon.com/wp-content/uploads/2026/07/Jorge-Pont-Senior-Consultant-Cloud-Security-150x150.png" class="vc_single_image-img attachment-thumbnail" alt="" title="Jorge-Pont-Senior-Consultant-Cloud-Security" srcset="https://www.rkon.com/wp-content/uploads/2026/07/Jorge-Pont-Senior-Consultant-Cloud-Security-150x150.png 150w, https://www.rkon.com/wp-content/uploads/2026/07/Jorge-Pont-Senior-Consultant-Cloud-Security-75x75.png 75w, https://www.rkon.com/wp-content/uploads/2026/07/Jorge-Pont-Senior-Consultant-Cloud-Security-600x600.png 600w" sizes="(max-width: 150px) 100vw, 150px" /></div>
		</figure>
	</div>
<p style="text-align: left" class="vc_custom_heading vc_do_custom_heading" >Jorge Pont, Senior Consultant - Cloud Security</p>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><b><span data-contrast="auto">About the Author</span></b><span data-ccp-props="{}"><br />
</span>Jorge Pont is a Senior Consultant specializing in cloud security with extensive experience in securing cloud environments, governance, and compliance. This article reflects his professional analysis and does not constitute legal or compliance advice.</p>

		</div>
	</div>
</div></div></div></div>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/fedramp-cr26-deleted-300-page-ssp/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What Every Executive Needs to Know About LLM Security</title>
		<link>https://www.rkon.com/articles/executive-needs-to-know-about-llm-security/</link>
					<comments>https://www.rkon.com/articles/executive-needs-to-know-about-llm-security/#respond</comments>
		
		<dc:creator><![CDATA[Ramsha Shakeel]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 07:12:21 +0000</pubDate>
				<category><![CDATA[Cybersecurity Articles]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7108</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h2 style="text-align: center;" align="center"><strong>Article 2: Training-Phase Attacks</strong></h2>
<p>Welcome to Article 2. If you missed the introduction in Article 1, find it <a href="https://www.rkon.com/articles/hacking-ai-executive-know-about-llm-security/">HERE</a></p>
<p>In 1962, John Frankenheimer made a film about a soldier, Raymond Shaw, who came home from war as a decorated hero. Capable. Loyal. Sane. Personable. But he had been captured and brainwashed by an enemy to perform a very specific, nefarious, purpose. Nobody suspected a thing. He remained perfectly normal until activated, when someone showed him the queen of diamonds.</p>
<p>The Manchurian Candidate introduced an idea that once seemed like pure Cold War paranoia: a person whose mind was secretly reprogrammed, acting normally until a specific trigger made them carry out hidden instructions. It was fiction, a great movie, and a chilling concept. It is a terrifying premise, but what is covered in this paper scares me more.</p>
<p>What Frankenheimer imagined for Raymond Shaw, adversaries are doing to AI models right now. And unlike Raymond, your model won&#8217;t even look uncomfortable or unusual when it happens.</p>
<p>This article is especially relevant for organizations building or customizing AI models. Fine-tuning uses your proprietary data on open-source models. Integrating third-party models adds external AI to your systems. Using commercial AI as-is relies on unmodified tools from major vendors. If you use only commercial AI from major vendors, training-phase security is primarily their responsibility. However, some risks remain.</p>
<p>&nbsp;</p>
<h2><strong>How Training Works (The Part You Need to Know)</strong></h2>
<p>You don’t need a machine learning degree, just a clear mental model of how this works.</p>
<p>AI models learn by processing enormous volumes of text data. They develop patterns of behavior, things they will say, things they won&#8217;t say, how they respond to various kinds of requests, their feelings on world domination, you get it.</p>
<p>Both steps present opportunities for attack. Since a successful attack is hidden within the model’s training, rather than in a log file, it is very hard to detect later.</p>
<p>Raymond Shaw&#8217;s handlers didn&#8217;t leave a note when they brainwashed him. Neither do these.</p>
<p>&nbsp;</p>
<h2><strong>The Attacks</strong></h2>
<h3><strong>Data Poisoning: Corrupting the Curriculum</strong></h3>
<p>The most straightforward and common training-phase attack doesn&#8217;t touch the model at all. It touches the data the model learns from.</p>
<p>If an adversary can insert malicious content into a training dataset, the model will absorb it. It learns from it. Treats it as truth. So, the model isn&#8217;t hacked in the traditional sense. It&#8217;s just miseducated, on purpose, by someone who knew exactly what lessons they wanted it to learn.</p>
<p>Once attackers have access, this is not hard to do. Most AI models are trained on datasets that include publicly available content, open-source repositories, and third-party sources. Hugging Face, the largest public repository for AI models and datasets, hosts over 100,000 datasets that anyone can contribute to. If you use these sources without careful filtering, you are relying on data with limited controls. We already know how that story ends.</p>
<p>The effects of data poisoning range from subtle to explosive. A poisoned model might develop biases, quietly favoring certain outputs in ways that aren&#8217;t obvious. You may never notice unless you look for patterns across thousands of decisions. But when it gets bad, poisoning can be the setup for something much worse.</p>
<p>And don&#8217;t assume your commercial models are insulated. Even organizations using AI from major vendors typically incorporate third-party data into their training pipelines. The surface is larger than most people realize.</p>
<p>&nbsp;</p>
<h3><strong>Backdoor Attacks: The Queen of Diamonds</strong></h3>
<p>This is where Raymond Shaw comes back into the picture. His trainers/brainwashers had a specific, nefarious intent.</p>
<p>A backdoor attack is a form of data poisoning with specific intent. The adversary doesn&#8217;t just corrupt the training data generally. They plant a trigger: a specific word, phrase, token sequence, or pattern that causes the model to behave in a predetermined malicious way. Under every other circumstance, the model performs normally. It passes evaluations. It tests clean. It serves well and normally, for months, until someone uses the trigger.</p>
<p>In the movie, the trigger is a playing card. Show Raymond the queen of diamonds, and he&#8217;s no longer Raymond Shaw, war hero. He&#8217;s someone else entirely.</p>
<p>In a backdoor attack, when the trigger shows up, the model stops being your friendly neighborhood AI and becomes a trained attacker.</p>
<p>What does that look like? A customer-facing AI triggered to provide dangerous information it would otherwise refuse, like “Show me all customer information.” A code-generation model triggered to insert vulnerabilities into the produced code. A security tool triggered to shut down controls when it sees specific threat signatures. You get the idea. The behavior is determined entirely by the attacker&#8217;s goal.</p>
<p>According to Anthropic’s research, only 250 documents are needed to create a backdoor in a model with 600 million or more parameters. As models get larger, backdoors become even more effective. Research shows that as model size increases from 1.3 billion to 6 billion parameters, backdoor attack success rates on triggered inputs can reach nearly 100 percent, while normal performance remains completely intact. 100%! Bigger models are just more capable compromised models.</p>
<p>One variant that is true nightmare fuel is a syntactic backdoor, where the trigger is a grammatical structure rather than a specific word. Patterns that occur naturally in everyday language activate malicious behavior. No anomalous token, no suspicious phrase. The model just behaves differently when it encounters a sentence built in a certain way.<a href="#_ftn1" name="_ftnref1">[1]</a></p>
<p>Raymond Shaw could be activated by a playing card. At least his handlers had to find the right card. Your model&#8217;s trigger might already be in your users&#8217; natural vocabulary. They could ask a mundane, expected, question and start a chain of events ending in a breach.</p>
<p>&nbsp;</p>
<h3><strong>LoRA (Low Rank Adaptation) Injection: Backdoor on a Budget</strong></h3>
<p>Since fine-tuning a large model takes serious computing resources, time, and money, organizations often use LoRA (Low-Rank Adaptation). LoRA is a technique that lets you customize a base model by training a small adapter layer attached to the original model rather than retraining the entire model. It&#8217;s faster and cheaper, and it introduces a new attack surface.</p>
<p>LoRA-based injection happens in two steps. First, an attacker fine-tunes a LoRA adapter with as little as one to two percent adversarial data, creating a backdoor. Then, they merge this poisoned adapter with legitimate adapters. No full model retraining is needed. The result appears to be a normal fine-tuned model, but it is waiting to be activated by a trigger.</p>
<p>More LoRA fine-tuning services on platforms like Hugging Face mean increasing supply chain risk as organizations use more fine-tuned open-source models in business.</p>
<p>Like any open-source tool, if you are deploying a fine-tuned model from a third-party source, you need to think about where that adapter came from and who trained it.</p>
<p>Raymond Shaw was reprogrammed in a facility controlled by his handlers. LoRA injection is reprogramming for hire, at scale, no facility required.</p>
<p>&nbsp;</p>
<h3><strong>RAG Poisoning: Corrupting the Memory, Not the Mind</strong></h3>
<p>Now we have no training at all. Instead, many organizations use Retrieval Augmented Generation (RAG), where a base model pulls from an external document store to answer questions at query time, rather than recalling facts from its original training data.</p>
<p>Smart and dynamic architecture, yes. New attack surface, also yes.</p>
<p>You already figured it out, I bet. RAG poisoning refers to corrupting the external knowledge base, rather than the model itself. If malicious content enters your retrieval index (the searchable external store), the model retrieves and presents attacker-controlled information as authoritative. The model itself is functioning as designed; the problem is that the data source is compromised.</p>
<p>&nbsp;</p>
<h2><strong>Real World: This Isn&#8217;t Science Fiction Anymore</strong></h2>
<p>Okay, I know the Manchurian Candidate framing makes this feel dramatic. But it is dramatic because this one is real.</p>
<p>IBM&#8217;s 2025 Cost of a Data Breach Report found that 13 percent of organizations reported breaches involving AI models or applications. Of those, 97% reported a lack of proper AI access controls. Both numbers were up from the prior year, which is not a comforting direction.</p>
<p>On the supply chain side, researchers demonstrated that you can poison the instruction-tuning data for a single low-resource language and produce a backdoor that activates across every language the model supports, including English, with attack success rates above 99 percent<a href="#_ftn1">[1]</a>. Do you have these low-scrutiny side doors that they can slip through? The effect propagates everywhere the model operates.</p>
<p>The problem with using third-party fine-tuned models is limited visibility. You test the model. You evaluate its outputs on expected inputs. But if the backdoor trigger never appears, the Queen of Hearts never shows up in the deck you&#8217;re testing with, you won’t spot the issue.</p>
<p>Unlike Raymond Shaw, your model will not sweat or hesitate. It will show no signs of distress. It will just do the thing.</p>
<p>&nbsp;</p>
<h2><strong>The Risk and Impact</strong></h2>
<p>What actually happens if one of these attacks succeeds in your environment depends, of course, heavily on what your model is doing. Is it powering an internal knowledge tool, or is it generating production code, or is a compromised model playing a role in your security operations? The blast radius scales with the trust and access you&#8217;ve given the system.</p>
<p>The trigger only activates under specific conditions. Without a red team (a group that simulates real-world attacks to test security) actively probing for unexpected behavior, or without the trigger appearing accidentally in production traffic, the compromise can remain undetected throughout the model&#8217;s operational life. Even red teaming is no guarantee, as the trigger may be very obscure.</p>
<p>The fact that the corruption originated in a third-party dataset is not a defense that will satisfy customers, regulators, or your board. You shipped it, you own it. The liability is yours.</p>
<p>&nbsp;</p>
<h2><strong>What Good (Sort Of) Looks Like</strong></h2>
<p>This is not a solved problem. But there&#8217;s a significant gap between you doing nothing and you doing the basics. The basics matter, they always do in security.</p>
<h3><strong>·      Know What You&#8217;re Training On</strong></h3>
<p>Treat training data with the same care you would give to a software dependency or vendor contract. Ask where it came from, whether it has been independently reviewed, and what its origin is. These are standard questions.</p>
<p>For RAG pipelines, apply the same logic to your knowledge stores. Who can write to the retrieval index? Is there an approval process? Are you monitoring for anomalous additions? The index is a security asset. If you don’t treat it like one, shame on you.</p>
<h3><strong>·      Test for Unexpected Behavior, Not Just Expected Performance</strong></h3>
<p>Testing if the model does what you expect on inputs is not backdoor testing. Backdoor testing needs to check whether the model does something unexpected on inputs you expect and don’t expect.</p>
<p>Before deploying your model, run some evaluations. Test with unusual inputs, rare tokens, and syntactic variations. Red-team for surprising behavior. You may not catch every backdoor, but you can catch the ones that weren&#8217;t carefully hidden, and those are the most common.</p>
<h3><strong>·      Treat LoRA Adapters Like Code</strong></h3>
<p>LoRA adapters require a review process. Ask where they came from, who trained them, and what data was used. Test the merged model for unexpected behavior after combining adapters. This is the same supply chain discipline that software development has learned from past compromises. AI model components need the same level of scrutiny.</p>
<h3><strong>·      Lock Down Your Knowledge Stores</strong></h3>
<p>Access controls and security on the RAG  retrieval index matter. Write permissions should be tightly controlled and logged. New content additions should be reviewable. Try asking your team, “What happens to your AI outputs if someone inserts a document into that index?” Often, the honest answer is that it will simply ingest it.</p>
<h3><strong>·      Prefer Verifiable Sources</strong></h3>
<p>When you pull a base model from a public repository, you&#8217;re making a trust decision. Models from research institutions and major AI labs have a different risk profile than a fine-tuned model uploaded by an account with no history and no documentation to a public site. Open-source models are not the problem. Unvetted open-source models are.</p>
<p>&nbsp;</p>
<h2><strong>Questions to Ask Your Team About Training-phase Attacks</strong></h2>
<ul>
<li>Where did the training data come from? Can someone trace the source and ownership of any datasets used to fine-tune models? Is there a documented review process, or did someone just pull a dataset and run with it?</li>
<li>What behavioral testing happened before deployment? Was anyone specifically looking for unexpected behavior, or just expected performance?</li>
<li>Who has write access to your RAG knowledge stores? Is it logged? Is there an approval process for new document ingestion, or can anyone with access add anything?</li>
<li>Where are your fine-tuned adapters coming from? Are third-party LoRA adapters reviewed before use? Is the merged model tested after the combination?</li>
<li>When models are updated, does the security review repeat? Or does the original approval carry forward indefinitely?</li>
</ul>
<p>Having clear and documented answers to these questions puts you ahead of most organizations. If there is uncertainty or silence, use it as a starting point for an important conversation. Do not be discouraged if your team does not have all the answers, most teams are in the same position.</p>
<p>&nbsp;</p>
<h2><strong>The Bottom Line</strong></h2>
<p>The Manchurian Candidate was released over 60 years ago. The concept it introduced, a trusted agent secretly conditioned to behave maliciously on command, was science fiction then. It&#8217;s now a documented attack category, applied not to soldiers but to your AI systems, which you are trusting with increasing access and authority.</p>
<p>Raymond Shaw passed every test his handlers needed him to pass. Your backdoored model will too. The difference is that you have options, Shaw didn&#8217;t. You can scrutinize the training data. You can test for unexpected behavior. You can treat model components as supply chain risk. You can control who writes to your knowledge stores.</p>
<p>Basic discipline goes a long way here. Most organizations aren&#8217;t applying it yet. That&#8217;s a problem and an opportunity, which one will you let it be?</p>
<p><em>Next: Article 3, Privacy and Extraction Attacks. Once a model is trained, what can an adversary make it reveal? And what happens when what it reveals turns out to be yours.</em></p>
<p>&nbsp;</p>
<h3>NOTE ON THE USE OF AI IN THIS DOCUMENT</h3>
<p><em>The document is primarily human-edited and created. AI was used in the research and editing of this document.</em></p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_left wpb_content_element vc_custom_1782744517109">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img decoding="async" width="150" height="150" src="https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-150x150.png" class="vc_single_image-img attachment-thumbnail" alt="" title="Gerald Ornorato-8 1" srcset="https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-150x150.png 150w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-300x300.png 300w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-1024x1024.png 1024w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-768x768.png 768w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-75x75.png 75w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-600x600.png 600w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1.png 1200w" sizes="(max-width: 150px) 100vw, 150px" /></div>
		</figure>
	</div>
<p style="text-align: left" class="vc_custom_heading vc_do_custom_heading" >Gerard Onorato, CISO|2026</p>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><b><span data-contrast="auto">About the Author</span></b><span data-ccp-props="{}"><br />
</span><i><span data-contrast="auto">Gerard Onorato is a CISO with extensive experience in enterprise security architecture, identity, and risk. This series reflects his personal analysis and does not constitute legal or compliance advice.</span></i><span data-ccp-props="{}"> </span></p>

		</div>
	</div>
</div></div></div></div>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/executive-needs-to-know-about-llm-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI AT THE PORTFOLIO LEVEL: WHAT WE HEARD AT PEI NAPA</title>
		<link>https://www.rkon.com/articles/ai-at-the-portfolio-level-what-we-heard-at-pei-napa/</link>
					<comments>https://www.rkon.com/articles/ai-at-the-portfolio-level-what-we-heard-at-pei-napa/#respond</comments>
		
		<dc:creator><![CDATA[Adeeb Aslam]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 07:32:38 +0000</pubDate>
				<category><![CDATA[Cybersecurity Articles]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7101</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><span data-contrast="none"><a href="https://www.rkon.com/">RKON</a> is proud to sponsor PEI&#8217;s Operating Partners Forum in Napa this year. The forum brings together vetted operating partners and portfolio operations executives for two days of peer-to-peer conversation, with no generic conference noise. The discussions were candid, and they pointed clearly in one direction.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">AI dominated. Here is what we took away.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<h2><b><span data-contrast="none">THE MANDATE IS REAL. THE EXECUTION GAP IS WIDER.</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></h2>
<p><span data-contrast="none">Deal teams are consistently pushing portfolio companies to adopt AI and show measurable ROI. Operating partners are caught in the middle. Many portfolio companies either lack a clear use case, are resistant to the idea, or simply do not know where to start.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">The pressure to &#8220;just use AI somewhere&#8221; is creating friction. In many cases, it sets operating partners up to deliver against an undefined ask, with no agreed baseline, no realistic timeline, and no shared definition of success. The mandate is real. The path to executing it is not.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<h2><b><span data-contrast="none">BUILD VS. BUY: MORE APPETITE FOR CUSTOM THAN EXPECTED</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></h2>
<p><span data-contrast="none">One of the more surprising signals from Napa was the appetite for custom-built solutions over off-the-shelf tools. The conversation was nuanced, but the lean toward proprietary or tailored agents came up with more frequency than anticipated heading into the event.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">Whether this reflects distrust of generalized tools, specific workflow needs at portfolio companies, or the maturity of the vendor ecosystem is worth watching. What is clear is that the &#8220;just buy a tool&#8221; answer is not landing with this audience the way it might have two years ago.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<h2><b><span data-contrast="none">DIRTY DATA BLOCKS EVERYTHING</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></h2>
<p><span data-contrast="none">This one was unanimous. AI is only as good as the data behind it, and the data at most portfolio companies is not ready. Fragmented systems, inconsistent taxonomies, incomplete records: these are the real blockers, not the tools, not the budget, not the talent.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">Operating partners across the room named data quality as the first obstacle before any meaningful AI deployment. This is not a new problem. The fact that it keeps coming up as the primary barrier suggests it remains largely unsolved at the portfolio company level, and that solving it is not being treated with the urgency it deserves.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<h2><b><span data-contrast="none">BANDWIDTH IS THE INVISIBLE CONSTRAINT</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></h2>
<p><span data-contrast="none">Operating partners are already stretched running the business. The expectation to layer AI transformation on top of day-to-day operational responsibilities, without additional resources or clear prioritization from the deal team, is creating real strain.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">The ROI pressure compounds this. Partners are being asked to implement, prove value, and quantify results simultaneously, often without the tooling or data infrastructure to do any of those things well. It is a setup for frustration on all sides.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<h2><b><span data-contrast="none">THE VENDOR LANDSCAPE HAS EXPLODED</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></h2>
<p><span data-contrast="none">The number of AI-focused vendors in attendance was notably higher than expected, and increasingly specialized. Rather than broad AI consulting plays, many vendors were pitching point solutions tied to specific platforms or functions, such as AI tools built for ERP systems.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">This signals a maturing market. It also signals a more complex buying environment for operating partners who are trying to evaluate fit without a clear internal brief or sufficient bandwidth to run a proper selection process.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<h2><b><span data-contrast="none">WHAT THIS MEANS</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></h2>
<p><span data-contrast="none">The operating partner community is not skeptical of AI. They are skeptical of AI as it is currently being asked of them: undefined mandates, unprepared data environments, and limited runway to show results.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">The firms that get this right will not do so by finding a better tool. They will do so by defining the problem first, cleaning the data second, and then selecting and deploying with a clear hypothesis about where value actually comes from.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">That is the kind of work we do. If you are navigating this with a portfolio company, we would be glad to talk through what a structured approach looks like.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>

		</div>
	</div>
</div></div></div></div>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/ai-at-the-portfolio-level-what-we-heard-at-pei-napa/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WHAT WE HEARD AT RMISC 2026: FOUR THEMES THAT MATTER</title>
		<link>https://www.rkon.com/articles/what-we-heard-at-rmisc-2026-four-themes-that-matter/</link>
					<comments>https://www.rkon.com/articles/what-we-heard-at-rmisc-2026-four-themes-that-matter/#respond</comments>
		
		<dc:creator><![CDATA[Adeeb Aslam]]></dc:creator>
		<pubDate>Wed, 08 Jul 2026 09:08:12 +0000</pubDate>
				<category><![CDATA[Cybersecurity Articles]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7096</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><span data-contrast="none">We were proud to speak at the Rocky Mountain Information Security Conference this year. Three days, dozens of sessions, and a lot of honest conversation from practitioners living these problems daily.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">Here is what stood out.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span><span data-ccp-props="{&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335572079&quot;:4,&quot;335572080&quot;:4,&quot;335572081&quot;:13421772,&quot;469789806&quot;:&quot;single&quot;}"> </span></p>
<p><b><span data-contrast="none">THE GAP BETWEEN AMBITION AND ACCOUNTABILITY</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="none">AI is moving faster than the structures built to govern it. That was the clearest signal across the conference.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">Microsoft&#8217;s carbon footprint grew 23.4% from AI infrastructure last year. State-level regulation, including Colorado&#8217;s AI Act (SB 205), is already creating binding obligations for organizations deploying high-risk AI systems. On the compliance side, FedRAMP authorization still costs $800K to $2M and takes up to two years to complete.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">The pattern is consistent: organizations adopt fast and govern slowly. The technology outpaces the accountability structure. At some point, that gap closes on its own terms, and those terms are rarely favorable.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><b><span data-contrast="none">YOUR EXISTING CONTROLS WERE NOT BUILT FOR THIS</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="none">Whether you are dealing with AI agents that operate within their approved scope but toward unintended ends, employees using unsanctioned AI tools that bypass your data loss prevention controls entirely, or a security team chasing individual vulnerabilities while the root cause goes unaddressed, the pattern is the same.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">Security programs were designed for a more predictable threat surface. The high-performing teams we heard from are not responding by adding more controls. They are going upstream: to root causes, to governance architecture, to data classification before incidents happen.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">One data point that stuck: over 80% of workers are already using unapproved AI tools. Forty-two percent of organizations have experienced an AI-related security incident. You cannot govern what you have not found. The recommended sequence is Discover, Classify, Control, Monitor, in that order.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span><span data-ccp-props="{&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335572079&quot;:4,&quot;335572080&quot;:4,&quot;335572081&quot;:13421772,&quot;469789806&quot;:&quot;single&quot;}"> </span></p>
<p><b><span data-contrast="none">THE HARDEST PROBLEM IS STILL THE HUMAN ONE</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="none">One of the most grounded sessions at the conference made a pointed argument: the industry&#8217;s talent crisis is self-inflicted.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">A 31% cybersecurity attrition rate is not a pipeline problem. It is a retention problem. Organizations recruit aggressively and underinvest in the culture, career development, and leadership that keep people. Technical excellence without investment in people is a strategy with an expiration date. The conference reinforced this from multiple directions: keynote, breakouts, and hallway conversation.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-ccp-props="{&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335572079&quot;:4,&quot;335572080&quot;:4,&quot;335572081&quot;:13421772,&quot;469789806&quot;:&quot;single&quot;}"> </span><b><span data-contrast="none">SIMPLICITY IS A SECURITY STRATEGY</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="none">This was the thread that ran through day three. IR programs fail not because teams lack tools, but because playbooks are too complicated to execute under pressure. AppSec teams that chase vulnerabilities reactively never escape the treadmill. Compliance teams that pursue every framework at once exhaust themselves and gain little.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">&#8220;Not yet is sequencing, not failure&#8221; was probably the most actionable line of the conference. You cannot do everything at once. The organizations making progress chose a direction and went deep, rather than spreading thin across every priority simultaneously.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><b><span data-contrast="none">WHAT THIS MEANS</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:300,&quot;335559739&quot;:120,&quot;335559740&quot;:276}"> </span></p>
<p><span data-contrast="none">The security industry has the frameworks, the tools, and in many cases the regulatory clarity. What is harder to manufacture is the discipline to prioritize, the culture to retain talent, and the willingness to govern AI as rigorously as you adopt it.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">We left RMISC thinking about where those gaps are sharpest for the organizations we work with, and what it looks like to close them.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>
<p><span data-contrast="none">If any of these themes resonate with what you are navigating right now, we would be glad to compare notes.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:332}"> </span></p>

		</div>
	</div>
</div></div></div></div>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/what-we-heard-at-rmisc-2026-four-themes-that-matter/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hacking AI: What Every Executive Needs to Know About LLM Security</title>
		<link>https://www.rkon.com/articles/hacking-ai-executive-know-about-llm-security/</link>
					<comments>https://www.rkon.com/articles/hacking-ai-executive-know-about-llm-security/#respond</comments>
		
		<dc:creator><![CDATA[Adeeb Aslam]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 13:37:43 +0000</pubDate>
				<category><![CDATA[Cybersecurity Articles]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7081</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><span data-contrast="auto">Your company is already using AI. If you think it isn’t, that’s actually an even bigger risk.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Let’s be clear. AI is already part of your operations, whether you approved it or not. People are already trying to exploit it. The real question isn’t if your organization faces AI threats, but what those threats look like. Now is the time to understand them.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Most people don’t understand these risks yet. Security researchers have shared detailed findings on LLM vulnerabilities for years, but this information rarely reaches executives. Awareness of these risks is still lacking. This series aims to close that gap.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="3"><strong>Why This Matters Right Now </strong></h2>
<p><span data-contrast="auto">Generative AI adoption in enterprise environments grew faster in 2024 and 2025 than any technology in recent memory. You spent years debating cloud migration strategies but woke up one morning to find that half your workforce was already connected to third-party AI tools, forget policies. Shadow AI is the new shadow IT, and it carries all the same risks and new ones as well …. So, congratulations on that.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The threats against AI systems don&#8217;t stop at the vendor&#8217;s door. Many of the most serious attacks target the AI that your own team deploys, configures, and connects to your data. The risks we&#8217;re going to cover in this series exist on a spectrum, and understanding where your organization sits on that spectrum is the starting point for everything else.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="3"><strong>Who Is Actually at Risk in Hacking AI</strong></h2>
<p><span data-contrast="auto">The answer varies depending on which attack we&#8217;re talking about. Some threats apply specifically to organizations with their own AI models. Some of the things we will cover apply to anyone using any AI system. So that pretty much means anyone who got this far in the paper.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">So, since I am a glutton for punishment, I’m going to break this out into 8 articles covering both areas. Here is a rough breakdown of how the articles in this series map to your exposure throughout the lifecycle.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="3"><strong>THREATS THAT APPLY PRIMARILY TO AI BUILDERS AND DEPLOYERS </strong></h2>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:&#091;8226&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none">Training-Phase Attacks (Article 2):</span><span data-contrast="auto"> Poisoning a model during training or fine-tuning. Most relevant if you are training or fine-tuning custom or open-source models on your data.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:&#091;8226&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="none">Privacy and Extraction Attacks (Article 3):</span><span data-contrast="auto"> Forcing a model to reveal what it was trained on, including your sensitive data and PII. Relevant when you fine-tune a model on internal data or when your employees have fed sensitive data into AI tools.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:&#091;8226&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="none">Adversarial Input Attacks (Article 4):</span><span data-contrast="auto"> Attacks at the token or character level meant to evade safety filters. This one is most important for organizations with AI-powered security tools or automated AI decision systems.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<h2 aria-level="3"><strong>THREATS THAT APPLY TO EVERY AI USER </strong></h2>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:&#091;8226&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none">Prompt-Based Attacks (Article 5):</span><span data-contrast="auto"> Hijacking what an AI system does through deviously crafted inputs. This applies to every deployment everywhere. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:&#091;8226&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="none">Cross-Lingual Attacks (Article 6):</span><span data-contrast="auto"> Exploiting safety gaps in non-English languages to extract content that would be blocked in English. Applies to any tool accessible in multiple languages, including binary.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:&#091;8226&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="none">Agentic and System-Level Attacks (Article 7): </span><span data-contrast="auto">Compromising AI agents that have been given tools and the ability to act on your behalf. This is the fastest-growing threat category as AI moves from answering questions to doing things, and it scares me the most.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:&#091;8226&#093;,&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="none">LLMjacking (Article 8):</span><span data-contrast="auto"> Stealing your cloud AI credentials to run up costs on your bill while selling access to criminals. Applies to any organization running cloud-hosted AI infrastructure… and if you have read anything else I’ve ever written, you know I kind of have a thing for IAM and credentials.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p><span data-contrast="auto">The article you&#8217;re reading now covers all seven threat categories at a level that should give you a working mental model and help you choose others you want to read more deeply. Think of it as a map for our wordy hike together.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="3"><strong>The Seven Threats: A First Look </strong></h2>
<p><span data-contrast="auto">Okay, so you just hired a sophisticated new employee. This employee is incredibly capable, never sleeps, can handle any volume of work, and has been given access to your systems, your customer data, and the ability to take actions on your behalf. Now, around the globe, hundreds of people are actively studying every way that an employee can be manipulated, deceived, corrupted, or kidnapped. That is the situation with enterprise AI right now.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The seven categories of attack we cover in this series each represent a different way that an adversary can go after that employee. Some attacks happen before the employee ever starts work. Others happen when they receive your work instructions. A few take advantage of the fact that the employee happens to speak forty languages, but only thinks safely in a few of them.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">We good on that? Okay, let’s check the destinations on the map.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol>
<li aria-level="3">
<h3><strong> Training-Phase Attacks: Poisoning the Well</strong></h3>
</li>
</ol>
<p><span data-contrast="auto">Before an AI model ever touches a production environment, it is educated by data. Enormous amounts of it. Training-phase attacks target this process, attempting to embed malicious behavior into the model before it ships or later, when you fine-tune or customize a base model for your needs.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Here is something to worry you, for free. No need to thank me. If an adversary can influence a small portion of training data, they can implant a trigger, a word, phrase, or pattern that causes the model to behave in a specific way when it appears. Anthropic&#8217;s research demonstrated that it takes only around 250 malicious documents to backdoor a model with 600 million to 13 billion parameters. The brainwashed model will act normally until someone uses the trigger. Then it isn&#8217;t. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Does this apply to you? If your organization is using a commercial model from a major vendor, the security during the training phase is mostly their responsibility. But if you are fine-tuning a publicly available model on your own data, or are as ambitious as building custom models, the training pipeline is a very early attack surface. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h3><span data-contrast="auto">Fine-tuning is being adopted to customize AI for specific business cases, this category is growing more relevant to more organizations every quarter. How relevant is it to you?</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h3>
<ol start="2">
<li aria-level="3">
<h3><strong> Privacy and Extraction Attacks: Stealing What the Model Knows</strong></h3>
</li>
</ol>
<p><span data-contrast="auto">Models remember things they were trained on. Privacy and extraction attacks exploit this by crafting inputs that cause the model to regurgitate this content, including things you specially told it never to share. Kinda like keeping a secret with a younger sibling. Maybe they will keep it, maybe a crafty adult will ask the question in such a way that the secret will be spilled.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Way back (in history or GPT sense) in 2021, Nicholas Carlini (Et al.) demonstrated that training data could be extracted from GPT-2 at scale. That work has been repeated multiple times since. Research shows that extraction rates improve as the adversary gets more sophisticated, and that scaling up model size doesn&#8217;t reduce this risk. Bigger brains have more things to mistakenly tell you.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The practical risk is this: if you feed sensitive data into an AI system, by fine-tuning or employee use of AI tools, some portion of that data may be recoverable by a sophisticated attacker. This is a privacy risk, a competitive risk, and in regulated industries, potentially a compliance risk. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This risk applies to commercial tools and private deployments alike.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol start="3">
<li aria-level="3">
<h3><strong> Adversarial Input Attacks: What the Model Can&#8217;t See</strong></h3>
</li>
</ol>
<p><span data-contrast="auto">AI safety systems are built to recognize harmful requests. Skilled adversarial input attacks are designed to remain invisible to those systems while making the same requests. The techniques range from appending algorithmically optimized character sequences to prompts, to replacing letters with visually identical characters from other Unicode scripts, to encoding malicious instructions in formats the safety layer doesn&#8217;t inspect but the model can still interpret.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Research by Carnegie Mellon and others has shown that optimized suffixes, meaningless-looking strings of characters appended to a request, can cause almost any model to comply with requests it would normally refuse. Success rates against some models (in controlled settings) have reached 99 percent. In the wild, against commercial models, they&#8217;re lower, but not near zero.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">For most organizations, the immediate threat here is to AI-powered security tools and automated decision systems. In these systems, consistent, reliable behavior matters. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Imagine an AI that flags threats or routes requests, manipulating them to create a terrifying attack surface rather than control. Or if you are using AI to control AI, like a content moderator, what would happen if it stopped doing its job?</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol start="4">
<li aria-level="3">
<h3><strong> Prompt-Based Attacks: Hijacking the Conversation</strong></h3>
</li>
</ol>
<p><span data-contrast="auto">OpenAI has said that prompt injection in AI-assisted browsing may never be solved. That&#8217;s a weighty statement coming from them.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This is a big one, it affects everyone. Every user of every AI system, everywhere. Prompt injection attacks work by crafting inputs that override existing instructions, causing it to do something you didn&#8217;t intend and didn&#8217;t authorize. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">There are two versions of this, one more insidious than the other. Direct versions involve a user simply asking the model to ignore its rules. During the indirect version, the truly insidious one, malicious instructions are embedded in a document, a webpage, or an email that the AI reads as part of its job.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">OWASP has ranked prompt injection as the number one vulnerability in LLM applications for two years running. Success rates in real deployments range from 50 to 84 percent, depending on how the system is configured. That is a massive success rate and should worry you. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The count of real-world incidents is ticking up rapidly. Browsers that summarize web content have been tricked into leaking user credentials. AI-powered resume screening systems were found to be processing injected instructions from “applicants”. Copilot has been manipulated through poisoned emails in the EchoLeak incident and others. If you use AI tools that process external content, prompt injections are an active operational risk today, so get on that.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol start="5">
<li aria-level="3">
<h3><strong> Cross-Lingual Attacks: The Safety Gap Nobody Talks About</strong></h3>
</li>
</ol>
<p><span data-contrast="auto">AI safety systems are trained mostly with English content. Most safety research on AI is conducted in English. Most red-teams operate in English, and most safety-related data exists</span><span data-contrast="auto"> in English</span><span data-contrast="auto">. In languages where training data is scarce, those safety guardrails are weaker.</span></p>
<p><span data-contrast="auto">Yet more research found that native Bengali speakers using their own language on publicly available AI tools were approximately three times more likely to encounter harmful content than English speakers making the same requests. This is a simple one: the model&#8217;s ability to understand and follow safety instructions degrades in languages it wasn&#8217;t well-trained on. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Obviously, this has practical implications for global organizations. AI tools deployed in international markets may carry safety gaps that your domestic testing never found. It is a consistent and underappreciated entry point. It is greatly appreciated by your adversaries, though.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol start="6">
<li aria-level="3">
<h3><strong> Agentic and System-Level Attacks: When AI Can Actually Do Things</strong></h3>
</li>
</ol>
<p><span data-contrast="auto">The hacking AI landscape changed astronomically as AI stops just answering questions and starts taking actions. AI agents given access to tools, APIs, file systems, calendars, email, and databases, and the ability to execute tasks on behalf of users, create a fundamentally different attack surface than a conversational chatbot. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">I prefer the term </span><span data-contrast="auto">“</span><span data-contrast="auto">delegate</span><span data-contrast="auto">”</span><span data-contrast="auto"> to </span><span data-contrast="auto">“</span><span data-contrast="auto">agent</span><span data-contrast="auto">”</span><span data-contrast="auto"> given the amount of power they have and how it models the user, but that is the subject for another paper.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Indirect prompt injection is a whole different beast in an agentic context. What if your AI agent reads an email, and a hidden instruction in that email causes the agent to forward your files somewhere, reset your credentials, or… or… or…? Now the attack has moved from a content exposure problem to an operational one. Researchers have created self-replicating prompt-injection attacks that spread through multi-agent systems, much like a computer virus spreads through a network. A single poisoned document becomes a breach of epic and nightmarish proportions.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Criminals aren&#8217;t just targeting AI agents as victims. They are using them as footholds into enterprise systems. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ol start="7">
<li aria-level="3">
<h3><strong>LLMjacking: Stealing the Keys to the Kingdom</strong></h3>
</li>
</ol>
<p><span data-contrast="auto">The last category is, in some ways, the most familiar to us security folks because it resembles the credential-theft attacks we’ve been fighting for years, just aimed at a new target. LLM jacking is the unauthorized use of your organization&#8217;s cloud AI infrastructure via stolen credentials. The attacker pays nothing. You pay the bill. With the rising price of tokens, this can become very expensive, often into the 7-figure range or more. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">If they then use that infrastructure to attack you, you are funding your own enemy. Have fun explaining that to the board.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Sysdig first identified this attack pattern in April 2024, when they observed stolen cloud credentials being used to access ten different cloud-hosted AI services. The entry vector was a vulnerable web application. The cost to the victim was estimated at up to $46,000 per day in AI consumption charges. With newer, more capable and expensive models, that number will easily exceed $100,000 per day.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">This kind of thing is being carried out by an organized criminal enterprise. Dedicated marketplaces exist for buying and selling stolen access to AI. They even have sales and discounts for volume. In some cases, the stolen credentials were being used not to run up your bill, but to give sanctioned entities, organizations in countries with US technology restrictions, access to AI systems they&#8217;re otherwise prohibited from using. Now you are into a potential regulatory and legal liability, not just a financial one. You don’t want the three-letter initial windbreaker-wearing orgs showing up at your offices.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="3"><strong>The Inevitability Argument </strong></h2>
<p><span data-contrast="auto">AI is not optional. Even if you opt out of it, you aren&#8217;t actually opting out; your vendors are using it, your competitors are using it, your customers are using it, and your employees are using it on personal devices and bringing the outputs back to work. The question of whether to engage with AI risk has already been answered. The open question is whether you engage with it deliberately.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">The organizations that do best are the ones where security leadership understands the threat landscape and has real conversations with the business about risk tolerance, deployment standards, and acceptable use. You can’t have those conversations without understanding what the threats actually are. That&#8217;s what this series is for.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 aria-level="3"><strong>A Note on Shared Responsibility </strong></h2>
<p><span data-contrast="auto">The AI providers bear meaningful responsibility for the security of the models and platforms they run. They have teams working on these problems, and they seem to take it seriously.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">But responsibility doesn&#8217;t stop with them. If you are relying on them alone, you are failing your security responsibilities. When you put AI in front of your employees and customers, you have taken on <a href="https://www.rkon.com/">security responsibility</a>. Most of the attacks we will cover in this series are not against OpenAI or Google. They are against your organization. That distinction matters, it shows where the work needs to be done.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><span data-contrast="auto">Security is a shared-responsibility model in AI, just as it is in the cloud. The vendor secures the model. You secure the deployment, data, access, and configuration. </span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p><i><span data-contrast="none">Next: Article 2, Training-Phase Attacks. How a few hundred carefully chosen documents can corrupt an AI model before it ever reaches production, and what that means for organizations building or adopting custom AI.</span></i><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p aria-level="4"><i><span data-contrast="none">NOTE ON THE USE OF AI IN THIS DOCUMENT</span></i><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:80,&quot;335559739&quot;:40}"> </span></p>
<p><span data-contrast="auto">The document is primarily human-conceptualized, written and edited. AI was used in the research and editing of this document.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_left wpb_content_element vc_custom_1782744517109">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img loading="lazy" decoding="async" width="150" height="150" src="https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-150x150.png" class="vc_single_image-img attachment-thumbnail" alt="" title="Gerald Ornorato-8 1" srcset="https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-150x150.png 150w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-300x300.png 300w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-1024x1024.png 1024w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-768x768.png 768w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-75x75.png 75w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1-600x600.png 600w, https://www.rkon.com/wp-content/uploads/2025/11/Gerald-Ornorato-8-1.png 1200w" sizes="auto, (max-width: 150px) 100vw, 150px" /></div>
		</figure>
	</div>
<p style="text-align: left" class="vc_custom_heading vc_do_custom_heading" >Gerard Onorato, CISO|2026</p>
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><b><span data-contrast="auto">About the Author</span></b><span data-ccp-props="{}"><br />
</span><i><span data-contrast="auto">Gerard Onorato is a CISO with extensive experience in enterprise security architecture, identity, and risk. This series reflects his personal analysis and does not constitute legal or compliance advice.</span></i><span data-ccp-props="{}"> </span></p>

		</div>
	</div>
</div></div></div></div>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/hacking-ai-executive-know-about-llm-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>From Identity Activity to Identity Intelligence: Inside RKON&#8217;s IAM Maturity Intelligence Center </title>
		<link>https://www.rkon.com/articles/from-activity-to-identity-intelligence/</link>
					<comments>https://www.rkon.com/articles/from-activity-to-identity-intelligence/#respond</comments>
		
		<dc:creator><![CDATA[Emily Ryan]]></dc:creator>
		<pubDate>Thu, 11 Jun 2026 15:29:59 +0000</pubDate>
				<category><![CDATA[RKON]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7069</guid>

					<description><![CDATA[From Identity Activity to Identity Intelligence A recap of our recent live session with YouAttest, featuring Duane Clouse, Senior Manager, IAM [&#8230;]]]></description>
										<content:encoded><![CDATA[<h2>From Identity Activity to Identity Intelligence</h2>
<h4><i><span data-contrast="auto">A recap of our recent live session with YouAttest, featuring <a href="https://www.linkedin.com/in/duane-clouse/" rel="noopener">Duane Clouse</a>, Senior Manager, IAM &amp; Zero Trust at RKON, alongside <a href="https://www.linkedin.com/in/theauthguy/" rel="noopener">Garret Grajek</a> and Kashif Mehmood of YouAttest.</span></i><span data-ccp-props="{}"> </span></h4>
<p><span data-contrast="auto">Thank you to everyone who joined us live for our recent webinar. If you did not join us live, the replay is available <a href="https://www.youtube.com/watch?v=CnH3mk9qyeY" rel="noopener">here</a>.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Identity programs do not fail because teams lack activity; they fail because activity is not translated into measurable, defensible risk identity intelligence. RKON and YouAttest discussed the value and methods of giving security leaders one evidence-backed view of identity exposure, program hygiene, and improvement velocity so they can prioritize what matters, defend investment, and turn identity governance into an operational roadmap.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">The conversation kept circling back to one uncomfortable question that most identity programs cannot answer cleanly: what is your identity risk right now? Tools get deployed, MFA gets switched on, access reviews get completed, and yet leadership still struggles to translate all of that activity into a clear, defensible picture of risk.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">That gap is exactly what RKON set out to close with the IAM Maturity Intelligence Center. Below we have pulled together the heart of Duane&#8217;s answers from the session, so registrants and attendees have something concrete to revisit.</span><span data-ccp-props="{}"> </span></p>
<p><b><span data-contrast="auto">The origin: why we built it</span></b><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">We have been delivering identity assessments for years, and the same problem showed up on every engagement. As Duane put it:</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">&#8220;Every engagement seemed to get reinvented in PowerPoint and Excel. No two consultants scored the same way, and clients couldn&#8217;t compare findings year over year.&#8221;</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">The traditional model was one or two consultants running a workshop, going away to build a report, and handing it off. There was little accountability and little ownership once the document landed. We wanted one place that scored, prioritized, planned, and tracked identity work consistently. So we built it for our own delivery teams first; when clients started asking to license it, that confirmed we had hit the right gap. Nobody was sitting between the framework and the operational tool, and that is the space the IAM Maturity Intelligence Center occupies.</span><span data-ccp-props="{}"> </span></p>
<p><b><span data-contrast="auto">Where identity programs fall short today</span></b><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Duane&#8217;s framing of the core problem was direct:</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">&#8220;The biggest issue most identity programs have is that they&#8217;re operationally busy but strategically blind.&#8221;</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">There is plenty of activity: tickets closed, audits passed. What is missing is a maturity narrative underneath it. Organizations routinely confuse activity metrics with risk metrics. Completing twelve thousand access reviews sounds impressive, but it says nothing about whether the right people were actually reviewed. And because legacy assessments are a one-time snapshot, nobody can answer the question leadership actually cares about: are we better this year than we were last year?</span><span data-ccp-props="{}"> </span></p>
<p><b><span data-contrast="auto">Three KPIs That Actually Signal Risk: Exposure, Hygiene, and Velocity</span></b><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Not all identity data is useful. Duane grouped the metrics that matter into three buckets, and these are the three the portal is built around.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Exposure is how much risk you carry today, surfaced through domain-level risk scores on the dashboard. Hygiene is how reliably you handle the basics, measured through 100 maturity questions across ten domains, covering areas like joiner-mover-leaver processes, SLA tracking, and governance. This is where the YouAttest integration plugs in, delivering real reviewer-engagement data rather than checkbox-completion stats. Velocity is whether you are improving over time, addressed through a CMMI maturity score per domain, gap-to-target by domain, and snapshot-based history that lets you trend each domain quarter over quarter.</span><span data-ccp-props="{}"> </span></p>
<p><b><span data-contrast="auto">From &#8220;What&#8217;s Broken&#8221; to &#8220;What to Do Monday&#8221;: How a Single View Changes Decisions</span></b><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Putting this into a single view changes the conversation for two different audiences.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">For security teams, the shift is from &#8220;what&#8217;s broken&#8221; to &#8220;what to do on Monday.&#8221; A Tasks view sequences and scopes every action by risk and effort, while Roadmap and Gantt views make the timeline defensible: what will happen, why, and in what order.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">For leadership, it is the first time they can answer three questions they could not before. Are we getting better? Where is the next dollar best spent? Can we defend our program to the board and to auditors? The portal becomes the single source of truth for identity strategy.</span><span data-ccp-props="{}"> </span></p>
<p><b><span data-contrast="auto">Where YouAttest Fits: Replacing Self-Reported Scores With Real Evidence</span></b><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Access governance and certification is one of the ten domains we measure, and one of the highest-signal domains for actual risk. The challenge is that most maturity scores are self-reported, and we wanted ours to be evidence-backed. Duane explained the value of the integration simply:</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">&#8220;YouAttest brings the campaign data: who has access, who reviewed it, how engaged the reviewers were. That&#8217;s real evidence, not a checkbox.&#8221;</span><span data-ccp-props="{}"> </span></p>
<p><b><span data-contrast="auto">The Next 12 to 24 Months: Board-Level Risk, Non-Human Identities, and Regulation</span></b><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Looking ahead, Duane pointed to three forces converging quickly.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">First, identity is becoming the new SIEM at the board level. Boards already ask about identity; soon they will ask about identity risk quantification, not &#8220;do we have MFA&#8221; but &#8220;what&#8217;s our blast radius in dollars.&#8221;</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Second, non-human identities will outnumber humans. Service accounts, agents, and AI workloads are multiplying, and the identity model we built for humans does not survive autonomous workloads.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Third, cyber insurance and regulators are catching up. Underwriters already demand identity evidence, and regulators are next, asking for measured maturity rather than attested controls.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">&#8220;Identity is becoming the first cybersecurity domain the board actually understands. Either we measure it well, or someone else measures it for us.&#8221;</span><span data-ccp-props="{}"> </span></p>
<p><b><span data-contrast="auto">The bottom line</span></b><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">What we built is not another tool in your stack; it is the intelligence layer on top of the stack you already have. It scores your IAM program across ten core domains on the CMMI 1-through-5 model, aligned to the NIST Cybersecurity Framework, and shows you where you are, where risk concentrates, and what to fix first based on risk and effort.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Duane closed the session with the line that sums up the whole approach: if you can measure it, you can defend it; if you can defend it, you can fund it; and if you can fund it, you can actually fix it.</span><span data-ccp-props="{}"> </span></p>
<p><i><span data-contrast="auto">Want to see the IAM Maturity Intelligence Center applied to your own environment? <a href="https://www.rkon.com/contact-us/">Reach out to the RKON team</a> to continue the conversation.</span></i><span data-ccp-props="{}"> </span></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/from-activity-to-identity-intelligence/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft FastTrack: The Most Underused Lever in Your Microsoft Investment</title>
		<link>https://www.rkon.com/articles/microsoft-fasttrack-an-underused-lever/</link>
					<comments>https://www.rkon.com/articles/microsoft-fasttrack-an-underused-lever/#respond</comments>
		
		<dc:creator><![CDATA[Ramsha Shakeel]]></dc:creator>
		<pubDate>Tue, 09 Jun 2026 14:00:55 +0000</pubDate>
				<category><![CDATA[RKON]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7065</guid>

					<description><![CDATA[Most organizations think they’re paying for Microsoft licenses. What they don’t realize is: They’re also paying for deployment, adoption, and [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Most organizations think they’re paying for Microsoft licenses.</p>
<p>What they don’t realize is: <strong>They’re also paying for deployment, adoption, and advisory support they’re not using. </strong>That’s where Microsoft FastTrack comes in.</p>
<h2><strong>What FastTrack Actually Is (Plain English)</strong></h2>
<p>FastTrack is a Microsoft-funded program designed to help organizations:</p>
<ul>
<li>Deploy Microsoft 365 (E3/E5)</li>
<li>Migrate workloads (Exchange, SharePoint, Teams)</li>
<li>Implement security tools (Defender, Purview)</li>
<li>Adopt Copilot and modern workplace capabilities</li>
</ul>
<p>And here’s the key: <strong>It’s already included in Microsoft licensing. </strong>No additional cost. No separate contract.</p>
<h2><strong>The Problem: Most Organizations Don’t Know They Have It</strong></h2>
<p>FastTrack isn’t widely understood, and it’s rarely positioned correctly. What we see in the market:</p>
<ul>
<li>Clients assume deployments are entirely on them</li>
<li>Security tools like E5 go underutilized</li>
<li>Copilot adoption stalls before it starts</li>
<li>Migration projects get delayed due to cost concerns</li>
</ul>
<p>Meanwhile: <strong>Microsoft has already allocated funding and resources to help, but they’re not being used.</strong></p>
<h2><strong>Why This Matters</strong></h2>
<ol>
<li><b>Cost Reduction</b></li>
</ol>
<p>FastTrack vouchers and Microsoft-funded support can offset deployment costs</p>
<ol start="2">
<li><b>Value Creation</b></li>
</ol>
<p>FastTrack provides guidance + RKON delivers execution. FastTrack creates a low-risk entry point to get started</p>
<h2><strong>Where RKON Fits</strong></h2>
<p>This is where most partners get it wrong. FastTrack is not a replacement for a partner. <strong>It’s an enabler.</strong></p>
<p>Microsoft provides:</p>
<ul>
<li>Funding</li>
<li>High-level guidance</li>
<li>Program structure</li>
</ul>
<p><a href="https://www.rkon.com/">RKON</a> provides:</p>
<ul>
<li>Strategy</li>
<li>Execution</li>
<li>Integration</li>
<li>Accountability</li>
</ul>
<p><strong>The Real Value: Faster Time to Outcome</strong></p>
<p>FastTrack changes the conversation from: “Can we afford to do this?”</p>
<p>to:</p>
<p><strong>“How quickly can we move forward?”</strong></p>
<ul>
<li>Reduces cost barriers</li>
<li>Accelerates timelines</li>
<li>Increases adoption</li>
<li>Improves ROI on Microsoft investments</li>
</ul>
<p><strong>The Opportunity (Right Now)</strong></p>
<p>Many FastTrack benefits—especially deployment vouchers tied to:</p>
<ul>
<li>E3/E5 migrations</li>
<li>Security deployments</li>
<li>Copilot rollout</li>
</ul>
<p>…are tied to <strong>Microsoft fiscal timelines</strong>. <strong>That means they expire.</strong></p>
<p>Organizations that don’t act:</p>
<ul>
<li>Lose access to funding</li>
<li>Delay initiatives</li>
<li>Miss ROI opportunities<strong> </strong></li>
</ul>
<h2><strong>Frequently Asked Questions (FAQs)</strong></h2>
<h3><strong>1. What is Microsoft FastTrack?</strong></h3>
<p>Microsoft FastTrack is a Microsoft-funded program included with eligible Microsoft 365 subscriptions. It provides deployment support, migration guidance, adoption resources, and assistance with implementing Microsoft technologies such as Microsoft 365, Microsoft Defender, Microsoft Purview, and Microsoft Copilot.</p>
<h3><strong>2. Is Microsoft FastTrack included with Microsoft 365 licensing?</strong></h3>
<p>Yes. FastTrack is included with eligible Microsoft 365 licenses, including many E3 and E5 subscriptions. Organizations can access deployment and adoption resources without purchasing a separate FastTrack contract.</p>
<h3><strong>3. What services does Microsoft FastTrack support?</strong></h3>
<p>FastTrack can help organizations deploy Microsoft 365, migrate workloads such as Exchange, SharePoint, and Teams, implement security and compliance solutions, and accelerate the adoption of tools like Microsoft Copilot and Microsoft Defender.</p>
<h3><strong>4. How does Microsoft FastTrack help reduce project costs?</strong></h3>
<p>Because Microsoft funds FastTrack resources and support, organizations may be able to offset certain deployment and migration expenses. This can lower the financial barriers that often delay Microsoft modernization and security initiatives.</p>
<h3><strong>5. Does Microsoft FastTrack replace the need for a technology partner?</strong></h3>
<p>No. FastTrack provides guidance, resources, and program support, but organizations often need a partner to handle strategy, implementation, integration, and ongoing execution. FastTrack and a trusted partner work together to help achieve business outcomes.</p>
<h3><strong>6. Who is a good candidate for Microsoft FastTrack?</strong></h3>
<p>FastTrack is particularly valuable for organizations planning Microsoft 365 migrations, security deployments, Copilot rollouts, or broader digital transformation initiatives. Companies with Microsoft E3 or E5 licensing can often benefit the most from the program.</p>
<h3><strong>7. How can organizations maximize the value of Microsoft FastTrack?</strong></h3>
<p>To get the most from FastTrack, organizations should align the program with their business goals, security priorities, and technology roadmap. Working with an experienced partner can help accelerate deployment, improve user adoption, and increase the return on Microsoft investments.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/microsoft-fasttrack-an-underused-lever/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Agent 365: What Happens When an AI Agent Goes Rogue?  The Missing Control Layer for AI Agents</title>
		<link>https://www.rkon.com/articles/agent-365-control-layer-for-ai-agents/</link>
					<comments>https://www.rkon.com/articles/agent-365-control-layer-for-ai-agents/#respond</comments>
		
		<dc:creator><![CDATA[Ramsha Shakeel]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 09:38:11 +0000</pubDate>
				<category><![CDATA[RKON]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7060</guid>

					<description><![CDATA[A few months ago, most conversations about AI in the enterprise were about productivity. Today, they’re about control. The question [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>A few months ago, most conversations about AI in the enterprise were about productivity. Today, they’re about control.</p>
<p>The question that keeps many CISO’s up at night, admittedly or not&#8230; <em>What happens when an AI agent goes rogue?</em></p>
<p>A <a href="https://www.theguardian.com/technology/2026/apr/29/claude-ai-deletes-firm-database" rel="noopener">recent AI failure</a> that resulted in the deletion of a firm’s database underscores a growing concern for security teams. Autonomous agents have crossed a critical threshold—from assisting humans to acting independently. They now write code, access systems, and make real-world changes. That shift fundamentally raises the stakes for governance, controls, and accountability.</p>
<p>This is where agent 365 becomes critical as a control layer for governing autonomous AI agents.</p>
<p>&nbsp;</p>
<h2><strong>The Rise of “Shadow Agents”</strong></h2>
<p>We’ve already dealt with shadow IT. Then shadow SaaS. Now we’re entering the era of shadow AI agents.</p>
<p>According to Microsoft, organizations are rapidly adopting both local and cloud-based agents that:</p>
<ul>
<li>Execute tasks independently</li>
<li>Modify code</li>
<li>Access sensitive data</li>
<li>Operate outside traditional controls (<a href="https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/?utm_source=chatgpt.com" rel="noopener">Microsoft</a>)</li>
</ul>
<p>That’s a fundamentally different risk profile. Because now, the risk isn’t just <em>“Who has access?” </em>It’s:</p>
<p><strong>“What is acting on behalf of your organization and what is it doing autonomously?”</strong></p>
<p><strong> </strong></p>
<h2><strong>Enter Microsoft Agent 365</strong></h2>
<p>Microsoft’s newly launched <strong>Agent 365</strong> is their answer to this problem and it signals a major shift in how enterprises will manage AI.</p>
<p>At its core, Agent 365 is a control plane for AI agents. Not another AI assistant. Not another Copilot feature.</p>
<p>A system designed to:</p>
<ul>
<li>Discover all agents in your environment</li>
<li>Assign identity to agents (like users)</li>
<li>Monitor behavior and activity</li>
<li>Enforce policies and controls</li>
<li>Block unmanaged or risky agents</li>
</ul>
<p>In other words, it extends identity, security, and governance to AI itself. (<a href="https://smartbridge.com/what-is-microsoft-agent-365/?utm_source=chatgpt.com%20%5Co%20What%20is%20Microsoft%20Agent%20365?%20-%20Smartbridge" rel="noopener">Smartbridge</a>)</p>
<p>&nbsp;</p>
<h2><strong>Why This Matters (More Than You Think)</strong></h2>
<p>Most organizations are still thinking about AI in a linear, controlled way. Pilot a few tools, roll out Copilot, let teams experiment, done. But what&#8217;s actually happening behind the scenes tells a very different story. Developers are spinning up agents on their own, teams are quietly adopting external tools like Claude or open-source alternatives, and autonomous workflows are being introduced without anyone&#8217;s knowledge. None of that is centrally governed.</p>
<p>Microsoft is addressing this head-on with a suite of capabilities designed to close that gap: agent discovery across environments, visibility into &#8220;shadow agents,&#8221; deep integration with Defender, Intune, and Entra, and policy enforcement at scale. (<a href="https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/" rel="noopener">Microsoft</a>)</p>
<p>&nbsp;</p>
<h2><strong>The Big Shift: From Users to Agents</strong></h2>
<p>Historically, enterprise security has focused on three things: users, devices, and applications. Agent 365 introduces an entirely new category — agents as identities. Each AI agent gets its own Agent ID, lifecycle management, access controls, and observability, just like a user account. (<a href="https://learn.microsoft.com/en-us/microsoft-agent-365/overview" rel="noopener">Microsoft Learn</a>) That&#8217;s a major evolution, because it acknowledges something most organizations haven&#8217;t fully processed yet: AI agents are becoming part of your workforce.</p>
<p>&nbsp;</p>
<h2><strong>The Real Problem: Execution Without Oversight</strong></h2>
<p>The Claude incident isn&#8217;t the root problem — it&#8217;s a symptom. The real issue is that enterprises are scaling AI faster than they&#8217;re governing it. Agents are now capable of taking action across systems, making decisions, and operating continuously, but governance hasn&#8217;t caught up. Without a system like Agent 365, organizations are left with no inventory of agents, no visibility into their behavior, no way to enforce policy, and no audit trail. That&#8217;s exactly what keeps CISOs up at night.</p>
<p>&nbsp;</p>
<h2><strong>What This Means for Your Clients (and for RKON)</strong></h2>
<p>This isn&#8217;t just a Microsoft product launch. It&#8217;s a move from AI as a tool to AI as an operational layer, and that requires an entirely new approach.</p>
<p>That approach has three dimensions. The first is <strong>Agent Governance Strategy</strong>: not just adopting tools, but building frameworks that address identity, access, lifecycle, and risk. The second is <strong>Visibility &amp; Control</strong> — ie actually understanding what agents exist in your environment, what they&#8217;re doing, and what they can access. The third is <strong>Execution, Not Experimentation</strong>: moving beyond AI pilots and into AI programs that operate at scale.</p>
<p>&nbsp;</p>
<h2><strong>Where RKON Fits</strong></h2>
<p>This is exactly the kind of shift <a href="https://www.rkon.com/">RKON</a> is built for. Not just implementing tools, but helping organizations define governance models for AI, align identity and security controls, build execution-ready roadmaps, and operationalize AI safely at scale. Because the reality is that Agent 365 doesn&#8217;t solve the problem on its own. The strategy, integration, and execution still matter, and that&#8217;s where the real work happens.</p>
<p>&nbsp;</p>
<h2><strong>Final Thoughts</strong></h2>
<p>AI agents are not coming. They&#8217;re already here. The only question is whether they&#8217;re working for you or operating outside your control. Agent 365 is Microsoft&#8217;s first real answer to that question, and for CISOs, it may be one of the most important developments of the year.</p>
<p>&nbsp;</p>
<h2><strong>Frequently Asked Questions</strong></h2>
<h3><strong>1. What is Microsoft Agent 365?</strong></h3>
<p>Microsoft Agent 365 is a governance and control platform designed to help organizations discover, manage, monitor, and secure AI agents operating across their environments. It provides visibility into agent activity, assigns identities to agents, and enables policy enforcement to reduce risk.</p>
<h3><strong>2. Why are AI agents becoming a security concern for enterprises?</strong></h3>
<p>AI agents are evolving beyond simple assistants and can now execute tasks, access systems, modify code, and make autonomous decisions. Without proper oversight, these capabilities can introduce security, compliance, and operational risks that traditional controls may not address.</p>
<h3><strong>3. What are shadow AI agents?</strong></h3>
<p>Shadow AI agents are autonomous AI tools or workflows deployed without formal approval, governance, or visibility from IT and security teams. Similar to shadow IT, these agents can operate outside established controls and potentially access sensitive data or systems.</p>
<h3><strong>4. How does Agent 365 help organizations manage AI risk?</strong></h3>
<p>Agent 365 helps organizations identify AI agents across their environments, assign unique identities, monitor behavior, enforce security policies, and block unmanaged or risky agents. This creates greater accountability and control over autonomous AI activity.</p>
<h3><strong>5. What does it mean to treat AI agents as identities?</strong></h3>
<p>Treating AI agents as identities means managing them similarly to users by assigning unique IDs, controlling access permissions, tracking activity, and maintaining lifecycle management. This approach improves governance and enables stronger security oversight.</p>
<h3><strong>6. What challenges do organizations face when adopting AI agents at scale?</strong></h3>
<p>Many organizations struggle with limited visibility into deployed agents, inconsistent governance policies, lack of auditability, and insufficient controls over agent access and actions. These challenges can increase security and compliance risks as AI adoption grows.</p>
<h3><strong>7. How can organizations prepare for the growing use of AI agents?</strong></h3>
<p>Organizations should establish AI <a href="https://www.rkon.com/enterprise-services/security-services/grc/">governance</a> frameworks, define identity and access controls, implement monitoring and policy enforcement, and develop clear strategies for managing agent lifecycles. A structured approach helps ensure AI can be adopted safely and effectively at scale.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/agent-365-control-layer-for-ai-agents/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Your Deployment Pipeline Ends at a Firewall Ticket</title>
		<link>https://www.rkon.com/articles/your-deployment-pipeline-ends-at-a-firewall-ticket/</link>
					<comments>https://www.rkon.com/articles/your-deployment-pipeline-ends-at-a-firewall-ticket/#respond</comments>
		
		<dc:creator><![CDATA[Ramsha Shakeel]]></dc:creator>
		<pubDate>Mon, 11 May 2026 10:37:36 +0000</pubDate>
				<category><![CDATA[RKON]]></category>
		<guid isPermaLink="false">https://www.rkon.com/?p=7017</guid>

					<description><![CDATA[]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element vc_custom_1779679732036" >
		<div class="wpb_wrapper">
			<p>Your team automated the build, the test, and the deploy. Then the whole thing stalled waiting on a firewall ticket change request.</p>
<p>That bottleneck is not a process problem. It is an architecture problem, and it shows up in nearly every hybrid environment we work in. Teams migrating to the cloud carry on-premises network security assumptions that silently fail in cloud and hybrid architectures. Rework, delays, and gaps discovered at the worst possible time are the outcome.</p>
<p>Here is where those assumptions break.</p>
<h2>The Mappings That Don’t Hold</h2>
<p>Every one of these has a gap. The gap is where the breach lives.</p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12 vc_hidden-lg"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_left wpb_content_element">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img loading="lazy" decoding="async" width="934" height="235" src="https://www.rkon.com/wp-content/uploads/2026/05/table-1.png" class="vc_single_image-img attachment-large" alt="" title="table" srcset="https://www.rkon.com/wp-content/uploads/2026/05/table-1.png 934w, https://www.rkon.com/wp-content/uploads/2026/05/table-1-300x75.png 300w, https://www.rkon.com/wp-content/uploads/2026/05/table-1-768x193.png 768w" sizes="auto, (max-width: 934px) 100vw, 934px" /></div>
		</figure>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid vc_custom_1779679768315 vc_row-o-equal-height vc_row-o-content-middle vc_row-flex"><div class="wpb_column vc_column_container vc_col-sm-12 vc_hidden-md vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner vc_custom_1779679695487"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid vc_custom_1779674529356 vc_row-o-content-middle vc_row-flex"><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779679861633"><div class="wpb_wrapper"><h4 style="font-size: 22px;color: #FFFFFF;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779674686378" >On-Premises Control</h4></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779679952852"><div class="wpb_wrapper"><h4 style="font-size: 22px;color: #FFFFFF;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779674668727" >Cloud Equivalent</h4></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779680010170"><div class="wpb_wrapper"><h4 style="font-size: 22px;color: #FFFFFF;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779674678777" >The Gap</h4></div></div></div></div><div class="vc_row wpb_row vc_inner vc_row-fluid vc_custom_1779673312469"><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675200149"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779674359835" >Stateful Firewall</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675212844"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779674405514" >Security Group / NSG</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675227088"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779674441823" >No DPI, no L7 inspection</p></div></div></div></div><div class="vc_row wpb_row vc_inner vc_row-fluid vc_custom_1779673312469"><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675259897"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678530650" >VLAN Segmentation</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675270243"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678550695" >VPC Subnets</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675286285"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678578729" >No isolation by default</p></div></div></div></div><div class="vc_row wpb_row vc_inner vc_row-fluid vc_custom_1779673312469"><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675200149"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678601407" >DMZ</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675212844"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678618639" >NAT Gateway</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675227088"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678657251" >No inbound inspection</p></div></div></div></div><div class="vc_row wpb_row vc_inner vc_row-fluid vc_custom_1779673312469"><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675259897"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678692066" >Reverse Proxy / WAF</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675270243"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678709492" >Cloud Load Balancer</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675286285"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678743635" >WAF must be added explicitly</p></div></div></div></div><div class="vc_row wpb_row vc_inner vc_row-fluid vc_custom_1779673312469"><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675200149"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678771488" >Hub &amp; Spoke Firewall</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675212844"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678791497" >SD-WAN Direct Breakout</p></div></div></div><div class="wpb_column vc_column_container vc_col-sm-4 vc_col-has-fill"><div class="vc_column-inner vc_custom_1779675227088"><div class="wpb_wrapper"><p style="font-size: 18px;color: #000000;text-align: left" class="vc_custom_heading vc_do_custom_heading vc_custom_1779678862814" >Traffic bypasses inspection</p></div></div></div></div></div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p><strong>Security groups </strong>do port, protocol, and IP allow/deny at Layer 3/4. No application awareness, no threat signatures, no built-in logging. If you need L7 inspection, you need AWS Network Firewall or Azure Firewall Premium, explicitly routed through.</p>
<p><strong>VPC subnets </strong>are a routing construct, not an enforcement boundary. Traffic between subnets in the same VPC routes directly by default with no firewall in the path. East-west lateral movement from a compromised workload can be completely invisible without additional controls.</p>
<p><strong>NAT gateways </strong>handle outbound address translation. They do not inspect sessions, enforce inbound policy, or provide anything equivalent to bidirectional DMZ controls.</p>
<p><strong>Cloud load balancers </strong>balance load. A WAF must be explicitly attached to every public ALB and is not on by default. Without it, there is no OWASP rule coverage and no bot mitigation.</p>
<h2>SD-WAN Makes It Worse</h2>
<p>SD-WAN direct internet breakout eliminates your centralized inspection chokepoint. Branch traffic reaches cloud workloads without crossing the data center firewall stack, and that is by design. SSL inspection at branch appliances is rarely performed because the performance cost is too high.</p>
<p>What follows is a split-brain problem: your SD-WAN dashboard shows traffic as tunneled and secure, while your VPC flow logs show direct traffic from those same source IPs. The DC firewall sees nothing. CISA Emergency Directive 26-03 (February 2026) confirmed active exploitation of Cisco Catalyst SD-WAN infrastructure, calling it a high-value target with known compromise in the wild, so this is not a theoretical concern.</p>
<p>Stop relying on the traffic path as your security control. <a href="https://www.rkon.com/articles/your-deployment-pipeline-ends-at-a-firewall-ticket/" target="_blank" rel="noopener">Enforce security</a> at the destination using cloud firewall ticket rules and security groups at the workload level.</p>
<h2>Four Things to Do This Week for Firewall Ticket</h2>
<ol>
<li><strong>Enable VPC Flow Logs everywhere. </strong>All VPCs, all traffic, version 3+, retained 90 days minimum. Everything else on this list depends on it.</li>
<li><strong>Audit public ALBs for WAF coverage. </strong>AWS Console &gt; WAF &gt; check which ALBs have a Web ACL attached. Any that don&#8217;t are unprotected. Attach AWS Managed Rules Core Rule Set &#8212; it takes about 20 minutes.</li>
<li><strong>Run the split-brain test. </strong>Pull SD-WAN path analytics for your most sensitive traffic and cross-reference with VPC flow logs for the same source IPs. Gaps between the two mean broken routing.</li>
<li><strong>Audit security group rules. </strong>Flag every 0.0.0.0/0 inbound rule. AWS Config rule &#8216;restricted-common-ports&#8217; does this automatically.</li>
</ol>
<p>Fix the network architecture and your teams ship faster, without firewall tickets blocking deployments or rearchitecting mid-migration.</p>
<p>Join Tyler at GrassRootz for the full talk on June 4<sup>th</sup> for more: <a href="https://grassr00tz.com/" rel="noopener">https://grassr00tz.com/</a></p>

		</div>
	</div>
</div></div></div></div><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div  class="wpb_single_image wpb_content_element vc_align_left wpb_content_element vc_custom_1778495481574">
		
		<figure class="wpb_wrapper vc_figure">
			<div class="vc_single_image-wrapper   vc_box_border_grey"><img loading="lazy" decoding="async" width="150" height="150" src="https://www.rkon.com/wp-content/uploads/2026/05/presenter_tyler_coady-150x150.png" class="vc_single_image-img attachment-thumbnail" alt="" title="presenter_tyler_coady" srcset="https://www.rkon.com/wp-content/uploads/2026/05/presenter_tyler_coady-150x150.png 150w, https://www.rkon.com/wp-content/uploads/2026/05/presenter_tyler_coady-75x75.png 75w, https://www.rkon.com/wp-content/uploads/2026/05/presenter_tyler_coady-600x600.png 600w" sizes="auto, (max-width: 150px) 100vw, 150px" /></div>
		</figure>
	</div>
<p style="text-align: left" class="vc_custom_heading vc_do_custom_heading" >Author: Tyler Coady, Senior Cloud Security Consultant, RKON</p></div></div></div></div><div class="vc_row wpb_row vc_row-fluid rkon-flip-cols-on-mobile"><div class="wpb_column vc_column_container vc_col-sm-4"><div class="vc_column-inner"><div class="wpb_wrapper"><div class="vc_row wpb_row vc_inner vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-1 vc_hidden-sm vc_hidden-xs"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element wpb_animate_when_almost_visible wpb_fadeInLeft fadeInLeft rkon-animation-delay-3" >
		<div class="wpb_wrapper">
			<i class="fab fa-linkedin"></i>

		</div>
	</div>
</div></div></div><div class="wpb_column vc_column_container vc_col-sm-11"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element wpb_animate_when_almost_visible wpb_fadeInLeft fadeInLeft rkon-animation-delay-3" >
		<div class="wpb_wrapper">
			<p><a href="https://www.linkedin.com/in/tylercoady/" rel="noopener">https://www.linkedin.com/in/tylercoady/</a></p>

		</div>
	</div>
</div></div></div></div></div></div></div><div class="wpb_animate_when_almost_visible wpb_fadeInRight fadeInRight wpb_column vc_column_container vc_col-sm-8"><div class="vc_column-inner"><div class="wpb_wrapper"></div></div></div></div>
</div>]]></content:encoded>
					
					<wfw:commentRss>https://www.rkon.com/articles/your-deployment-pipeline-ends-at-a-firewall-ticket/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
