'You need your own bots' to wage war against rogue AI, warns Varonis VP
Infosec pros are urged to get serious about data access control and automation to thwart AI breaches


The world is facing an AI hurricane, and organizations must batten down the hatches by securing their data vaults and deploying "bots" to combat rogue AI.
So warns, Matt Radolec, vice president of Incident Response and Cloud Operations at Varonis, who said that AI poses an existential threat to their organizations if they fail to control data access and police AI prompts.
"AI is the biggest opportunity and biggest threat to your organization," Radolec declared, setting the tone for his RSA Conference 2024 talk "Reducing AI's Blast Radius: How to Prevent Your First AI Breach."
Radolec, who has spent over 15 years safeguarding sensitive data from state secrets to corporate jewels, argued that the obsession with malware, threat actors, and CVEs has distracted organizations from the real prize: data. "Data is where the damage happens. Data is where you'll feel the pain of AI," he cautioned.
Drawing on real-world examples from Varonis' incident response investigations, Radolec highlighted the grave consequences of data breaches and corruption,. These were wide-ranging and included disrupting Alzheimer's research, crippling a city's utilities, all the way through to causing a literal "sh*tstorm" by compromising sewer systems.
"We all know an AI superstar when we see one, and Jensen Huang nailed it. AI is a data problem," Radolec said, quoting the Nvidia CEO. "Your data is your company's source code. It's intellectual property. It's worth a lot."
To combat the AI tempest, Radolec urged organizations to shift their focus from endpoints to data vaults, monitoring every transaction, detecting anomalies, and policing every AI prompt. He stressed the importance of granular access control, noting that the average organization has 17 million files open to all employees and over 40 million unique access control lists to manage.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"You have to police your prompts. Think about it. Has anyone ever gotten a speeding ticket or another type of moving violation? I know I have a few. Does the fear of getting one of those stops you from driving like a maniac? You have to issue tickets and take reckless drivers off the road even more so when people abuse their co-pilots," Radolec advised. “Because having weak access controls and not policing your prompts would be akin to giving every employee a Ferrari and letting them loose to race on residential streets.”
RELATED WHITEPAPER
Perhaps his most provocative suggestion was the need for organizations to deploy AI and automation to combat rogue AI. "If you want to survive AI, you will need your own bots on your side. Automation and AI is the only way to combat AI. Trust me," he said, leaving the audience to ponder the impending bot wars.
Radolec concluded his talk by urging attendees to embrace their role as data protectors, reminding them: "Data is looking up at you and it's saying 'Help me RSA conference attendees. You're my only hope.'"
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Enterprises face delicate balancing act with data center sustainability goals
News High energy consumption, raw material requirements, and physical space constraints are holding back data center sustainability efforts, according to new research from Seagate.
By Emma Woollacott
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
CrowdStrike CEO: Embrace AI or be crushed by cyber crooks
News Exec urges infosec bods to adopt next-gen SIEM driven by AI – or risk being outpaced by criminals
By Rene Millman
-
Microsoft security boss warns AI insecurity 'unprecedented' as tech goes mainstream
News RSA keynote paints a terrifying picture of billion-plus GenAI users facing innovative criminal tactics
By Rene Millman
-
APIcalypse Now: Akamai CSO warns of surging attacks and backdoored open source components
NEWS Apps and APIs bear the brunt as threat actors pivot to living off the land
By Rene Millman
-
AI is changing the game when it comes to cyber security
News With AI becoming more of an everyday reality, innovative strategies are needed to counter increasingly sophisticated threats
By Rene Millman
-
RSAC Chairman urges collaboration to ensure collective defense in security
News Chairman emphasizes the critical need for cooperation among cyber security experts
By Rene Millman
-
IT Pro Live: The future of encryption
Video AI and quantum ccomputing could be about to change the face of security forever
By IT Pro
-
Mobile apps now most common method of fraud
News RSA Security report highlights the rise in burner devices and rogue apps
By Bobby Hellard
-
Ransomware in reality: people pay
News In real life, noble intentions give way to business truths
By Jane McCallion