Cybersecurity Awareness Month Drives Home a Key Challenge: Agentic AI

Today brings yet another Cybersecurity Awareness Month, with the Cybersecurity & Infrastructure Security Agency (CISA) releasing guidance for how organizations can combat faster, smarter threats. One key topic CISA pointed out was that of artificial intelligence (AI), which it says is “accelerating the rate at which hackers can find and take advantage of weak spots in our computer software and systems” and placing “our country and economy at risk.”
Nick Heddy, President and Chief Commerce Officer at Pax8, comments, “Cybersecurity is entering a new era. For the last two decades, security has largely been about protecting networks, devices, and identities. In the years ahead, it will increasingly be about protecting autonomous systems, AI agents, and the growing web of digital interactions they create on our behalf. As organizations embrace AI to drive productivity and innovation, attackers will use the same technologies to scale threats faster than ever before. The result is an arms race where speed, automation, and intelligence become the defining advantages.”
An Agentic Era of Cybersecurity
The topic of AI agents in particular has gained notable traction in recent months. From the incident of an OpenAI agent hacking Hugging Face to Google’s Gemini AI breaching three companies, AI agents have emerged as a concern.
Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint, says, “Recent warnings about AI safety from Anthropic and other hyperscalers have raised awareness of how quickly AI is moving. AI capabilities are developing faster than many organizations’ ability to govern them, and that gap is creating real risk. AvePoint’s own research has found that 88% of organizations experienced an agent-related security incident in the past year. As many still work to implement AI governance fundamentals, the technology continues to take off in new directions that are starting to sound alarm bells at the highest levels.
“Nvidia’s launch this week of a runtime safety platform for AI agents, following the OpenAI agent breach of Hugging Face, shows where enterprise controls now need to go. Security teams need to treat every agent as a non-human identity with an owner, scoped credentials, explicit tool permissions, network egress limits, and policy enforcement outside the model. Organizations also need tested controls to revoke tokens, quarantine an agent, terminate queued actions, and restore affected data and configurations to a known-good state.
“AI is outpacing AI governance, and it’s even outpacing our ability to anticipate and regulate its actions. In this environment, we all have a duty to do more.”
As AI continues to evolve, governance is struggling to keep pace. Late last month, world leaders meeting at the United Nations (UN) were called on by leaders in the AI space to establish controls, asserting the technology could be a risk if not properly governed.
Diana Kelley, CISO at Noma Security, explains, “We need to stop thinking about AI agents as if they were people. They are software systems: models combined with code, permissions, tools, data, and network access. Anthropomorphizing agents can distract us with questions about what the AI ‘wanted’ to do. The more useful questions are architectural: What can this software reach? What can it change? What constrains it? And what happens when it is wrong? AI creates new failure modes, but the answer still starts with strong security architecture: least privilege, segmentation, monitoring, deterministic control points, and containment. Rather than fearing what AI ‘wants,’ we need to govern what we enable it to do.”
Recognizing Cybersecurity As a Business Imperative
This Cybersecurity Awareness Month, security leaders are encouraged to not just bolster technology capabilities, but to approach cybersecurity as an organizational matter.
Heddy concludes, “As we look toward the next generation of technology, one thing is clear: cybersecurity is no longer a technology issue alone. It is a business imperative, a trust imperative, and ultimately a human imperative. The organizations that thrive in the future will be those that view security not as a barrier to innovation, but as the foundation that makes innovation possible.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!








