This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Accelerate AI innovation securely with AI-SPM

Download resources

About this session

Bryan Rosensteel, head of public sector product marketing at Wiz, argues that AI adoption is repeating the cloud transition, but faster and with worse visibility, and pitches AI Security Posture Management (AI-SPM) as the fix. He traces how cloud broke perimeter-based, siloed security tooling, leaving teams overwhelmed by duplicate, uncontextualized alerts, and shows the same pattern in AI: more than 70 percent of organizations report using a managed AI service, often with shadow AI nobody documented. He frames four questions a program must answer: what AI services are running, what risks exist in the pipeline, which risks are top priority, and how to detect misuse, illustrating each with real incidents (a large accidental cloud exposure, the DeepSeek database left open that Wiz's threat intel team discovered and responsibly disclosed). He proposes a risk-based, agentless, graph-based approach connecting identities, data sensitivity and workloads across the pipeline so remediation is prioritized and automatable rather than dumped on teams without context. An extended Q&A covers SaaS-embedded AI, remediation types (preventive, proactive, reactive), and on-premises versus cloud AI.

As organizations increasingly migrate to the cloud, the landscape of cybersecurity is evolving at a rapid pace. The advent of Artificial Intelligence (AI) brings both unprecedented opportunities and challenges, making it imperative for cloud security strategies to advance accordingly. Join this session to hear from Wiz why organizations are adopting AI-SPM (AI Security-Posture Management) into their CNAPP strategy and how you can effectively secure AI workloads in the cloud while accelerating AI innovation securely.

Key takeaways

  • Inventory AI services with a top-down, agentless API scan rather than trusting team self-reports; shadow AI is common and usually undocumented, not malicious.
  • Treat risk as a function of likelihood times impact, not a raw vulnerability count; prioritize the AI component that connects to sensitive data over one that scores worse in isolation.
  • Map the full AI pipeline (network path, storage, training data, model, endpoints, identities) before judging any single component secure, since excessive admin permissions on an AI identity can expose production data laterally.
  • When adopting a third-party SaaS product with embedded AI, ask the vendor the same four questions you'd ask internally: what's deployed, what risks exist, what's prioritized, and how misuse is detected.
  • Build both a proactive remediation habit (fix risky pipeline configuration before an attack) and a reactive one (detect deviations from baseline behavior in real time), not just preventive code scanning.

Speakers

Bryan Rosensteel
Bryan Rosensteel
Head of Public Sector Product Marketing · Wiz
Bryan Rosensteel, Head of Public Sector Product Marketing at Wiz, has 20+ years of public sector experience. He has advised the US Federal Government on many cybersecurity initiatives, including ICAM, worked on several NCCoE projects leading to NIST… Read moreRead less

Bryan Rosensteel, Head of Public Sector Product Marketing at Wiz, has 20+ years of public sector experience. He has advised the US Federal Government on many cybersecurity initiatives, including ICAM, worked on several NCCoE projects leading to NIST 1800 series special publications, helped form and run working groups at non-profit organizations such as ATARC, and assisted with the design and implementation of several government IT modernization projects.

Resources

Tags

More from GoSec 2025

Also from Bryan Rosensteel

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.