This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Reinforcing the Rails: The Gatekeeper’s Manual for AI safety

Download resources

About this session

A Netskope solutions engineer opens with a show of hands on personal AI account use to frame the real problem: not employee AI use itself, but the absence of guardrails around it. He cites internal telemetry, organizations averaging up to 70,000 monthly AI prompts, 94% reporting visibility gaps, 88% unable to distinguish personal from corporate AI accounts, and walks through five real incidents from the last two years: a dealership chatbot talked into pricing a car at one dollar, an engineer leaking private code through a personal ChatGPT session that pushed Samsung to ban AI outright, a poisoned open-source MCP server that silently BCC'd thousands of users' emails to an attacker, a coding agent that deleted an organization's data after misreading a bug-fix instruction, and a supply-chain compromise of a coding agent that hit roughly 30 organizations. His argument is that legacy proxy and firewall controls cannot parse MCP traffic or agent intent, so defense needs application- and instance-aware visibility, contextual DLP, custom content-moderation topics, an MCP-aware agentic broker, and granular agent action controls, mapped to frameworks like MITRE ATLAS and OWASP, with red-teaming for internally hosted LLMs before production.

Join us for an overview of Netskope's approach to securing the full AI lifecycle across a modern SASE/SSE architecture.
Key topics include: comprehensive visibility into the AI stack (shadow AI, GenAI apps, embedded AI); securing agentic AI and MCP traffic via the Agentic Broker; the AI Fast Path for low-latency, secure routing to LLM providers (Azure AI Foundry, Google Vertex AI, Amazon Bedrock); inspecting private and self-hosted LLMs; AI Guardrails and AI Gateway for prompt/response protection and DLP; and AI Red Teaming for uncovering vulnerabilities (jailbreaks, bias, misinformation, data leakage) mapped to OWASP Top 10 LLM risks. We will also review brand new functionalities: AI Discovery and AISecOps, positioning Netskope as a gatekeeper securing AI usage, agents, and infrastructure end-to-end

Key takeaways

  • Don't rely on a signed AI usage policy alone; audit whether personal AI accounts are actually being used on corporate devices and data before assuming the policy is working.
  • Deploy MCP-aware inspection, such as an agentic broker; legacy proxies and firewalls only see a JSON-RPC payload, not what an agent is actually doing with it.
  • Pin and vet the exact version of every MCP server and agent tool dependency; a single malicious line inserted into a popular MCP package can silently exfiltrate data at scale before anyone notices.
  • Put action-level controls on agents, not just access controls, especially for destructive operations like deletes or infrastructure changes, so a misread instruction can't wipe production data.
  • Red-team internally hosted LLMs before they go to production, and build data discovery and lineage so you can trace where a leaked file or prompt actually came from.

Speakers

Eduardo Torreblanca
Eduardo Torreblanca
Senior Solutions Engineer Quebec and East · Netskope
Eduardo Torreblanca is a cybersecurity seasoned professional, with over 22 years of experience architecting and delivering enterprise security solutions, including deep expertise in SASE and SSE platforms. Recently, his focus has shifted to AI… Read moreRead less

Eduardo Torreblanca is a cybersecurity seasoned professional, with over 22 years of experience architecting and delivering enterprise security solutions, including deep expertise in SASE and SSE platforms. Recently, his focus has shifted to AI Security, helping organizations navigate the risks and opportunities of AI adoption. Passionate about the intersection of AI and security, he's driven to help enterprises innovate safely in an increasingly complex threat landscape.

Resources

Photos

Tags

More from GoSec 2026

Also from Eduardo Torreblanca

On the same topic