Security leaders are being asked to scale AI while strengthening control over data, governance, resilience and operating models.
Sharing his key takeaways from the sessions at Security Edge, Matt Boon, Senior Research Director at ADAPT, highlighted practical steps to strengthen governance, resilience and collaboration as organisations scale.
Key takeaways:
- Inventory every AI tool in use, build governance into the architecture and pressure-test agent chains before production.
- Budget for the real cost of AI and create a genuinely blended security, technology and business team.
- Assess your data architecture and governance maturity honestly, then define the next capability you need to build.
Most organisations are still building their foundations
Many organisations remain in the “koala” stage, with relatively low data architecture and governance maturity.
Matt’s conversations with security and technology leaders reveals the lack of clear line of sight across data is a recurring challenge, made more difficult by rapidly changing compliance and sovereignty expectations.
Everything still rests on data governance.
Organisations should map their maturity honestly, decide what they need to achieve and focus on the next practical step rather than assuming every organisation must reach the same endpoint.
Reliability compounds across an agent chain
A single AI agent that is 92% reliable may sound acceptable, but linking five such steps into one customer journey can mean that only around two-thirds of customers reach the end.
This is why agent chains need to be tested as complete journeys, not assessed only at the level of individual tools.
The same principle applies to resilience.
As Greg Rattray, former Global CISO at JPMorgan Chase explained, organisations will take hits; the important question is how quickly they can recover and continue providing essential services.
The new battleground is the operating model
Funding and staffing gaps remain familiar challenges, but fragmented operating models are becoming more damaging as attackers and technology move faster.
Security, technology and business teams need to work as one blended team, with governance built into architecture rather than added after deployment.
That also means understanding the real cost of AI, including token usage and the infrastructure needed to support it.
FinOps principles can help organisations budget for AI as an ongoing operational cost rather than a simple licence decision.
Matt’s five practical actions are to map the organisation’s maturity honestly, inventory every AI tool in use, build governance into the architecture, pressure-test every agent chain before production and establish an integrated security, technology and business team.
These steps provide a realistic path from experimentation to controlled, valuable adoption.