Forward Thinking

“Governing trust is now more important than protecting systems”
François Van Deventer, Director & CTO Emerging Markets, Midis Group Local Office, on what Cybersecurity must become in the AI era
Enterprise AI has moved well beyond productivity. It is now embedding itself into our business processes, our enterprise applications, our data analysis, our software development cycles, and increasingly our operational decision-making. AI isn’t just assisting from the side; it is becoming part of how organizations run. The value of AI grows as it moves closer to what makes an organization unique: its competitive advantage, its institutional knowledge, its data. That is also where the risk becomes most significant. When AI becomes part of the operating layer of the business, Cybersecurity must become the trust layer.
BEYOND THE FIREWALL
For many years, cybersecurity was often discussed in terms of infrastructure protection: securing networks, endpoints, servers, applications, and data. Although these remain essential, enterprises are more distributed whilst being more connected, and more intelligent. We all want choice – to work from anywhere and from any device, but our applications span cloud, SaaS, data centers, and legacy systems. Identities across an organization now include not only employees and contractors but also service accounts, APIs, and increasingly AI agents.
“In the AI era, cybersecurity is no longer only about protecting our systems. It is about governing trust: who or what can act, what they can access, and whether that behaviour is legitimate”
THE ATTACK HAS ALREADY EVOLVED. HAS THE DEFENSE?
Attackers understand this change and they are moving faster every day. They rely more on identity abuse, exploiting cloud and SaaS environments, targeting edge devices, and using legitimate tools and access paths to avoid detection – outside of the obvious malware approaches. It is not enough to only rely on a standard secure log-in approach to our systems – They begin with a compromised identity, a trusted application, a misconfigured permission, an unmanaged device, a vulnerable edge system, or an employee unknowingly sharing sensitive information with an unmanaged AI tool. This is why the Cybersecurity conversation must change. It is no longer enough to ask, “Is this system protected?” We must also ask: Who or what is acting? What data can they access? Is this behaviour expected? Is the decision explainable? Can we contain the impact? Can the business continue to operate if trust is abused? More importantly, can we see what is happening? These questions become more urgent as AI moves deeper into enterprise workflows.
THE RISK YOU DIDN’T APPROVE
Adoption of AI does not wait for a managed transformation program. It enters through the daily behaviour of knowledge workers, and the blind spots it creates are real: sensitive information placed into unmanaged tools, teams adopting AI before security, compliance, or legal are involved. Another point of concern is that vendors may embed AI into their products without enough transparency around data use, model training, retention, or access controls. AI will work through the systems people already use today: browsers, SaaS platforms, virtual desktops, enterprise applications, internal repositories, and regulated business applications. That means security cannot treat AI as something separate from the business. AI must be governed where work already happens. AI needs to be appropriately governed based on what it can do, what data can be reached, what decisions it can influence, and when & where a human must remain in the loop.
“Security should not become the department of ‘no.’ It should help the business get to ‘yes,’ safely”
The answer cannot simply be to block everything. A more practical approach is a safe and managed transformation program: clear acceptable-use policies, approved AI platforms, data classification, identity controls, monitoring, user education, vendor governance, and human review for high-impact decisions.
GOVERNING THE NEW DIGITAL WORKER
AI security is not only about defending against AI risk. It is also about using AI carefully to improve the security function itself. Maturity around AI security can be framed around three priorities: protect AI, utilize AI, and govern AI.
Protecting AI means securing the AI models, its prompts and data, agents, any integrations, APIs, plugins, and business workflows that make AI useful.
Using AI within security teams means applying it where it can help teams analyze alerts, investigate faster, summarize threats, and improve response – without removing human judgement or accountability.
Governing AI means bringing AI use into the open – knowing where it is being used, what data it touches, who owns the use case, and whether the risks are understood and managed.
RESILIENCE IS THE NEW BENCHMARK
No organization can assume it will prevent every attack, mistake, or misuse of technology. But mature organizations can see clearly, respond quickly, limit impact, recover confidently, and continue serving their customers. In the AI era, resilience becomes the real measure of Cybersecurity maturity.
“The organizations that succeed will not simply be those that deploy AI the most. They will be those that make AI secure, visible, governed, explainable, and resilient”
If AI is becoming the operating layer of modern work, Cybersecurity must become the trust layer that allows innovation to move faster, safer, and with greater confidence.
