Enterprises are making big bets on AI as they look to automate workflows, better connect with customers and extract more value from their data.
But they’re not the only ones taking advantage of the technology. Cybercriminals are doing the same, but they don’t have to worry about guardrails, data protection or best practices.
The result is a cybersecurity arms race, forcing companies to think very carefully about exactly where they host enterprise applications and workloads. IDC research shows worldwide security spending will grow 12.2% this year, as cyber threats are accelerated by AI, including generative AI (genAI).
Some companies are hunkering down, boosting their on-premises infrastructure or repatriating data or projects. Research by Flexera showed just over a fifth (21%) of cloud workloads and cloud-based data have been “repatriated.”
Splendid isolation might offer a heightened sense of security. But it’s important to consider the full range of security options, scalability and access to other services that an enterprise grade AI strategy requires.
Security in the cloud
Cloud operators will typically take a wide-ranging, defence-in-depth stance on security. This will include a shared responsibility approach. For example, AWS explicitly assumes the massive burden of securing its underlying cloud infrastructure, from the physical assets up to the host operating system and virtualisation layer.
Customers are responsible for the guest operating system, applications and “configuration of the AWS provided security group firewall.” And, critically, customers will be responsible for securing their own data and applications.
So, enterprises should consider exactly what types of data, applications and AI models they are working with. This will leave them in a far better position to think about what actions to take and what additional services to leverage to protect them.
Cloud services typically offer data encryption as standard, both in transit and at rest. But encryption must be managed, for example, by auditing key use and spotting potential issues.
Managing identities
Likewise, data sovereignty is increasingly important. Having the ability and the tooling to manage where your data resides is key to ensuring compliance and serving customers appropriately, wherever they are.
Identity management goes hand in hand with data security. Smart tech leaders will operate their estates on a least privilege basis. But they will likely want to manage access and controls as granularly as possible. It is essential their cloud provider gives them the tools to do this.
And it’s important to remember that workloads and AI agents are all “identities” in their own right. Their permissions also need to be tracked and managed. So, the organisation’s tool set must be flexible and scalable enough to match this.
It’s foolish to think that any system is completely impregnable. If they are connected to the outside world, systems will come under attack – reconnaissance is one area that criminals have been quick to automate with AI.
Security is non-negotiable, and AI only ups the ante. For most enterprises, operating with a cloud partner may provide a far more holistic view of the potential threats – and a much wider range of tools to counter them.
