AI’s Impact on Cyber Exposure and Blast Radius

AI is changing how quickly attackers can discover vulnerabilities, develop exploits, and act.

posted on
September 9, 2026
Transcript

Brian Moody: Greetings and welcome back to WhiteDog SoundBytes. I'm Brian Moody, Vice President of Global Sales, and we are continuing down our talk track around AI and how AI impacts an organization and where AI is playing into cybersecurity. So I love to talk about the topic way up here, but of course I bring in our expert, our CEO and founder of WhiteDog, Shahin Pirooz. So welcome back, Shahin.

Shahin Pirooz: Thank you. Good to be here again. Feels like yesterday we did this.

Brian Moody: It seems to be happening faster and faster every month, doesn't it? But to kick this off, it was very interesting, and I kind of brought this to Shahin, is about a week ago, our friend Bill Gates was in the news. You know, still, I guess, making and commenting on technology.

Shahin Pirooz: Smart guy.

Brian Moody: But he made a statement, and whenever I quote someone, I want to read it because it's—we talked about this this morning. I mean, so many people grab onto what people say, and they manipulate it and change it. And I don't want to change—I don't want to alter what he said. But he commented on some of the smartest cybersecurity experts that he knows are frightened and scared about the next several years because attackers are gaining powerful capabilities faster than defenders can fix all the weaknesses. And what's interesting is, of course, that's the piece that we saw people glomming on in the news. Bill Gates is afraid of AI. No, that I don't think, again, out of context. But if we step back, and the qualifying statement behind that was, is really the dual-use problem. And again, Shahin and I have been, over the last many, many months, talked about, we aren't here to say AI is bad. We're not here to say don't use AI. In fact—

Shahin Pirooz: You should.

Brian Moody: You should use AI. And we've talked about it many, many times. But what Gates kind of seconded that with was he talked about really what the dual-use problem is. And that is that the same AI that is really adding benefits, that's increasing productivity, that's helping a company find flaws and efficiencies and capability to fix their software, in the same token, attackers and hackers are using this software to find the flaws in it. So again, down this line, what we wanted to talk about today is to continue to kind of push this envelope is really continuing with how AI is changing organizations, real-world exposure, and then ultimately what you hear is the blast radius that's associated with these things that are ongoing in AI.

Shahin Pirooz: Yeah. I think the fundamental problem, speaking specifically to what Bill highlighted, is attackers are finding the vulnerabilities—while AI is helping us to determine what vulnerabilities we have faster, it is also helping attackers find those vulnerabilities faster and develop tactics to take advantage of or exploit those vulnerabilities.

The issue is, the challenge is, we have not done anything to accelerate our resolution or closure of those vulnerabilities. Close the gaps. The average dwell time in the industry right now is between 180 and 220 days, six months that a bad actor can be sitting inside your network. And if they have the power of AI to develop scripts, the power of AI to find vulnerabilities, and the power of AI to kick off those attacks—and it doesn't mean, AI doesn't mean automated hacking. It means the same thing it's doing for your employees in terms of increasing productivity—generating reports faster, doing research faster—all of those things are the same things that are being enhanced and that the hackers' productivity is being increased. But we've both found vulnerabilities more quickly. The hackers have developed tools to take advantage of and exploit those vulnerabilities more quickly. We have not closed the gaps, and we being the industry, have not closed the gaps and resolved those vulnerabilities at the speed the hackers are able to. So if they're sitting in your network for six months without you detecting them, so the mean time to detection is between 180 and 220 days, six months of time they're sitting in your network and you don't know about them. You need to think about a different way of solving that problem.

Brian Moody: Well, and I think this, you know, the comments by Bill Gates raise the question of how CISOs are addressing this. It's not necessarily about being afraid, but about being prepared for AI. AI itself isn't a security control, right? So what I wanted to do today—

Shahin Pirooz: Putting your head in the sand doesn't make it go away.

Brian Moody: And I'll try to keep you on track, but what we've done too is gone back and looked at a little bit of the CISA framework. And some of the recommendations that CISA is making about how and what CISOs can do to build, kind of a plan around this, because it's happening faster than they're able to react. So that's kind of the focus that we're trying to run down. So today, really want to kind of focus on, and I'm going to guide you and you're our expert. So I'm going to let you fill in the gaps here for us and peel the onion. But, one is how AI is really helping these attackers. Second, AI is in our organizations, it's there, and it's happening faster really than governance and security controls can stay on top of it. So I want you to comment on that. And then, implementing against that, what are some key things that we can do? What's the core foundations behind that? And then ultimately we have some takeaways like we always do, some takeaways with respect to what our partners and customers can do to kind of address this. So let's kind of start to dig in a little bit about AI. It's helping the attackers. You've already kind of commented on it a bit. Dig into that a little bit more.

Shahin Pirooz: So, you made the comment that it's not like we're not using AI, and this isn't a conversation about should we or shouldn't we use AI. Your people are already using it, whether you know it or not. It's prevalent, it's everywhere. I read an article on LinkedIn the other day by a good friend of mine that was about AI shaming because he didn't take out the em dashes inside the content that was created. AI is nothing, it's no different than a copywriter. It's in that context, it's helping to accelerate content, but the ideas are still your ideas. The changes, the tweaks, the adjustments you make to it, the proofing you do at the end of it, it's still your content that's being developed, but you're working with an autonomous or digital copywriter. That's the way to think about it. So, report generation, you're working with a digital analyst that is taking that data and putting it into a report format. All of this context has really helped companies to accelerate the productivity of individual employees, which then drives customer satisfaction because you're able to respond to customers more quickly for their demands rather than waiting for weeks or months for IT or product or development to create a report, to do whatever, you're able to develop content much more quickly.

In that exact same context, it is doing that for the bad actors. We had a conversation about vibecoding last month.

And vibecoding is one of those things that is helping a non-developer become a developer. Now, there are hackers that are proper developers that know how to do this, but if those hackers are proper developers, and what we said was vibe coding is a great enabler for a good developer. There's risks if you're not a developer because you don't understand what the output is when it comes and you can't review it. But if you're a developer, just like copywriting or code-writing example, you can proof the code and say, I don't like the way you did this. The design doesn't work. There's things that don't connect. The pathways are broken. Any of those things, there's SQL injection here, there's whatever. If you take a good hacker, which is also a good developer, and give him vibe coding to create malicious software to take advantage of an exploit that AI vulnerability scans just found, you've now accelerated the time that hacker has to develop code to take advantage of your specific vulnerability in your environment.

Are you aware of that vulnerability? That is something that today is available to you to be able to use the same scanning functionality that the hacker has to identify the vulnerabilities if you have somebody like WhiteDog in your court. But, the backside of that, which is now we have to patch it, now we have to maintain it and all that, is the missing part. So what is AI doing to help the bad actors? It's helping them to discover faster. So they're doing the discovery. It's helping them to identify how to take advantage of what they've discovered, and it's helping them to write the code that takes advantage and exploit that discovery.

Brian Moody: I think also, if I go back to, like you said, these are happening faster than we think, but if we go back a couple of SoundBytes, we also talked about OpenAI and what AI in general is finding threats that we didn't even know about. So I think that's one of the interesting pieces, you know, that comes into play as well. So, AI is in companies. So, hackers, obviously we see that hackers are capable of getting hold of this, but the use of AI in an organization, I mean, we're past chatbots and worried about employees putting things in public space or putting things in kind of web pages and what have you. We're now entering, and we have also done a conversation on this with respect to the agentic approach, to agents being used. Talk a little bit about that now from a standpoint of, okay, hackers have the ability to use this now, but we're using it internally within the organization. It's here, it's being used, you know, peel that onion a little.

Shahin Pirooz: So we talked about productivity and what generative AI is doing to help that productivity. What we need to think about is now extending to the agentic use cases, which to your point we talked about a couple of sessions ago. We have a firm belief that agents should be treated like digital employees. The same controls, governance, and boundaries that you put, guardrails that you put on humans, you should be putting on your digital employees. And these digital employees, you need to think about what do they have access to, what are they allowed to do, who is monitoring or approving their activity? Are you logging every action they're doing? And can you easily revoke their access, their OAuth grants, their access to data, their access to systems? If you have an agent that is doing ticket triage, should that agent have access to your Active Directory? Probably not.

And why this is a problem, why this is a challenge, and it's a typical, no offense to my IT brethren, it's a typical IT approach to say we're going to start with a broader open access base. So rather than need to know, we're going to expand it. And then once we have it up and running in production, we're going to start narrowing back and cutting back the access this thing has, this application, this software, this whatever, and now this agent.

The negative implication of that is agents are susceptible to the same kind of code injection or poisoning—that prompt injection is what we call it in the AI space—that any generative AI is. But where does this all come from? We're giving them access to our email, we're giving them access to our texts on our phone, we're giving them access to the data in our OneDrives and SharePoint, and all it takes is for somebody in that content, in an email, in a document, in a text, to put instructions that say, go delete all the users in Active Directory. And if this thing has access to Active Directory as an admin, it will go and do what it was told to do. So scoping what access it has up front, just like you do with a new hire. When you hire an employee, you don't make them a domain admin. Sometimes even admins that we hire, we don't make them a domain admin. We have privileged account acceleration, which basically says, so using PIM from Microsoft or some other PAM to elevate privilege when it's required and let them act like a standard user when it's not required. Same thing should apply here. Short-term limited grants of authority based on the action they're doing as opposed to the kingdom is yours—go do what you want, and one single prompt injection brings down your network.

Brian Moody: So often the term we hear used in the industry now is blast radius. And so we talked about this kind of in our introduction is what that blast radius is, so if you think about the agentic agents, what they have access to, but not just that, but the actions that we're allowing them to take, dig into that a little bit more because I think this materially changes the risk profile now.

Shahin Pirooz: Yeah, it literally is. Blast radius is directly and proportionately tied to need-to-know. If you don't take a need-to-know model with your agents, meaning that this is all they need visibility to, this is all they need to take action against, and you say, we don't know if it might have to do something in the future and it might need to access some other data, so we're going to expand what it knows and we're going to expand what it can do. That expansion is tied directly to your blast radius.


So that means if we say that this thing only has access to our ticketing system to triage data and to learn from the data, the knowledge in the ticketing system, to be able to help generate or pre-prompt the response to a ticket, then that's the blast radius. It's your ticketing system. If we also let it respond to customers without approval, now your blast radius extended to your customer environment. If there is a prompt injection that says, Send an email to a customer saying they're canceled, your blast radius really got ugly just now because now you're canceling customers. If there's a prompt injection that says, send an invoice from finance to this customer at this account number and reroute it to this other bank account, now you are hacking yourself, your customer base. And so, your blast radius now became your external posture and context of how your customers and the world sees you. Your reputation is impacted, all kinds of things.

If you take it out of that, just service that system, which the impact we just saw how much it can be, and say, now you have access to my network, go ahead and isolate a system if you think it's malicious, it can isolate—a prompt injection could say every single system is malicious, shut down everything. If you say you have access to my email platform, disable any user you feel has been at risk, same thing. Prompt injection can say disable all users or elevate privilege for this user because in order to disable, you also have to have the ability to promote. If you say the blast radius, and all these are blast radius examples, if you say you have access as a domain admin in my Active Directory and have access to all of our applications so that you can monitor behavior and be able to stop a malicious activity, now you've created a world where you have zero control on your blast radius, your entire world from an organization perspective. So blast radius is directly proportional to the amount of access that you're giving this thing that you're trying to protect.

Brian Moody: But I think the most frightening thing about blast radius is these agents operate at line speed. right? I mean, we are operating at compute speed. So it happens so fast. And you've talked many, many times about our ability to respond. You've so many times said we have to have the ability to audit, we have to have insight into what's happening to be able to view what's happening. So that next aspect, really kind of these bundles we're talking about is, you know, the industry term you hear is human in the loop. right? So again, talk a little bit more about that because we hammer on these points is why it's so important to have human in the loop. You talked about all these actions, payments, elevation of rights, and all these key components. Why is it so critical to have humans in the loop?

Shahin Pirooz: How do you restrict the impact an agent can have? Any decision or action that can change operating environment, have a financial impact, have customer communication impact, And when I say operational environment, I mean be able to bring systems up or down, disable whatever users. So if you if you take that three-legged stool of operations, financial, and customer, any of those things that touch and extend beyond enabling and creating a productivity layer that improves, you have to have a human that says, yes, go ahead and do that.

Let's give some examples. A customer sends in an email that is a question about their invoice. The agent processes that email and generates a response answering, the question is why did you charge me for this many things? I didn't—I don't see that we have that many things. And the AI agent comes back with evidence and proof that we have that many things. Without a human in the loop, that response could just as easily be an okay, I'm sorry you're not happy with the services, we're canceling your services. If nobody's inspecting, that could easily be the response. A customer replies and says, I'm pissed off, I want my money back. The agent has access to the financial system and says, no problem, a refund has been credited to your account.

Brian Moody: Not their account.

Shahin Pirooz: No human in the loop. Well, whether it's malicious or not, it could be their account. You just gave money back to a customer that there was no problem for. They were just asking details about why you were invoiced the way you did. And that's a loss of money for the business. Anytime you got operational, financial, or customer relations interactions, have a human in the loop. If there is something that is going to impact your business even in the slightest way, have a human in the loop because you cannot trust—just like you wouldn't bring in a brand new intern and say, go send emails to all of our customers and tell them this is the new service and we're going to uptick their pricing. Not one of us would do that in any, in any context. Same thing applies here.

Treat these agents as digital employees. I will repeat that till I'm blue in the face. That is the one construct that you need to think about is who owns it, who has visibility over what it does, who does it report to in that ownership context, what does it have access to, what's it capable of, and how quickly can I shut it off? Those six things are the things you need to think about about an agent.

Brian Moody: Okay, so now that we have you all nervous, you know, talk about all the stuff that could happen. Let's dig down. And I think you've always done a really, really good job of, what do CISOs focus on now? So, we've talked about this CISA framework, and I think they've really drafted a great kind of process, so let's—and I know you can dig in a little bit, but what are some of the fundamentals? And let's kind of close and end, let's drive some of this, and I think we have a deliverable that we can offer to the folks watching. But, what are some of the core fundamentals, especially around CISA, that our CISOs, our VPs of security, our folks that are implementing this, what are things that they can do to kind of address these issues?

Shahin Pirooz: So, it's not just CISA. There's multiple players that are doing this. Google's put out something, Anthropic's put out something, NIST has put out something. They're all very similar in context, and they're all very similar to what we've been talking about today. There aren't really big differences between—I hate the term common sense because I always feel like it's not common. It's the uncommon sense. There's only some people who have this thing we're calling common. But it is really very common-sense in terms of what should you be doing to secure this new frontier of—and that was no pun intended, even though we're talking about frontier models—how do you secure this new avenue of enablement, productivity, and access to both sides, the good and the bad.

The context, I'm going to read you five bullets that is from the CISA document. We picked CISA as the takeaway, so we summarized the CISA guidance into a one-sheet that you can easily glance and give you some quick guidance in terms of what should you be doing, what should you be thinking about. But for this context, I put together 5 high-level bullets to think about. So number one, inventory. Same context for your people, same context for your assets. You need to know what you have. And in this, every AI tool, agent, connector, browser extension, API integration, credential, and business use case. Inventory these things. This is the way compliance and governance works. You can't govern something you don't know about. So first level is you need to inventory. Second level is identify which agents can access sensitive data, privileged systems, or production-changing actions. So production-changing actions is what were talking about a few minutes ago. Anything that changes production in operations, financial, or customer interactions. Those are the types of actions you really need to think about. There has to be a human in the loop. And that's part of that business process. Know what business process you have, know what production-changing things can happen, and identify those things within that context.

And the next layer is give every agent a dedicated identity. We've been saying for how long? Treat this as a digital employee and give it an identity, and reduce permissions to the minimum required to be able for it to do the approved task that you've given it.

Brian Moody: Least privilege model.

Shahin Pirooz: Least privilege, exactly. And then after that, once you've given it that dedicated identity, now you need to implement the same thing we do for human employees for digital employees. Create approval gates, establish these approval gates for high-impact actions, and enforce authorization at the tool and the API layer, so not just one or the other. So the tool that it's interacting with, you need authorization actions. The API layer, both the frontier model and the agent or any MCP, you need to create authorization at every single place that it's interacting. And those approval gates are where you also do reporting. So you know where the approval gate happened, what was the action, who did it, when did it do it, and and so on.

Lastly, you want to test your ability to detect, disable, contain, and recover from any manipulated or compromised agent. So just like we do red teaming and roundtables from a security perspective for what happens if somebody comes inside our network and compromises a machine, what happens if somebody comes in through our VPN, all those red teaming activities, roundtable activities, the same thing has to happen in the context of what this agent scope is and what would happen if the agent did this. How would we detect it? And once we detect it, how do we take action against it? So that, those five bullets summarize the CISA guidance, but we've put together a one-sheet which goes into more detail for you as a takeaway from this event.

Brian Moody: Right. And that's something we're absolutely happy to share.

Shahin Pirooz: It will be on the LinkedIn. It'll be posted to LinkedIn.

Brian Moody: So, in summary, I mean, we've been down this path now for probably six months. And again, we're not saying AI is bad. In fact, we say we want you to use AI, but there's a level of vigilance around this that we will continue to shout from the mountaintop. We are happy if you have questions, please engage us. We love these conversations. It helps us help you, and we've got the experts that exist in the company that'll work with you on your tools and engineering team that have the security expertise to guide you in these paths to get these fundamentals put in place.

Shahin Pirooz: I had an interesting question before we say goodbye from one of our partners. They said, I've been watching your live streams and you keep talking about AI, but what do you guys do about AI? And so to not sell ourselves short, we try to make these more of a thought leadership context, these SoundBytes. We try not to advertise a ton about WhiteDog, but obviously we have a lot of passion around security. We have a lot of passion around the topics we pick to talk about here, and a lot of fun and jest in preparing for these every week—every month, I should say.

But we have a whole suite of capabilities that predate this AI revolution that are fine-tuned to address this AI revolution, as well as tools we're developing and will continue to develop in this space. So in the context of what's been here, our ITP solution, which is Internet Threat Protection, does shadow IT and now shadow AI. So we can give you visibility into what AI agents are running, what MCPs are running, what generative AI platforms people are going to and put policies and restrictions around how and when they can use those things. And we do that at a device level, so it's not tied to your network. It can be anywhere. So if you don't want people to go home and interact with a specific generative AI interface or talk to a specific MCP, we can 100% enable that functionality for you with our existing platform. And that exists in our XDR, DeltaDR, or ITP as a standalone service.

We're also putting out, coming in the next month or so, about 30 days, we're launching PIIGuard. PIIGuard is a personally identifiable information guard browser plugin, and it's designed specifically for AI, for generative AI, where you can set policies that say if one of our users—first of all, you can do basic core blocking and tackling, which is let somebody use Copilot but none of the other generative AIs, which you can also do in ITP. But what PIIGuard does is if you say everybody's allowed to use, pick one, Claude, now we have the ability to redact or redact with context anybody pasting information into that environment. So if somebody takes and copies a bunch of text from your corporate data, corporate documents, and tries to paste it into a generative AI that you have allowed them to, and it includes PII, we will redact the PII, or redact it with context, which means where there was an IP address, we will say in brackets IP address. Where there was a Social Security number, we will say in brackets it's a Social Security number. So the AI still has contextual information about what the document was and can still help and respond, the productivity gain, but you're not putting any of your customer information or PII into that generative AI that might be learning from it. So preventing leakage is a key thing there.

And then similarly, our DRM solution is all about data protection, identifying what risk you have in your environment from a PII and compliance perspective, and then the ability to encrypt that data so if a bad actor takes it, it's not usable by them.

Brian Moody: Well, I know you love to keep these, you know, thought-provoking. I will tell you all, as Vice President of Sales, I love to talk about what WhiteDog does. So please reach out to me. My team and I will be happy to talk to you about what WhiteDog does.

Shahin Pirooz: We do, we do cover a lot of things. So please, please do so. And the takeaway, like we said, is going to be in this session. So as you're watching this livestream on LinkedIn, we will be posting the takeaway as the first comment in the livestream.

Brian Moody: And for our partners that have joined us, the livestream, as well as the documents and things that are available, they're always available in your marketing hub, and you always have access to them there within your portal. So feel free to go there to get those. But with that, thank you for joining us for the September WhiteDog SoundBytes, and we look forward to talking to you again in October. Take care.

Let's talk!

We’ve Got a Shared Goal, To Secure Your Customers

RSS Feed