Visualização normal

Hoje — 7 de Setembro de 2026Communities
  • ✇cybersecurity
  • What do you use for AI security in a large enterprise? /u/Any_Yesterday_6617
    We’re starting to see AI move from internal experimentation into workflows that can access knowledge bases, tickets, code, and sometimes production-adjacent systems. For teams in larger enterprises, what are you actually using for AI security beyond standard IAM, DLP, and vendor questionnaires? Interested in how people are handling model access, prompt injection, agent permissions, audit trails, and testing before new AI tools are approved. Is this owned by the security architecture team, the A
     

What do you use for AI security in a large enterprise?

7 de Setembro de 2026, 05:09

We’re starting to see AI move from internal experimentation into workflows that can access knowledge bases, tickets, code, and sometimes production-adjacent systems. For teams in larger enterprises, what are you actually using for AI security beyond standard IAM, DLP, and vendor questionnaires?

Interested in how people are handling model access, prompt injection, agent permissions, audit trails, and testing before new AI tools are approved. Is this owned by the security architecture team, the AI platform team, or shared across both?

submitted by /u/Any_Yesterday_6617
[link] [comments]
Antes de ontemCommunities
  • ✇cybersecurity
  • Best platforms for continuous security validation in 2026? /u/Any_Yesterday_6617
    Most of our assurance spend has gone into scheduled pen tests and occasional red team style engagements. They still have value and do uncover real issues, but they give a snapshot rather than a living view of control effectiveness. Once we close the findings, the environment has already moved on. We are considering moving some of that budget toward continuous security validation to get ongoing feedback on exposure and detection coverage. The idea is to treat pen tests as one input, not the only
     

Best platforms for continuous security validation in 2026?

9 de Julho de 2026, 23:49

Most of our assurance spend has gone into scheduled pen tests and occasional red team style engagements. They still have value and do uncover real issues, but they give a snapshot rather than a living view of control effectiveness. Once we close the findings, the environment has already moved on.

We are considering moving some of that budget toward continuous security validation to get ongoing feedback on exposure and detection coverage. The idea is to treat pen tests as one input, not the only validation mechanism, and to rely on continuous assessments to reveal where controls and detections fail over time. We would like a platform that can exercise realistic attack paths across endpoints, identity, cloud, and email, and that does not require a dedicated team just to keep it running.

If you have already gone down this path, which platforms have actually worked for you in practice? I am interested in names, but even more in why they worked: did they cover enough of the kill chain to be useful, integrate cleanly with your SIEM and EDR stack, and give reports that helped you prioritize real fixes instead of just adding noise? I am also curious whether you found that some platforms looked good in a proof of concept but failed to deliver once you tried to use them as a core part of your assurance program.

How did you explain the trade to leadership that is used to seeing classic pen test reports as evidence of due diligence, and how did the platform you chose help with that conversation? If you could restart the move from point in time testing to a platform driven continuous validation approach, what would you avoid and what would you double down on in terms of both tooling and process?

submitted by /u/Any_Yesterday_6617
[link] [comments]
❌
❌