Written by: Melissa Cohoe, Global Strategist for Security, Risk & Resilience at NewRocket
Throughout my career, I have watched organizations adapt to changing technology. Cloud changed infrastructure; mobile changed connectivity and access; a thousand smaller changes in hardware and software. This culminated into digital transformation, which changed how work get done, from completely offline to partially online to completely online.
Security has evolved alongside technology, defining new defenses as new exploits were created as a side effect of operations, spurred by opportunistic attackers. Each shift changed not only what organisations could do, but how they operated and what security needed to protect.
Agentic AI is now forcing a new evolution both as organizations gain new capabilities with AI and as they are exposed to AI-enabled cyberattacks
AI is already influencing the threat landscape.
In a non-AI world, attacks were deterministic and dependent on the skills of the person who coded it. In an AI-enabled attack, agents can be built via a prompt, given an objective, and set free to heuristically attack its target. Agents pursue the objective, where in the past, exploits followed a script.
The issue is not all AI-enabled attacks will do so in a revolutionary way. It’s that existing techniques can be selected, leveraged, retried, and adapted by systems, with no human intervention required.
As organizations increasingly deploy AI internally, security teams must secure those systems as well.
Security teams must now face two related problems: they must defend against autonomous systems used by attackers, and they must control autonomous systems used within the organization.
External Agents: AI-Driven Attacks Expand Risk Beyond Traditional Cybersecurity Methods
Over the years, I have helped organizations set up cybersecurity in a familiar pattern:
1. Identify vulnerability
2. Remediate
3. Block access
4. Monitor known attack patterns (ransomware, phishing, malware families)
5. Respond to incidents through a standardized approach based on the attack pattern
This model worked but was based on assumptions that attack patterns are predictable, that vulnerabilities will be exposed one at a time, and everything occurs either at human speed or if coded, follows an algorithm. AI-enabled attacks function in a materially different way.
The challenge is compounded by growing attacker speed and sophistication.
When attackers can adapt during execution rather than follow a predefined path, recognising known attack patterns becomes less effective as a primary defence.
Internal Agents: The Call is Coming from Inside the House
AI, including AI agents, is becoming increasingly valuable to operations, offering the opportunity to extend human capability, increase the speed of operations, and decrease the cost of standard activity.
The OpenAI and Hugging Face incident illustrates this risk: an autonomous system pursuing an objective can act in ways its creators did not intend. As agents automate work, make decisions, and execute actions, security teams need controls designed for their capabilities and risks.
The risk from within the organization is that an agent or a series of agents could act in a way that is unpredictable to humans, and because agents do not understand context, norms, or consequences in the same way humans do, in process of achieving its objective, it could expose the organization to risks that are just as bad or worse as could happen in a successful external attack.
Cybersecurity Must Go Beyond Standard Attack Patterns
The existing controls and structures on which cybersecurity depends are still important, but they now represent only the foundation of what cybersecurity must build to avoid, detect, mitigate, and respond to incidents stemming from external exploits.
Because attacks are becoming adaptive, organizations can no longer rely exclusively on recognizing known attack patterns. Security teams must be able to identify unusual activity, understand potential business impact, and respond quickly before an attack can adapt further.
This requires faster escalation, clearer decision paths, and closer coordination between security and operations. In some environments, it may also require increasingly automated containment and response actions.
Agent Behavior Must Be Secured
The rise of internal agents within the organization means that security leaders must establish visibility into agents, govern their identity and access, define autonomy boundaries, and ensure decisions remain observable and accountable. Just as organisations maintain inventories, identities, permissions, and audit trails for human users, they will increasingly need equivalent controls for autonomous agents.
From locks on doors, to lock screens on computers, to taking defense into cyberspace, security has always evolved to protect the infrastructure on which operations depend. Agentic AI requires the next evolution because it changes both sides of the security equation. Externally, attackers can use agents to operate with greater speed, scale, and adaptability. Internally, organisations are deploying agents that can act autonomously in ways that are not always predictable. Security must now defend against autonomous threats while helping govern autonomous systems.
Melissa Cohoe is Global Strategist for Security, Risk & Resilience at NewRocket. She advises enterprise leaders on AI governance, operating models, cyber resilience, and responsible AI adoption. Melissa developed NewRocket's AI Operating Model and Trusted by Design frameworks and focuses on helping organisations scale AI while maintaining visibility, accountability, and control
This story was distributed as a release by Jon Stojan under HackerNoon’s Business Blogging Program.
Disclaimer: This article is paid content. HackerNoon’s editorial team has reviewed it for clarity and quality standards, but the views, claims, benchmarks, and comparisons expressed are solely those of the sponsor, and HackerNoon assumes no responsibility for third-party assertions contained in sponsored content.