In the era of generative AI, the zero-trust principle remains effective in its ability to adapt to emerging security challenges. But Prakash Venkata, principal of cyber, risk and regulatory at PwC, said many organizations have yet to figure out how to address the new technology and the threats it brings using this principle.
Venkata emphasized zero trust is not a mere technology or a package of tools, but “more of a principle on which you're going to build your enterprise security architecture.”
“There are new threats that are happening and we have to evolve. It's not the technology that is the problem; the way we use that technology is the challenge. So I would rather say it's not the principles that are going to change. Now there are new risks and new threats that are coming out. How do we address that in our principle?” he added.
As new threats from the development of artificial intelligence (AI) emerge, “how much and where we push [for the zero-trust principle] is what is going to be different," Venkata said, adding that traditional security models need to become more dynamic by shifting the focus to real-time response and escalation.
On the other hand, he expects the trend of using more genAI and other AI and machine learning capabilities will drive up the adoption rate of zero trust.
“With all the new threats that are coming in, a lot of those zero-trust principles will be automated to an extent. The connectivity that needs to happen and the amount of data that's available, and building models on top of it, I think that will only become advanced and that will make people's life easier,” Venkata said.
He argued if organizations don’t adapt to the new development and adopt the zero-trust principles, “they probably will be going out of business in this digital world.”
How can zero trust address generative AI threats?
The application of zero-trust principles in real time is essential to address genAI-associated threats such as sophisticated phishing, stealing models, data poisoning, and injecting malicious inputs through prompt injection or extracting confidential information from the training data.
“How are you going to differentiate: It looks like authentic traffic and everything looks really authentic? Are you letting them go into compromise? This is where I started working with zero-trust principles,” Venkata said, because “the bad guys are adapting faster.”
He explained that real-time monitoring and adaptive response are crucial aspects of a zero-trust strategy. This might involve temporarily blocking suspicious traffic or diverting it for further analysis to enhance an organization's remediation capabilities and advance security planning.
In addition, zero-trust security goes beyond specific tools. It is a principle that should be flexible enough to accommodate new threats and traffic from generative AI, requiring either tool enhancement or putting a detection function in the intermediary.
Venkata also highlighted the need for threat intelligence to understand the origin and nature of threats.
Zero trust for different use cases
Zero-trust models often include least-privilege access, microsegmentation, continuous monitoring and evaluation, data protection, secure software development lifecycle, and risk assessment and management functions.
Venkata argued the model should be layers of security and control measures based on zero-trust principles, and the model needs to be implemented according to each industry’s needs to address the specific genAI challenges it is facing.
“We usually go through each of the use cases and do a threat modeling and then say, how is our debt, how can this be compromised? And then [figure out] what is going on. What are the tool layers that are there, what are the controls there? To an extent … in certain areas, humans actually have to look at it and say if this makes sense and approve it,” Venkata explained.
Comments