Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Ultimate Guide to API Security in AI Applications

API security is the practice of protecting the interfaces that connect your applications, models, and data from unauthorized access, abuse, and data theft. In AI applications, APIs carry prompts, model responses, customer PII, and agent instructions, which makes them the single most exposed layer of your AI stack. Securing them requires authentication, rate limiting, encryption, and a layer most teams miss: protection of the sensitive data in every API call.

It's Not If Attackers Get In. It's What Happens Next | Insurity CISO Jay Wilson

"Usually it's not a question of if the bad guys get in. It's a question of what happens when they do." Jay Wilson, CISO and CIO at Insurity, and Garrett Hamilton, CEO of Reach, joined Shubhangi Dua on The Security Strategist from EM360Tech to talk about why the controls you already own are where exposure quietly builds up. That's Jay's line, and one every security leader has lived. Defense in depth only holds if every inner layer is configured the way you think it is. The outer door gets the attention. The inner doors are where incidents actually get stopped, or don't.

AI Kill Switch Architecture: How to Stop a Rogue AI Agent

AI agents today are becoming a part and parcel of everyday enterprise operations. They can access databases, trigger workflows, send emails, approve requests, and interact with business systems with very little human involvement. What started as AI assistants is now evolving into autonomous operators capable of making decisions and executing actions at machine speed.

Why AI Projects Stall and How CIOs Can Respond

Across enterprises, a familiar pattern is emerging. A business unit identifies an AI tool with a clear upside in productivity or revenue. Their proposal moves into procurement. Security raises concerns, and the legal team asks new questions about the tool. Compliance starts hesitating and the momentum slows. Finally, the project stalls. This friction is not due to resistance to innovation. It reflects a deeper structural issue: Most enterprise governance models were not designed for AI.

Agentic AI Visibility and Risk Scoring: What Cyberhaven Sees That Others Miss | (Part 3 of 4)

Knowing an AI tool exists is not the same as knowing what it did with your data. This is Part 3 of Cyberhaven's 4-part AI Security product launch series, covering Agentic AI Visibility and AI Risk IQ, Cyberhaven's evidence-based risk scoring system for every AI app and agent in your environment.

Real-Time AI Enforcement Powered by Data Lineage | Cyberhaven (Part 4 of 4)

Visibility without enforcement is just an alert backlog. This is Part 4 of Cyberhaven's four-part AI Security product launch series, covering how Cyberhaven enforces risk-based controls at the data level, not the tool level, using Data Lineage as the foundation.

Shadow AI Discovery: How to Find Every AI Agent in Your Environment | Cyberhaven (Part 2 of 4)

Security teams cannot govern what they cannot see. This is Part 2 of Cyberhaven's four-part AI Security product launch series, focused on Shadow AI Discovery and how Cyberhaven automatically inventories every AI app and agent running across your organization.

AI Security for Autonomous Agents | Cyberhaven Product Launch (Part 1 of 4)

Autonomous AI agents are running on enterprise endpoints right now, accessing files, processing sensitive data, and executing actions outside the visibility of most security programs. This is Part 1 of Cyberhaven's four-part AI Security product launch series. What this video covers: Most AI security tools were built for browsers and SaaS apps. They cannot see agents operating at the OS level, coding assistants running in IDEs and CLIs, or MCP servers executing in the background. Cyberhaven's AI Security platform was built to close that gap.

Do You Know How Many MCP Servers Are Running in Your Environment Right Now?

Most organizations have no idea how many MCP servers are running in their environment—and attackers are counting on that. In this clip, Adrian Culley breaks down the exact steps security teams need to take now: run the network scan, apply stringent code review to every MCP server project you find, and mandate authentication. Authorization may be optional in the MCP spec—but it doesn't have to be optional in your deployment.