Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How Organizations Can Assess and Manage AI-Related Risks

Organizations assess and manage AI-related risks by establishing a cross-functional governance framework, mapping risks based on impact and financial likelihood, and instituting continuous monitoring that connects AI asset discovery to risk quantification, compliance, and enforcement. The most effective programs treat AI risk management not as a one-time assessment but as a continuous, data-driven discipline that evolves alongside the AI systems it governs. ‍

Why You Must Still Review AI Code

In this video, we break down why skipping code reviews is a massive mistake that will ultimately slow you down, leave you vulnerable, and compromise your system's accountability. We dive into three concrete reasons why reviewing AI-generated pull requests actually makes you a faster, safer developer, including a real-world story of a production bug caught in under 90 seconds. Resources Chapters.

AI Governance on AWS: Discover, Observe, and Control AI in Production

AI adoption within AWS environments is accelerating faster than most security and governance programs. AI agents, APIs, MCP servers, and model integrations are entering production across cloud environments, often without centralized visibility or runtime controls. In this webinar, you’ll see how teams can discover AI workloads across AWS accounts, understand what AI systems are actually doing at runtime, enforce policy in real time, and generate continuous governance evidence without slowing engineering teams down. The session focuses on practical operational capabilities for AI systems already running in production.

What Is Firewall Configuration and Why Is It So Important?

Firewall configuration is the set of rules, policies, and settings that define how a firewall behaves. Without configuration, a firewall is hardware and software waiting for instructions. With configuration, it becomes a control that determines what traffic is permitted, what is blocked, and what gets inspected before a decision is made. Get the configuration right, and the firewall does its job. Let it drift, and you have the appearance of protection without the substance of it. This is not an edge case.

AI Control Platform vs. AI Firewall vs. AI Gateway: Clearing Up The Terminology

Editor's note: This article was originally published by Tim Erlin on LinkedIn. It has been republished here with the author's permission. It seems like every security vendor now sells "AI security." The WAF companies, the API gateway companies, the cloud platforms, the proxy startups: all of them have an AI story, and most of them have attached one of three labels to it. AI gateway. AI firewall. AI control platform. The terms often get used as if they're interchangeable, but they are not.

Coding Agents Are Moving Faster Than Security. Here's What CISOs Need to Know.

Coding agents have become one of the fastest-adopted AI technologies in the enterprise. They help developers write code, debug applications, automate repetitive tasks, and ship software faster than ever before. They also introduce a security challenge unlike anything most organizations have faced. Unlike traditional AI assistants that generate content, coding agents take action.

Data leakage risks with DBHub MCP servers

Organizations keep their databases behind firewalls for a reason: the data inside is the data they can least afford to lose. A new class of AI middleware–Model Context Protocol (MCP) servers–exists specifically to reach into those protected systems on an AI model's behalf. One of them, DBHub, connects directly to SQL databases.

Agentic AI Governance Requires a New Enforcement Model

AI has swiftly shifted from a browser-based chat interface to an autonomous actor operating within enterprise environments. Agents run locally on endpoints, inherit employee permissions, access sensitive data in bulk, and execute multi-step workflows with no human approving each step. That shift fundamentally changes the enforcement surface. The governance programs most organizations have built were designed for a different model: one user, one prompt, one decision.

Two Months After PocketOS: What a 9-Second Database Deletion Taught Us About Agentic AI Security

Nine seconds. One API call. A car rental software company’s production data was gone. That’s the headline from the PocketOS incident, and it’s the reason this story spread across engineering and security circles the way it did in late April. Two months later, the incident is no longer breaking news. But it hasn’t aged out of relevance; it has aged into a pattern.

Secure Enterprise AI Innovation with Cato AI Security

Enterprise AI is spreading fast across employees, applications, and agents. Security teams need a way to enable AI adoption without losing visibility, control, or governance. In this demo, see how Cato helps organizations secure AI across three fronts: · AI employees use, including sanctioned and unsanctioned AI tools· AI applications teams build, including LLM apps connected to enterprise data· Agentic AI, where agents can access tools, data, and workflows.