How to Build an AI Security Program from Scratch

How to Build an AI Security Program from Scratch

🎙 Cloud Security Podcast 👥 39K 📅 January 15, 2026 ⏱ 42 min 👁 13K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

AI SecurityGovernanceData Security Posture ManagementZero TrustModel Cards

Summary

In this episode of the Cloud Security Podcast, host Ashish Rajan interviews Shannon Murphy, a Global Security & Risk Strategist at Trend Micro, about building an AI security program from scratch. They discuss the common pitfalls in AI adoption, emphasizing that 95% of AI projects fail due to a lack of governance and stakeholder alignment. Shannon outlines a three-stage maturity model: adopters, builders, and scalers, each requiring different security approaches. The conversation covers the essential components of an AI security blueprint, including data security posture management (DSPM), AI-specific vulnerability scanning, and treating AI agents as identities. They highlight the inadequacy of traditional DLP in the AI context, using the example of asking a chatbot for a boss’s salary. The episode also touches on the importance of model cards for transparency, the role of AI governance committees, and the need to shift left in security testing. Shannon emphasizes that security teams must have an IQ in AI and that a platform approach is necessary to manage the complexity. The discussion concludes with practical milestones for implementing an AI security program and a light-hearted segment on personal topics.

186 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners seeking a practical roadmap for AI security. Shannon provides concrete examples and actionable advice, such as the importance of data provenance and the need for AI-specific vulnerability scanners. The argumentation is coherent and well-structured, building from risk scenarios to a detailed blueprint. However, some claims, like the 95% failure rate, are presented without citing specific studies, relying on industry reports that are not named. The discussion is grounded in real-world experience, which adds credibility, but the lack of empirical evidence weakens the scientific rigor.

Scientific Rigor, Source Quality, Title Accuracy

The episode references established frameworks such as NIST AI RMF, OWASP Top 10 for LLMs, and MITRE ATLAS, which are credible and widely recognized. The title accurately reflects the content, which is a practical guide rather than a theoretical discussion. The sources cited in the description are primarily promotional (podcast website, bootcamp, newsletter), not directly related to the content. The conversation is based on expert opinion and industry experience, not peer-reviewed research, which limits the scientific rigor. The adéquation between title and content is strong, as the episode delivers on its promise of building an AI security program.

206 words

Title / Content Match

The title accurately reflects the content, which provides a step-by-step guide to building an AI security program.

Quality & Reliability

7/10

The episode features an experienced security strategist discussing practical AI security frameworks and best practices. It references established frameworks (NIST AI RMF, OWASP, MITRE ATLAS) and provides actionable advice, but relies on anecdotal evidence and industry experience rather than peer-reviewed research.

Chapters

Cited Sources

Concurring Sources

Contribution & Novelties

The episode provides a structured approach to AI security, categorizing organizations into adopters, builders, and scalers, and offering a blueprint that integrates data, application, and identity security. It emphasizes the need for governance and stakeholder alignment, which is often overlooked. The discussion on treating AI agents as identities is a forward-thinking concept.

Pour aller plus loin :

103 words

Radar Profile

The radar profile shows a balanced approach with high scores in information quantity and quality, moderate technical depth, and strong reliability. This indicates a well-rounded discussion suitable for security professionals seeking practical guidance.

Reliability 7/10

💬 No comments were provided for analysis.