AI And Cybersecurity: Why Securing The Intelligent Enterprise Requires A New Security Model
Muhammad Affan Habib | Director of IT at Sharjah Maritime Academy | AI Governance & Digital Transformation Leader.
gettyAI is no longer sitting at the edge of the enterprise as an experimental technology. It’s moving into day-to-day operations, supporting employees, interacting with institutional knowledge, assisting customers and, increasingly, taking actions across business systems.
I’ve seen this transition firsthand while leading digital transformation and cybersecurity initiatives at Sharjah Maritime Academy. We’ve progressed from exploring AI use cases to implementing AI-enabled services across admissions, employee support, teaching and learning and internal knowledge management.
AI can analyze large volumes of security telemetry, detect unusual behavior, accelerate investigations, support vulnerability management and help analysts prioritize complex alerts. The NIST AI Risk Management Framework provides a useful foundation by helping organizations consider trustworthiness and risk throughout the design, development, deployment and use of AI systems.
One of the most significant changes I’ve observed is that AI is becoming part of the enterprise attack surface. GenAI and agentic systems create additional risks, including prompt injection, sensitive information disclosure, insecure integrations, model or data poisoning, supply chain vulnerabilities and excessive agency.
This became a practical consideration as we developed AI-enabled services at SMA. For example, our AI admissions and registration assistant was designed to answer prospective students’ questions, explain programs and admission requirements, guide applicants and connect them with the appropriate team.
Its purpose was clearly defined, but so were its boundaries. An admissions assistant should provide accurate guidance and facilitate the applicant journey. It shouldn’t independently make admission decisions, access information beyond its purpose or perform unrestricted actions in institutional systems.
We applied the same thinking to our internal AI knowledge assistant, which is intended to help employees find policies, procedures and institutional information through voice and chat. The value of such a system comes from its ability to locate relevant knowledge quickly. Yet that same capability introduces risk if the assistant can retrieve information that the requesting employee isn’t authorized to see.
In my experience, organizations should avoid giving an AI agent broad access simply because doing so makes the initial integration easier. Convenience during implementation can become a long-term governance weakness.
Organizations are understandably eager to connect AI to enterprise knowledge. Employees can ask questions in natural language and receive answers drawn from policies, procedures, reports and operational data.
This is why our approach to a secure, private AI environment hasn’t been limited to selecting a model or creating a user interface. We’ve also had to consider where institutional data is processed, how it’s classified, which sources the AI can use, how access is controlled and what interactions must be logged.
The NIST Generative AI Profile complements the broader AI Risk Management Framework by addressing risks specific to GenAI.
In our AI-enabled learning initiatives, AI can help faculty transform course materials into podcasts, video explanations, mind maps, flash cards, quizzes and learning pathways. These capabilities can save time and create more engaging learning experiences. However, academic quality and accuracy still require faculty oversight. The AI supports the educator; it doesn’t remove the educator’s accountability.
The cybersecurity team alone can’t own AI security. It requires cooperation among technology, cybersecurity, data governance, legal, compliance, enterprise risk, procurement, HR and business leadership.
This has been especially clear in my own work. Deploying AI in a higher-education and maritime environment requires protecting student and employee data, maintaining academic integrity, ensuring regulatory compliance, managing third-party risk and preserving trust in institutional decisions.
ISO/IEC 42001:2023 provides an international management system framework for establishing, implementing, maintaining and continually improving an AI management system. It can help organizations move AI governance from a collection of isolated principles into a structured operating model.
The NIST Cybersecurity Framework 2.0 complements this by providing a broader structure for managing enterprise cybersecurity risk. NIST’s developing Cyber AI Profile further reflects the growing convergence between securing AI systems and using AI to strengthen cybersecurity.
However, adopting a framework isn’t the end goal. Organizations must translate governance into ownership, controls, risk assessments, testing, monitoring, incident response and measurable accountability.
The most successful AI programs won’t necessarily be those that deploy the greatest number of tools or give AI the highest level of autonomy. The future of cybersecurity will be about establishing digital trust between humans and intelligent machines operating within the same enterprise.
From my experience leading both cybersecurity and AI transformation, one conclusion is clear: Securing AI must be designed into the AI journey from the first use case, the first dataset and the first decision about autonomy.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?