4004 news
· HMZE · 5 min read

Miro CISO on AI Security Strategy

Miro's CISO outlines a pragmatic, layered security framework for AI adoption. The strategy prioritizes institutional knowledge capture, rapid iterative deployment over perfection, and strict agent identity segregation to mitigate emerging risks.

Executive Brief: Strategic AI Security at Miro

Miro’s Chief Information Security Officer, Marc Strand, provides a pragmatic framework for navigating the rapid integration of AI into enterprise workflows. With a background spanning three decades of tech evolution, Strand emphasizes that the current AI shift mirrors historical paradigm changes, such as the transition from dial-up to broadband. The core strategic imperative is not to halt innovation but to layer security controls that allow for bleeding-edge adoption while maintaining robust risk management.

Layered Defense Architecture

Strand advocates for a "Swiss cheese" approach to security, rejecting single-point-of-failure solutions. This model combines hard base-layer controls (such as device management and pipeline checks) with softer, context-aware policies embedded in system prompts. Crucially, this is augmented by real-time detection capabilities that analyze multi-dimensional data streams. This holistic approach ensures that while individual layers may have gaps, the combined architecture creates significant inertia against breaches, whether from malicious actors or benign AI errors.

Agent Identity and Segregation of Duties

A critical shift in security operations is the management of AI agent identities. Traditional human-centric access models, which often rely on over-privileged roles and human judgment, fail in AI contexts. Strand highlights the necessity of strict segregation of duties for agents. For instance, an agent processing invoices must not have the entitlement to execute financial transactions. This prevents both malicious prompt injections and non-malicious errors caused by missing context, requiring a 100x increase in granular entitlement management compared to human users.

Speed Over Perfection

A counter-intuitive but vital insight is the preference for rapid, 80% effective solutions over delayed, perfect ones. In a landscape where AI capabilities evolve monthly, waiting for perfect security frameworks creates unacceptable risk exposure. Strand argues that security leaders must deliver iterative improvements quickly, leveraging the agile principle of continuous feedback. This approach allows organizations to stay two steps ahead of attackers without succumbing to the paralysis of perfectionism.

The Value of Institutional Knowledge

Finally, Strand identifies the capture of institutional knowledge as the primary long-term competitive advantage. Companies that successfully encode their unique workflows, decision-making processes, and data into AI agents will achieve enormous lock-in and operational power. This strategic focus shifts the value proposition from mere tool usage to the accumulation of proprietary, automated intelligence, positioning early adopters for sustained market leadership.

Key insights

  1. Traditional human-centric access control models are insufficient for AI agents, requiring a 100x increase in granular entitlements and strict segregation of duties to prevent toxic combinations of privileges.

    Security Architecture →

    Impact: Organizations must redesign identity management systems to handle non-human actors, preventing both malicious exploitation and benign operational errors.

  2. A layered "Swiss cheese" security model, combining base-layer controls, soft policies, and real-time detection, is more effective than relying on single-point solutions for AI risk mitigation.

    Risk Management →

    Impact: This holistic approach creates significant inertia against breaches, allowing companies to adopt bleeding-edge technologies without compromising security posture.

  3. Capturing and encoding institutional knowledge into AI agents creates a significant competitive moat, as this proprietary data is difficult for competitors to replicate or transfer.

    Competitive Strategy →

    Impact: Early adopters who systematize their workflows will achieve operational efficiencies and market lock-in that outpace competitors relying on generic tools.

  4. Deploying security measures at 80% effectiveness immediately is superior to delaying deployment for perfect solutions, as the rapid pace of AI evolution makes static perfect solutions obsolete quickly.

    Operational Agility →

    Impact: This iterative approach reduces risk exposure time and allows for continuous improvement based on real-world feedback, aligning security with agile development practices.

  5. Peer-to-peer knowledge exchange through cross-company hackathons and executive sponsorships is more effective than vendor marketing for validating the efficacy of new AI tools and workflows.

    Knowledge Management →

    Impact: Direct experience sharing helps organizations bypass marketing noise and adopt proven, efficient practices, accelerating their own AI maturity curve.

Action items

  • Audit and redesign AI agent identity management to enforce strict segregation of duties, ensuring no single agent holds conflicting privileges such as data processing and transaction execution.

    Impact: This mitigates the risk of prompt injection attacks and non-malicious errors by preventing toxic combinations of agent capabilities.

  • Implement a layered security architecture that combines device management, pipeline checks, and real-time AI-specific detection tools to create a holistic defense against emerging threats.

    Impact: This multi-layered approach ensures that gaps in one control layer are covered by others, providing robust protection while allowing for technological innovation.

  • Develop and deploy tailored security awareness training that focuses exclusively on the specific knowledge gaps and risks relevant to your organization's AI usage, avoiding generic compliance modules.

    Impact: Targeted training increases employee engagement and effectiveness, ensuring that staff are equipped to handle the specific nuances of their AI workflows.

  • Adopt an iterative security deployment strategy, releasing 80% effective solutions quickly and refining them based on real-world feedback rather than waiting for perfect, comprehensive frameworks.

    Impact: This approach reduces the window of vulnerability and allows the security team to adapt to rapidly changing AI capabilities and threat landscapes.

  • Establish cross-company peer exchange programs, such as hackathons or executive sponsorships, to validate AI tooling and workflows through direct experience rather than relying on vendor marketing.

    Impact: This facilitates the rapid adoption of proven best practices and helps organizations avoid costly mistakes by learning from the direct experiences of other industry leaders.

Quotes

“I consider guardrails to be that backstop. They are not immovable rules. Guardrails can't change. Otherwise, they wouldn't be guardrails, right?”
“You don't want to over-entitle an AI, so then you have to kind of 1,000x or 100x the amount of entitlements or roles that... you needed to have for humans.”
“I think that the companies that are learning how to collect institutional knowledge, they are probably the biggest winners.”