Enterprise Security Weekly (Audio)

Mitigating attacks against AI-enabled Apps, Replacing the CIA triad, Enterprise News - David Brauchler - ESW #429

10 snips
Oct 20, 2025
In this insightful discussion, David Brauchler, Technical Director at NCC Group and an expert in AI security, shares his expertise on protecting AI applications. He reveals the futility of eliminating prompt injection vulnerabilities and offers architectural solutions to mitigate risks. David discusses the need for trust modeling in AI interactions, the limitations of traditional defenses like firewalls, and proposes an updated security model to replace the CIA triad. He emphasizes designing with secure AI frameworks to manage the evolving threat landscape effectively.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Assume Prompt Injection Is Inevitable

  • Prompt injection is inevitable and must be treated as a design assumption when building AI-enabled apps.
  • Architect systems so exposed models lose privileged capabilities when fed untrusted data.
ADVICE

Protect Assets, Not Just Inputs

  • Model your defenses around preventing access to critical assets rather than trying to perfectly detect prompt injection.
  • Prioritize architectural controls that limit what an exploited model can do over input-only filtering.
INSIGHT

Agents Aren't Autonomous Users

  • Treat agents as dependent systems, not autonomous users that self-regulate access.
  • Preserve deterministic backend access controls rather than trusting agents to enforce permissions.
Get the Snipd Podcast app to discover more snips from this episode
Get the app