I remember being at the beginning of this. My first job at Micrsoft was as a Security Architect teaching customers how to adopt the SDL, perform Threat Modeling, and implement security technologies like PKI. While the world, and corresponding threat landscape has evolved, best practice security development is still gounded in baking security in from the inception phase and continuing it through deployment and maintenance.
You absolutely cannot bolt security on as an afterthought when a pentest shows how many security vulnerabilities your newly released product has. They will be ineffectual when compared to baked-in security. I cannot express enough how security is not a feature you add on after you've built all your user stories. Every class, method, library, interface and web page has to be built from a zero trust standpoint.
The AI era is no different. AI systems are software systems at their core. All of the foundational security measure that must be built into software from the beginning apply to AI. AI just brings in more attack vectors fo us to consider and more defensive measure to consider.
As an AI Security specialist, I see organisations deploying prototypes into production to keep up with the industry. To move at that speed, the first thing they shed is security reviews and checks. Even basic things like securing your data stores against anonymous access, proper managed identities, and least privilage are overlooked in the rush to market.
I've always been of the opinion, If you don't have time to do it right the first time, what makes you think you have time to do it again? While it may cost you a bit more time to ensure you've applied as much due dilligance as required, you'll still be up and running while the groups that rushed to market are dealing with breaches, and public embarassment while they take down and rebuild their systems.
Twenty years ago, we launched the secure development lifecycle, and now we're evolving it for the new age of AI. Tune in as Charlie Bell reveals our three-fold plan for the Secure Future Initiative. Details here: https://msft.it/6040iL8Ok #SecureByDesign #GenerativeAI
Congratultions, Lenovo! ??