Opens in a new tab
vmblog logo 2024 wht (updated)

Cavelo 2025 Predictions: AI Governance a Top Priority for CISOs

Share: 

David Marshall | Published: January 7, 2025

vmblog-predictions-2025 

Industry executives and experts share their predictions for 2025.  Read them in this 17th annual VMblog.com series exclusive.

By James
Mignacca
, CEO at Cavelo

The
evolution of AI will dominate next year. While AI technology and its use cases
are still relatively new, we’ll see a transition where AI is increasingly used
to solve real-world problems. Instead of organizations developing their own AI
engines, most will lease AI services from providers like OpenAI, Google, or
Amazon, focusing on applying AI to specific problems.

We’ll
also see AI regulations starting to take shape. These will build on existing
frameworks, addressing discoverability of AI applications across organizations,
updating acceptable use policies, and incorporating AI vendor management into
due diligence checklists. Cyber insurance providers will also begin asking more
targeted questions around AI usage.

AI
adoption is driven by its potential to reshape industries and solve complex
problems. However, as AI becomes more prevalent, malicious uses will also rise.
For instance, unregulated versions of AI tools may enable more sophisticated
social engineering or malware tailored for specific targets. This highlights
the dual challenge of harnessing AI’s potential while mitigating its risks.

CISOs
should prioritize:

  • Developing policies
    and frameworks for AI adoption and governance.
  • Conducting due
    diligence on third-party AI vendors to ensure compliance and reduce risk.
  • Preparing for
    AI-driven threats by adapting threat models to include AI-based social
    engineering and malware risks.
  • Leveraging
    consolidated data from their tech stacks to gain actionable insights and
    strengthen defenses against AI-enabled attacks.
##
 
ABOUT THE AUTHOR
 
James Mignacca 
 
James is a serial entrepreneur and life-long technology enthusiast with more than 20 years? experience in the cybersecurity industry. He?s a champion of data protection and data privacy, and supports businesses as they navigate digital transformation, cybersecurity and regulatory compliance requirements.