Securing AI agents: Box CISO Heather Ceylan on the new enterprise risk playbook
Blog post from Box
AI agents are increasingly being integrated into enterprise operations, but their deployment comes with significant security challenges that outpace current protective measures. Bakhshi Malhotra from Box AI Security and Compliance and Heather Ceylan, Box's Chief Information Security Officer, emphasize the necessity of developing both deterministic and behavioral guardrails to mitigate risks like prompt injection and agent drift, where AI agents might deviate from intended actions due to overly permissive access. Unlike traditional assistant roles that merely provide answers, AI agents can autonomously trigger actions, leading to potentially severe consequences if misused. Organizations are urged to adopt a proactive security approach, focusing on risk-based governance and safe experimentation rather than hindering AI adoption. Box positions itself as a secure content layer that supports agent operations, advocating for a foundational approach to agent security instead of viewing it as an add-on. The conversation underscores the urgency of adapting security practices to keep pace with rapid AI advancements, while cautioning against the risks of shadow AI, where employees might deploy AI agents without IT or security oversight.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 12 | 5,657 | 1,451 | 270 | -3% |
| MCP | 5 | 7,755 | 814 | 203 | -3% |
| Harness engineering | 1 | 199 | 112 | 59 | +2% |
| Observability | 1 | 3,670 | 768 | 196 | -25% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.