CODECAVE
olga team member 1.png

Olga Zakruzhnaya

Marketing specialist

Все статьи эксперта
Ещё по темам
Поделиться
Время чтения: 2 мин.

5 shifts in cybersecurity and AI adoption that every CISO should address now

Codecave team are users of Cloudflare and creators of a range of technologies to secure, optimize and speed up web applications. We recently attended Cloudflare Connect on Tour, where the focus was on the Agentic Web: a web increasingly shaped by AI agents, automated traffic, new attack surfaces and shifting expectations around digital trust.

Over the day, we heard from tech leaders discussing the same underlying challenge: how organizations can keep pace with a web that is becoming more automated, more intelligent and more exposed at the same time. The most important takeaway was clear: a business strategy, governance, and risk shift. The internet is changing fast, and the assumptions that once shaped digital strategy, security architecture and operational resilience are already becoming outdated.

Below are five themes that stand out, and what they mean for organizations trying to stay secure, resilient, and competitive.

1. AI adoption is no longer optional, but safe adoption is the real challenge

Pressure to adopt AI is now coming from boards, executives and customers alike. The message from the event was clear: most organizations are no longer asking whether to use AI, but how to use it without creating new risk. That shift matters, because every new AI capability can also become a new route for data exposure, misuse, or attack. One of the strongest ideas from the day was that organizations fall into different AI maturity profiles. Some are cautious and defensive. Others are experimenting with guardrails. A smaller group is already embedding AI into core operations and governance. According to McKinsey report: "the top 3 barriers to AI adoption are concerns about AI itself (46 percent); regulatory, ethical, or legal concerns (44 percent); and organizational challenges, including change management (39 percent)". What matters most now is visibility. One in six organizations have no clear C-level owner for AI-adoption. Organizations need to know which tools are being used, what data is entering them, and who is accountable for the decisions those tools make. Without that, AI adoption becomes shadow adoption — and wasted investment.

What organizations should do:

  • map all approved and unapproved AI tools in use;
  • set clear policies for what data can and cannot be shared with AI systems;
  • define governance for both human users and AI agents;
  • treat AI security as an operating model issue, not just an IT issue.

2. The threat landscape is being accelerated by automation

The cybersecurity picture is no longer defined only by traditional phishing, malware, or perimeter attacks. Adversaries are now using AI to move faster, scale wider, and target more precisely. At the same time, the growth of SaaS, cloud services, and connected tools has created a much larger and more fragmented attack surface. Typical companies use 1,400+ cloud services, but security teams know less than 30% of them. At Cloudflare Connect, they shared a real case: one compromised SaaS account infected 1,000+ connected systems — the attacker used AI to move lightning-fast. 85% of SaaS users have excessive permissions. Forgotten ex-employee accounts, open sharing settings, and no MFA for admins create perfect conditions for hackers. Insider threats have evolved to deep-fake profiles and fake employees. Companies undergoing AI transformation are especially vulnerable. Even Google hired fake employees with deepfake profiles. Now they're mass-producing LinkedIn bot accounts with fake reviews, using gaze correction filters and facial expression tweaks to look natural on video calls, faking GitHub activity streaks, plus all those old tricks: can't remember what they said five minutes ago, voice changes between calls, never turning on camera without excuses.
The lesson here is not simply that threats are more advanced. It is that the pace of attack has increased. Security teams must be able to detect, decide, and respond faster than before.

What organizations should do:

  • strengthen logging and monitoring across SaaS and cloud environments;
  • review identity controls and access pathways across all connected systems;
  • assume adversaries may be using AI to shorten dwell time and speed up lateral movement;
  • test incident responses for fast-moving, multi-system attacks.

3. Agentic AI is creating a new governance problem

If AI-assisted work is the first wave, AI agents are the next one. Unlike chatbots or copilots, agents can take action, call tools, access systems, and make decisions on behalf of users. That changes the governance model significantly. The rise of protocols such as MCP makes this even more important, because agents now have a standard way to connect to data and tools. That creates real opportunities for productivity and automation, but also new risks around access control, data leakage, and unintended behavior. In practical terms, organizations need to know not just whether they are using agents, but what those agents can do, what they can access, and how they are constrained.
The key point is simple: agentic workflows need the same discipline as human workflows, but with more control and more traceability.

What organizations should do:

  • inventory all AI agents and connected tool integrations;
  • apply least privilege and zero trust principles to agent access;
  • extend DLP and policy controls to prompts, responses and agent actions;
  • build audit trails for every action agents take.

4. Digital sovereignty is becoming a strategic issue

As regulation, geopolitical risk and data localization concerns increase, digital sovereignty has moved from a legal or compliance discussion into a strategic one. Organizations are no longer only asking where their data is stored. They are also asking who can process it, where workloads run, and how resilient operations remain across jurisdictions.

This matters because many sovereignty strategies focus too narrowly on residency while ignoring processing transit, and operational control. A truly resilient model needs to address all three. For enterprises with regional obligations or sensitive data, sovereignty is becoming part of architecture design rather than a standalone policy. The best approach is not to fragment systems unnecessarily, but to build control into the platform layer from the start.

What organizations should do:

  • map where data is stored, processed, and logged;
  • review vendor posture around jurisdiction, access and transparency;
  • assess continuity of risk across regions and legal environments;
  • treat sovereignty as part of resilience planning, not only compliance.

5. The internet economy is being rewritten by bots and AI agents

One of the most significant shifts discussed at the event was the changing economics of web traffic. Over 50% of global traffic is now bots. Some of these are bad and some are good. Nowadays, it is harder than ever to identify good from bad, but Cloudflare's technology allows clearer identification of bot traffic which can then allow, rate limit or block as applicable. The traditional model assumed that search engines and crawlers would index content and send users back in return. That bargain is weakening. AI systems increasingly consume content without always driving meaningful referral traffic back to the source. This creates a major issue for publishers, content owners, and digital businesses. If bots are consuming content at scale without attribution or value exchange, the economics of publishing, lead generation and content monetization begin to change. For many organizations, this is not a technical nuisance. It is a revenue and control issue. That is why bot management is no longer just about blocking bad traffic. It is about understanding who is accessing content, why they are accessing it, and what value your organization receives in return.

What organizations should do:

  • review crawler access policies and bot permissions;
  • measure the volume and source of automated traffic;
  • protect valuable content from unauthorized extraction and reuse;
  • explore commercial models for licensed or controlled access.

Final thought

The biggest takeaway for leaders is this: If you’re not seriously engaged in exploring Agentic Internet and cybersecurity in-house, you’re putting your organization at a competitive disadvantage. Codecave helps organizations turn Cloudflare’s platform capabilities into real business outcomes. As an experienced technology partner working at the intersection of cybersecurity, digital infrastructure, and AI adoption, we help teams translate complex platform features into clear, workable solutions that fit their environment, risk profile, and growth goals. Whether you are strengthening your zero-trust foundation, setting guardrails for AI adoption, improving visibility across SaaS and cloud environments, or preparing for the realities of the Agentic Internet, Codecave brings the technical depth and strategic perspective to help you move forward with confidence.

If any of the themes in this post reflect challenges your organization is facing, we’d be glad to continue the conversation. Get in touch with Codecave to explore how we can help.

We wish you a great mood!