Secure AI Networking
Key Highlights
-
Zero Trust is strengthened, not broken, by AI. The proposed framework reinforces “Assume Breach” and “Never Trust, Continually Verify” by independently verifying every actor—including AI agents—and every network transaction.
-
Ransomware-like or otherwise high-impact transactions can be quarantined pending human approval, combining automated security controls with human oversight rather than assuming AI can always be trusted.
-
While rogue/agentic AI and AI-generated software create new security challenges, AI is also accelerating vulnerability discovery, patching, and software defense. The framework therefore emphasizes continuous monitoring, third-party software verification, secure development practices, and ongoing identity validation.
Ransomware Prevention in the AI Age
Since writing this summer’s article on the state of AI, I spent much time looking at the impact of changes in AI, security and networking as it evolved in real time. An important question was, “Did these changes break Zero Trust Security Networking or the methodology in my “Assume Breach” article, written, unbelievably, just 18 months ago. The world has changed so much since then. I had to see if the challenges regarding AI identity and untrustworthy rogue models now prevented the interception of ransomware attacks. I was not confident!
However, as you will see by the end of this article, I came up with a new Zero Trust Framework that is not reliant on AI adhering to guardrails, where Identity can be verified, and where the premise is that threat actor ransomware attacks can be caught in a Zero Trust Framework. At the same time, that ransomware is rapidly increasing, but so is the astounding, exponential pace of AI detecting and fixing vulnerabilities in mainstream software, strengthening an organization’s defenses and business operations.
Escalation of high-impact actions to now require human approval is an important safety net.
A novel safety net adds human approval for high-risk transactions. Also, the realization that, just like cybersecurity, assuming that AI can be 100% secure is not an achievable goal. The original reason, the “why”: minimizing ransomware and other attacks, is now enhanced.
The reasons why breaches are best detected and removed in the network were covered in the Assume Breach article Cybyr.com/assumebreach. Here, the focus is on the “what” and “how” of the approach and calls out new relevant issues.
Figure 1 shows the Service Provider Zero Trust approach from a network transactional perspective since almost every breach traverses a network. Larger enterprises can also use the approach directly. The description and comments follow.
Examples of Subject and Target Actors who conduct transactions.
(1) Users communicating with a remote host, database or hosted application via user portal, agent software, data center or cloud application, etc.
(2) Software and applications of any kind, including the system software that controls this network system—easily the most common type of actor.
(3) An Agentic AI system, software or a device conducting automated functions. Increasingly, these are now proxies for user functions.
(4) Devices such as IoT devices, Medical Robots or critical infrastructure devices in OT networks. They could also be systems that act as a proxy for a non-intelligent device.
Transaction Endpoints
Where the Subject Actors begin the journey across the network and then finally exit at their destination. Function: the Transaction Endpoint must get permission from the Transaction Manager to begin a transaction. Nothing and no-one are trusted.
The Transaction Manager
Verify that the requested transaction is permitted by the Identity Manager and Authentication Software, and that the requested functions are within the approved Access Control policies for that actor, etc. It then completes the pairing by checking the permission of the Target Actor to conduct the transaction. The identity of Agentic AI Actors must be carefully verified.
A Critical new safety net approach requires human approval to allow all high-risk transactions (i.e., those typified by Ransomware attacks) to be quarantined pending human approval as a critical collaboration between humans and systems as inspired by the Spring article at cybyr.com/integration.
Once authorized, the Transaction Manager intercepts the transactions, calling upon integrated security functions designed to detect and remove threats, including examining the payloads. This includes detection of out-of-policy or altered requests, use of Extended Detection and Response Software and many more shown in Figure 1 and described in detail at cybyr.com/san.
When a transaction begins, the Transaction Manager adds it to the Monitoring Database.
Continuous Monitoring Functions
Notify the Transaction Manager when changes occur that may result in the transaction being blocked or quarantined. This includes functions being initiated by AI agent software. When a transaction is blocked or quarantined pending approval, a secure event notification is initiated. This is likely to be at an external Network Operations Center.
Continuous monitoring after authorization to detect agentic or out-of-policy shifts is essential.
New Rules of Operation
In all cases, software supplied by third parties must be verified and never trusted. This is a developing function as using the latest AI models to discover vulnerabilities and conduct real-time patching becomes the norm. It would be considered very high risk to use software created using AI vibe coding without checking the code the AI agent created.
Proper self-attestation and demonstrable use of security best practices —DevSecOps, SBOM, etc. External NOC systems should not use AI Agents that can initiate transactions.
Why I wrote This Article
Nothing here removes the need for an AI implementation plan or adherence to the organization’s Security Policy. In fact, this article and ongoing work on my site is intended as a framework for such plans or for writing RFPs.
Conclusions and Lessons Learned
- The Zero Trust principle: “Assume Breach” applied by service providers or enterprises with a strategic framework to intercept attacks is not just confirmed but is enhanced.
- The Zero Trust principle: “Never Trust, Continually Verify” becomes even more important.
- The use of AI to detect software vulnerabilities and the requirement for all software to conform to high standards and be automatically updated is taken to a new level.
- We do not assume that verifying an agent once is sufficient. Even if they adapt and transform and spawn new agents, their identity must still be constantly monitored and verified.
- The approach is scalable and can grow organically to verify and enforce the transaction independently of the actor.
- Verifying the identity of an actor must always be in the context of when, from where and the permissible actions plus what the target actor will allow.
- Continuous monitoring after authorization to detect agentic or out-of-policy shifts is essential.
- Escalation of high-impact actions to now require human approval is an important safety net.
- The approach does not attempt to provide a perfect solution but greatly strengthens an organization’s resilience, especially when applied with enhanced defensive strategies.
As usual, the journey is never complete. There’s much more detail with ongoing developments on my website, at cybyr.com/san. If you need help with your network plans or just have questions/comments, email me at [email protected].
Stay Connected with ISE Magazine
Subscribe to our newsletters and magazine for the latest telecom insights, explore the current issue for in-depth features and strategies, and register for upcoming webinars to learn directly from industry leaders.
About the Author
Mark FishburnMark Fishburn
Provider of Strategic Network, AI, Cybersecurity, Software, and Marketing Services
Mark is President of cybyr.com and has five decades of experience in software, networking, and security. He is a member of ONUG, Mplify, and CSA network and security working Groups, CISA contributor and publisher of the Holistic Cybersecurity book: Hey Who Left The Back Door Open? For more information, or to give feedback, email [email protected] or follow him on LinkedIn.

