{"id":23334,"date":"2026-04-30T09:00:00","date_gmt":"2026-04-30T16:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?p=23334"},"modified":"2026-06-10T16:29:57","modified_gmt":"2026-06-10T23:29:57","slug":"microsoft-ciso-advice-apply-engineering-fundamentals-to-securing-ai","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/insidetrack\/blog\/microsoft-ciso-advice-apply-engineering-fundamentals-to-securing-ai\/","title":{"rendered":"Microsoft CISO advice: Apply engineering fundamentals to securing AI"},"content":{"rendered":"\n

Agentic AI, like any software, is just one part of a business solution. It is not the only element that needs to be secured. Engineers need to approach securing agentic AI in the corporate IT ecosystem the same way they would consider any security problem\u2014from end to end.<\/p>\n\n\n\n

Yonatan Zunger, CVP and deputy CISO for Microsoft, suggests focusing exclusively on hardening a piece of software to security threats may make it difficult to use and introduce a new risk when users get frustrated and try to bypass controls. This is why engineers need to consider not just individual components but how they work together to maintain productivity.<\/p>\n\n\n\n

\u201cThink of every system as a socio-technical system containing many parts, and all of them working together in unison have to be secured,\u201d Zunger says.<\/p>\n\n\n\n

\n
\n
\"\"<\/figure>\n<\/div>\n\n\n\n
\n

Learn from our experience <\/strong><\/strong><\/p>\n\n\n\n

Read our practical advice about applying security fundamentals to AI.<\/a><\/p>\n<\/div>\n<\/div>\n\n\n\n

\n