© WAVESTONE | 1
Picture 18
Lead the Shift
How CISOs must lead the AI transformation
Claire CARRÉ
Partner
Picture 4
Gérôme BILLOIS
Partner
DRAFT
Image 8
Image 13
© WAVESTONE | 2
Picture 73
ABOUT US
360° expertise
Covering the full spectrum of CSO & CISO
priorities for IT, OT and products.
Recognized by peers at
Black Hat, RSAC, DEFCON…
1000+ cyber consultants
700+ trained in AI security
150+ trained in AI engineering
11 countries
Global reach, local insight through
strong ties with communities and regulators
4000+ tier-1 clients
Trusted for 20+ years across
public and private sectors
Human-led, AI-accelerated
Combining human judgement, deep expertise and our own AI platforms to accelerate delivery and deepen analysis.
Independent & makers
An unbiased approach to ensure the best choice for you, drawing on our hands-on experience with leading solutions and in-house building capabilities
Wavestone, helping you lead cyber transformation in an AI-driven world
From strategy to
forward-deployed engineering
We ensure the successful delivery of all your transformation programs, bringing adoption and value at scale
Our technology vendors collaborations
Picture 24
Picture 29
Picture 31
In-house AI platforms: benchmark, secure by design, risk, pentesting, IAM, crisis
Cyber & AI Lab
Picture 3
Image 79
Image 81
Image 45
Image 89
Strategic Vision: Top 30 for 2030
Cyber & AI benchmarks
AI4Cyber
Modern Data Protection
Image 30
Image 27
Picture 2
IAM Maturity
Picture 2
Picture 2
Picture 2
© WAVESTONE | 3
Picture 73
02
Decoupled from LLMs
API calls to the client’s AI, or even a local model depending on the context
01
Decoupled from infrastructure
Autonomous agents that do not depend on any client stack using standalone HTML pages
Homemade AI agents to accelerate and add value to our engagements
ABOUT US
That can be used in all environments, ours and yours!
One API key per engagement, tied to a predefined budget
03
Governed by usage
Image 45
Image 49
Image 44
Image 46
Image 48
CrisisMaker
Crisis exercise stimuli creation studio
Booster RM
Risk analysis accelerator
Web Recon Accelerator
Deterministic assistant for pentesters
Auto Cyber Benchmark
Interview and analysis insight amplifier
Image 47
Picture 1052
Picture 1056
Image 18
IdentiVEX
Role mining advisor
Image 41
Image 40
Smart Identity Analyzer
IAM data quality improver
Cyber-By-Design Agent
Architecture review and improvement accelerator
© WAVESTONE | 4
Image 4
Image 57 Image 3
Image 35
Image 13 Image 15
Image 19
Image 25 Image 43 Image 47
Image 51
Image 53
Image 75 Image 77
Image 91
Image 73
Image 71
Image 27 Image 1
AI has changed the game…
And the need to navigate its challenges has never been stronger
Image 5
© WAVESTONE | 5
Image 2 Image 16
How do you embrace the full potential of AI
and lead the shift?
© WAVESTONE | 6
Image 2 Image 14
Three shifts have emerged on a single timeline…
2023
2025
2026
2030…
…requiring a common orientation to win the AI race
CYBER AGAINST AI
>
Reset the defensive baseline
CYBER FOR AI
>
Secure the ecosystem
CYBER WITH AI
>
Defend at machine speed
© WAVESTONE | 7
Image 17 Image 19
01
CYBER
FOR AI
Secure the ecosystem
Image 9
› From protecting models to controlling platforms, agents and actions
© WAVESTONE | 8
72%
have built data privacy compliance into the AI development lifecycle
have identity and access management fit for AI agents
15%
AI IDENTITY
87.5%
generate logs in their AI applications
50%
run dedicated AI security testing (AI red team)
send those logs to the SOC for analysis and response
8%
implement security capabilities beyond native solutions
11%
AI PLATFORM SECURITY
2026 AI Cyber Benchmark
Breaking the agentic wall
72%
identify AI use during new procurement processes
88%
have adapted their risk management processes to AI and appointed a group-level AI security lead
know AI systems or components external to their platform
12%
cover agentic AI in their risk analyses
33%
AI DISCOVERY & RISK MANAGEMENT
31%
45%
+14 points of maturity in one year, but progress stops at agentic AI.
Three topics to break through:
© WAVESTONE | 9
1
Set up governance
Align IT and AI teams on one agent policy and owners
2
Invest in a discovery tool
Tooling that discovers agents and feeds the registry automatically
3
Track and authorize
Run discovery continuously and reconcile it with the registry
Break the wall 1/3
Find every agent and register it
Freeform: Shape 4
AI DISCOVERY & RISK MANAGEMENT
AI PLATFORM SECURITY
AI IDENTITY
Graphique 3
Enterprise
agentic
platform
SaaS app
SaaS app
SaaS app
Enterprise
agentic
platform
BYOA
BYOAI
Personal
AI
Citizen
AI
Organization
perimeter
Entreprise AI
› Review platforms & contracts
› Scan repos: AI keys, models & libraries
SaaS applications
› Identify AI apps via web gateway
› Use categories & risk scores
Citizen AI & BYOW AI
› Audit mail & file permissions
› Monitor direct AI API calls
› Detect local AI tools & MCP configs
› Review AI subscriptions & expenses
Graphique 43 Graphique 45 Graphique 47
Where to look
© WAVESTONE | 10
2026 AI Cyber Benchmark
Breaking the agentic wall
72%
have built data privacy compliance into the AI development lifecycle
have identity and access management fit for AI agents
15%
AI IDENTITY
87.5%
generate logs in their AI applications
50%
run dedicated AI security testing (AI red team)
send those logs to the SOC for analysis and response
8%
implement security capabilities beyond native solutions
11%
AI PLATFORM SECURITY
72%
identify AI use during new procurement processes
88%
have adapted their risk management processes to AI and appointed a group-level AI security lead
know AI systems or components external to their platform
12%
cover agentic AI in their risk analyses
33%
AI DISCOVERY & RISK MANAGEMENT
© WAVESTONE | 11
Break the wall 2/3
Secure the platforms agents run on
Freeform: Shape 4
AI DISCOVERY & RISK MANAGEMENT
AI PLATFORM SECURITY
AI IDENTITY
Graphique 3
What an AI security platform must cover
Example of an agentic AI architecture
Inputs & execution
Knowledge / RAG
Tools & external systems
LLMs / models
Orchestrator / Harness
Agents
skills, memory
User interface
Application frontend
End users / Systems
Build / runtime infrastructure
Monitoring & observability
3
Data & RAG security control agent retrieval
3
2
Model protection secure the AI supply chain
2
4
4
Sandboxing isolate code and tool execution
4
1
Guardrails filter prompts and outputs
1
5
Posture management find exposed AI services
5
6
Detection & response send AI logs to the SOC
6
Graphique 36
Evaluate your platforms
Map the security functions of your current platforms and usage
Select an AI Security platform
Linked to an AI GW so every AI flow goes through it
Test its strength (AI red teaming)
From the dev environment to internet-facing functions
Image 9125
Graphique 44
Graphique 47
© WAVESTONE | 12
2026 AI Cyber Benchmark
Breaking the agentic wall
72%
have built data privacy compliance into the AI development lifecycle
have identity and access management fit for AI agents
15%
AI IDENTITY
87.5%
generate logs in their AI applications
50%
run dedicated AI security testing (AI red team)
send those logs to the SOC for analysis and response
8%
implement security capabilities beyond native solutions
11%
AI PLATFORM SECURITY
72%
identify AI use during new procurement processes
88%
have adapted their risk management processes to AI and appointed a group-level AI security lead
know AI systems or components external to their platform
12%
cover agentic AI in their risk analyses
33%
AI DISCOVERY & RISK MANAGEMENT
© WAVESTONE | 13
Break the wall 3/3
Find every agent and register it
Freeform: Shape 4
AI DISCOVERY & RISK MANAGEMENT
AI PLATFORM SECURITY
AI IDENTITY
Graphique 3
Assess platform capabilities & design patterns
> Map what identity providers, agentic platforms, security gateways and xDR can enforce, then identify gaps and compensating tools
Define & promote identity guidelines
> Set minimum requirements for every agent: unique identity, human sponsor, delegation, least privilege, short-lived credentials and traceability
Run an enforcement POC
> Connect your solutions and test on real agent end to end: identity → human delegation → scoped access → runtime decision → action-level logging
Mature
DISCOVERY & REGISTRY
Emerging
DELEGATION
Emerging
AUTHORIZATION
Early
INTENT VALIDATION
Emerging
RUNTIME ENFORCEMENT
Mature
AUDIT & GOVERNANCE
AI/Agent Governance
AI/Agent ACCESS
AI/Agent PROTECT
What is its intent?
Allow this action now?
What did it do?
On behalf of whom?
What can it do?
Who is the agent?
© WAVESTONE | 14
Mastering Resilience
› Ability to switch/rebuild models
› Recover datasets/knowledge bases
› Validate integrity, ensuring confidence in AI decisions
Mastering Open-weight Models
› Assess model security pre-adoption
› Validate fine-tuning integrity
› Monitor modifications
› Secure the AI supply chain model security, governance and lifecycle management
Picture 57
Picture 57
Picture 57
Picture 57
Securing the AI ecosystem: the other emerging challenges to master
© WAVESTONE | 15
Discover more of our AI cyber Benchmark
Image 3 Image 5
Access the full presentation & contact our experts to know where you stand!
https://www.wavestone.com/en/
© WAVESTONE | 16
AI security benchmark: breaking the agentic wall
31%
45%
+14 points of maturity in one year, but progress stops at agentic AI. Three topics to break through:
72%
identify AI use during new procurement processes
12%
know AI systems or components external to their platform
88%
have adapted their risk management processes to AI and appointed a group-level AI security lead
33%
cover agentic AI in their risk analyses
87.5%
generate logs in their AI applications
8%
send those logs to the SOC for analysis and response
50%
run dedicated AI security testing (AI red team)
11%
implement security capabilities beyond native solutions
72%
have built data privacy compliance into the AI development lifecycle
15%
have identity and access management fit for AI agents
01
AI DISCOVERY & RISK MANAGEMENT
02
AI PLATFORM SECURITY
03
AI AGENTIC SECURITY
© WAVESTONE | 17
Image 0
Image 3
… and rolling out three actions to start now
Must DO
Helps
Will DO
Mature
DISCOVERY & REGISTRY
Emerging
DELEGATION
Emerging
AUTHORIZATION
Early
INTENT VALIDATION
Emerging
RUNTIME ENFORCEMENT
Mature
AUDIT & GOVERNANCE
AI/Agent Governance
AI/Agent ACCESS
AI/Agent PROTECT
Understand what to identify, and what can help you do it…
Assess platform capabilities & design patterns
> Map what identity providers, agentic platforms, security gateways and xDR can enforce, then identify gaps and compensating tools
Define & promote identity guidelines
> Set minimum requirements for every agent: unique identity, human sponsor, delegation, least privilege, short-lived credentials and traceability
Run an enforcement POC
> Connect your solutions and test on real agent end to end: identity → human delegation → scoped access → runtime decision → action-level logging
Master the Agentic Identities
Who, what, where, why and how!
What is its intent?
Allow this action now?
What did it do?
On behalf of whom?
What can it do?
Who is the agent?
01 AI DISCOVERY
02 AI PLATFORM SECURITY
03 AI AGENTIC SECURITY
Enlever lignes + màj la partie du dessous mettre comme en haut
© WAVESTONE | 18
Image 17 Image 19
01
CYBER
FOR AI
Secure the ecosystem
Image 9 Image 2
01
CYBER
FOR AI
Secure the ecosystem
02
CYBER
AGAINST AI
Reset the
defensive baseline
› AI does not make every threat new. It challenges the old defensive tempo
© WAVESTONE | 19
Picture 3
The threat has entered faster waters...
Defenders need to catch up !
And AI will be in the real world…
5x more efficient AI-powered phishing now compared to human-crafted attempts
AI-ENABLED SOCIAL ENGINEERING
Less than 30 minutes to deploy adaptive ransomware end-to-end testing dozens of attack paths in minutes
JADEPUFFER
10,000+ vulnerabilities autonomously discovered, chained and exploited in one month
MYTHOS
700 self-organizing agents executing a 5-phase covert attack, breaching 3 organizations
HUGGINGFACE / OPENAI
AI agent breached government files bypassing existing access controls
AUSTRALIAN GOVERNMENT / OPENAI
Image 30
Image 34
Image 35
Image 36
Image 71
Image 75
© WAVESTONE | 20
Picture 14
AI did not change the fundamentals…
Graphique 26
Zero trust remains the right model
Graphique 28
Proven security approach still apply
… it changed the speed
>
© WAVESTONE | 21
A new defensive baseline, with the authority to act without waiting for business approval
REDUCE
Keep obsolete critical assets below 5%
• Inventory infrastructure, installed software and application libraries
• Named owner and exit date for every exception
• Monthly backlog reduction reviewed at executive level
REBUILD
< 2 days to rebuild any critical system from a trusted baseline
• Hardened golden images
• Infrastructure and configuration as code
• Quarterly real-life rebuild test
REMEDIATE
< 24h to patch or keep protected any exploited exposed asset
• Exposure-first remediation queue
• 24/7 Cyber, IT and application-owner task force
• Three predefined options: patch, virtual patch or isolate
CONTAIN
< 3h to contain a critical exposure without business validation
• Pre-approved isolation scenarios
• Cyber emergency authority
• Network and application kill-switches tested quarterly
DETECT
< 24h to detect and assign every new Internet-facing asset
• Continuous external attack-surface scanning
• Automatic reconciliation with CMDB
• Owner and criticality assigned within 24h
Technical projects to speed things up, but only
with IT and cyber governance, and the budget to sustain efforts
© WAVESTONE | 22
&
Sea Frame Right
LAYER
TYPICAL CONTROLS
Edge / Internet
◯
WAF, CDN, Reverse Proxy, API Gateway
Network
◌
Firewall rules, IPS, NDR, micro-segmentation
Endpoint / Workload
❄
EDR, XDR, application control
Runtime /
Application
✦
RASP, feature flags, configuration changes
Cloud / Containers
☁
Network Policies, CNAPP, Admission Controllers, Service Mesh
Virtualization
▦
VM isolation, NSX policies, hypervisor controls
Identity & Access
✦
Conditional Access, PAM, MFA enforcement, privilege restrictions
Detection &
Response
◉
SIEM, SOAR, threat hunting, automated containment
Identify the tools that will allow you to do it
VIRTUAL PATCHING CONTROL STACK
Picture 14
Image 41
Identify the patching that needs to be done
ASSESS THE VULNERABILITY RISK
Picture 57
Using Vulnerability Operations to ensure patching
Picture 57
Deep Dive
© WAVESTONE | 23
40%
5%
TRYING to keep up
Create remediation task forces
› Regain control of the obsolescence program: decommission unsupported / legacy software versions and close all MFA gaps
› Rework patch industrialization to meet SLAs on internet-facing systems
› Clear the backlogs: close critical exploitable gaps and re-assess underperforming tools (e.g., CMDB/EDR refresh)
Building the new base
Run a transformation program
› Agentify and automate cyber operations
› Rethink platforms and processes, including patch management practices
› Deploy new tools, refresh legacy ones, and introduce deceptive security
Ready to accelerate
Industrialize actions
› Operate cyber as a modern IT function: infrastructure as code, CI/CD, SDLC
› Operate a transformed RUN
› Look for AI accelerators
Identified actions require organizations to move at AI speed…
Three tempos in the race to accelerate
Investment is heavy, but market visions are still very uneven…
20%
© WAVESTONE | 24
Image 9 Image 2
01
CYBER
FOR AI
Secure the ecosystem
02
CYBER
AGAINST AI
Reset the
defensive baseline
Image 3
01
CYBER
FOR AI
Secure the ecosystem
02
CYBER
AGAINST AI
Reset the
defensive baseline
03
CYBER
WITH AI
Defend at machine speed
© WAVESTONE | 25
Image 0
Level 1 | AI Acculturation: the TOP10
Human does, AI assists
AI ≈ 20%
Human ≈ 80%
Use cases land in every CISO team.
Mostly built locally, they help teams perform existing tasks faster and better, while quickly proving value
CISO Chief Information Security Officer
RESILIENCE
Cyber Crisis Stimuli Generation
Graphique 1224
Hugo
IAM
Role mining reviews
Application onboarding analyzer
Graphique 1207
ROI: 50-80% time saved
Relancer Nicolas
SEC BY DESIGN
Secure-by-Design architecture reviewer
Risk Analysis
ROI : 30% time saved
Graphique 1201 Graphique 1203
?
GRC
TPRM
questionnaire review
Awareness
Video and text generation
Graphique 1205
?
?
INFRA SEC
Firewall rules review
Graphique 1209
?
DEFENSE
Automated SOC L1 Alert Triage
ROI: 6 → 1 FTE + agents
Graphique 1223
Redteam acceleration & report
ROI : ≈5h saved/pentest
© WAVESTONE | 26
Image 3
Existing or already identified use cases
Wavestone use case catalog + market feedback
Graphique 930 Graphique 932
FIRST IMPLEMENTATION
TO VALIDATE THE CONCEPT
Build first demonstrators
Prompting and no-code, ROI measured from day one
Graphique 938
IDEATION PHASE
CHALLENGE VALUE & REALISM
Assess realism immediately
Workshops with an AI maker: value × complexity
Graphique 940
ROADMAP
MAKE OR BUY, MAKE-TO-BUY, AND CHANGE
Scale to full application
Build or buy, with training and change management
Graphique 936
Picture 57
Picture 57
Deep Dive
Identify two drivers
New value-adding activities, or pain-point fixes
Graphique 934
How to identify the right use cases?
A 3 MONTHS ENGAGEMENT
© WAVESTONE | 27
Image 0
Level 2 | Platform renewal, one step at a time
Human-agent teams
AI ≈ 50%
Human ≈ 50%
IGA / PAM
IGA, PAM, machine & agent identities, access governance
Business Continuity
Dependencies, impact analysis, recovery orchestration
Data security
DLP, DSPM, classification, data risk
US Insurance
AI-native GRC
Continuous controls, compliance, TPRM and vendor risk
UK Bank
AI SOC
Detect, investigation, response, threat hunting
AI pentest
Continuous exposure discovery, validation & remediation
Global Manuf.
Global Insurance
CISO Chief Information Security Officer
IAM
Graphique 1207
RESILIENCE
Graphique 1224
INFRA SEC
Graphique 1209
GRC
Graphique 1205
DEFENSE
Graphique 1223
SEC BY DESIGN
Graphique 1201 Graphique 1203
App security
App security posture management, code & pipeline security
EU manufacturing
Data & AI Office
AI adoption accelerates as platform renewal unlocks cyber ROI at scale. Integrated platforms enable automated context sharing, faster insights, consistent policies and cross-function action
Scaling AI across cyber requires a common approach: Create a Cyber Data & AI Office
© WAVESTONE | 28
Picture 3
Image 7
AI-FIRST CISO OPERATING MODEL
Automotive experience
21-month program
€3.6M investment
10 FTEs mobilized
40 AI workflows targeted by end-2026
50 AI agents deployed in the SOC
XX tools consolidated
How?
Embed AI by design > Unify platform > Upskill teams > Align staffing, ownership & partners
Picture 57
Picture 57
Deep Dive
LEVEL 2 | PLATFORM RENEWAL
Two approaches, one objective
ENTERPRISE DATA PROTECTION AT SCALE
Insurance experience
XX-year program
$XXX investment
1,500 applications
65,000 collaboration sites
50,000 files shared
40 PB of data
How?
Unify governance, processes & technology > Strengthen data visibility & control > Remediate risk at scale
© WAVESTONE | 29
Picture 3
Level 3 | Cyber at machine speed
Human-led, agent-operated
APIs
AGENTIC AI PLATFORM
Cyber Agents
…
Access rights / DLP
Patching & Config.
EDR / NDR / FW
MCP & APIs
Cyber Data
Lake
Graphic 11 Graphic 12
Graphic 13
Graphic 20 Graphic 12
Graphic 13
SOC / EDR
CTI / Vuln.
Assets / Configs
GRC / TPRM / Risks
…
1
Use the big to create your CYBER DATA LAKE
› Turn fragmented, slow-moving cyber data into real-time context
› Collect, enrich, and normalize data through APIs
2
Use AGENTIC AI PLATFORM
› Built on existing processes and control models
› Delegate actions with the appropriate level of human oversight
DEFENSIVE
React to incidents, team by team
PROACTIVE
Anticipate drift in real time, act across teams
To operate at machine speed, cyber needs a unified data foundation for agentic operations
© WAVESTONE | 30
Cyber graph (OT / IT) | Data lake + graph · OT stays human-in-the-loop
Level 2 | Platform renewal, one step at a time
Human-agent teams
AI ≈ 50%
Human ≈ 50%
Currently a big changes are occurring, one platform at a time within our client. Large platforms allow automatic bridges such as automated context sharing, faster insights, consistent policies, cross-functional actions. Here are some ideas and examples of platforms that we have developed …
GRC
SEC BY DESIGN
INFRA SEC
IAM
CYBER DEFENSE
RESILIENCE
Graphique 1360 Graphique 1361 Graphique 1362 Graphique 1363 Graphique 1365 Graphique 1367 Graphique 1369
CISO Chief Information Security Officer
High value cyber //
Data & AI Office
Trust & TokenOps
Good version
Continuous Build : continuous pour adapter les agents et les données
Run : experts in the loop
Check : vérification indépendante de la confiance, de l’efficacité et des couts
CONTROL COST OVER TIME
Keep the platform sustainable as usage scales
Graphique 654
PRESERVE TRUST
Keep humans accountable for delegated actions
Graphique 652
OBSERVE PERFORMANCE
Know what agents do and how well they perform
Graphique 650
› Quality and evaluation
› Reliability and observability
› Decision traceability
› Human oversight
› Ownership and accountability
› Cost management
› Maintenance lifecycle
› Change and model governance
IN THE WORKS
© WAVESTONE | 31
Image 0
AI ≈ 80%
Human ≈ 20%
Graphique 15
SET DECISION RIGHTS
Risk appetite set by the business, escalation thresholds
Graphique 18
GOVERN AGENTS
Identity, rights, traceability and audit of every agent
Graphique 21
EMBED EXPERTS
Cyber experts inside business, IT and OT teams
Graphique 1201 Graphique 1203 Graphique 1205 Graphique 1207 Graphique 1209 Graphique 1223 Graphique 1224
GRC agent
Sec-by-design agent
Infra sec agent
IAM agent
Cyber defense agent
Resilience agent
Level 3 | Cyber at machine speed
Human-led, agent-operated
Switch from a defensive to a proactive security position, in real time, using the following golden rules & cyber graph
Cyber graph (OT / IT) | Data lake + graph · OT stays human-in-the-loop
Assets
Identities
Vulnerability
Controls
Third parties
Data
Business processes
DEFENSIVE
React to incidents, team by team
PROACTIVE
Anticipate drift in real time, act across teams
IN THE WORKS
© WAVESTONE | 32
Picture 3
Start focused, demonstrate the shift, then EXPAND
A focused transformation ambition
A transversal team with authority to act
A lighthouse transformation that creates momentum
SET THE AMBITION | Choose where AI should genuinely transform the model
› Identify the workflows where speed or outcomes must change radically
› Define the target level of transformation
› Align Cyber, IT and business leadership on the ambition
Graphique 12
BUILD A LIGHTHOUSE | Use one workflow to demonstrate the new model
› Select an end-to-end workflow with visible operational value
› Redesign the workflow, rather than automating isolated tasks
› Use the first results to prepare the next transformations
Image 24
REORGANIZE THE FLEET | Break silos to scale the transformation
› Bring together Cyber, IT, Data, AI and operational teams
› Establish clear ownership with one executive sponsor and one transformation lead
› Give the transformation team clear decision rights and authority to act
› Redesign roles and responsibilities as AI reshapes how work gets done
Graphique 23 Graphique 25
Bet on your teams !
Empower the crew to navigate the transformation
IN THE WORKS
© WAVESTONE | 33
Image 9 Image 1
01
CYBER
FOR AI
Secure the ecosystem
02
CYBER
AGAINST AI
Reset the
defensive baseline
03
CYBER
WITH AI
Defend at machine speed
> Go beyond technical changes
Transform your organization
© WAVESTONE | 34
Image 11
02
CYBER
AGAINST AI
Reset the
defensive baseline
01
CYBER
FOR AI
Secure the ecosystem
Image 55
03
CYBER
WITH AI
Defend at machine speed
02
CYBER
AGAINST AI
Reset the
defensive baseline
01
CYBER
FOR AI
Secure the ecosystem
Go beyond technical changes
Transform your organization
@pauline
© WAVESTONE | 35
Image 1
Lead the human shift: cyber teams that secure AI and use it
Two goals for every CISO team: secure the company's AI, and put AI to work inside cyber
01
Managing change
• Show the way: leaders use AI in their own daily work first
• Say early which tasks move to agents and which roles grow
02
Training
• AI security basics for every cyber role: prompt injection, agents, data leaks
• Hands-on labs: build and red-team an agent in a sandbox
03
New org chart
• New roles: AI security architect, agent identity owner, AI red teamer
• Rebuild junior paths as L1 tasks shift to agents
04
New accountability
• A named human owner for every agent and its actions
• Shared AI risk with IT, data and business teams (RACI)
Graphic 337 Graphic 338 Graphic 339 Graphic 340
A new team:
Cyber Data & AI Office
/ With your own data scientists and AI engineers
/ Build and maintain the Cyber Data Lake & AI agents
/ Upskill and empower all cyber teams through AI literacy
Reprendre commentaires de GBI lors de la présentation
@pauline
© WAVESTONE | 36
Image 11
Image 2
QR Code
CYBER AGAINST AI
>
CYBER FOR AI
>
> Dicover an dmange your agents
> Protect your AI platform
> Manage Agent identity
> Secure emerging risks : resilience & open weight=
CYBER WITH AI
>
How do you lead the shift to AI?
BET ON YOUR TEAMS: Empower them to lead the shift
> Upskill teams, give them ownership and break silos to scale
> Enforce the new cyber baseline 24 / 48 / 72
> Take the ownership of defensive actions
> Accelerate cyber teams
> Renew major platfomrs
> Build your cyber graph to go at machine speed
© WAVESTONE | 37
Wavestone logo Wavestone logo