To reap the AI benefits, users must have confidence that the AI will behave as designed, and outcomes are safe, secure, and responsible manner. AI systems can be vulnerable to adversarial attacks, where malicious actors intentionally manipulate or deceive the AI system. The adoption of AI can introduce or exacerbate existing cybersecurity risks to enterprise systems. These can lead to risks such as data leakage or data breaches, or result in harmful, unfair, or otherwise undesired model outcomes. We have put together practical mitigation measures, practices and recommendations .

Securing AI Systems

Understanding the difference

A fundamental difference between AI and traditional software is that while traditional software relies on static rules and explicit programming, AI uses machine learning and neural networks to autonomously learn and make decisions without the need for detailed instructions for each task. As such, organizations should consider conducting risk assessments more frequently than for conventional systems, even if they generally base their risk assessment approach on existing governance and policies. These assessments should be supplemented by continuous monitoring and a strong feedback loop. 

We use four steps to tailor a systematic AI defense plan.

Conduct risk assessment, focusing on security risks to AI systems

We conduct a risk assessment, focusing on the security risks related to AI systems, either based on best practices or our client's existing Enterprise Risk Management Framework. 

Prioritize areas to address based on risk/impact/resources

Prioritize which risks to address, based on risk level, impact, and available resources. 

Identify and implement the relevant actions to secure the AI system

Identify relevant actions and control measures to secure the AI system and implement these across the AI life cycle. 

Evaluate residual risks for mitigation or acceptance

Evaluate the residual risk after implementing security measures for the AI system to inform decisions about accepting or addressing residual risks. 

Planning & Design

Organizations should understand the potential security risks posed by AI, in order to make informed decisions about adoption. 

  • We provide training and guidance on the security risks of AI to all personnel, including developers, system owners and senior leaders. 
  • We formulate the risk management strategies informed by security risk assessments, which help to determine key risks and priorities. 
  • We apply a holistic process to model threats and risks to an AI system, in accordance with relevant industry standards/best practices.  

AI Development

The AI supply chain includes training data, models, APIs, and software libraries. Each of these components may introduce new vulnerabilities that could enable attackers to extract and inject malicious software onto user machines. 

CyberActa can assess and monitor potential security risks of the AI system’s supply chain across its life cycle. 

  • Ensure that our clients' suppliers adhere to security policies and internationally recognized standards, or that risks are otherwise managed through Software Bills of Material "SBOM", code checking, or against vulnerability databases.
  • Identify, track and protect AI-related assets ensuring that sensitive data, models, prompts, logs, intellectual property and organizational assets are protected from threats and breaches. 
  • Bolster the AI environment to eliminate insecure development environment which can introduce risks of data breaches, and make AI models vulnerable to attacks.

AI Deployment

The AI supply chain includes training data, models, APIs, and software libraries. Each of these components may introduce new vulnerabilities that could enable attackers to extract and inject malicious software onto user machines. 

CyberActa can assess and monitor potential security risks of the AI system’s supply chain across its life cycle. 

  • Ensure that our clients' suppliers adhere to security policies and internationally recognized standards, or that risks are otherwise managed through Software Bills of Material "SBOM", code checking, or against vulnerability databases.
  • Identify, track and protect AI-related assets ensuring that sensitive data, models, prompts, logs, intellectual property and organizational assets are protected from threats and breaches. 
  • Bolster the AI environment to eliminate insecure development environment which can introduce risks of data breaches, and make AI models vulnerable to attacks.

AI Operations AND MAINTENANCE

The AI supply chain includes training data, models, APIs, and software libraries. Each of these components may introduce new vulnerabilities that could enable attackers to extract and inject malicious software onto user machines. 

CyberActa can assess and monitor potential security risks of the AI system’s supply chain across its life cycle. 

  • Ensure that our clients' suppliers adhere to security policies and internationally recognized standards, or that risks are otherwise managed through Software Bills of Material "SBOM", code checking, or against vulnerability databases.
  • Identify, track and protect AI-related assets ensuring that sensitive data, models, prompts, logs, intellectual property and organizational assets are protected from threats and breaches. 
  • Bolster the AI environment to eliminate insecure development environment which can introduce risks of data breaches, and make AI models vulnerable to attacks.

SaMD: Medical Software Insights

“Software as a Medical Device” (SaMD) has been defined as software intended to be used for one or more medical purposes that perform these purposes without being part of a hardware medical device.  

What is needed to create and launch an SaMD?

  1. An organizational structure that provides leadership, accountability, and governance with adequate resources to assure the safety, effectiveness, and performance of SaMD 
  2. A set of SaMD lifecycle support processes that are scalable for the size of the organization and are applied consistently across all realization and use processes; and
  3. A set of realization and use processes that are scalable for the type of SaMD and the size of the organization; and that takes into account important elements required for assuring the safety, effectiveness, and performance of SaMD

Be able to answer the following questions:

  1. Is there a valid clinical association between your SaMD output and your SaMD’s targeted clinical condition?  
  2.  Does your SaMD correctly process input data to generate accurate, reliable, and precise output data? 
  3. Does use of your SaMD’s accurate, reliable, and precise output data achieve your intended purpose in your target population in the context of clinical care?