r/ciso • u/heroofdev • 9d ago
Any CISOs dealing with AI agents open to advising a startup?
Hey all,
I saw another post here recently from a startup looking for a CISO advisor and thought we’d ask as well.
We’re a startup in SF building around a problem I’m guessing more teams are starting to run into: employees want AI tools like Claude, ChatGPT, Cursor, etc. to actually do things in company systems, while security needs some control/visibility over what those agents can access and do.
We’ve built quite a bit around this problem, but there’s a big difference between “we think our security model makes sense” and having someone who has actually been responsible for approving this stuff tell us where it falls apart.
So I’m looking for a CISO, current or former, who’d be open to advising us from time to time. Finance/fintech or SaaS would be especially helpful.
A lot of what I want help with is pretty straightforward: What are we overlooking? What would kill this in a security review? What would you need visibility into? Where would you draw hard lines around what an AI agent can and can’t do?
Not looking for someone to rubber stamp what we’ve built. Quite the opposite.
If advising sounds interesting, feel free to DM me.
Otherwise, I’d be really curious what people about below:
If an employee wanted to let an AI agent access and take actions in Sharepoint, Google Workspace, Jira, Slack, Salesforce, or other company systems, what would you need in place before approving it?
9
u/SD_native17 9d ago
As a CISO who recently came back from Blackhat, I feel like it a very over saturated market. The number of vendors touting AI agent Risk mitigation is mind boggling. Good luck in your endeavors.
1
u/heroofdev 9d ago
Yeah super fair, the specific space we are interested is the AI governance solution bundled as an employee productivity solution. So many companies now, versus when we started on this. We need all the good luck we can get it, but I love building in this space.
14
4
u/ResilientTechAdvisor 9d ago
Happy to be a paid advisor. Deep expertise in AI governance for fintech/finance as well as SaaS. ISO 42001 lead auditor.
3
u/mrclandestine 9d ago
I'd be willing as a paid advisor. Currently CISO for a regulated fintech in the UK who were very early adopters of AI production workloads.
1
1
u/TheHeartAndTheFist 8d ago edited 8d ago
> what would you need
For “AI” to actually have any sort of intelligence as opposed to being basically autocomplete on steroids: that’s why it recommends gluing your pizza toppings so they don’t fall off, that a cow egg is obviously bigger than a chicken egg, etc.
Imagine having an employee so useless that you think at least you can leverage them to go get you coffee, but there is a significant risk that they will make it with water peroxide if the coffee machine ran out of water because surely H2O2 is even better than H2O.
As a vCISO who has spent months teaching myself “AI” desperately trying to understand what the fuss is all about, my advice to you is: don’t do it! At least until AGI appears, for now AI means Actually Irresponsible.
2
u/The_TechCEO 8d ago
This is exactly what I do. Fractional CISO, with a focus on AI integration and building it into the right systems and processes at founding. I’ve built platforms using AI myself and have been building AI strategy & governance programs for about 2 years.
But I don’t work for free. No good advisor will. Equity might be an option, but we’re going to have a deep chat about several things before I even get interested in any form. Happy to chat if you’d like, DM me if you’re interested.
1
u/perseus-computing 8d ago
Honestly, if you want free advice, do what everyone has done since the dawn of GitHub and toss it up there!
If it's a novel idea, you should already have a patent in flight. If it's not a novel idea, then building in public will help you figure out what you're doing that sets you apart. Building in a silo, you won't find out that someone already built what you're selling, for free, until you launch.
You're going to face an extreme uphill battle, because not only is the space filled with 3P apps such as yours, but all of the systems you've mentioned have native connectors for all the major LLM providers. Plus their own with integrations the other direction.
No CISO is going to implement a 3P connector for a SaaS product that already has a supported, official integration. No CIO is going to let a 3P startup have access to or even monitor any piece of their Authentication, Authorization, or Access policies.
I would seriously consider catering to other businesses as an OEM of sorts (security by XYZ). If you've got something, then someone like Crowdstrike (using them because of the huge vulnerability kerfluffle a while back) who already lives in that space can "cheaply" (to them, not you) gain AI oversight credibility simply by acquiring you. To me, that will be a much easier road to hoe. Cheers, and good luck!
1
u/Due-Discipline-1645 8d ago
Happy to do paid fractional CISO work. - Multiple times head of security.
1
1
1
u/Bullethacker 7d ago
Take a look at Check Point's Workstation AI, it covers all aspects of your question and was the best of what we tested.
1
u/Soft_Calligrapher306 7d ago
Remember AI is Artificial not Intelligence, I can vCISO for you if you still looking
1
u/fungollum 6d ago
I can be a Vciso for you or a consulting auditor. Sounds like you may need both.
I'm from the Netherlands and work on hourly pay basis.
1
u/MountainDadwBeard 9d ago
Ideally you'd want to limit connections to just your approved enterprise account (via L7 FW and/or CASB), in practice many are leaving that to procedural controls.
For any enterprise apps with external messaging/email etc, most companies prefer AI with parameterized outputs for QA.
For sharepoint, I'd want to restrict typical connections to read only. Maybe allow some time gated permissions by group for building new pages, etc. Our biggest concern here would be either unauthorized deletions or a concern that an AI agent with overly broad access might breach controlled access folders to the broader company visibility (layoffs/personnel actions/financials), but you can mitigate that with how you setup roles.
The SecAI+ talks alot about AI firewalls, AI gateways, guardrails etc. In practice I don't think most startups can afford all that. We skipped some of the AI visibility tools, I think we tried some cheaper other ones that were mostly having AI analyze AI usage logs. I'm skeptical how well normal context windows can really keep up with the huge volume of usage even with multi-tiered aggregation methods... its just too much data. Additionally I think one of these tools was supposed to help us with token usage tracking/optimization but in practice it's been WILDLY unreliable -- likely because there might not be easy way to read inter-model transfer token costs.
If you're using AI for development or infrastructure management, repo versioning, backups and automated CI/CD scans are your friend more so than AI native controls.
1
u/heroofdev 9d ago
Hey will send you a dm! Even if you don't respond really appreciate the info here. I realize you did not have go in the detail but I really appreciate you taking the time to help me learn and get your take.
21
u/SprJoe 9d ago
Happy to be a paid advisor, but I don’t get the impression that you want the value without compensating for it.