Guardians of the Enterprise — Insights from leading cyber experts.

Listen Now →

Why betting your security stack on one AI model is a business continuity risk

As frontier AI models from the US and China approach parity, enterprises face a new strategic question: what happens when your entire security architecture depends on a single provider?

Ashish Tandon, Founder and CEO, Indusface

In this conversation with CISO Forum, Ashish Tandon, Founder & CEO of Indusface, argues that model diversification isn’t just about cost or performance, it’s about resilience. From comparing outputs across models to catch missed vulnerabilities, to the risks of unmonitored AI-to-system connections, he unpacks why the real vulnerability often lies not in the model itself, but in the sprawling web of APIs, agents, and integrations around it, and why remediation speed, not detection, is the next battleground.

China has always been catching up. But one has to understand the structure. These are all very large language models, which need a lot of investment, a lot of hardware, and a lot of capability to build.

Both the U.S. and now China are clearly demonstrating that they can create these frontier models, and they are extremely capable. From an industry or business perspective, I’m pretty excited that one has options now, especially given the geopolitical situation. It is important to have options.

It’s a very positive thing that we have equivalent options for businesses to leverage and take advantage of. Am I surprised? I don’t think so. Everyone is working on it, everyone realises the power and the value of this capability, and it’s going to catch up and keep getting better, bigger, faster, and more efficient as we go forward.

The way to look at it is that when you do business, you need the business to be resilient. When I say resilient, you don’t have a single point of failure. We’ve all heard about business continuity and those aspects.

Having comparable models available is great from a business perspective, because you’d generally want multiple options so that if there is any challenge, for example, a model becomes unavailable, or a government decides that model shouldn’t be available to anyone in the world, you aren’t stuck having built your entire business on one option with no alternative.

So I feel this is a good thing: we have multiple options. It improves resilience, it ensures business continuity. From a competitive perspective, the creators of a model will have a harder time commanding a higher price, but from a consumer and business perspective, that’s great news.

We leverage models ourselves, so it’s good for us to have options too. We don’t have a single point of failure because we don’t depend on any one model.

Exactly what I mentioned. If you depend only on one model, and that model becomes unavailable to you within 90 minutes, think about where your security architecture, and the entire plan built on it, stands.

Reliance on a single model, or really reliance on any single anything critical, in this day and age, means you need an option. My strong recommendation is that you have multiple options.

It depends from business to business, but the most important thing from a security officer’s mindset is to use this to compare results across models.

These days, you find differences between models in terms of vulnerabilities. When we tested three different models, each one came up with unique vulnerabilities that differed from the others.

That gives a security officer more information and more attack-surface coverage, because he’s always thinking about how to make sure he’s found enough and covered the attack surface properly. Having multiple models helps with that.

How you integrate it depends on how the business works. For anything we test or use to detect vulnerabilities, we generally leverage two models. First, we compare them to make sure we haven’t missed anything, then integrate both findings into a single system where we review the outcome and take action. Security officers would follow a similar strategy.

The models are working at machine speed. With GLM-5 and models like it, they’re clearly demonstrating that they can detect vulnerabilities at machine speed, and what took days or months is now done in a few hours.

There’s no doubt vulnerabilities exist, and these are often critical business-logic vulnerabilities a hacker can exploit. There’s no debate that discovery of weaknesses in systems is moving at machine speed.

What’s really required is this: how do businesses first accept that vulnerabilities are being exposed at machine speed, identify them, and then protect against them at that same speed?

On our platform, as soon as we detect a vulnerability, we build autonomous virtual patching that humans verify, helping customers virtually patch those vulnerabilities at similar speed and in a similar motion.

The answer now lies in how fast you can remediate. Detection at machine speed is a foregone conclusion. Every CISO, every security officer, is thinking about how to build a protection mechanism that also runs at machine speed.

One has to realise that a model doesn’t work in isolation. It connects to an MCP server, it talks to an API, it talks to your application, it talks to your database. It has a lot of connections to come up with an outcome.

The challenge is that the agents or the model, the machine itself, is talking to all these systems and taking action. Every point, every agent, every aspect of AI that talks to various systems must be monitored, the right kind of access must be ensured, everything must be tested, data leakage and DLP mechanisms must be in place, and humans must verify the outcome with an audit trail.

You have to put in place a system that accounts for what humans used to do, now that agents and machines do it at machine speed. How do you ensure compliance and regulatory mechanisms are in place so every agent action is monitored and audited, and isn’t doing something it isn’t supposed to? At the end of the day, the business owner is responsible for the outcome that comes out of the system.

The model itself isn’t the risk. The risk is whether it works across the system, and whether the outcome is audited, consistent, and monitored. Putting a compliance mechanism around each of these connections, and monitoring everything, is critical. That’s the weakest link in the architecture, not the model itself.

It’s the same philosophy. It’s great that we have open-source models. Open-source or regional models help mitigate risk. You might focus on a smaller, open-source model that fits your de-risking criteria, where you can leverage multiple models and make sure your business isn’t dependent on just one.

It’s a very good aspect. Enterprises should embrace them and use each one depending on what fits. More options is a very positive thing, and I’m glad it’s moving so quickly.

Have clarity before you zero in on an enterprise contract. Once you clearly understand and identify your needs, you can start looking at enterprise contracting. But most organizations are still in the phase of figuring out what the models are, what the strategy should be, what’s best for business continuity, and how to put an option in place.

I’d lean toward enterprises still moving and evaluating that aspect before finalising a contract. The global narrative shows most people are using and trying these models out, so enterprise contracts are still a little way off.

Everybody has realised there’s genuine power in AI, and everyone wants to leverage those capabilities. But a lot of companies, including us, have started realising that a model becomes richer and better with the data you feed it, the prompts you give it, and the quality of that data.

Everybody assumes everything gets fed into a global model and becomes available to everyone. So the question for a business or a cybersecurity product company is: how do you keep delivering the capabilities you’ve built over the years to your customers?

We’ve started deploying models within our own data centres, using our own data to train them and provide value to our customers. We have years of data specific to our security capabilities, vulnerabilities, and attack vectors. How do we use that, feed it back, improve our model with it, and keep it as our own IP while still leveraging it?

That’s where most businesses will start moving: how to avoid commoditising the model while retaining your own IP and leveraging it more. I see that shift starting, especially among technology companies like us.

You won’t exist if you don’t wake up today. AI is real, it’s here, and it has phenomenal benefits. It also comes with challenges, but the benefits far outweigh them.

If you’re not going to join the bandwagon quickly, you might not be part of it. In my view, AI will remain relevant, and you’ll stay ahead of the curve if you adopt it quickly. Those that don’t will face serious, even existential, challenges.

Read More…

Indusface
Indusface

Indusface secures the web, API, and AI applications of thousands of organizations across 95 countries. Backed by leading institutional investors, Indusface is recognized by Gartner, Forrester, and IDC for its innovation in application security and meets globally accepted security and compliance standards, including ISO 27001, SOC 2, PCI DSS, and GDPR. Its globally distributed cloud infrastructure spans Asia, the Middle East, Europe, and North America, enabling low-latency protection and regional data residency for enterprises worldwide.

APPTRANA WAAP

Web apps, APIs, and AI systems. Protected from day one. Autonomously.

OWASP Top 10 protection from day one. Zero false positives, guaranteed. Vulnerabilities discovered and patched at the edge. Experts verify enforcement before policies go live. 24x7 managed services included.

✓ Gartner Customers' Choice 4 years running 100% customer recommendation rate

No credit card required