Risk Requires Both Threats and Vulnerabilities

▶ Watch (3:14)

A pyramid needs at least three blocks. The bottom two are vulnerabilities and threats. If one is missing, there is no risk. Juroviesky said most AI breaches stem from OWASP issues — over-privileged accounts, security misconfigurations, and injection. He urged teams to prioritize based on practical exploitation, not James Bond scenarios. Track vulnerabilities in an Excel spreadsheet, but follow through. Verify fixes formally. Document every decision.

AI Blurs the Line Between Data and Code

▶ Watch (18:44)

SQL injection was discovered in 1997 and still appears in 15% of CVEs. Prompt injection is the same class of bug. AI muddies the boundary between parameters and executable code. Juroviesky highlighted MCP’s weak controls: authentication is optional, authorization is binary, and Atlassian’s MCP only allows an allowed-listed domain. He warned that users can sign up for personal Cursor accounts, OAuth into company Google Drive, and the AI inherits their full permissions. Data layer controls — who, what, where — are the first line of defense.

Communicate Risk in Business Terms

▶ Watch (33:10)

Executives see risk as lost revenue, not ransomware. Juroviesky told the audience to frame impact by asking how the business generates money. Use your financial planning team — they already know the cost of a three-day outage. Present exhaustive threat models alongside alternative solutions. When an executive says “just accept it,” reply: “I can’t accept it. You need to accept it.” Provide formal documentation for them to sign. AI risk is a living risk; vendors quietly roll out agentic features that may shift compute to US data centers, creating GDPR issues.

Track Risk as a Living Document

▶ Watch (46:25)

Juroviesky showed a risk tracking document that includes owner, mitigation, business logic, and a revisit date. Mitigations expire. He advised linking every data flow diagram, ticket, and conversation to the risk entry. Even eliminated risks stay on the document to prove past decisions. When an executive suddenly accepts a risk they rejected two years ago, point to the record and ask what changed. Prioritize based on actual exploitation likelihood, or you will drown in CVEs.

Notable Quotes

It’s impossible to build a pyramid with blocks with less than three blocks. Sean Juroviesky · ▶ Watch (5:20)

Prompt injection, or not prompt injection, SQL injection was discovered in 1997. Sean Juroviesky · ▶ Watch (19:41)

All you can do is say which AIs are allowed to interface with it via MCP. Sean Juroviesky · ▶ Watch (22:20)

I can’t accept it. You need to accept it. Here’s the formal documentation of you accepting this risk. Sean Juroviesky · ▶ Watch (43:38)

Key Takeaways

  • AI risks are old OWASP vulnerabilities with an abstraction layer.
  • Threat model with multiple focused data flow diagrams, not one sprawling map.
  • Frame AI impact in business revenue terms to get executive buy-in.
  • Track every risk as a living document with owner, mitigation, and revisit date.
  • Proactively partner with AI enthusiasts to build guardrails, not blockades.

About the Speaker(s)

Sean Juroviesky is a dedicated security and risk management expert with extensive experience navigating complex environments. Sean excels at developing a comprehensive understanding of intricate systems and crafting strategic roadmaps to revitalize security programs. By identifying high-risk areas and optimizing the use of existing resources, Sean removes barriers between teams to enhance communication and coordination, driving effective security outcomes. Beyond their professional pursuits, Sean finds joy in backpacking through the mountains with their adventurous Australian Shepherd, partner and twins, embracing the serenity of nature and the thrill of exploration.