What 90 days and a small budget can buy in AI agent security
Organizations deploying open-weight AI models internally often underestimate total costs, including GPU infrastructure, licensing, and staffing requirements, while security hardening and incident response become the buyer's responsibility. A Versa Field CISO discusses red-teaming approaches for AI agents, failure criteria, and five critical questions organizations should evaluate when selecting agent platforms, particularly relevant for resource-constrained teams with limited time and budget.
The Trump administration has issued a ban on acquiring foreign-made equipment and components used for power generation and electricity management, citing concerns that adversaries are deliberately creating and exploiting vulnerabilities in these systems. The move reflects growing national security concerns about potential cyber backdoors in critical infrastructure that could be leveraged by foreign actors to disrupt energy systems.
Over 100 companies including OpenAI, Anthropic, Google, and Microsoft are calling for a coordinated global effort to strengthen AI-powered cyber defenses, warning that there is a limited "defenders' window" before threat actors develop more sophisticated AI-enabled attacks. The coalition emphasizes the urgency of advancing defensive capabilities now while the opportunity exists to outpace evolving threats.
As of March 31, 2025, all 51 previously optional "best practice" requirements in PCI DSS 4.0 are now mandatory and will be fully assessed in 2026 evaluations. A significant portion of the new assessment weight focuses on application-level controls under Requirements 6 and 11, including inventory management of custom applications and APIs along with continuous protection measures. Organizations must prepare for stricter compliance scrutiny on these application security requirements in upcoming PCI DSS assessments.
This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.