
Illumio's Trevor Dearing explains why you need to maintain good cyber hygiene before implementing AI. This article was originally published on Insight Jam, the enterprise IT community that enables human conversation on AI.

In the race to deploy AI, the most important question is often overlooked: Is the infrastructure secure enough?
Having worked in the security industry for a long time, I've seen this pattern repeat itself with every major technology shift, from early digital transformation to cloud to now AI. Technology changes, but behavior remains the same. Business teams race to be first. The security team hears a voice saying, “Don't slow down.” The results are predictable. Attackers identify and exploit vulnerabilities.
Security cannot be an afterthought. To turn AI into a competitive advantage and avoid creating an unprotected attack surface, organizations must prioritize good cyber hygiene. Powerful segmentation and proactive security measures ensure you don't get exposed at the expense of innovation.
What does good cyber hygiene look like in an AI project?
Every AI project should start with the question, “What are the risks of implementing this?”
Determine the answer by mapping which systems your AI will access, determining what data your AI will access, and determining whether your AI will run on-premises, in the cloud, or in a hybrid environment. Additionally, assess what happens if an AI system goes offline or behaves unexpectedly, or if an attacker gains access to its credentials or training data.
Connect those questions to business impact. If a system fails, which processes stop? If sensitive information is compromised, what is the impact on customers, partners, and employees? If it becomes a gateway deep into the environment, how far can an attacker penetrate before segmentation stops them? The answers to these questions should guide where and how you deploy AI.
Risk assessments that ignore segmentation often yield unpleasant answers. We now know that one compromised workload can reach a significant number of critical assets.
As we strengthen hygiene within each AI project, we also need to be aware of how the AI itself is reshaping the threat landscape. The same technology that allows your team to move faster and see more information can also enhance the tools attackers use against you.
good and bad points
On the defensive side, AI helps security teams make sense of vast amounts of data. Consider what happens when you connect network logs, endpoint events, segmentation policies, cloud observability data, and vulnerability information into a single security graph. This will be an AI-driven map of how assets and entities relate to each other.
Given that context, analysts can provide AI tools with simple prompts such as “highlight workloads that communicate with things that should never reach them” or “list misconfigured segments that allow unnecessary east-west traffic.” AI leverages network detection and response (NDR), cloud detection and response (CDR), and other telemetry sources to provide that information. It also reveals blind spots that are hidden in traditional dashboards and manual queries.
This visibility is only useful if you can act on it. Microsegmentation allows teams to translate AI insights into policies, increase control over high-risk workloads, block unnecessary communication paths, and reduce the scope of compromised assets in minutes.
Of course, attackers also know how to use AI to automate reconnaissance, test stolen credentials, map exposed services, and generate more targeted phishing. In flat, poorly segmented networks, this combination can be deadly. AI allows you to find weak points faster and rotate the entire system laterally with less resistance.
And while you can't stop an attacker from using AI, strong hygiene and segmentation can give them more effort and give your team more room to react. But even the best controls won't work if your team is built in isolation. To keep your AI project safe, you need to coordinate the right groups.
Force true collaboration across teams
AI is rarely limited to one team. The data team manages the input. The platform team owns the environment. Security is responsible for control and monitoring. Business units own results and budgets.
When these groups are unable to work together, gaps arise. Some people think, “Security will take care of it later.” Another thinks that “the platform team has already locked this down.” No one is responsible for lateral movement risk or how far an attacker can move within the environment before segmentation thwarts the attack.
Gather your team before building. Agree on what data AI can use. Define who can access the system. Before enabling anything, decide which parts of your network and which applications require strong segmentation.
Security doesn't have to be a “no” department. It must be the department that sets up safe guardrails so that businesses can move forward faster with less fear and less risk.
In today's post-breach world, where breaches are inevitable, organizations must build security with the assumption that attackers will get in. That mindset is already driving investments in NDR, cloud observability, and CDR platforms.
But visibility alone is not enough. Segmentation gives you the power to calmly stop that movement. And what ties it all together is hygiene: patching known issues, removing unnecessary services, deleting old accounts, and enforcing least privilege access.
Resilience comes from a combination of visibility, containment, and hygiene. Discover threats, stop them in their tracks with segmentation, and recover without disrupting your business.
Pursuing speed and achieving sustainable innovation even at the expense of cost
Every major technology change begins with a focus on speed at all costs. Then reality sets in as security incidents increase, regulators respond, and boards demand answers. Only then will many organizations refine their controls.
With AI, you don't have to repeat that cycle. Before expanding AI across your business, focus on these three steps.
- Perform clear risk assessments for each AI initiative and connect them to business impact.
- Bring security, IT, data, and business stakeholders together in the same room and assign shared responsibilities.
- Invest in segmentation so you can contain the incident and reduce the blast radius, rather than if something goes wrong.
Security is the foundation for sustainable and confident AI adoption. By treating hygiene and segmentation as design requirements rather than afterthoughts, you can become more resilient and act faster and more safely. By building security into every AI project, you can transform AI from a potential risk to a competitive advantage.
