5 Strategies for Advising on AI System Security

By Contributing Writer



Managed service providers (MSPs) face a complex challenge as their clients rapidly adopt artificial intelligence systems. These AI implementations expand the attack surface in ways traditional security measures weren't designed to address, introducing vulnerabilities that conventional tools struggle to detect or prevent. To remain trusted advisors in this evolving landscape, MSPs must move beyond standard cybersecurity practices and develop specialized strategies tailored specifically to securing AI systems.

1. Understand the New AI-Driven Threat Landscape

The first step for MSPs is to educate themselves and their clients about the new categories of AI-specific risks. AI functions both as a tool for attackers and as a target itself, creating a dual threat environment that traditional security frameworks struggle to address.

The Cybersecurity and Infrastructure Security Agency identifies three distinct threat types in its guidelines for mitigating AI risks, which are attacks using AI, attacks targeting AI systems and failures in design. Adversaries can leverage AI to enhance, plan or scale cyber compromises, making attacks more sophisticated and harder to detect. Systems themselves become targets through methods that exploit their unique architecture.

For example, prompt injection attacks manipulate systems by inserting malicious instructions that override intended behavior, while training data poisoning corrupts the datasets that models learn from. Unauthorized API access exploits the interfaces through which systems communicate, and adversarial attacks use carefully crafted inputs to deceive machine learning models. These represent new security risks posed by generative AI that cyber threats will exploit whenever weaknesses emerge.

2. Implement a Formal AI Risk Management Framework

MSPs should guide their clients toward structured approaches to AI governance that replace temporary solutions. A formal framework provides systematic methods to identify, measure and manage risks while helping meet emerging regulatory requirements surrounding transparency, privacy and accountability.

The NIST AI Risk Management Framework offers a structured approach for building governance strategies and outlines the four core functions of Govern, Map, Measure and Manage. These functions help incorporate trustworthiness into system design and development from the earliest stages.

Clear governance reduces uncertainty for those navigating unfamiliar AI territory. It establishes accountability structures and defines risk tolerance levels while creating consistent evaluation criteria. Risk management should also evaluate how sensitive data flows through systems, ensuring information-handling practices align with privacy requirements and security standards throughout the AI life cycle.

3. Adopt a "Secure by Design" Philosophy for AI Systems

Security must be integrated from the start of AI implementations. MSPs should encourage clients to adopt a Secure by Design approach that incorporates protection measures at every stage of the development life cycle, emphasizing proactive measures and minimizing vulnerabilities before deployment.

AI is software that needs to run with a specific identity and limited permissions. Applying security fundamentals to AI requires the same precision as other software systems, if not more.

Utilize the principle of least agency, meaning systems should only access the capabilities and APIs they absolutely need to function, which limits potential damage if a system becomes compromised. Security requirements should be defined at the project's beginning and integrated into architectural decisions before validation through testing prior to production deployment. Treating security as a fundamental design requirement significantly reduces risk exposure.

4. Use Advanced AI-Powered Cybersecurity Platforms

Traditional rule-based security tools prove insufficient for detecting AI-driven attacks. Using AI to fight AI means deploying platforms that leverage machine learning to detect anomalous behavior indicating threats.

Darktrace exemplifies this approach through its unique threat detection methodology. The platform applies machine learning to understand normal patterns of activity within environments, enabling it to identify subtle deviations that may indicate emerging threats, insider risks or previously unseen attack techniques.

What makes this approach distinctive is that it operates without prior assumptions about what threats look like. Instead, it learns every device, user and interaction to develop an understanding of normal from direct observation.

Static security solutions adopt rules that often interpret threats too broadly and result in alert fatigue. Darktrace's multi-layered AI looks for anomalous events, reducing false positives compared to tools that rely on historical attack patterns. Darktrace’s AI learns legitimate activity patterns for specific businesses in about a week. Most environments see meaningful insights emerge within this initial period, with a thorough understanding of normal behavior forming over 30 days.

Darktrace's Cyber AI Analyst investigates every alert and determines whether it is part of a wider cybersecurity incident, which might reduce the number of alerts appearing in a security operations center analyst's queue from 100 to just two or three critical incidents that need attention. This second level of analysis threads together subtle behavioral anomalies that indicate genuine threats while filtering out benign activity.

For MSPs advising clients on securing AI, platforms like Darktrace are top solutions for AI system security, offering broad coverage across on-premise networks, cloud applications and infrastructure, operational technology, endpoints and email systems. With integration typically happening quickly, often through one-click deployment from a customer portal, implementation is straightforward even in complex environments.

5. Prioritize Continuous Learning and AI Safety Research

AI is increasingly used in businesses, with 78% of organizations using AI in 2024. As AI technologies are incorporated and evolve, so do the associated security risks. Security strategies that are effective today may become insufficient as new attack methods, AI capabilities and regulatory requirements emerge. As such, AI security requires ongoing commitment, as MSPs and their clients must stay informed about an evolving AI landscape.

Continuous learning includes monitoring developments in AI safety research, following emerging industry standards and best practices, and participating in AI-focused cybersecurity training programs. It also involves reviewing threat intelligence related to attacks and conducting regular security awareness sessions to keep defenses up to date.

MSPs can advise organizations to periodically review their AI governance policies and reassess risks whenever new AI applications, models, or vendors are introduced. Each addition to the AI ecosystem brings unique security considerations that existing policies may not address. With regular policy reviews, ensure governance frameworks evolve alongside technology deployments.

Future-Proofing Security Advisory for the AI Era

AI is reshaping both business operations and cybersecurity, creating new opportunities alongside new risks. For MSPs, advising clients on AI system security requires a proactive, strategic approach that combines technical expertise with strong governance and continuous improvement.

By understanding the evolving AI threat landscape, implementing formal risk management frameworks, embracing Secure by Design principles, leveraging advanced cybersecurity solutions such as Darktrace and staying informed through ongoing AI safety research, MSPs can help organizations confidently adopt AI while minimizing security risks.



Get stories like this delivered straight to your inbox. [Free eNews Subscription]
SHARE THIS ARTICLE
Related Articles

Putting Expert Network Troubleshooting in Every Technician's Hands

By: Erik Linask    7/28/2026

Giving field technicians step-by-step network troubleshooting guidance can help MSPs reduce escalations, shorten resolution times, avoid repeat truck …

Read More

5 Strategies for Advising on AI System Security

By: Contributing Writer    7/28/2026

Managed service providers (MSPs) face a complex challenge as their clients rapidly adopt artificial intelligence systems. These AI implementations exp…

Read More

AI for Security Infrastructure: Rebalancing Cybersecurity for the Decade Ahead

By: Special Guest    7/27/2026

AI-powered cybersecurity infrastructure can help security architects detect configuration drift, optimize existing controls, reduce exposure, and shif…

Read More

Why DNS Security and Threat Detection Need to Work Together

By: Erik Linask    7/21/2026

DNSFilter and Blumira have launched a native integration that combines predictive DNS threat blocking with continuous security monitoring to help orga…

Read More

From Generic VSaaS to Vertical Expertise: A Growth Strategy for MSPs

By: Erik Linask    7/15/2026

MSPs can build tailored VSaaS offerings for healthcare, education, logistics, and other industries by combining flexible VMS platforms with vertical-s…

Read More