What happens when the walls of your organisation can no longer keep your data safe? AI, remote work, and fast-moving data are changing how organisations operate, and the traditional perimeter model is becoming harder to maintain. In this episode of the Security Strategist Podcast, host Chris Steffen sits down with Dr Bill Anderson of Mattermost and JP Ayyappan, Director of Product Management at Virtru, to explore why the future of security isn't about stronger walls. It's about protecting the data itself.
Zero Trust Beyond the Network
Anderson, who trained as a cryptographer, says this blind spot has been around for decades. Organisations built networks like fortresses, assuming that anyone inside could be trusted. But that approach no longer reflects how people work. Employees use phones, home networks and third-party platforms every day, meaning the traditional security perimeter is no longer enough. Major breaches have shown how risky that assumption can be.
This is where zero trust comes in. But Anderson argues that many organisations still apply it mainly to networks and devices, rather than to the data moving through them. Collaboration tools have made this gap even clearer. People are creating and sharing sensitive information every day through meetings, chats and shared documents, often without a way to identify and protect that data as soon as it is created.
How AI Changes Data Classification
The conversation then turned to one of the biggest challenges facing security teams: AI can combine information in ways that are difficult to predict. Anderson described how a series of seemingly harmless questions about flight paths, weapons ranges, and timing could be combined by an AI system to produce sensitive information, even if no one set out to create it.
Steffen gave a similar example. A simple first prompt can lead to a series of follow-up questions, with each response shaping the next. By the third or fourth exchange, the AI could produce highly sensitive information without a clear record of how it was created. This creates a problem for traditional data classification. Rules designed for static documents are harder to apply when information is generated and combined in real time.
Ayyappan pointed out that AI can also help address this problem. It can be trained to classify and tag information as new context emerges, but only if organisations already have a clear and consistent tagging structure.
Security Becomes Business-Ready
Why boards must treat cybersecurity as an adaptive business capability, balancing AI adoption, identity control and resilience-by-design.
Security That Protects the Data
Rather than relying on network access to determine who can be trusted, Virtru's approach applies permissions directly to the data through an open framework called the Trusted Data Format. Ayyappan explained that files can carry their own access rules, allowing organisations to control who can access them regardless of the network or device being used. This approach keeps protection with the data, even when a file is shared outside the organisation. It can also make it easier to give external partners or emergency teams access to specific information without giving them access to the wider network.
AI Agents Need Access Controls Too
Both guests agreed that AI agents, integrations and plugins need to be treated as identities within an organisation's access control model. Anderson explained that Mattermost applies the same user, resource and action controls to AI agents as it does to people. This allows organisations to control what each AI system can access.
Ayyappan added that two executives using the same AI agent and accessing the same data could receive different answers based on their individual permissions. This allows organisations to use AI without giving every user or system access to all available data. For security teams, both experts recommended starting with clear limits on which AI systems different groups can access. As organisations develop clearer classification rules, more of these controls can be automated.
Inside AI Agents And Identity Risk
How non-human identities, agentic AI and exposure-aware security are reshaping governance for ecommerce and enterprise platforms.
Ayyappan also stressed that data privacy and protection need to be considered from the start. Once sensitive information has been exposed through an AI workflow, fixing the problem afterwards may be too late. The shift towards AI means organisations need to rethink how they classify, protect and control data. Instead of relying only on network security, organisations need controls that stay with the data wherever it goes. Listen to the full episode and learn how Mattermost and Virtru are helping organisations take a data-first approach to security. Visit mattermost.com or virtru.com to learn more, and follow Dr Bill Anderson and JP Ayyappan on LinkedIn.
Takeaways
- Rethinking zero trust by putting security closer to data.
- The role of AI in enhancing data security and decision support.
- Challenges of data classification and access control in AI environments.
- The concept of data self-description and attribute-based access control.
- Treating AI agents as quasi-human entities in security models.
- The importance of disciplined data tagging and classification.
- Risks of data spillage and the need for proactive safeguards.
- Evolving from perimeter-based to a data-centric security model.
Comments ( 0 )