Albert Evans is the Chief of Information Security at ISO New England. He brings over 20 years of cross-sector experience in cybersecurity, risk management, and team leadership across the military, government, and Fortune 500 companies. Known for his servant leadership style, he combines strategic insight with technical expertise to build high-performing teams and guide organizations through complex security challenges.
Through this article, Evans highlights the urgent need for organizations to immediately embed AI-specific security and governance frameworks to mitigate rising threats and comply with evolving global regulations.
Bottom Line Up Front
MITRE’s ATLAS catalog now tracks 14 tactics and more than 80 techniques explicitly aimed at AI systems (MITRE, 2025), while the OWASP Top 10 for LLM Applications identifies critical vulnerabilities that traditional security controls cannot address. Regulators in the U.S. (CISA, NSA), Europe (EU AI Act, Article 15), and Australia (ASD) already require provable AI controls for deployed systems. Organizations deploying AI without specific security frameworks face unprecedented risk exposure.
1. Put Governance on Paper
Day 0-30
• Charter an AI Security Council - CISO chairs; CIO, CTO, Legal and Data leaders vote.
• Publish an AI Risk Register - use NIST AI RMF 1.0 to map every model to a data owner.
• Add a threat map - link each critical model to its relevant ATLAS techniques.
• Draft a compliance matrix - one row per mandate, one column per control, and one link to evidence.
“Attackers are integrating LLMs into ransomware operations faster than most organizations can adapt their defenses. Recent Unit 42 research quantifies this threat: GenAIassisted attacks achieve data exfiltration in 25 minutes versus the traditional two-day timeline, demonstrating how AI acceleration fundamentally reshapes the cybersecurity battlefield”
Executive first step: Charter the council and fund enterprise-wide AI discovery, including Shadow AI detection.
2. The New Attack Surface in One Glance
3. Match Controls to Workloads
• Public SaaS LLM (ChatGPT, Claude) → secure web gateway blocks unsanctioned domains; AI-aware DLP scans prompts and outputs
• Cloud AI platforms (Azure, Bedrock, Vertex) → ZTNA around endpoints; secrets vault for keys; AI firewall in API mode; signed model registry
• Embedded copilots (Microsoft 365, Salesforce) → DSPM maps lineage; quarterly entitlement recertification
• Custom RAG/agent stacks → SBOM for every artifact, cryptographically signed weights, a quarterly purple team on ATLAS top-10 techniques.
• Edge/CPS AI (robots, smart-grid) → TPM attestation, secure boot, and local DLP before any inference happens Three pillars cut across every pattern: DSPM to locate sensitive data, AI-SPM to log prompts and versions, and signed SBOMs to prove what ran when.
4. Meet Regulatory and Security Requirements
5. The 12-Month Sprint
6. Metrics Your CEO Will Remember
• Mean time to detect AI incidents < 15 min
• Shadow-AI block rate > 95 %
• Models with verified SBOM 100 %
• AI incident trend decisively down year-over-year
7. Your 30-Day Checklist
1. Sign the council charter and fund discovery
2. Scan traffic, DNS, and endpoints for unapproved AI use
3. Enforce MFA on every AI admin account; block unvetted LLM domains
4. Approve the 12-month roadmap and tie exec bonuses to the KPIs above
Lead or Lag
Attackers stitch LLMs into ransomware faster than most firms can schedule a steering committee. Embed secure-by-design AI now, and you’ll turn tomorrow’s headline risk into a strategic moat instead.
The choice is decisive: secure AI leadership or accept the escalating consequences of inaction.


