Tech Interviews

THE AGENTIC AI ERA: RETHINKING CYBER RISK, GOVERNANCE AND RESILIENCE

Published

on

Exclusive interview with Bilal Baig, Vice President, Solutions Engineering, Trend Micro

What is Trend Micro showcasing at GISEC Global 2026, and how does it reflect the shift towards proactive, AI-powered cyber risk management?

We are highlighting our unified cybersecurity platform, Trend Vision One, which is designed as a proactive security platform.

AI has shifted how organisations, governments and agencies respond to threats. It is no longer enough to take a reactive approach. Security needs to become proactive, particularly given the speed at which AI is developing.

We are using AI in two ways. First, we are using AI internally within the platform to identify vulnerabilities. Second, we are using AI to protect our customers.

At GISEC, we are showcasing agentic SIEM, agentic SOAR, XDR capabilities and our full-stack AI security platform. We are also highlighting new developments in AI security, including how AI can help protect against vulnerabilities and zero-day attacks.

How has Trend Micro evolved in both using AI for cybersecurity and securing AI systems themselves?

AI has increased the speed at which organisations can move into production. At the same time, both defenders and attackers now have access to AI. The key question is how organisations manage that risk and how quickly they can protect customers and predict an attack before it becomes a breach.

We created Cybertron, an industry-first cybersecurity LLM, and we also work with frontier AI providers including Anthropic, OpenAI and Microsoft. We use frontier AI to consume vulnerability information, while our customers have access to our broader AI security capabilities.

We are now moving into the agentic AI era, where AI agents can make decisions on behalf of humans. These agents can access systems, emulate human behaviour and perform tasks independently.

For us, agentic AI security comes down to four key areas: visibility, observability, governance and response.

Visibility means understanding what is happening. Observability goes a step further by understanding what an action performed by an AI agent could cause. Governance determines how those agents should be controlled, while response is about deciding what action to take.

What new security and governance challenges arise as agentic AI moves from experimentation to enterprise deployment?

One of the biggest questions is whether an agentic AI system should be treated like a human identity or like software.

A software system needs updates, patches and maintenance. A human has an identity, a job and defined responsibilities. Agentic AI combines elements of both.

Organisations therefore need to give AI agents an identity, establish guardrails around what they can do and ensure that someone within the governance structure is responsible for their actions.

If an agent is given additional responsibilities, organisations need to understand how those permissions are managed and eventually removed when they are no longer required.

In an agentic AI environment, every communication and action needs to be considered within a governance framework. Organisations need to look at every interaction, understand its potential outcome and decide whether an action should be allowed to proceed or stopped.

What does the rise of autonomous or rogue AI agents mean for cybersecurity?

We are entering a world where rogue AI agents can become highly sophisticated systems. This means security cannot focus only on whether the underlying AI model is secure. Organisations also need to examine the actions those models are performing and whether those actions could create a cybersecurity problem.

The attack surface is now changing in terms of both scale and sophistication. Attackers have AI capabilities that can help them launch sophisticated attacks much faster.

This means organisations need AI on the defensive side as well. Security solutions need to match that speed and sophistication while ensuring that governance frameworks prevent malicious outcomes.

How should organisations manage the growing number of vulnerabilities identified by AI?

AI and frontier models can identify vulnerabilities that may not have been visible previously. An organisation that once had to manage 30 or 40 patches could suddenly face thousands.

It is not realistic to address every vulnerability in the same way. Organisations need to prioritise based on the risk and importance of their environment.

They need to identify which vulnerabilities are most important for their particular environment rather than simply looking at a vulnerability’s CVE score.

This is where cyber risk exposure management becomes important. Organisations need to understand the risk, the asset and the identity involved, and then decide which security gaps are most important to close.

How is the UAE’s cyber threat landscape changing as AI adoption and digital transformation accelerate?

The UAE is at the forefront of AI transformation. We are seeing multiple initiatives from the UAE Government, including AI training for government employees, government-focused AI initiatives and the introduction of AI education in schools.

There are already AI systems operating within government, so the digital transformation of AI in the UAE is moving forward rapidly.

Our focus is on helping secure that transformation. As AI systems become more interconnected and increasingly make decisions, the attack surface becomes more complicated.

A layered security approach is therefore important, from the large language model and API access through to the decision-making processes of AI agents, while monitoring for malicious activity.

What should organisations consider around security controls and data sovereignty as they expand their cloud and AI environments?

There is sometimes a misconception that moving to the cloud automatically means an organisation is secure. When cloud computing emerged, we often talked about security as a shared responsibility.

The exposure changes as organisations move from on-premises environments to the cloud and then into AI. The same threat can look very different across these environments.

Organisations need to consider where their assets and identities are located and how they will manage security across these different layers.

For highly sensitive environments, including air-gapped networks and systems involving critical data sovereignty, security may need to remain on-premises. In some national security environments, data cannot be processed outside the country.

Trend Micro has Vision One Sovereign and Private Cloud, which extends our AI cybersecurity unified platform to air-gapped and sovereign environments, with a focus on data sovereignty, localisation and air-gapped deployments.

What role does government-industry collaboration play in strengthening national cybersecurity preparedness and resilience?

Government-industry collaboration is extremely important. Working with organisations such as the Cybersecurity Council, national CERTs and government security services brings together different perspectives.

As governments move towards greater use of AI, industry can help secure that journey while governments provide the regulations and governance frameworks needed to manage these systems.

Without close collaboration, it becomes difficult to create policies that reflect what is actually happening in the private sector.

The objective should be to support innovation without overlooking cybersecurity. Technology is developing extremely quickly, particularly AI, so cybersecurity needs to be considered alongside that innovation.

Government and the private sector need to work together to make sure that while organisations remain at the forefront of technological development, they do not overlook the cybersecurity implications.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version