Site navigation

CymruSec 2025 | Turning AI Chaos into Cyber Clarity

Elizabeth Greenberg

,

ai security
At DIGIT’s inaugural CymruSec, Matilda Rhode, head of security operations at Dŵr Cymru Welsh Water, answers the big questions on AI: what is it, what are its biggest risks, and how do we secure ourselves against them?

AI is everywhere, from the forefront of technological innovation to your back pocket, infiltrating conversations of the most powerful people in the world, in boardrooms and universities, down at the pub and at family holidays. 

While the prolific technology definitely has a high profile, what AI actually is can often be misunderstood and vaguely defined, despite its availability to the everyday person. 

“A lot of people compare AI to the cloud, to kind of dismiss the hype,” Matilda Rhodes said at DIGIT’s inaugural CymruSec conference in Cardiff. “But I wasn’t talking about the cloud with my in-laws on Christmas day, but I do have to talk about AI.” 

Matilda Rhode has to talk about AI –  no matter how it is defined – a lot. She serves as the head of security operations at Welsh Water, but previously worked with AI as a data scientist when the technology had a more narrow definition and scope. 

People used to talk about breakthroughs in Google DeepMind, the potential for driverless vehicles – AI still seemed nebulous and futuristic, the stuff of films rather than reality, back when Rhode was working on foundational systems. 

Then, ChatGPT happened in November 2022, and Rhode was bombarded by the incessant question: “What are we doing about AI?” 

“You can almost reframe the question from a security perspective as ‘what are we doing about technology?’” To answer either question, Rhode took us through the varying definitions of AI, and how it is impacting governance, data protection, and general security

So what is AI, and how do we deal with it from a security perspective. 

Rhode provided helpful definitions, explained security risks, and delved into best practices in a packed room at CrymruSec 2025 in Cardiff. 

Defining AI for 2025

“AI has become this massive branding success. It’s now applied to technologies that we wouldn’t have traditionally said were actually using data-driven or AI technologies, and it needs breaking down,” she explained. 

People often use a variety of diagrams to explain what AI is – and what it isn’t – but these often conflate AI applications together, adding more confusion and complexity to one of the most profound and readily available transformative technologies to hit the 21st century. 

“The word AI is now being used to capture this really wide range of technologies, but what do we really mean?” 

Rhode presented her own bespoke breakdown of AI, its various modes and applications, to try and simplify this complex landscape. 

Automation: “This is your normal programme that you are writing,” she explained. Here, humans create the rules. Automation is a bit easier to test than human programmes, but you do not rely on the data to infer the logic of your programme. Automation is a bit more basic, but is often now being described as AI,” Rhode explained. 

Next, she ventures into narrow machine learning (ML) with specific applications. For these, you need your own data source to focus on a specific problem. These are handy for detecting anomalies, recognising patterns, and matching signatures. These systems need to be trained on your own data, and includes exploratory data science and statistics. 

“It’s good for finding bad, finding weird things, and modeling risks.”

Now onto general purpose models – think ChatGPT. 

“These are models that are trained on hardware that you can’t afford, with data sets that you can’t store because the data set’s probably the whole internet,” Rhode explained. 

General purpose AI, like the name suggests, has “a myriad of applications – you can waste a lot of time playing with it,” she also warned. 

“That’s why you need to focus on the ‘why’ question with regards to AI in both a personal and professional context.”

For this, Rhode suggests that the best application for general purpose models in enterprise is for human/machine teaming. 

Think of something with a complex data set where LLMs can be used to structure data, but still requires a human in the loop for “a level of ingenuity and to operationalise it.” LLMs can be used to do the grunt work of major data sets, leaving the strategic problem solving to humans. 

Finally, Rhode touches on one of the newest buzzwords in the AI hype: Agentic AI. When it comes to security, Rhode questions if we are anywhere near trusting agentic AI, or AI with the agency to take data, solve problems, all on its own, especially with sensitive data sets. 

Now that we have a bit of a better understanding of what AI is, the many roles it can play in an organisation, and various applications, we can move on to an even more difficult set of questions: how do we secure it? 

First of all, we need to again, understand what AI risks are, and then how we can protect against them. 

AI risks come in the form of five categories: 

General Purpose AI 

These risks tend to do with the use of general purpose AI models and their integration into systems. Zero-day vulnerabilities within these systems can create potentially devastating consequences. 

For these risks, Rhode suggests thinking of ways to mitigate the potential for zero-day vulnerabilities, such as ring-fencing sensitive data so AI systems cannot compromise it. 

Bespoke

Bespoke AI systems come with design flaws often inherent in any new technology adoption. These systems require access controls so they cannot be hacked and sensitive data cannot be leaked. They also, however, come with service risks, where lab tested, successful solutions fail in the real world. Working with various development teams to understand AI use-cases for purpose-built systems that reflect reality by design can help mitigate these issues. 

Ambient AI 

This is background AI, which often involves automated filters and systems. These can create service issues, which in turn can generate security issues. These need to be addressed, understood, and relayed across the entire department. Procurement processes for ambient AI need to take security and data protection into account, even if their applications are seemingly harmless. 

Outside AI or Shadow AI

Rhode described this AI risk factor as “outside of the organisation use,” but it is often known as shadow AI. This is when workers use AI systems for work outside of approved in-house applications, or use work data in AI applications without authorisation. This creates a high-level of data protection risk, but blanket bans on using AI appear to not be working, as data shows a high level of Shadow AI, especially in IT applications. Regulating the use of approved AI systems, as well as communication basic security protocols to their use, is more recommended. 

AI Used By Attackers 

These are the AI security risks that tend to get the most attention. From deepfakes to social engineering, most cyber-attack that employ AI do so to enhance the effectiveness of these attacks, rather than in creating new attack vectors of methods. AI has transformed phishing, has made deepfake-ing certain biometric identifiers possible, and can even make entry-level malware. While brand new security risks may not be popping up, AI is making traditional risks more effective, so security defences need to catch up. 

All these security risks bring together issues that are not necessarily new. Access and identity management is still vital, data protection, cyber awareness when it comes to phishing, using authorised tools, protecting sensitive data against zero-days – are all essential cyber hygiene anyway. 

“So AI, this new type of technology, whatever you want to call it: does it actually need a new approach or are we fine as we are?” Rhode postures. 

To answer, she delves into four key takeaways when it comes to cybersecurity in this new age of AI. 


Recommended reading


Skills 

“If we’re going to put in new technologies, we can’t just fit and forget them,” she said. 

“We need people who are going to monitor them, maintain them, just with any security tool.”

As AI transforms the workforce, workers will need the appropriate training to transform with it. 

If a person’s new job is to monitor and critique the AI doing their old job, then “those people need retraining on how to be the human in the loop. They can’t just move from doing that job to criticising an AI model. They need to understand its weaknesses.”

Security Defences 

Data governance is also vital in protecting the data these systems rely on to function. “We need access control, especially if you’re going to use agents. Those need locking down.” 

Understanding how to protect sensitive data from AI – be it in bespoke systems, shadow AI, or zero-day threats, is vital, just as it is with any new technology. 

New controls are also arising with AI, but so are threats, and traditional patching may not be possible, Rhode warns. 

Security teams should also try their best to understand the cost-benefit for attackers when implementing new AI systems. 

Cyber Awareness

Classic cyber awareness, across the entire organisation, will still be essential, but new concerns need to be addressed. As deepfakes become more and more common, and regulation has yet to catch up, organisations need to be aware and prepared. 

Sensitive data also needs to be protected from potential AI security risks, and sensitive data must be ring-fenced from shady Shadow AI uses. 

Vagueness as an Advantage

In Rhode’s talk, it was clear that AI does not have one definitive definition, and its complexity will only expand as the technology and its applications evolve. While Rhode presented understandable definitions of AI, it remained clear that AI anything but clear and simple. 

It’s overarching capabilities, insidious tendency to spread its tentacles across an organisation’s tech stack, the FOMO of boards desperate to brag about their AI applications, means that AI is looming over every technology innovation, ever budget meeting, every cyber-attack, and is the stuff of cyber leader’s nightmares. 

But Rhode says this vagueness can be used to cyber’s advantage. 

“AI risk is often brought to the security team first, but it’s a risk that affects lots of different areas,” she said. “This is actually an opportunity to work closer with colleagues who operate across different risk domains.”

“You can harness the vagueness to your advantage,” she said. “Use it to drive security improvements.” 

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data