Cloud CISO Perspective: Achieving AI's Defense Advantage with Deep Context
Key point
As AI-driven agentic attacks accelerate, Google presents deep context as the key to giving defenders the advantage.
Details
AI is dramatically increasing the speed and scale of cyberattacks. In 2025, the transition between attack stages takes just 22 seconds, and Google recently recorded its first zero-day attack orchestrated entirely by AI.
However, defenders hold a powerful advantage. While attackers infiltrate from outside with limited information, defenders possess complete internal context (deep context) — asset locations, application behavior, ownership, and more. To maximize this advantage with AI, Google built the Google AI Threat Defense platform.
This platform integrates Gemini's reasoning capabilities, Wiz's cloud context, CodeMender's code remediation, and Mandiant's threat intelligence. It operates through a 4-stage framework:
- Prepare: Uses Wiz to map exposed applications, APIs, identities, and runtime environments, and simulates attack paths to strengthen the foundation before vulnerabilities reach production.
- Scan & Prioritize: Runs broad scans with lightweight models, then applies deep analysis with Gemini frontier models to high-risk assets, converting mass alerts into validated, actionable risk.
- Remediate: Deploys CodeMender in developers' IDEs/CLIs to automatically generate verified code fixes, replacing slow manual patching with automated code-level remediation.
- Monitor: Links AI agents with Wiz to track vulnerabilities and anomalies across network, identity, and application telemetry, working with Google Security Operations to rapidly hunt unknown threats.
The Morgan Stanley case study demonstrates the framework's effectiveness. By consolidating fragmented tools, they cut mean time to detect (MTTD) threats by 99.9%, shifting from a reactive 45-minute response to proactive mitigation in under 90 seconds.
Defending in the AI era also requires human strategic oversight. Like Wiz's Red, Blue, and Green agents, connecting automated AI agents directly to supporting human teams maintains autonomy while ensuring supervision. Organizations must also enforce Zero Trust for AI and block 'shadow AI' risks arising from unapproved models and agents downloaded by employees.
Google emphasized that "every AI conversation is a security conversation," concluding that AI infrastructure must be designed with security built in from the start, not patched on afterward.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.