Information Security 3 min read

Modern cybersecurity strategies in the age of artificial intelligence

An overview of modern AI security challenges, the use of NIST frameworks, and the implementation of semantic DLP filters for data protection.

The integration of artificial intelligence (AI) and large language models (LLMs) into corporate workflows is dismantling the traditional security perimeter. According to the Cisco Cybersecurity Readiness Index 2025, AI security is becoming a foundational element of cyber readiness, as traditional DLP and SIEM systems fail to understand the context of LLM interactions.

Why traditional DLP systems fail against AI

Traditional DLP systems look for signatures and regular expressions but are powerless against semantic leaks. This occurs when sensitive information is transmitted in a paraphrased form or through RAG (Retrieval-Augmented Generation) mechanisms, where an AI agent accesses data that the user does not have permission to view.

Threat modeling and the NIST AI RMF 1.0 framework

To counter new attack vectors, AI threats are integrated into SOC monitoring using the MITRE ATT&CK matrix. The urgency of this is highlighted by the ENISA Threat Landscape 2025 report, which recorded 4,875 incidents, with over half of the affected organizations (53.7%) classified as essential entities under the NIS2 directive.

Systemic protection is offered by the voluntary NIST AI RMF 1.0 framework, which is built on four functions:

  1. Govern: establishing security policies and an AI usage culture.
  2. Map: classifying data and identifying attack vectors.
  3. Measure: assessing the safety and reliability of models.
  4. Manage: implementing technical controls.

Architectural solutions for LLM security

A secure architecture requires the implementation of semantic DLP gateways and development based on Security by Design principles. Ukrainian developers from Intecracy Group are building solutions with built-in security. Notably, Softengi is certified under the ISO/IEC 42001:2023 standard.

The technological foundation for such systems is the UnityBase low-code platform, which ensures security through built-in mechanisms:

  • Row-level security (RLS) and ACL: restrict AI agents' access to data at the kernel level.
  • DBMS-agnostic ORM: protects against direct database injections.
  • Audit Trail: records all actions for subsequent analysis in the SOC.

What changes for the sector

The dismantling of the traditional security perimeter means businesses face unprecedented risks of semantic leaks and unauthorized data access via RAG mechanisms. With over half of affected organizations classified as essential entities under the NIS2 directive, failure to adapt AI security measures could lead to severe compliance penalties, systemic data breaches, and a total loss of trust in corporate AI systems.

Steps for businesses

To secure corporate workflows, organizations should take the following practical steps:

  • Adopt the NIST AI RMF 1.0 framework to govern, map, measure, and manage AI risks.
  • Implement semantic DLP gateways and build systems based on Security by Design principles.
  • Utilize secure platforms like UnityBase that offer row-level security (RLS), DBMS-agnostic ORM, and comprehensive Audit Trails.
  • Ensure partners and developers are certified under standards like ISO/IEC 42001:2023.

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Intecracy Group products and solutions referenced in this article.

  1. UnityBase — unitybase.info
  2. Розробка ПЗ з використанням ШІ та AI-консалтинг — softengi.com
  3. Megapolis.DocNet — inbase.com.ua
  4. А5 Персонал — inbase.com.ua
  5. Xplorum AI Platform — softengi.com
  6. Ionbond AI Visual Inspection — softengi.com