Intelligent CISO Issue 100 | Page 39

f

e

a

t

u

r

e

Restore what matters, in a state you can trust
AI will keep changing both attack and defence, but the organisations that withstand that shift will be those that combine strong fundamentals, trusted recovery foundations, controlled use of defensive AI, and repeated validation under pressure.
Cyber-recovery is different from Disaster Recovery. No longer is restoring everything at once, as quickly as possible, the best approach. It is about restoring what matters most, quickly, safely, and in a state the business can trust, without attacker persistence, poisoned configurations, or compromised credentials that will cause extended business disruption.
Kris Voorspoels – Director of Products & Solutions at OPSWAT
Every board is asking the same question:‘ How are we using AI to stay competitive?’ For CISOs and IT leaders in sectors such as defence, critical infrastructure and financial services, however, there is an equally important consideration: how can organisations embrace AI without increasing their risk profile?
The answer increasingly lies in architecture. Hardware-enforced one-way mechanisms, such as data diodes, are emerging as a critical control for enabling AI safely. Unlike software controls, a data diode physically enforces one-way data transfer, allowing information to move into an AI environment while making reverse flow impossible, regardless of software behaviour, misconfiguration or compromise. This allows organisations to feed AI systems the information they need without creating a pathway for sensitive data or derived outputs to leave the environment.
AI is following the cloud journey
This shift mirrors the evolution of cloud computing. Critical industries were initially reluctant to adopt the public cloud until private, sovereign and hybrid cloud architectures enabled them to modernise while retaining control.
AI is now following a similar path. Many organisations are deploying Agentic AI locally or within tightly controlled environments rather than sending sensitive information to external platforms. However, local deployment alone does not guarantee security. AI systems still rely on continuous feeds of logs, telemetry, sensor data, threat intelligence and operational information. Feeding those systems inevitably creates new data pathways.
Eliminating architectural ambiguity
Traditional controls such as firewalls, segmentation and access policies are designed to regulate these pathways, but they remain software-enforced. Misconfigurations occur, APIs expose more than intended and complex environments make absolute certainty difficult.
As AI becomes more autonomous, any bidirectional connection creates the potential for unintended outbound data movement. The risk is not only external attackers or malicious insiders but architectural ambiguity itself.
Data diodes remove that uncertainty. By enforcing one-way data transfer in hardware, they eliminate the possibility of reverse flow rather than relying on policies or application behaviour to maintain it. AI systems can ingest threat intelligence, operational telemetry or lower-trust network data, but they cannot transmit anything back across that boundary.
WWW. INTELLIGENTCISO. COM 39