Agents on the frontline: How Box is using AI to supercharge cybersecurity
How can enterprises adopt AI agents in a safe and secure manner?
Findings from Box’s State of AI in the Enterprise survey show 83% of enterprises are now running agents in some capacity.
These bots are enabling teams to drive productivity and efficiency, but as with any new technology, smooth integration can be a challenge - and security risk. Recent agent-related incidents in the tech industry have sparked concerns about long-term security implications.
In this week’s episode of the ITPro Podcast, Ross Kelly and Bobby Hellard speak with Box CISO Heather Ceylan to discuss how Box is using agents internally, and how enterprises can adopt the technology in a safe and secure manner.
Highlights
“I think for security teams, we can finally, you know, start having the capacity to outpace these attackers. So we've got five core areas of investment for agents for our security team in particular that we've invested in over probably the last year, and we're starting to measure ROI on those right now.
“So the first one is in the SOC. I think that's probably the most obvious choice where we've got a lot of operational work. We see the same kinds of incidents. We're automating the triage, we're automating the enrichment, the log correlation, things like that that take a lot of human effort.
“But there's still human judgment in the end in terms of what gets escalated to be an incident and what doesn't.”
Moving fast in the age of agentic AI
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
“We're not going to be able to move fast enough. So, we have agents kind of built throughout our software development process, doing those security design and architecture reviews, and if you think about it, it’s way more powerful than a human can be because those agents don't just necessarily call out design flaws; they can enforce fixes for those flaws.”
“Things are changing quickly. Sometimes it feels like you take two steps forward and then you read something in the news and you're like, oh my gosh, we need to rethink everything.
“So I think a lot of security teams are really feeling that now and getting a little bit of fatigue from that.“
The benefits of a multi-model approach
“One of the things that we're trying to carry across all of these that I wasn't really thinking about a year ago, but I'm thinking a lot about now is having that multi-model approach.
“We're not in a place where most of the work we do, we can't be reliant on a single model. If you look at vulnerability discovery, we're moving away from being tied to any one specific vendor or any one specific model because you're going to get better results when you take a multi-model approach.”
Related content
- The State of AI in the Enterprise report (Box)
- Box unveils new controls to secure AI agents
- How OpenAI models breached Hugging Face
- The OpenAI and Anthropic containment breaches are a bit spooky, but also quite silly
- CISOs are keen on agentic AI, but they’re not going all-in yet
Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
DDoS attacks might be dwindling, but they’re intensifyingNews While law enforcement efforts have had their effect, the rise in super-botnets and hijacked cloud servers has increased the intensity of attacks
-
Oracle expands HPE Juniper Networking deal to support AI infrastructure build-outNews The deal is aimed at supporting scale, performance, and availability as Oracle expands its AI superclusters
-
Google's Spirit Airlines auction & TrendAI insider threat reportPodcast Google's Spirit Airlines auction & TrendAI insider threat report
-
Can responsible AI beat hallucinations?Businesses are more eager than ever to implement AI in their workflows, but ambition doesn’t always translate into success
-
What the OpenAI rogue bot story really says about the state of AI securityPodcast
-
The evolution of digital twinsITPro Podcast No longer just a simple replica of a factory floor, the term digital twin is taking on new meaning
-
The end of tokenmaxxing – and what comes nextPodcast The rise and fall of tokenmaxxing has been dramatic. We ask why it fell apart and what happens next.
-
Do we have enough talent and power for the future of AI?Podcast Also, has the EU really made a true alternative to Google Workspace and Microsoft 365?
-
The AI pricing time bombPodcast How should enterprises approach AI agents, and in particular, their AI budgets?
-
Dell Technologies World 2026: agents, hardware, and tokenomicsJane, live from Las Vegas, takes us through her week at Dell’s AI agent extravaganza