Prompt Injection Is a Data Access Problem | Sundar Krishnamurthy | EP 114
Musings from the Cyber Trench
0:00 / 0:00
Prompt Injection Is a Data Access Problem | Sundar Krishnamurthy | EP 114
25 просмотров · 4 дня назад
Musings from the Cyber Trench
21 подписчик
25 просмотров · 4 дня назад
You cannot secure AI by filtering prompts alone. Prompt injection becomes a much harder problem when an AI agent can retrieve sensitive data or execute actions without enforcing identity and authorization at the point of access.
In this episode of Musings from the Cyber Trench, I sit down with Sundar Krishnamurthy, Senior Security Architect at Expedia Group, to discuss prompt injection, AI guardrails, non-human identities, and what it takes to secure AI in real enterprise environments.
We examine why architecture and data-access decisions matter more than surface-level prompt checks. We also discuss how an AI agent’s identity must remain tied to the human it represents—and why testing, isolation, logging, and authorization must be designed into the system before an MVP becomes production infrastructure.
Sundar shares practical insights on:
Turning threat-model assumptions into automated tests that detect removed security controls
Using one LLM to review code generated by another while keeping humans in the decision process
Why vague requirements and prompts produce unreliable code
How indirect and multilingual prompts can bypass word-based guardrails
Enforcing fine-grained authorization where data is retrieved
Preserving both human and non-human identity context during agent-driven actions
Using separate vector stores and network boundaries to limit cross-tenant exposure
Why security shortcuts taken during an MVP become difficult and expensive to correct
Protecting private enterprise data when using open-source and commercial AI models
The central message is simple: Do not trust the prompt layer to protect sensitive data. Enforce identity, authorization, isolation, and governance as close as possible to the data and action being requested.
ABOUT SUNDAR KRISHNAMURTHY
Sundar Krishnamurthy is a Senior Security Architect at Expedia Group. He conducts architecture reviews across applications, cloud, networks, infrastructure, and AI and machine learning security. His background includes work with AWS, SAP Concur, and Microsoft, and he has shared security lessons at BSides events and IBM InterConnect.
ZERO TRUST READINESS ASSESSMENT
Responsible for ICAM, Zero Trust, or identity security within a federal agency, prime contractor, or large regulated enterprise?
If you are trying to move from strategy to execution, start with Zephon’s Zero Trust Readiness Assessment:
https://zephon.tech/zt
Questions or guest suggestions?
[defend@zephon.tech](mailto:defend@zephon.tech)
CHAPTERS
00:00 Why we trust AI more than we should
02:18 Security controls that survive code changes
07:42 Prompt injection is a data-access problem
11:50 Identity context for AI agents
14:47 Why companies overtrust AI
21:16 Using isolation to reduce the blast radius
25:32 When AI blurs data and control
37:11 AI, machine learning, and open-source models
46:20 Getting to know Sundar
49:18 Stuxnet, autonomous pentesting, and emerging threats
53:56 Envelope encryption and practical security lessons
58:16 Zero Trust readiness assessment