{"id":9084,"date":"2026-08-10T16:51:50","date_gmt":"2026-08-10T16:51:50","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9084"},"modified":"2026-08-10T16:51:50","modified_gmt":"2026-08-10T16:51:50","slug":"how-fidelis-xdr-supports-ai-risk-management-across-network-endpoint-and-deception-layers","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9084","title":{"rendered":"How Fidelis XDR Supports AI Risk Management Across Network, Endpoint, and Deception Layers"},"content":{"rendered":"<div class=\"elementor elementor-43462\">\n<div class=\"elementor-element elementor-element-c7ce062 e-ecs-flex e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-column-slider-no wpr-equal-height-no e-con e-parent\">\n<div class=\"e-con-inner\">\n<div class=\"elementor-element elementor-element-9fc6cb1 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>AI systems are infrastructure now, and adversaries treat them that way, probing inference APIs, poisoning training pipelines, riding generative AI tools into the credential theft and lateral movement behind most breaches today.<\/p>\n<p><a href=\"https:\/\/fidelissecurity.com\/fidelis-elevate-extended-detection-and-response-xdr-platform\/\">Fidelis Elevate<\/a>\u00ae answers this with XDR delivered through three named products under one CommandPost: Fidelis Network watches the traffic, Fidelis Endpoint\u00ae watches the workstations where AI gets built, Fidelis Deception\u00ae catches whoever\u2019s already inside. None of it touches a model\u2019s weights or reasoning directly. What it secures is the infrastructure those models depend on, which is the right frame for AI risk management generally: a security operations problem, not an AI-native one.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-7c491728 elementor-widget elementor-widget-Table\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\tFidelis ComponentWhat It WatchesAI Lifecycle StageDetects\t\t\t\t<\/p>\n<p>\t\t\t\t\t<a href=\"https:\/\/fidelissecurity.com\/solutions\/network-detection-and-response-ndr\/\">Fidelis Network<\/a>\u00aeNetwork traffic, all ports and protocols, encrypted sessionsTraining, inference, deploymentData exfiltration, RAG abuse, anomalous API traffic<a href=\"https:\/\/fidelissecurity.com\/solutions\/endpoint-detection-and-response-edr-solution\/\">Fidelis Endpoint<\/a>\u00aeWorkstations, servers, processesDevelopment, trainingPipeline tampering, credential theft, model IP theft<a href=\"https:\/\/fidelissecurity.com\/solutions\/deception\/\">Fidelis Deception<\/a>\u00aeDecoys, breadcrumbs, AD objectsPost-compromise, lateral movementReconnaissance inside AI infrastructure\t\t\t\t<\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-685b664 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">How Does Fidelis XDR Actually Work Across Network, Endpoint, and Deception?<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-454f442 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Each of the three components covers ground the other two can\u2019t, starting with the one that sees everything moving across the wire.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-94e14df elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">What Does Fidelis Network Do for AI Security?<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-d4054cf elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>AI workloads throw off distinct traffic. Inference calls, RAG queries, ingestion jobs, generative AI integrations, all forming patterns that, watched continuously, become a baseline. Deviation from that baseline is where attacker activity shows up.<\/p>\n<p>Fidelis Network\u00ae inspects traffic bidirectionally, <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/network-security\/detecting-east-west-traffic-anomalies-in-real-time\/\">east-west<\/a> and north-south, across all ports and protocols, using Deep Session Inspection. DSI pulls over 300 metadata attributes per session, well past what standard netflow captures. The 20 GB 1U sensor runs this at line speed, reaching into nested, compressed, obfuscated content, encrypted traffic, ephemeral containerized workloads too, exactly where most 2026 AI deployments live between scheduled scans.<\/p>\n<p>A simple case. An attacker tries moving training data out through an HTTPS session to an external endpoint. Netflow sees encrypted bytes leaving and not much else. <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/network-security\/deep-session-inspection\/\">DSI<\/a> sees the session content, the protocol behavior, the destination, and can tell ordinary browsing apart from machine-driven exfiltration on encrypted traffic. That gap is the difference between catching it and not.<\/p>\n<p>DLP runs across network, email, and web traffic with pre-built compliance policies. Someone pastes confidential data into an unapproved generative AI tool, the platform flags the transfer and logs it. Continuous asset classification, covering unmanaged IoT, legacy systems, <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/cloud-security\/shadow-it-risks-examples-and-detection\/\">shadow IT<\/a>, keeps the inventory accurate even when AI teams spin up cloud infrastructure outside procurement.<\/p>\n<p>Network traffic tells you what\u2019s moving. It doesn\u2019t tell you what happened on the machine before that traffic ever left, which is where the next layer picks up.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-f7d69dd elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">What Does Fidelis Endpoint Do for AI Security?<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-d19db0b elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>A data scientist\u2019s workstation holds model weights, pipeline credentials, training data access, all in one place. Compromise it, and an attacker injects corrupted data or steals model IP before anything ships, invisible to tools that only watch post-deployment.<\/p>\n<p>Fidelis Endpoint\u00ae runs single-agent across Windows, Mac, Linux, watching every process and child process for behavior, registry changes, file activity, network connections, in real time. On detection, it <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/endpoint-security\/endpoint-isolation-and-containment\/\">isolates the endpoint<\/a>, triggers one of over 100 built-in response scripts, investigative, forensic, or destructive. The Live Console gives analysts direct remote access into disks, files, registries, processes, as if sitting at the machine. It preserves a copy of every file and script executed even when an attacker tries wiping their tracks afterward.<\/p>\n<p>This is the layer that catches phishing-to-pipeline intrusion before it reaches a model. Detections <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/endpoint-security\/mapping-edr-to-mitre-attack\/\">map automatically to MITRE ATT&amp;CK<\/a>. A single anomalous API call from a dev workstation looks like noise alone, but a sequence following a model extraction pattern, correlated with process behavior on that same machine, becomes a documented MITRE ATLAS technique. That correlation only happens because Endpoint talks to Network and Deception, not because any one piece works alone.<\/p>\n<p>Network and endpoint coverage both assume the attacker is still moving, still generating signal somewhere. The third layer is built for the attacker who\u2019s gone quiet.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-ba684f3 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">What Does Fidelis Deception Do for AI Security?<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-543a697 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Network and endpoint monitoring both handle known patterns well. <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/deception\/what-is-deception-in-cybersecurity\/\">Deception<\/a> handles the harder case: someone already in, quietly mapping the environment before making a move.<\/p>\n<p>Fidelis Deception\u00ae continuously maps cyber terrain, scores asset risk, deploys decoys and breadcrumbs from real assets, emulated services, cloud resources, enterprise IoT devices, using machine learning to keep placement current. Decoys span hardware, software, cloud, including fake Active Directory accounts. Breadcrumbs are files, credentials, registry keys, canary files, placed beside real ones. Touch one and there\u2019s no legitimate explanation. The alert is true by design, no tuning required.<\/p>\n<p>For AI infrastructure specifically, decoy model endpoints, fake training repositories, deceptive API credentials sit next to real assets. An attacker probing the environment hits these before reaching anything real, handing over presence, technique, intent, well before any actual compromise lands. Red Team and Blue Team simulations keep refining placement as the AI environment shifts underneath it.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-920fcd3 elementor-blockquote--skin-quotation elementor-blockquote--align-left elementor-widget elementor-widget-blockquote\">\n<div class=\"elementor-widget-container\">\n<p class=\"elementor-blockquote__content\">\n\t\t\t\t&#8220;AI scales offense; deception turns that scale into exposure.&#8221;\t\t\t<\/p>\n<div class=\"e-q-footer\">\n\t\t\t\t\t\t\t\t\t\t\tJim Skelly, Senior Sales Engineer, Fidelis Security\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-4ae3beb elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Three layers, three different jobs. The question is what happens when an attack doesn\u2019t fit neatly into just one of them.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-10bfd3c elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">Why Do You Need Network, Endpoint, and Deception Together?<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-14c1cdb elementor-widget elementor-widget-Table\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\tScenarioFidelis NetworkFidelis EndpointFidelis Deception\t\t\t\t<\/p>\n<p>\t\t\t\t\tTraining data exfiltration attemptFlags anomalous upload via Deep Session InspectionDetects and isolates the compromised workstationAD deceptive objects catch lateral movement firstUnsanctioned generative AI data leakDLP flags the transfer, classifies sensitive contentSecondary layerSecondary layerEvasion attack against an AI-based detectorIndependent monitoring sees the full session regardlessSecondary layerCatches the reconnaissance the model missed\t\t\t\t<\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-0c270a0 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>No single layer tells the whole story of an attack on AI infrastructure. CommandPost correlates alerts, context, and evidence across all three through <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/xdr-security\/active-threat-detection-with-fidelis-elevate\/\">Active Threat Detection<\/a>, and provides retrospective analysis for tracing a full attack timeline after the fact, the audit trail NIST\u2019s Manage function and the EU AI Act\u2019s Article 12 actually want to see.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-5313f7f e-con-full e-ecs-flex e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-column-slider-no wpr-equal-height-no e-con e-child\">\n<div class=\"elementor-element elementor-element-5d0f9c10 e-con-full e-ecs-flex e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-column-slider-no wpr-equal-height-no e-con e-child\">\n<div class=\"elementor-element elementor-element-21bce5da elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Catch the Threats that Other Tools Miss<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-46df73d1 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Detect and Correlate Weak Signals<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Active Threat Detection<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Evaluate Findings Against Known Attack Vectors<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Proactively Secure Systems<\/span><\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-5c2b4f4d elementor-widget elementor-widget-button\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/fidelissecurity.com\/resource\/datasheet\/active-threat-detection\/\"><br \/>\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\"><br \/>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download Now<\/span><br \/>\n\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-47d6d71d e-con-full elementor-hidden-tablet elementor-hidden-mobile e-ecs-flex e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-column-slider-no wpr-equal-height-no e-con e-child\">\n<div class=\"elementor-element elementor-element-3d818af3 elementor-widget elementor-widget-image\">\n<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-69915ce elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Why Are AI Systems a Different Kind of Cyberattack Target?<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-e91816e elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Regular attacks go after code, credentials, network access. Attacks touching AI go after something quieter: training data feeding a model, the API exposing it, the workstation where a data scientist builds it. Understanding these risks associated with AI is step one in any serious AI risk management effort, because the controls that catch a normal intrusion miss these slower, lower-signal paths most of the time, which is exactly why Network, Endpoint, and Deception need to work as one system rather than three separate tools.<\/p>\n<p>MITRE ATLAS tracks this in numbers. Version 5.1.0, November 2025: 16 tactics, 84 techniques, 56 sub-techniques, 42 real-world case studies. Spring 2025 added 19 techniques for RAG poisoning, prompt crafting, AI supply chain compromise. By October, MITRE and Zenity Labs had added 14 more, aimed at AI agent vulnerabilities like context poisoning and tool-invocation exfiltration.<\/p>\n<p>Not hypothetical. Cisco\u2019s State of AI Security 2026 report found 83% of organizations plan to deploy agentic AI. Only 29% feel ready to secure complex AI models once they\u2019re live. That gap is where managing AI risk stops being a slide in a deck and starts being an actual operational priority.<\/p>\n<p>Four patterns matter most, and each maps to one of the layers above.<\/p>\n<p>Adversarial evasion attacks alter input data at inference time so a model misclassifies malicious activity as benign. Poisoning as little as 0.001% of a training dataset can degrade an AI system\u2019s performance in ways nobody notices until much later. A successful evasion attack against an AI-based anomaly detector suppresses alerts quietly while a real intrusion runs underneath, undetected by the tool meant to catch it. This is exactly the case Fidelis Network\u2019s independent monitoring and Fidelis Deception\u00ae\u2018s reconnaissance detection are built to catch from outside the compromised system.<\/p>\n<p>Generative AI data exposure happens when employees feed sensitive personal data or confidential data into unsanctioned tools, opening exfiltration paths most security teams aren\u2019t watching. Attackers who reach retrieval-augmented generation systems pull enterprise knowledge stores straight through the model interface, no need to touch the underlying data stores at all. <a href=\"https:\/\/fidelissecurity.com\/solutions\/network-dlp\/\">Fidelis Network\u00ae\u2018s DLP<\/a> is the control built for exactly this.<\/p>\n<p>Pipeline and supply chain exposure shows up when training pipelines sit accessible from corporate networks. Adversaries slip corrupted historical data into a retraining cycle. The model validates fine during testing and misbehaves only when a specific trigger appears, sometimes months later. Trend Micro\u2019s State of AI Security Report 1H 2025 found more than 3,000 exposed Ollama servers and over 200 unprotected Chroma vector databases sitting open on the public internet, direct paths into AI development environments, unguarded. This is where Fidelis Endpoint\u2019s process monitoring on development workstations does the heavy lifting.<\/p>\n<p>Shadow AI is the quiet one. Gravitee\u2019s State of AI Agent Security 2026 report found only 47.1% of deployed AI agents are actually monitored. The rest run unwatched, and any compromise or misuse involving them goes unnoticed until something downstream breaks.<\/p>\n<p>None of this surfaces through endpoint agents or firewall logs alone. Conducting regular <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/threats-and-vulnerabilities\/effective-cyber-risk-assessment\/\">risk assessments<\/a> against AI infrastructure means watching network, endpoint, and behavioral signals together, not any one in isolation.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-47b43c9 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">What Do NIST AI RMF and the EU AI Act Require for AI Security?<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-031387c elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Two frameworks now define what responsible AI practices look like operationally, and both carry real implications for the controls a security team has to run, which is the regulatory backdrop the three-layer approach above is built to satisfy.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-753c2f7 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">What Does the NIST AI Risk Management Framework Require?<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-c0cb229 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>NIST\u2019s Artificial Intelligence Risk Management Framework, published January 2023, gives a structured approach to identifying, assessing, and managing risks across the AI lifecycle. Four functions: Govern, Map, Measure, Manage. They run continuously, not once a year. NIST-AI-600-1, the Generative AI Profile, followed in July 2024, proposing specific actions for generative AI risk management tied to organizational goals. AI RMF 2.0, February 2024, tightened alignment with the EU AI Act.<\/p>\n<p>The Playbook says it plainly. Effective AI risk management practices require ongoing measurement of an AI system\u2019s performance under real conditions, adversarial ones included, using both quantitative and qualitative metrics to track behavior over time. Conducting regular risk assessments, documented <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/threat-detection-response\/incident-response\/\">incident response<\/a> tied to actual identified risks, not a generic policy binder nobody reads.<\/p>\n<p>Responsible AI under this framework isn\u2019t a position paper. It needs infrastructure that generates continuous monitoring data, because a quarterly scan won\u2019t catch the slow, low-signal attacks that work AI pipelines over weeks or months, which is precisely the gap CommandPost\u2019s <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/threat-detection-response\/retrospective-analysis-and-incident-response\/\">retrospective analysis<\/a> is meant to close.<\/p>\n<p>NIST\u2019s framework is voluntary. The next one isn\u2019t, and it comes with a number attached.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-39d30f4 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">What Are the EU AI Act Cybersecurity Requirements?<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-846c0aa elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>In force since August 1, 2024. GPAI obligations since August 2, 2025. May 2026\u2019s Digital Omnibus pushed the high-risk system deadline to December 2, 2027, but Article 5 prohibited practices have applied since February 2025, and the European Commission opened its first formal investigations in early 2026. This isn\u2019t a future problem.<\/p>\n<p>Article 15 is what security teams should read closest. High-risk AI systems must hold up against adversarial attacks, data poisoning, confidentiality breaches, throughout their operational life. Logs retained six months minimum. <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/xdr-security\/cyber-risk-management-with-xdr-technology\/\">Risk management<\/a> documented from day one, not bolted on after something goes wrong.<\/p>\n<p>Three consequences follow.<\/p>\n<p><strong>Financial:<\/strong> up to EUR 15 million or 3% of global turnover for high-risk violations, EUR 35 million or 7% for the worst ones.<strong>Operational:<\/strong> a manipulated AI system can run undetected for weeks, quietly skewing financial decisions or security classifications before anyone notices the output is off.<strong>Trust:<\/strong> recovering from a model integrity failure means technical fixes plus reputational repair, and neither comes back fast.\t\t\t\t\t\t\t\t<\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-32916098 e-con-full e-ecs-flex e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-column-slider-no wpr-equal-height-no e-con e-child\">\n<div class=\"elementor-element elementor-element-60c499a e-con-full e-ecs-flex e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-column-slider-no wpr-equal-height-no e-con e-child\">\n<div class=\"elementor-element elementor-element-66b3e232 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">Five Ways You Can Use Deception in the Mythos-like AI Era<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-5771ddf7 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Generates High-Confidence Alerts<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Disrupts Autonomous and AI-Assisted Attacks<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Extends Detection Across Hybrid Environments<\/span><\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-3b0ac5c3 elementor-widget elementor-widget-button\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/fidelissecurity.com\/resource\/whitepaper\/using-deception-against-threats-in-the-mythos-like-ai-era\/\"><br \/>\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\"><br \/>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Read the Guide Now<\/span><br \/>\n\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-64c7ec98 e-con-full elementor-hidden-tablet elementor-hidden-mobile e-ecs-flex e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-column-slider-no wpr-equal-height-no e-con e-child\">\n<div class=\"elementor-element elementor-element-bc309a elementor-widget elementor-widget-image\">\n<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-4ee4373 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Why Does AI Governance Depend on Security Operations?<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-b19f0e0 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>NIST AI RMF and the EU AI Act land on the same demand from different angles: security controls active across every stage an AI system touches, development through retirement. No single telemetry source covers that whole AI lifecycle. Training pipeline integrity needs <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/threat-detection-response\/ndr-edr-integration-closing-detection-gaps\/\">network and endpoint working together<\/a>. Inference-time attacks need traffic analysis and behavioral detection. Forensics need stored history with a clear event chain. Compliance needs tamper-evident logs held for months. That\u2019s the practical case for one integrated platform over three disconnected tools managing AI risk separately, each blind to what the others see.<\/p>\n<p>The MITRE ATT&amp;CK mapping built into Network and Endpoint extends naturally to AI-specific threat modeling. Security teams translate MITRE ATLAS techniques into detectable patterns inside existing SOC workflows instead of building a parallel stack just for AI. Roughly 70% of ATLAS mitigations map onto controls organizations already run, so the investment compounds across traditional threats and AI-adjacent ones both.<\/p>\n<p>AI brings new risk surfaces and considerably tighter regulatory stakes than most organizations have dealt with before. The discipline needed to manage AI risk isn\u2019t new, though. Security operations, applied consistently, across wherever the AI systems actually sit, network, endpoint, and the terrain in between. <a href=\"https:\/\/fidelissecurity.com\/fidelis-elevate-extended-detection-and-response-xdr-platform\/\">Fidelis XDR<\/a>, through Fidelis Elevate\u00ae, does that by securing the environment around AI rather than claiming to read what happens inside the model. The value isn\u2019t in what the platform says about AI. It\u2019s in what it catches around it, every day, without anyone having to ask.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-2f1aaa1d e-ecs-flex e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-column-slider-no wpr-equal-height-no e-con e-parent\">\n<div class=\"e-con-inner\">\n<div class=\"elementor-element elementor-element-285f52da elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Frequently Asked Questions<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-648a27e9 elementor-widget elementor-widget-eael-adv-accordion\">\n<div class=\"elementor-widget-container\">\n<div class=\"eael-adv-accordion\">\n<div class=\"eael-accordion-list\">\n<div class=\"elementor-tab-title eael-accordion-header active-default\">\n<h3 class=\"eael-accordion-tab-title\">Does Fidelis Elevate analyze AI model outputs or training weights directly?<\/h3>\n<\/div>\n<div class=\"eael-accordion-content clearfix active-default\">\n<p>No. Network, Endpoint, and Deception watch the infrastructure around AI systems, traffic, endpoint behavior, attacker reconnaissance, not the math inside a model. Interpretability and AI-native security are different disciplines from what Fidelis provides.<\/p>\n<\/div><\/div>\n<div class=\"eael-accordion-list\">\n<div class=\"elementor-tab-title eael-accordion-header\">\n<h3 class=\"eael-accordion-tab-title\">Can Fidelis Elevate help meet EU AI Act Article 15 requirements without replacing existing SIEM or SOAR tools?<\/h3>\n<\/div>\n<div class=\"eael-accordion-content clearfix\">\n<p>Yes. CommandPost feeds correlated telemetry, including the retention and audit trail Article 15 expects, into whatever SIEM or SOAR workflow a SOC already runs. It integrates rather than replaces.<\/p>\n<\/div><\/div>\n<div class=\"eael-accordion-list\">\n<div class=\"elementor-tab-title eael-accordion-header\">\n<h3 class=\"eael-accordion-tab-title\">How does deception help with AI supply chain risk specifically, versus network monitoring alone?<\/h3>\n<\/div>\n<div class=\"eael-accordion-content clearfix\">\n<p>Network monitoring catches data as it leaves. Deception catches attackers before they reach anything real, by placing decoy training repositories and fake credentials in their path. For supply chain attacks, where the goal is quiet, sustained access rather than one fast exfiltration event, that early trip-wire counts for more than traffic analysis on its own.<\/p>\n<\/div><\/div>\n<\/div><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-156b85af content-align-cta-default elementor-widget elementor-widget-eael-cta-box\">\n<div class=\"elementor-widget-container\">\n<div class=\"eael-call-to-action cta-basic bg-img cta-preset-1\">\n<p class=\"title eael-cta-heading\"><span class=\"eael-cta-title-text elementor-repeater-item-4182408\">Our customers detect<\/span> <span class=\"eael-cta-title-text elementor-repeater-item-49f9954\">post-breach attacks over<\/span> <span class=\"eael-cta-title-text elementor-repeater-item-bb4e738\">9x Faster<\/span> <\/p>\n<p>Detect Advanced Threats Before Damage Escalates TrustedCybersecurity Leader for 20+ YearsSee why security teams choose us over other solutions<a href=\"https:\/\/fidelissecurity.com\/get-a-demo\/\" class=\"cta-button cta-preset-1  \">Request a Demo<\/a><a href=\"https:\/\/fidelissecurity.com\/resource\/demo\/fidelis-elevate-in-action\/\" class=\"cta-button cta-secondary-button \">See Fidelis in Action<\/a>\t<\/p><\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-598e440 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<p class=\"elementor-heading-title elementor-size-default\">Citations:<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-1c43cdb elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/fidelissecurity.com\/#cite1\">^<\/a><a href=\"https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\" target=\"_blank\" rel=\"noopener\">https:\/\/www.nist.gov\/itl\/ai-risk-management-framework<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite2\">^<\/a><a href=\"https:\/\/doi.org\/10.6028\/NIST.AI.600-1\" target=\"_blank\" rel=\"noopener\">https:\/\/doi.org\/10.6028\/NIST.AI.600-1<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite3\">^<\/a><a href=\"https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\/nist-ai-rmf-playbook\" target=\"_blank\" rel=\"noopener\">https:\/\/www.nist.gov\/itl\/ai-risk-management-framework\/nist-ai-rmf-playbook<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite4\">^<\/a><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/regulatory-framework-ai\" target=\"_blank\" rel=\"noopener\">https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/regulatory-framework-ai<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite5\">^<\/a><a href=\"https:\/\/ai-act-service-desk.ec.europa.eu\/en\/ai-act\/article-15\" target=\"_blank\" rel=\"noopener\">https:\/\/ai-act-service-desk.ec.europa.eu\/en\/ai-act\/article-15<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite6\">^<\/a><a href=\"https:\/\/atlas.mitre.org\/\" target=\"_blank\" rel=\"noopener\">https:\/\/atlas.mitre.org\/<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite7\">^<\/a><a href=\"https:\/\/arxiv.org\/pdf\/2603.09002\" target=\"_blank\" rel=\"noopener\">https:\/\/arxiv.org\/pdf\/2603.09002<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite8\">^<\/a><a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/<\/a><a href=\"https:\/\/fidelissecurity.com\/#cite9\">^<\/a><a href=\"https:\/\/www.ibm.com\/reports\/data-breach\" target=\"_blank\" rel=\"noopener\">https:\/\/www.ibm.com\/reports\/data-breach<\/a>\t\t\t\t\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>The post <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/xdr-security\/ai-risk-management-across-network-endpoint-and-cloud\/\">How Fidelis XDR Supports AI Risk Management Across Network, Endpoint, and Deception Layers<\/a> appeared first on <a href=\"https:\/\/fidelissecurity.com\/\">Fidelis Security<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>AI systems are infrastructure now, and adversaries treat them that way, probing inference APIs, poisoning training pipelines, riding generative AI tools into the credential theft and lateral movement behind most breaches today. Fidelis Elevate\u00ae answers this with XDR delivered through three named products under one CommandPost: Fidelis Network watches the traffic, Fidelis Endpoint\u00ae watches the [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9085,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-9084","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9084"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9084"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9084\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9085"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9084"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9084"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}