All AI News
    IT ProFriday, September 4, 2026 2 min read
    AI

    Agents on the Frontline: How Box Is Using AI to Supercharge Cybersecurity

    Security teams using multi-model AI agents can finally outpace attackers—but fatigue and vendor lock-in remain real risks.

    Key takeaways
    • 01With 83% of enterprises running AI agents, Box CISO Heather Ceylan argues security teams now have a genuine edge over attackers—if they execute carefully.
    • 02Box deploys agents across SOC triage, log correlation, and secure software design reviews, with human judgment retained at escalation points.
    • 03Ceylan's emerging conviction: relying on a single model is a liability.
    • 04Vulnerability discovery now runs across multiple vendors to improve results and reduce dependency risk.
    Koko brief

    Security teams using multi-model AI agents can finally outpace attackers—but fatigue and vendor lock-in remain real risks.

    With 83% of enterprises running AI agents, Box CISO Heather Ceylan argues security teams now have a genuine edge over attackers—if they execute carefully. Box deploys agents across SOC triage, log correlation, and secure software design reviews, with human judgment retained at escalation points. Ceylan's emerging conviction: relying on a single model is a liability. Vulnerability discovery now runs across multiple vendors to improve results and reduce dependency risk.

    Watch: Whether multi-model agent architectures become a de facto security standard as single-vendor AI incidents accumulate.

    In brief · from itpro.com

    Findings from Box’s State of AI in the Enterprise survey show 83% of enterprises are now running agents in some capacity. These bots are enabling teams to drive productivity and efficiency, but as with any new technology, integration can be a challenge - and a security risk. Recent agent-related incidents in the tech industry have sparked concerns about long-term security implications.

    Read the full article at itpro.com
    Show the full text · 2 min read

    Findings from Box’s State of AI in the Enterprise survey show 83% of enterprises are now running agents in some capacity. These bots are enabling teams to drive productivity and efficiency, but as with any new technology, integration can be a challenge - and a security risk. Recent agent-related incidents in the tech industry have sparked concerns about long-term security implications. In this week’s episode of the ITPro Podcast, Ross Kelly and Bobby Hellard speak with Box CISO Heather Ceylan to discuss how Box is using agents internally, and how enterprises can adopt the technology in a safe and secure manner. Highlights “I think for security teams, we can finally, you know, start having the capacity to outpace these attackers. So we've got five core areas of investment for agents for our security team in particular that we've invested in over probably the last year, and we're starting to measure ROI on those right now. “So the first one is in the SOC. I think that's probably the most obvious choice where we've got a lot of operational work. We see the same kinds of incidents. We're automating the triage, we're automating the enrichment, the log correlation, things like that that take a lot of human effort. “But there's still human judgment in the end in terms of what gets escalated to be an incident and what doesn't.” Moving fast in the age of agentic AI “We're not going to be able to move fast enough. So, we have agents kind of built throughout our software development process, doing those security design and architecture reviews, and if you think about it, it’s way more powerful than a human can be because those agents don't just necessarily call out design flaws; they can enforce fixes for those flaws.” “Things are changing quickly. Sometimes it feels like you take two steps forward and then you read something in the news and you're like, oh my gosh, we need to rethink everything. “So I think a lot of security teams are really feeling that now and getting a little bit of fatigue from that.“ The benefits of a multi-model approach “One of the things that we're trying to carry across all of these that I wasn't really thinking about a year ago, but I'm thinking a lot about now is having that multi-model approach. “We're not in a place where most of the work we do, we can't be reliant on a single model. If you look at vulnerability discovery, we're moving away from being tied to any one specific vendor or any one specific model because you're going to get better results when you take a multi-model approach.” Related content The State of AI in the Enterprise report (Box) Box unveils new controls to secure AI agents How OpenAI models breached Hugging Face The OpenAI and Anthropic containment breaches are a bit spooky, but also quite silly CISOs are keen on agentic AI, but they’re not going all-in yet

    Don't miss tomorrow's

    The Daily Pulse in your inbox each morning — sourced and linked.

    How often
    Keep going — across the app