Protect AI. Protect the business from AI.
Artificial intelligence is becoming part of business operations through assistants, autonomous agents, SaaS applications, APIs and integrations with internal systems. At the same time, attackers are using AI to make fraud, impersonation, social engineering and cyberattacks more convincing, faster and easier to scale.
DEC works with organisations across both areas: securing AI-powered systems and protecting the organisation against the new threats enabled by artificial intelligence.
Security for assistants, agents and AI systems
We assess the security of AI assistants, chatbots, autonomous agents and Large Language Model applications by analysing not only the model itself, but the entire application chain: data, APIs, connected tools, identities, permissions and accessible business systems.
Test scenarios
- Prompt injection and indirect prompt injection, including model manipulation through documents, websites, emails and external content.
- Data exfiltration and information leakage, with particular attention to confidential data, credentials, internal documents and intellectual property.
- Abuse of connected tooling, where an AI agent can access email, databases, files, cloud environments, APIs, administrative tools or business applications.
- Privilege escalation and excessive permissions, determining what the AI system can do compared with what it is intended to do.
Application chain and dependencies
- Autonomous agent manipulation, including unexpected behaviour caused by malicious inputs, untrusted sources or chained actions.
- Insecure output handling, where model output is consumed by downstream systems without sufficient validation.
- System information exposure, including internal prompts, configuration, knowledge bases and data used for RAG or fine-tuning.
- AI supply-chain risk, covering dependencies on models, providers, plugins, APIs and third-party services.
The goal is not simply to determine whether a model responds correctly, but to understand the operational consequences of an AI system being manipulated or compromised.
AI Agent Security
An AI agent does more than generate text: it may read documents, query databases, send emails, modify tickets, invoke APIs, create files or interact with business infrastructure. DEC therefore assesses AI agents as privileged components of the IT architecture.
Assessment areas
- Identities and privileges assigned to agents.
- Separation between users, agents and systems.
- Access to sensitive data and tools.
- The ability to chain actions into unintended outcomes.
- Controls around high-impact operations.
- Logging, auditability and decision traceability.
- Approval mechanisms and human-in-the-loop controls.
- The ability to rapidly contain or disable a compromised agent.
Protection against AI-enabled threats
AI security is not only about protecting systems that use artificial intelligence. It is also about recognising and containing attacks in which AI is used against the organisation.
Audio and video deepfakes
Impersonation of executives, employees, suppliers or customers using synthetic voice or video to authorise payments, obtain information or bypass internal procedures.
AI-powered phishing and spear phishing
Highly personalised and linguistically convincing messages generated using public or compromised information about the organisation.
Advanced Business Email Compromise
The combination of email, synthetic voice, messaging and contextual information to make attacker impersonation significantly more convincing.
Digital impersonation
Automated creation of identities, conversations, documents, images and falsified content designed to deceive employees and business processes.
Automated social engineering
Campaigns capable of adapting their language, tone and strategy in real time according to the victim’s responses.
Cyberattack automation
Use of AI to accelerate reconnaissance, vulnerability analysis, payload development, credential discovery and activity inside compromised environments.
Deepfakes and impersonation: securing business processes
When dealing with deepfakes, determining whether a voice or video looks real is not enough. Defence must be built into business processes.
DEC analyses high-risk workflows — payments, bank-account changes, credential resets, system access, urgent executive requests, data transfers and administrative changes — to identify where a synthetic identity could turn into an actual security incident.
Technical and procedural controls
- Independent-channel verification.
- Strong authentication for sensitive operations.
- Segregation of duties.
- Multi-party approval.
- Digital identity verification.
- Anomaly detection.
- Protection of communication channels.
- Impersonation containment procedures.
The objective is to ensure that even a perfectly convincing deepfake is not enough to compromise the organisation.
Shadow AI and loss of control over corporate data
AI tools and chatbots are often adopted directly by employees before the organisation has defined how they should be used. Confidential documents, source code, contracts, customer information and operational data may therefore be transferred to external services without centralised control.
Reducing Shadow AI risk
- Identifying which AI tools are being used.
- Assessing what information can be shared with them.
- Determining which providers and models can be authorised.
- Identifying which data must be blocked or anonymised.
- Reviewing which integrations can access internal systems.
- Defining technical controls that can restrict unauthorised use.
The objective is not to prevent the use of AI, but to make it controllable, auditable and appropriate to the organisation’s risk profile.
AI Security Assessment
DEC can perform a dedicated assessment of an organisation’s AI exposure.
Engagement scope
- Mapping AI systems and tools currently in use.
- Analysing integrations with corporate data and systems.
- AI- and agent-specific threat modelling.
- Prompt injection and data-exfiltration testing.
- Verification of agent privileges and operational capabilities.
- Shadow AI risk analysis.
- Assessment of exposure to deepfakes and impersonation.
- Review of business processes vulnerable to AI-enabled fraud.
- Review of logging, auditing and incident-response controls.
- Remediation prioritisation.
At the end of the assessment, DEC provides a clear view of the vulnerabilities identified, their operational impact and the controls required to reduce the associated risk.
AI Red Teaming
For critical AI systems, DEC can simulate realistic attack scenarios.
AI Red Teaming examines how assistants, agents and integrations behave when deliberately exposed to malicious inputs, manipulated content and attempts to abuse their capabilities.
The objective is to determine what an attacker could achieve: accessing confidential information, inducing an agent to perform operations, bypassing safeguards, abusing connected tools or exploiting trust relationships between systems.
A new attack surface
An AI system can simultaneously be an application that must be secured, a privileged identity, an interface to sensitive data and a tool available to attackers.
AI security therefore cannot be treated as an isolated control. DEC combines cybersecurity, offensive security, identity security, infrastructure, incident response and business continuity expertise to assess the impact of AI across the entire organisation.
Assessing your AI exposure
If your organisation uses assistants, agents, Copilot, chatbots, language models or AI integrations — or if you want to understand how exposed your business processes are to deepfakes, impersonation and AI-enabled attacks — DEC can assess the real-world risk and define the controls required to contain it.