ClearTech Loop: In the Know, On the Move

ClearTech Loop: Marcus Cylar on Why Cybersecurity Fundamentals Still Matter

August 11, 2026

Download Transcript (pdf)

AI Agents Are New. The Security Fundamentals Are Not.

As ClearTech Loop shifts the conversation toward AI governance, Marcus Cylar makes the case that securing an agentic workforce may start with something decidedly less new: getting the fundamentals right. 

The conversation around AI is changing. 

We have spent plenty of time asking what AI agents can do, what could go wrong and who should be accountable when they act outside their intended authority. 

Now the questions are getting more practical. 

How do we govern AI agents? How do we control their access? Does leadership fully understand the risk? And what should enterprises actually do next? 

That shift is where this new season of ClearTech Loop begins. 

I recently sat down with Marcus Cylar, a cybersecurity professional focused on governance, risk and compliance, security awareness and building stronger security cultures. 

 Listen to the full episode: https://www.buzzsprout.com/2248577/episodes/19628135

Watch more ClearTech Loop episodes: https://www.youtube.com/@ClearTechResearch 

Marcus Cylar LinkedIn profile: https://www.linkedin.com/in/marcusacylar/

The Fundamentals Still Matter for AI Agent Security

AI agents can hold delegated credentials, make decisions in real time and operate across multiple systems. That has led many security leaders to conclude that traditional identity and privileged access tools were not built for this environment. 

Marcus offered some immediate pushback. 

The technology may be new, but the fundamental responsibility of cybersecurity has not changed. Organizations still need to protect the confidentiality, integrity and availability of their systems. 

Least privilege still matters. Role-based access still matters. Separation of duties, approval workflows, logging and clearly assigned ownership still matter. 

Before declaring existing security models obsolete, enterprises should ask a harder question: 

Have we consistently implemented the controls we already know we need? 

As Marcus put it: 

“That path starts with a passionate return to the fundamentals of cybersecurity.” 

Marcus Cylar quote about returning to cybersecurity fundamentals for AI security.

That idea carried through the rest of our conversation. 

AI governance is not only a technical problem. It is also a culture problem. 

Employees are already using AI in their daily work, often faster than formal policies can be developed or approved. Marcus argues that organizations need stronger security awareness, but they also need an environment where employees can be honest about the tools they are using. 

That means security teams cannot simply become the Department of No. 

Shadow AI can be a security risk, but it can also be a signal that employees have needs the organization has not addressed. If workers believe they will be punished for admitting they are using an unapproved tool, leadership will never have an accurate view of what is happening inside the business. 

And governance without visibility is not much governance at all. 

AI Governance Starts With Knowing What You Have  

When I asked what a CISO starting from zero should do in the next 30 days, Marcus did not recommend forming another committee or buying another platform. 

He recommended starting with inventory. 

Before an organization can build an AI inventory, it needs a reliable inventory of its existing systems and tools. From there, security leaders need to understand which systems already include AI agents, what permissions those agents have, who owns those controls and whether any of those permissions should be revoked. 

Then comes the harder part: asking employees what additional AI tools they are already using. 

That requires trust. 

Leaders need to make it clear that the goal is discovery, not punishment, and then treat those answers as signals about what their workforce is trying to accomplish.   

AI governance framework showing system inventory, AI agents, permissions, ownership and shadow AI.

As enterprises move deeper into agentic AI, I am watching whether organizations apply least privilege to agents as consistently as they do to people, whether they understand which approved platforms have added AI capabilities, and whether they treat shadow AI as simply an employee problem or as evidence of an unmet business need. 

The companies that manage this transition successfully may not be the ones with the newest AI security products. 

They may simply be the ones with the clearest inventory, strongest fundamentals and enough organizational trust to understand what is really happening.  

What This Conversation Makes Clear About AI Governance 

AI governance cannot live only in a policy document or steering committee. 

It has to show up in permissions, workflows, ownership, workforce training and everyday decisions about how technology is used. 

AI agents may require new controls. But those controls will not compensate for weak security fundamentals or a culture where employees are afraid to tell the truth. 

You cannot govern what you cannot see. You cannot secure what no one owns. And you cannot uncover shadow AI if employees believe honesty will be punished. 

Stay in the Loop 

Subscribe to the ClearTech Loop newsletter for new conversations on AI security, governance, cloud strategy and cyber risk. 

https://www.linkedin.com/newsletters/7346174860760416256

Watch full episodes and subscribe to ClearTech Research on YouTube. 

https://www.youtube.com/@ClearTechResearch