Enterprises that have been rapidly adding AI tools and services into their workflows are often not prepared for the internal and external threats that could expose weaknesses in their systems, analysts said.
“I don’t think they are ready,” said Pete Shoard, chief of research for cybersecurity at Gartner. “I think the underlying thing here is that we’ve been doing the same thing for so long — and it hasn’t been working — that it’s time for a change.”
External threats can emerge when sensitive information leaks to large language models (LLMs) without users realizing the problem. AI tools could also wind up uploading sensitive files to public repositories like GitHub.
“The number one risk at the minute is hard-coded secrets being uploaded through vibe-coded applications to GitHub, and then providing a route in [to a company],” Shoard said.
As a result, companies need to get ahead of the curve by detecting internal and external threats before they materialize. That’s led to renewed interest in attack surface management tools, which assess internal and external systems to predict and prevent possible attacks.









