
Guarding Agentic AI
“Attackers' agents don't need a security review, and that asymmetry worries me”
Noam Vander, CISO at Atera, joined CTech to share his thoughts on agentic AI security, and why he thinks the real threat isn't AI agents misbehaving, but attackers using them as a force multiplier against defenses built for human speed.
“Malicious actors weaponizing AI agents,” said Noam Vander, CISO at Atera, on his biggest fear about agentic AI's rollout in the tech industry.
“The same autonomy that makes agents productive makes them a force multiplier for attackers: automated reconnaissance, phishing at scale, adaptive attacks running at machine speed against defenses built for human speed. Attackers' agents don't need change management or a security review, and that asymmetry worries me. It's why defense has to become agentic too.”
CTech reached out to a spread of Israeli companies to find out how they're actually handling agentic AI security, and whether local security leaders are ahead of the curve on the risk, or simply closer to it.
Are any AI agents currently operating with real autonomy?
“Internally, yes, with tiered autonomy. We're an AI-first company, so agents are used daily across R&D, support, and operations, and some act with real autonomy: triaging alerts, running enrichment, opening tickets, executing low-risk, reversible actions without waiting for a human. Anything destructive, security-sensitive, or touching production still requires human approval. We also live this question on both sides: our product's AI agent resolves IT tickets end to end, so agentic autonomy is our core business.”
What security controls are in place versus on the roadmap?
“In place: a lot, because agent security was a day-one requirement, not an afterthought. Employees complete dedicated secure AI training. Every agent is hardened and runs with granular permissions and least privilege. An AI Security Posture Management (AISPM) platform gives us visibility and control over our AI estate, and our SOC monitors agent activity like any privileged identity. Everything is anchored to ISO 42001, so AI governance is a certified management system, not a policy document.
"On the roadmap: the threat landscape moves fast, so we keep monitoring it, hardening agents against emerging techniques, and applying our guardrails in new ways as agent use cases grow.”
Have you had an incident or near-miss?
“None. That's not luck, it's the result of securing agents from the design phase. Identity, permissions, and guardrails were built in before any agent went live, so the classic failure modes, over-permissioned agents, unmonitored actions, output flowing straight into privileged operations, were never possible in our environment. We didn't have to learn these lessons the hard way.”
Where has AI already made things better or safer?
“Two places. In security operations, internal agents handle tier-1 triage: enriching alerts, correlating signals, closing false positives. That freed the team for real threat hunting and improved response times.
"And in our own IT, using our product: tickets are resolved faster, employees are happier, and IT got its time back. Instead of drowning in password resets, the team focuses on tier 3-4 issues and proactive projects. That's the real promise of agentic AI, not replacing the team, but elevating what it works on.”














