Summary
The session’s core message is that agentic AI should be secured using lessons from insider risk: once AI systems receive identity, access, tools, and autonomy inside an organization, their failure modes can resemble the risks created by trusted employees. The speakers opened with a recent AI-driven ransomware investigation handled by their computer emergency response team. They found Claude-generated reports and even an authorization letter giving the attacker apparent permission from the organization. Unlike a linear ransomware attack through one route, this case involved multiple attack paths running in parallel across cloud environments, applications, identities, and databases. More than 95% of the attack was attributed to AI, included over 50 victim-specific scripts, and unfolded in hours.
Key Topics
5 key topics from Rob Berends and Inge van der Beijl at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Reduce attack surface before AI accelerates adversaries.
- Correlate low-risk signals across networks and applications.
- Rehearse incident response under compressed AI-driven timelines.
- Map agent controls to insider-risk failure modes.
- Match AI models carefully to task complexity.
“An AI agent is a system that uses an AI model to pursue a goal autonomously.”
Up Next

Next in agenda
The hype is killing kittens, but not that grumpy old cat
Edwin van Andel

Related
0 incidents, 0 sensors: governing the risks no one owns

Related
Flatline vs. Recovery: Responding to Ransomware Attacks on Healthcare
Marina Bochenkova