“Ultimately, our goal is to help enterprises move from experimenting with AI to deploying it confidently at scale, without losing control over what their AI agents can do,” says Edward Chen, NCS Chief AI Officer.
Image:
Edward Chen, NCS Chief AI Officer
While Singapore continues to see innovation in AI development and deployment, cybersecurity concerns are also mounting. Specifically, there are two major shifts that NCS, a Singaporean-headquartered solutions provider is seeing in cybersecurity.
First, cyber threats are evolving as attackers adopt AI. Second, as enterprises deploy agentic AI, they are introducing a new class of autonomous digital actors that must be secured and governed.
These trends also come with several challenges that NCS is looking to help customers deal with. According to Edward Chen, NCS Chief AI Officer, the first challenge is balancing speed with safety.
“Customers want to capture the benefits of AI without slowing innovation. We believe good governance actually enables speed. Rather than debating risks for every deployment, NCS helps enterprises establish reusable governance frameworks, with controls proportionate to the consequences of AI decisions and actions,” he said.
The second challenge is agent identity and accountability. Chen explained that traditional zero-trust, identity management and privileged access management provide a strong foundation, but AI agents introduce new complexities.
“Agents can be created rapidly, operate autonomously and delegate tasks to other agents. Every agent must therefore have a verifiable identity, clearly defined authority, an accountable human owner and auditable actions. Autonomy must not mean anonymity or an absence of accountability,” he explained.
The third challenge is continuous assurance. Unlike conventional software, Chen shared that AI agents can behave unpredictably in different contexts. He added that NCS has built continuous assurance capabilities to test agents for prompt injection, excessive agency and unsafe tool use before deployment, while extending guardrails, monitoring and oversight into production.
“Ultimately, our goal is to help enterprises move from experimenting with AI to deploying it confidently at scale, without losing control over what their AI agents can do,” he said.
Dealing with autonomous and rogue agents
According to Chen, as autonomous AI agents take on greater operational agency, rogue or compromised agents represent a very real cybersecurity risk for organizations across Asia. He explained that when an agent gains autonomy to execute code, access internal data, or transact across systems, any unintended drift or malicious manipulation can cascade rapidly into operational disruption.
As such, he feels that organizations must prepare for this shift by moving away from reactive patching to adopting an end-to-end Agent Development Lifecycle (ADLC) approach. He also feels that essential security and ethics guardrails must be engineered into the foundational architecture from day zero.
At the same time, Chen believes that enterprise leaders must maintain absolute operational control. This includes establishing an effective kill switch for rogue agents requires governance to be architected at both the runtime and platform layers. A reliable kill switch combines real-time anomaly detection, zero-trust privilege boundaries, and dynamic quarantine policies to instantly isolate an agent without disrupting the broader business ecosystem.
“Managing rogue agent risks requires building engineering rigour into AI deployments from day one. At NCS, we address this through Sunshine.core, our enterprise AI platform that provides a reusable, sovereign-ready foundation to build and operate enterprise-grade AI agents within a single control plane. Complementing this is Sunshine.Guardian, an AI safety and assurance engine that continuously tests AI agents for safety and security risks at every release while generating audit-ready compliance evidence. By embedding repeatable, automated testing around non-deterministic AI behaviour, enterprises can safely unlock the transformational power of autonomous agents,” Chen explained.
The human factor in cybersecurity
For Chen, in the current threat landscape, the key element driving cybersecurity strategy is speed with control. With machine-speed threats powered by generative and agentic AI moving far too quickly for manual incident response, defending against today’s automated, highly evasive AI threats requires upgrading security controls beyond legacy frameworks to modern AI-powered Security Operations Centres (SOCs) capable of autonomous threat intelligence, real-time telemetry analysis, and automated counter-defence.
“AI-powered defence relies directly on the strength of the underlying data strategy. AI algorithms require clean, contextual, and high-fidelity enterprise data to spot subtle anomalies. A robust data strategy breaks down information silos and ensures security AI models have transparent, unified visibility across endpoints, clouds, and agent networks, significantly mitigating attack surfaces,” Chen said.
As AI takes on more of the detection and execution work, Chen also believes that humans must fundamentally shift towards strategic governance: setting the direction through foresight, defining the parameters, and owning the outcomes.
“Security professionals must think one step ahead by predicting how threat vectors will evolve, refining defensive governance, and training AI models to anticipate tomorrow’s risk scenarios. At NCS, our perspective centres on human-led, AI-augmented digital resilience: placing intelligent automation at the frontline while empowering human teams to remain the ultimate strategists, ensuring speed maintains control,” he concluded.
