Join our Newsletter — 33% off our NHI Course

LLM security and OWASP Top 10 2025: what changes for IAM teams

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Governance and runtime protection are paired with a 2025 State of AI Data Security Report, highlighting prompt injection, sensitive data disclosure, excessive agency, and unbounded consumption as the main enterprise risks, according to Cyera. The security model is shifting from policy intent to continuous enforcement because static controls do not reliably contain LLM behaviour in production.

Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “Securing LLMs: Cyera’s AI Guardian and the OWASP Top Ten 2025”.

By the numbers:

  • 86 percent of respondents say they’re concerned about AI leaking sensitive data, and two-thirds have already discovered AI tools accessing data they didn’t need.

Key questions

Q: How should teams govern LLMs that can initiate actions as well as generate text?

A: Treat action authority as a separate control plane from model output.

Q: Why do static policies fail to secure production LLMs?

A: Because the most important risk appears after deployment, when prompts, outputs, connected tools, and data flows interact in real time.

Q: What are the signs that an LLM is being misused or manipulated?

A: Common signs include unexpected completions, sudden shifts in tone, policy violations, and outputs that break normal guardrails or reveal rule-bending behavior.

Practitioner guidance

  • Map LLM data flows end to end Inventory prompts, retrieval sources, embedded apps, outputs, and downstream systems so you can see where sensitive data and tool access actually move.
  • Separate trusted instructions from untrusted content Design prompt handling so system instructions, user input, and retrieved context remain isolated and cannot overwrite one another at runtime.
  • Restrict model-initiated actions Apply least-privilege boundaries to tool calls, scheduling, and system changes so the model can only initiate the actions it genuinely needs.

Bottom line: Cyera’s article argues that LLM security depends on runtime enforcement because static policy cannot reliably contain prompt injection, disclosure, and excessive agency in production.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Static policy is the wrong control plane for production LLMs. Policy describes intent, but LLM risk is expressed in runtime behaviour: what the model ingests, reveals, and executes after deployment. That makes continuous enforcement the real governance layer, not the policy document itself. Practitioners should treat policy as necessary but insufficient.

A few things that frame the scale:

  • AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.
  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: How do runtime controls change the way security teams should measure LLM governance?

A: Measure whether the organisation can see, block, and redact risky behaviour in production, not just whether a policy exists. If dangerous prompts, outputs, or actions still move through the system, the governance model is not working.

👉 Read our full editorial: LLM security hinges on runtime controls, not static policy


This post was modified 4 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.