Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • AI

UltraViolet Cyber Launches AISec Study, First Benchmark for AI Security


UltraViolet Cyber Launches AISec Study, First Benchmark for AI Security
  • by: Business Wire
  • |
  • August 31, 2026

UltraViolet Cyber (UltraViolet), the only security operations partner that unifies red, blue and purple team capabilities into one integrated offering, today released findings from its AISec Study, an inaugural, interview-based benchmark of how organizations are actually securing and governing enterprise AI.

Each engagement delivers a private report, benchmarking the organization against industry patterns and peer practices, together with prioritized recommendations for closing the gaps that matter most.

Quick Intel

  • UltraViolet Cyber introduces AISec Study, first practitioner-led benchmark for enterprise AI security based on confidential interviews.
  • Methodology similar to BSIMM measures what organizations actually do, not what framework says they should do.
  • Findings span banking, financial services, enterprise software, healthcare, manufacturing, hospitality, government and nonprofit.
  • Governance & Policy strongest capability, AI Incident Response weakest; breadth 86% started vs 59% depth-weighted repeatable.
  • Sharpest gap in AI-driven development lifecycle: all approved AI coding assistants but zero have repeatable tracking of AI-written code.
  • Only one organization has detection for automated AI-driven attack behavior; 80% observed agent identity controls but zero fully established.

Evidence-Based View Replacing Guesswork with Data

Most AI security guidance today is prescriptive, drawing on standards and checklists that describe what a program should look like. The AISec Study is different: It draws on a methodology similar to BSIMM (the Building Security In Maturity Model), a long-established benchmark for software security programs. The company designed the AISec Study to measure what organizations actually do, not what a framework says they should do.

"This study gives security leaders something the industry hasn't had: a clear, evidence-based picture of where AI security programs actually stand, not where a checklist says they should be," said Aravind Venkataraman, VP of Technology and AI Security, UltraViolet Cyber. "The pattern is consistent across every organization we assessed: the decisions have been made, and now the work is building the engineering and assurance to back them up. That's exactly where we help close the gap between tested and detected."

Engineering and Depth Still Catching Up to Governance Decisions

UltraViolet found that Governance & Policy was the strongest capability, while AI Incident Response was the weakest, and Direction & Oversight, Assurance & Protection and Engineering & Usage averaged in the middle — a consistent split between deciding what to do with AI and building the controls that defend it.

The gap shows up again when breadth is measured against depth. On average, participating organizations have started roughly 86% of the framework's activities but are depth-weighted at about 59% — a large difference between beginning a control and making it repeatable and enforced. Starting a control is the easy part; standardizing it is where coverage scores are won or lost.

The study's sharpest finding centers on how software now gets built. Every organization in the study has approved a variety of AI coding assistants, which is the single most adopted control observed. But the controls that would make that AI-driven development lifecycle accountable are still emerging: no organization has established a repeatable way to track which code an AI agent wrote, screen that code for license and IP risk or detect automated attacks targeting AI systems. Only one organization in this study has established detection for automated, AI-driven attack behavior.

Participants also aligned on the same open problem: giving non-human AI agents their own identities, scoping what they're allowed to do and containing the blast radius when something goes wrong. That capability was observed in some form at 80% of organizations, but was fully established at zero.

"The AISec Study gave us visibility into more data-driven insights to measure and improve our AI initiatives," said Sandy Blackwell, Global Senior Director, Software Security, 74 Software. "This allows us to compare our practices against those of other organizations, and helps identify potential gaps as well as gauge what to prioritize in terms of improvements."

 

About UltraViolet Cyber

UltraViolet Cyber is the only security operations partner that unifies red, blue, and purple team capabilities into one integrated team  finding what's vulnerable, stopping active threats, and validating that your defenses hold under real pressure. Built by former U.S. intelligence community operators with 30+ years of experience, we serve 400+ Global 2000 enterprises and federal agencies. Our practitioner-led and AI-accelerated closed-loop operations turn offensive findings into defensive weapons immediately so gaps close in real time and defenses improve before attackers can exploit what testing uncovers. Offense informs defense. Defense sharpens offense. Security that gets smarter and stronger with every iteration.

  • AI SecurityEnterprise AICyber Security
News Disclaimer
  • Share
Enterprise Tech News