Cyber Defense Magazine: How to Keep Your Organization Secure When Implementing Open-Source AI
Cyber Defense Magazine’s April issue featured insights from NetSPI Advisory CISO & Managing Director, Phil Morris, on how organizations can securely adopt open-source AI. He outlined key strategies including strong governance, cross-functional collaboration, employee training, and red teaming to help companies mitigate emerging AI risks while driving innovation. Read the preview below or view it online.
+ + +
As organizations integrate open-source GenAI models and tools to accelerate innovation and enhance productivity, executives and security leaders need to be aware of the inherent security risks these tools pose. To put this into perspective, in February 2019 there were a little more than 10,000 open models available on Hugging Face, the online AI open-source repository. As of mid-February 2025, there are nearly 1,500,000. That level of growth means an increased potential for bad actors to introduce vulnerabilities into your ecosystem if you are implementing, or plan to implement, open-source AI. To mitigate potential risks, there are steps companies should take in order to best protect against today’s latest threats. Let’s explore what those are.
You can read the full article here.
Authors:
Explore More News
NetSPI and Synack to Merge, Forming A Leading Offensive Cybersecurity Platform
September 2, 2026 – NetSPI®, a global leader in modern penetration testing, and Synack, a global leader in continuous security validation, today announced a definitive agreement to merge and form the industry’s leading offensive cybersecurity platform. The combination brings together two of the premier expert-led offensive security organizations and integrates agentic AI across the combined platform to deliver continuous testing and validation at enterprise scale.
NetSPI Expands Suite of AI-Powered Continuous Pentesting Services as Organizational Attack Surfaces Grow
NetSPI expands suite of Human-Led, AI-Powered Continuous Pentesting Services, including a first-of-its-kind AI Findings Validation service, as well as continuous testing for web applications and internal networks.
AI’s Role in the Next Era of Pentesting
This article discusses how AI can accelerate penetration testing, but without human expertise to validate findings and apply business context, organizations risk confusing faster output with stronger security.