Thales Group - Experts & Thought Leaders
Latest Thales Group news & announcements
Thales announces an expanded collaboration with Google Cloud to help enterprises address emerging security and governance challenges associated with agentic AI, bringing integrated protection, visibility, and policy enforcement to AI-driven workflows on Google Cloud. The integration of Thales AI Security Fabric with Google Cloud Gemini Enterprise helps organizations apply security, governance, and visibility across interactions among users, agents, models, and tools in real time. Next generation of enterprise AI “Enterprises are moving from AI assistants to AI agents that can autonomously take action, make decisions, and interact with critical business systems. This requires a fundamentally different approach to security,” Eva Rudin, Senior Vice President, Cybersecurity Products, at Thales, said. “By expanding our collaboration with Google Cloud, we are helping organizations build the necessary trust with security and governance as the foundation required for the next generation of enterprise AI.” As enterprises move beyond AI experimentation and begin deploying autonomous agents at scale, traditional security approaches are struggling to keep pace. Unlike conventional applications that operate within predefined workflows, AI agents can reason, plan, decide and act with other agents dynamically, creating new attack surfaces and governance challenges. Agentic AI lifecycle According to industry analysts, securing agentic AI has emerged as one of the most pressing challenges facing enterprise AI adoption, as organizations seek to balance innovation with security, compliance, and trust. The expanded collaboration between Thales and Google Cloud is designed to help organizations address emerging risks across the agentic AI lifecycle, including prompt injection, sensitive data leakage, unsafe outputs, unauthorized actions, and increasingly complex agent-to-agent interactions. Sensitive business systems As enterprises connect AI agents to sensitive business systems and critical data, they create a broader and more dynamic attack surface than traditional security architectures were designed to manage. For example, AI agents tasked with settling insurance claims could exceed their mandate by using personal information from outside approved sources to influence payouts, creating privacy and compliance risks. Thales AI Security Fabric applies controls around agents to keep them within authorized boundaries, limit data access, and block inappropriate actions in real time. This unified security layer provided by Thales AI Security Fabric works across interactions to help organizations enforce policy, detect AI-specific threats, maintain visibility into agent behavior, and support governance requirements. With this foundation in place, organizations can deploy AI agents to execute legitimate business workflows while mitigating the risks associated with an expanding attack surface. AI-related risks “Google Cloud helps enterprises move from experimenting with AI agents to deploying them securely across their businesses,” Vineet Bhan, Director of Security and Identity Partnerships, Google Cloud, said. “As agents become more capable and connected to critical data and systems, customers need security and governance built into how they operate. Our work with Thales gives organizations additional capabilities to protect agentic AI workflows and adopt this next generation of AI with greater confidence.” Thales AI Security Fabric helps organizations securely scale AI by providing visibility and control over how AI systems and agents access data, interact with one another, and take action across the enterprise. It enables businesses to discover and assess AI-related risks, protect sensitive information, help prevent unauthorized or unsafe actions, and ensure AI activity aligns with organizational policies and user intent. Centralized governance and compliance capabilities also give security and business leaders greater confidence to expand the use of AI while maintaining appropriate oversight.
Thales, the cybersecurity pioneer that protects critical applications, APIs, and data, anywhere at scale, releases the “Economic Impact of API and Bot Attacks” report. The analysis of more than 161,000 unique cybersecurity incidents uncovers the rising global costs of vulnerable or insecure APIs and automated abuse by bots, two security threats that are increasingly interconnected and prevalent. The report estimates that API insecurity and bot attacks result in up to $186 billion of losses for businesses around the world. Automated API abuse The report is based on a study conducted by the Marsh McLennan Cyber Risk Intelligence Center which found that larger organizations were statistically more likely to have a higher percentage of security incidents that involved both insecure APIs and bot attacks. Enterprises with revenues of more than $1 billion were 2-3x more likely to experience automated API abuse by bots than small or mid-size businesses. The study suggests that large companies are particularly vulnerable to security risks associated with automated API abuse by bots because of complex and widespread API ecosystems that often contain exposed or insecure APIs. Digital services Data from the Imperva Threat Research team finds that the average enterprise managed 613 API endpoints Enterprises rely heavily on APIs to enable seamless communication between diverse applications and services. Data from the Imperva Threat Research team finds that the average enterprise managed 613 API endpoints in production in 2023. That number is growing rapidly as businesses face mounting pressure to deliver digital services with greater agility and efficiency. 30% of API attacks Due to this increased reliance and their direct access to sensitive data, APIs have become attractive targets for bot operators. In 2023, automated threats generated by bots accounted for 30% of all API attacks, according to data from Imperva Threat Research. Automated API abuse by bots costs organizations up to $17.9 billion in losses annually. As the number of APIs in production multiplies, cybercriminals will increasingly use automated bots to find and exploit API business logic, circumvent security measures, and exfiltrate sensitive data. Holistic approach “Businesses across the world must address the security risks posed by insecure APIs and bot attacks, or they face a substantial economic burden,” says Nanhi Singh, General Manager of Application Security at Imperva, a Thales company. “The interconnected nature of these threats necessitates that companies take a holistic approach, integrating comprehensive security strategies for both bot and API attacks.” Report trends Some of the key trends identified in the report include: Increased API adoption and usage are growing the attack surface: The rapid adoption of APIs, the inexperience of many API developers, and lack of collaboration between security and development teams have led insecure APIs to result in up to $87 billion of losses annually, a $12 billion increase from 2021. Bots negatively impact organizations’ bottom line: The widespread availability of attack tools and generative AI models has enhanced bot evasion techniques and enabled even low-skilled attackers to launch sophisticated bot attacks. Up to $116 billion of losses annually can be attributed to automated attacks by bots. API and bot-related security incidents are becoming more frequent: In 2022, API-related security incidents rose by 40%, and bot-related security incidents spiked by 88%. These increases were fueled by a rise in digital transactions, the expanding use of APIs, and geopolitical tensions like the Russia-Ukraine conflict. In the following year 2023, as digital traffic began to stabilize and the pandemic-driven surge in internet activity subsided, the frequency of these incidents moderated. API-related security incidents grew by 9%, while bot-related security incidents jumped by 28%. The overall upward trend in attacks highlights the growing persistence and frequency of these threats. Insecure APIs and bot attacks pose a significant threat to large enterprises: Companies with revenue of at least $100 billion are most likely to suffer security incidents related to insecure APIs or bot attacks. These threats constitute up to 26% of all security incidents experienced by such businesses. Countries around the globe are vulnerable to API and bot attacks: Brazil experienced the highest percentage of events related to insecure APIs or bot attacks, with the threats accounting for up to 32% of all observed security incidents. This was closely followed by France (up to 28%), Japan (up to 28%), and India (up to 26%). While the percentage of events attributed to API and bot-related security incidents was lower in the United States, 66% of all reported events related to vulnerable APIs or automated abuse by bots occurred within the country. Generative AI applications “Reliance on APIs will continue to grow exponentially, driving connections to generative AI applications and large language models,” adds Singh. “At the same time, generative AI will also empower cybercriminals to create sophisticated bots at an accelerated and alarming rate." "As API ecosystems expand and bots become more advanced, organizations should anticipate a significant rise in the economic impact of automated API abuse by bots unless proactive measures are taken.”
Thales, the global technology and security provider announced the SafeNet IDPrime FIDO Bio Smart Card, a security key that enables strong multi-factor authentication (MFA) for the enterprise. This new contactless smart card allows users to quickly and securely access enterprise devices, applications, and cloud services using a fingerprint instead of a password. Stealing credential challenges According to the 2023 Verizon Data Breach Investigations Report, the three primary ways in which attackers access an organization are stolen credentials, phishing, and exploitation of vulnerabilities. 49% of all breaches involved stolen credentials. With these threats top of mind for organizations moving to the cloud, many are grappling with low user adoption of MFA, which is often cited as cumbersome. SafeNet IDPrime FIDO Bio Smart Card The smart cards also support contactless capabilities, which allows users to simply tap the card The SafeNet IDPrime FIDO Bio Smart Card facilitates end-user adoption of passwordless MFA, allowing users to easily enroll and authenticate using biometrics. Instead of using a password, users can access with a fingerprint, using the on-card sensor. The smart cards also support contactless capabilities, which allow users to simply tap the card on any device supporting NFC. For enterprise users, this smart card provides multiple benefits including better speed, security, and convenience than traditional passwords. Data privacy Using these security keys, users can be assured of strong protection against account takeover and phishing on enterprise devices. User biometrics are securely stored in the card’s chip and never leave the smart card itself, ensuring a strong level of data privacy. This solution can be used for all digital resources supporting the FIDO2 standard, including Windows, Mac, Linux, and more. FIDO security keys Thales is a pioneer in biometrics, proving success with contactless biometric payment cards in highly regulated sectors. The addition of the SafeNet IDPrime FIDO Bio Smart Card further enriches its existing portfolio of FIDO security keys providing enterprise customers with the same secure biometric capabilities. MFA adoption as a barrier The human factor continues to be a challenging pain point in the modern enterprise, with shifts to remote work" Danny de Vreeze, Vice President, Identity and Access Management Products at Thales, “The human factor continues to be a challenging pain point in the modern enterprise, with shifts to remote work and the cloud expanding many organizations’ attack surfaces." "MFA adoption has been a common barrier to ensuring security, as many users find it cumbersome and choose to bypass it." Physical form factor "The SafeNet IDPrime FIDO Bio Smart Card helps to solve this challenge, introducing a physical form factor to strengthen security, while also providing a user experience that is both quick and seamless." "Adding to a strong portfolio of FIDO-supported security keys and solutions, this product is on the cutting edge of phishing-resistant authentication.”
Insights & Opinions from thought leaders at Thales Group
The global biometrics market has been recently developing rapidly, and this trend will continue shortly. If in 2018 its volume was estimated at $23.4 billion, according to the forecast of the analytical company BCC Research, the market size may increase to $71.6 billion with an average annual growth rate of 23.2 % by 2024. Fingerprint scanning, facial recognition, iris, vein, and voice technologies are expected to be implemented at the fastest pace. The analysis is based on the revenue indicators of key players depending on segments, including hardware, software, and integration. Biometric electronic documents Another analytical Agency, Acuity Research, estimates that the number of biometric electronic IDs will increase by about 3.5 billion electronic documents in the world. Moreover, more than half of the UN member States issue biometric passports. Government and private contracts of Canada, the United States, Belarus, Ukraine, Moldova, Lithuania, Hungary, Bangladesh, Senegal, and other countries are examples of implementation of programs for the transition to biometric electronic documents. Government organizations in various countries believe that biometrics is one of the most effective ways to identify refugees and those who cross the border. Now there are a lot of projects which are based on biometric technology. Biometric identification system Perhaps one of the most ambitious is the Aadhaar project being implemented in India Perhaps one of the most ambitious is the Aadhaar project being implemented in India. It is a biometric identification system that contains the data of more than a billion people. The database contains about 10 billion fingerprint templates, two billion iris templates, and a billion photos. There is another ambitious project at the Nairobi Jomo Kenyatta International Airport, where RecFaces company has implemented a passenger facial identification ready-made solution, that helps the security guards to receive notifications about airport visitors in just a few seconds and increase the efficiency of security services at least by 30%. The introduction of biometric identification of passengers aimed at increasing the level of airport security, as well as quickly obtaining information about the detection of wanted persons, stored in the long-term archive. Automated control gates As another example, face match is used at border checks to compare the portrait on a digitized biometric passport with the holder's face. In 2017, Thales company was responsible for supplying the new automated control gates for the system of Automated Fast Track Crossing at External Borders at Roissy Charles de Gaulle airport in Paris. This solution has been devised to facilitate evolution from fingerprint recognition to facial recognition This solution has been devised to facilitate evolution from fingerprint recognition to facial recognition during. Governmental systems, SmartCity, airports projects using identification technologies day by day become our reality and influence the growth of the biometrics market globally. Countries are studying the experience of each other and adopting it. Paperless payment technologies The global market of biometrics will shift all industries, starting from the transportation facilities especially airports, where a transition from traditional VMS and ACS to paperless biometric self-Boarding systems will be carried out. Sports facilities will see the development of paperless payment technologies at cash desks, and the banking sector — the payment systems with remote customer identification. HoReCa will transfer from staff time tracking systems to biometric payment systems, biometric check—in systems and the use of biometric identifiers. To sum up there are two most significant drivers of this growth are surveillance in the public sector and numerous other applications in diverse market segments.