Google Cloud、AI 時代におけるセキュリティ基本の重要性を強調
本文の状態
日本語全文を表示中
詳細モードで約11分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Google Cloud AI
Google Cloud の Chris Betz は、2026 年 8 月のニュースレターで、AI 時代においてセキュリティの基本に依存することが以前にも増して重要であると説明した。
AI深層分析を開く2026年8月22日 01:56
AI深層分析
キーポイント
AI 時代のセキュリティ基本原則の再評価
Chris Betz は、AI が敵対者の能力を加速させる一方で、従来のセキュリティ基本原則が不要になるという誤解が一般的であることを指摘し、その重要性を強調している。
攻撃者と防御側の AI 活用による変化
AI は自動化の限界を超え、両者とも大規模かつ高度に特化した動作を前例のない速度で実行可能にする catalyst(触媒)となっている。
CISO が直面する課題と戦略
CISO の役割は、新しい AI 技術を安全に導入しつつ、敵対者のスピードに合わせて本質的で効果的な防御慣行を拡張することにある。
攻撃対象領域の縮小と防御AIの文脈強化
これらの技術は集団的に攻撃対象領域を縮小し、防御AIがビジネスの推進役となるために必要な深い文脈を提供する。
AI駆動型防御の成功条件の創出
これらはAIを活用した防御を成功させるための必要不可欠な環境を整備する役割を果たす。
重要な引用
It's a dangerous and unfortunately common misconception that traditional security fundamentals are becoming obsolete.
For CISOs, the challenge is to adopt new AI technology securely while scaling essential, effective defensive practices to move at the speed of the adversary.
Collectively, these technologies reduce the attack surface and contribute to the deep context that defensive AI needs to be a business enabler — and create the necessary conditions for successful AI-powered defenses.
Adversaries are deploying new malware with just-in-time AI that dynamically generates malicious scripts and obfuscates code mid-execution to evade detection.
編集コメントを表示
編集コメント
この記事は、技術的な新機能の発表ではなく、AI 時代におけるセキュリティ戦略の根本的な考え方を問うものである。組織が AI の導入を進める中で、基礎的な防御体制を見直す重要性を再認識させる内容となっている。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
2026 年 8 月の第 1 回 Cloud CISO Perspectives にようこそ。今回はクリス・ベッツが、AI の時代においてセキュリティの基礎に立ち返ることの重要性がいっそう高まっている理由を解説します。
Cloud CISO Perspectives は、他のニュースレターと同様に Google Cloud ブログ に掲載されています。ウェブサイトでこの記事をお読みで、メール版を受け取りたい場合は、こちらから購読 できます。
AI 時代にセキュリティの基礎をどう維持するか
*クリス・ベッツ氏(Google Cloud CISO)*

AI が攻撃者の能力を加速させる中、基礎的なセキュリティの強さが「レジリエンス(回復力)」と「脆弱性」を分ける主要な要因となっています。従来のセキュリティの基礎が時代遅れになりつつあるという考えは、危険であり、かつ残念ながらよくある誤解です。
CISO にとっての課題は、新しい AI テクノロジーを安全に導入しつつ、本質的で効果的な防御プラクティスを拡張し、攻撃者のスピードに合わせて動くことです。
攻撃者側も防御者側も、AI は最適化とイノベーションの触媒となっています。従来の自動化が大量の反復作業を可能にしたのに対し、AI は両者が極めて具体的でカスタマイズされたアクションを、かつてない規模と速度で実行することを可能にします。これらの技術は集合的に攻撃対象領域(アタックサーフェス)を縮小し、防御用 AI がビジネスを推進する役割を果たすために必要な深い文脈を提供すると同時に、AI 駆動の防御が成功するための必要条件も整えます。
脅威の発生は、ほぼリアルタイムで進行しています。敵対者は、実行中に動的に悪意のあるスクリプトを生成し、コードを難読化して検知を回避する「その場限りの AI」を活用した新しいマルウェアを展開しています。また、身元盗用やビジネスメール詐欺のために、高度な音声フィッシング(ヴィッシング)やディープフェイクを利用するケースも増えています。さらに、許可されていない AI ツールの利用が「シャドウエージェント」と呼ばれる存在の台頭を招く事例も見られます。
AI を活用したセキュリティ脅威に対抗するには、既存のセキュリティ慣行を加速させるだけでは不十分です。根本的なセキュリティ基盤と多層防御を見直し、再構築する必要があります。正しいガードレールを設けた多層防御を構築し、長年投資してきた基礎的なサイバーセキュリティの構成要素を活用することが極めて重要です。
この基盤への注力をさらに強化します。具体的には、多要素認証(MFA)、ゼロトラストフレームワーク、一貫したシステムパッチ適用、そして包括的な検知と対応技術です。これらを総合的に活用することで攻撃対象領域を縮小し、防御 AI がビジネスの推進役として機能するために必要な「深い文脈」を提供します。その結果、AI を活用した効果的な防御を実現するための必要条件が整います。
脆弱性管理の革命
わずか数年で、脆弱性の特定と修正は、主に手作業に頼る手間のかかるプロセスから、AI ツールが以前にもない規模で脆弱性を発見するプロセスへと進化しました。さらに、攻撃者が脆弱性を悪用できる時間的余裕(エクスプロイト・ウィンドウ)は実質的に消滅しました。
しかし、今日のような膨大な量の脆弱性を前に、単に発見するだけでは不十分です。まずはシステムやネットワークに最も深刻な影響を与えるものから優先的に修正し、それに対応してスマートな緩和策を迅速に講じる必要があります。組織では複数のモデルを用いて欠陥を検出し、エンジニアがすぐに本番環境へ導入できる高品質なコード修正案を提示します。これには AI 脅威防御 のような機能を活用しています。
AI を活用することで、発見からテスト、デプロイに至るまでのソフトウェア開発ライフサイクル全体を自動化でき、標的となる脅威よりも速く防御態勢を進化させることが可能になります。
脅威モデリングの強化
また、脅威モデリングという基本概念にも大きな影響が現れています。効果的な脅威モデリングには、コード、クラウドアーキテクチャ、システム設計、ネットワーク経路などから文脈を統合する必要があります。これは容易ではありませんが、AI を活用することで、これらのデータを統合して一貫した全体像を描き出す能力をスケールさせることが可能になります。
チームは、システム情報の収集や脅威の列挙のためにマルチ AI モデルの実験を続けています。私が 6 月に指摘した通り、Google Cloud のエンジニアリングチームは現在、製品ローンチにエージェントベースのセキュリティレビューパイプラインを導入しています。高リスクの兆候は自動的に人間によるレビュー対象としてフラグが立ち、静的な脅威モデルに代わり、リアルタイムで更新される動的なプロダクトドシエールを採用しました。
CISO は戦略的なビジネスリーダーである
私が知る中で最も効果的なセキュリティリーダーたちは、単なる技術者ではありません。彼らは戦略的なビジネスリーダーです。AI の脆弱性に対する世界的な関心の高まりにより、サイバーセキュリティはかつてないほど取締役会や経営陣の最前線に位置づけられています。この注目度は、リーダーシップを発揮する絶好の機会です。CISO には、取締役会から C レベル、そして日常業務で彼らに依存するセキュリティチームに至るまで、明確なコミュニケーションが求められます。AI の複雑さをナビゲートしながら組織の成長を守る能力を持つ、有能な戦略家としての資質を示すことが必要です。
セキュリティの基本原則をビジネス目標と整合させ、AI を活用して防御力を強化することで、私たちは組織を安全に未来へと導くことができます。
AI エラにおいて強固なセキュリティ基盤を構築・維持する方法について詳しく知りたい方は、最新の Defender's Advantage: Cyber Snapshot Report をご覧ください。
見逃した方へ
今月のセキュリティチームからの最新アップデート、製品、サービス、リソースをご紹介します。
- Wiz で AI 脅威への備えを強化: AI エラに向けて組織の準備を整えるため、可視性を拡大し対応を加速する新しい Wiz の機能を発表しました。これにより、セキュリティチームは機械並みの速度で防御を行えます。**詳しく読む**。
- 平文での PQC: Google Cloud のポスト量子暗号化ロードマップ: 当社は長年、インフラにおけるポスト量子暗号化の取り組みと展開を積極的に進めてきました。2029 年までに PQC への移行を行う、更新された Google Cloud のロードマップをご紹介します。**詳しく読む**。
Google Cloud のセキュリティ対策と最新動向
Google Cloud では、新たな脅威の検知、封じ込め、防御をどのように行っているかをご紹介します。必要なツール、ガバナンス、インフラストラクチャを提供し、ワークロードの安全なデプロイと長期的な信頼の維持をサポートしています。
プライバシーを最優先した医療 AI と MedPerf、Google Cloud の連携
Google Cloud と MedPerf が機密計算(Confidential Computing)を活用し、セキュアでプライバシーを重視した協働型の医療 AI 評価を実現する方法をご紹介します。
暗号解読の進展が、かえってセキュリティを強化する
最先端 AI モデルの近年の進歩は、暗号技術の崩壊を意味するものではありません。むしろ、これらは追加の「暗号解析者」として捉えるべきです。
多層防御で Chrome を悪意ある通知から守る仕組み
Chrome Security が Firebase Cloud Messaging(FCM)や Safe Browsing と連携し、通知の悪用を大幅に削減し、すべてのユーザーにとってウェブエコシステムのセキュリティと品質を向上させた取り組みをご紹介します。
Google Cloud のセキュリティブログでは、今月公開されたその他のセキュリティ関連記事もぜひご覧ください。
脅威インテリジェンスニュース
敵対的 AI に対抗するためのエージェント型ソースコードレビュー: Google Cloud で採用しているアプローチに類似したエージェント型の防御策を実装する支援のため、私たちは初めて「Agentic Vulnerability Discovery Harness(AVDH)」のアーキテクチャの詳細を公開します。AVDH は、CodeMender の継続的なスキャンと併用することで、二層構造の防御戦略を構築することも可能です。
2026 年前半のクラウド脅威ハイライト: 2026 年の前半、Wiz の研究チームと CIRT(Computer Incident Response Team)は、数千ものクラウド環境に影響を与える脅威を追跡しました。活動量の顕著な増加が確認され、サプライチェーン攻撃は過去に例を見ない規模で発生。また、開発者向けツールチェーンや AI インフラストラクチャに対する注意も高まっています。
パッケージの補強:サプライチェーン侵害への対策ガイド
GTIG と Mandiant は、ここ数年にわたりオープンソースソフトウェアのサプライチェーンを標的とした攻撃が継続し、かつ増加していることを把握しています。ここでは、顧客サポートを通じて得た知見も踏まえ、ソフトウェアサプライチェーンを保護するための緩和策と強化推奨事項をご紹介します。
複数ブランドを狙う音声詐欺による恐喝:金融サービスおよびエンタープライズクラウド環境が標的
テレメトリデータとインフラ分析から、脅威グループ UNC6671 は解散しておらず、Redact、Pink、Helix、Falcon といった複数の恐喝戦線に活動を広げていることが明らかになりました。同グループは依然として音声詐欺(ボイシング)を主な手段とし、企業の従業員を狙い続けています。
Keyv および Cacheable の npm パッケージがサプライチェーン攻撃で乗っ取られる
Wiz Research は、複数の keyv/cacheable npm パッケージに影響を与えるソフトウェアサプライチェーン攻撃の調査を継続中です。
「Metabase SQL インジェクションの内部:野外で悪用される」では、Wiz が AI を活用して Metabase の CVE-2026-72898 を逆解析し、防御策の加速を図った取り組みについて解説しています。詳しくは こちら。
今月の脅威インテリジェンス記事については、Google Cloud ブログもぜひご覧ください。こちらからアクセスできます。
今週の注目:Google Cloud のポッドキャスト
- Cloud Security Podcast: Project Atlas と Wiz の AI 脆弱性研究について: Wiz の脆弱性研究責任者、Near Orfeld 氏が、クラウドインフラにおける高影響ゼロデイ脆弱性の発見に多エージェント AI システムをどう活用しているかについて語ります。こちらで聴くことができます。
- Cloud Security Podcast: Google が大規模な脆弱性クラスを排除する方法: AI がコードを書き、レビューする時間がない状況でもセキュリティが維持されるよう、Google スケールの堅牢な基盤をどう築くか。Google のシニアセキュリティエンジニア、Christoph Kern 氏が、AI エラにおける「設計段階からのセキュリティ(secure-by-design)」の真意を探ります。こちらで聴くことができます。
Cloud CISO Perspectives を月2回お届けするニュースレターにご登録いただくと、最新のお知らせを直接お受け取りいただけます。登録はこちら。数週間後には、Google Cloud からのセキュリティ関連アップデートをお届けします。
原文を表示
Welcome to the first Cloud CISO Perspectives for August 2026. Today, Chris Betz explains why the AI era makes it more important than ever to lean into security fundamentals.
As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.
aside_block
- ), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', )])]>
How to stay strong with security fundamentals in the AI era
By Chris Betz, CISO, Google Cloud

As AI accelerates the capabilities of adversaries, foundational strength becomes the primary differentiator between resilience and vulnerability. It’s a dangerous and unfortunately common misconception that traditional security fundamentals are becoming obsolete. For CISOs, the challenge is to adopt new AI technology securely while scaling essential, effective defensive practices to move at the speed of the adversary.For both attackers and defenders, AI has been a catalyst for optimization and innovation. While traditional automation has allowed us to perform repetitive tasks at scale, AI enables both sides to execute highly-specific, customized actions at massive scale and unprecedented speed.
Collectively, these technologies reduce the attack surface and contribute to the deep context that defensive AI needs to be a business enabler — and create the necessary conditions for successful AI-powered defenses.
We can see the threat developing almost in real-time. Adversaries are deploying new malware with just-in-time AI that dynamically generates malicious scripts and obfuscates code mid-execution to evade detection. They use sophisticated vishing and deepfakes for identity theft and business email compromise. We even see unauthorized AI tools lead to the rise of shadow agents.
Defending against AI powered security threats requires more than accelerating current security practices; it means stepping back and beginning with the security foundation and layered defenses. It’s critically important to build and use a layered defense with the right guardrails — foundational cybersecurity building blocks that we’ve been investing in for years.
Doubling down on this foundation: technologies like multi-factor authentication (MFA), Zero Trust frameworks, consistent system patching, and comprehensive detection and response. Collectively, these technologies reduce the attack surface and contribute to the deep context that defensive AI needs to be a business enabler — and create the necessary conditions for successful AI-powered defenses.
Revolutionizing vulnerability management
In just a few short years, identifying and fixing vulnerabilities has evolved from a mostly laborious, manual process to one driven by AI tools discovering vulnerabilities at volumes never seen before. Further, the time to exploit window has essentially been eliminated.
However, it’s not enough to merely discover vulnerabilities, especially at today’s volumes. You still need to prioritize fixing those that have the most critical impact on your systems and networks first, and that necessitates an equally-rapid response in smart mitigation.
Organizations use multiple models to scan for flaws and then suggest high-quality code fixes that engineers can quickly move into production, leveraging capabilities like AI Threat Defense. AI allows us to automate the entire software development lifecycle, from discovery to testing and deployment, ensuring that our defensive posture evolves faster than the threats targeting us.
Enhancing threat modeling
We’re also seeing the fundamental concept of threat modeling have an outsized impact. Doing threat modeling well requires bringing context together from your code, your cloud architecture, system design, and network pathways.
While it isn’t easy, using AI can scale our ability to bring that data together into a coherent picture. Teams have been experimenting with multi-AI models to collect system information and enumerate threats.
As I noted in June, engineering teams at Google Cloud now route product launches through an agent-based security review pipeline. High-risk indicators automatically get flagged for human review, while we’ve replaced static threat models with dynamic product dossiers that update in real-time.
The CISO as a strategic business leader
The most effective security leaders that I know today are more than just technologists: They are strategic business leaders. The intense global focus on AI vulnerabilities has brought cybersecurity to the forefront of boardroom and executive attention like never before.
This visibility is an opportunity to lead. We CISOs are expected to communicate with clarity, from the board to the C-suite to the security teams who look to them on a daily basis, demonstrating their ability as capable strategists who can navigate the complexities of AI while safeguarding the organization's growth.
By aligning security fundamentals with business objectives and using AI to enhance defense, we can lead our organizations securely into the future.
To learn more about building and maintaining strong security foundations in the AI era, read our newest Defender’s Advantage: Cyber Snapshot Report.
aside_block
), ('btn_text', 'Watch now'), ('href', 'https://www.youtube.com/watch?v=CmGWIwgHR60'), ('image', )])]>
In case you missed it
Here are the latest updates, products, services, and resources from our security teams so far this month:Driving AI threat readiness with Wiz: Announcing new Wiz capabilities that can help organizations prepare for the AI era by expanding visibility and accelerating response, so your security teams can defend at machine speed. Read more.
- PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap: We’ve long been actively working on and rolling out post-quantum cryptography in our infrastructure. Here’s our updated Google Cloud roadmap to migrate to PQC by 2029. Read more.
- How Google Cloud detects, contains, and protects against emerging threats: Learn more about how Google Cloud empowers you with the tools, governance, and infrastructure you need to securely deploy workloads and maintain long-term trust. Read more.
- Privacy-first medical AI with MedPerf and Google Cloud: Discover how Google Cloud and MedPerf use Confidential Computing to enable secure, privacy-first collaborative medical AI evaluation. Read more.
- More cryptanalysis makes us all safer: Recent advances in frontier AI models do not signal the downfall of cryptography. Here’s why they’re best viewed as additional cryptanalysts. Read more.
- How layered defenses harden Chrome against abusive notifications: Learn how Chrome Security has collaborated with Firebase Cloud Messaging (FCM) and Safe Browsing to significantly reduce notification abuse, and improve the security and quality of the web ecosystem for everyone. Read more.
Please visit the Google Cloud blog for more security stories published this month.
aside_block
- ), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', )])]>
Threat Intelligence news
Staying ahead of adversarial AI through agentic source code review: To help defenders implement agentic approaches similar to our approach at Google Cloud, we are sharing the details of our Agentic Vulnerability Discovery Harness architecture for the first time. AVDH can also be used alongside CodeMender’s ongoing scanning to create a two-layered defense strategy. Read more.
- Cloud threat highlights from the first half of 2026: In the first half of 2026, Wiz's Research and CIRT teams tracked threats affecting thousands of cloud environments. We saw a notable increase in the volume of activity, with supply-chain attacks running at a previously unseen scale and developer toolchains and AI infrastructure drawing serious attention. Read more.
- Batten down your packages: Mitigation guidance for supply chain compromise: GTIG and Mandiant have tracked ongoing and increasing open source software supply chain compromise campaigns over the past several years. Here are our mitigation and hardening recommendations to secure software supply chains, including insights we have developed as a result of supporting customers. Read more.
- Multi-brand vishing extortion targets financial services and enterprise cloud environments: Telemetry and infrastructure analysis reveal that UNC6671 has not disbanded. Instead, the threat group has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon and continues to rely on voice phishing to target enterprise employees. Read more.
- Keyv and cacheable npm package hijacked in supply chain attack: Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages. Read more.
- Inside the Metabase SQLi: Exploited in the wild: Wiz has reverse engineered Metabase CVE-2026-72898 with AI to accelerate defense. Here’s what we learned. Read more.
Please visit the Google Cloud blog for more threat intelligence stories published this month.
Now hear this: Podcasts from Google Cloud
- Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Near Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
- Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.
To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み