
Tackling your board's next big question
How CFOs guard against AI swarms
Sep 18 | 7 min read | By Tim Cooper
TLDR;
Rogue AI agents are causing real world damage to companies. CFOs are beefing up internal and external controls in response. But it’s no precise science; the threat is new and evolving fast.
Watch every tool: List every active AI agent, including connectors, access, authorities, and APIs. Set expiry dates so nothing runs unreviewed.
Auto kill: Embed real-time behavioral monitoring into the internal audit function.
Tighten access: Eliminate AI agent’s broad continuous access to ERPs, billing, and bank portals. Replace with minimum essential privileges.

60% of finance leaders admit they're spending more on AI than they can justify (and the other 40% probably haven't looked…)
And most AI cost data is a black box: complete, accurate, and only readable after the crash.
What protects CFOs is reading the box mid-flight. Among over-budget teams, same-day data cut serious consequences from 97% to 64%.
Same overrun, totally different meeting. That’s one of seven findings in CloudZero's survey of 260 finance leaders.

As if there’s not already enough “oh shit” events happening in the world, news broke recently that AI can now autonomously hack cyberdefenses. In part one, we looked at how this is happening in real companies today, and how it could impact finance functions.
Now, let’s get into how CFOs are dealing with the threat, starting with a real-life attack response.
Corina Tham, director of finance at Trading FX VPS, said her company recently encountered an attempted breach using coordinated AI agents to exploit her platform. But the team mitigated it with human analysis plus advanced AI monitoring, including real-time detection of irregularities such as in transaction behavior.
Tham recommended decentralizing your systems and backups, as swarm-like attacks thrive in centralized set-ups.
“We’ve witnessed how even smaller-scale AI-driven breaches can threaten critical financial infrastructures,” said Tham. But “our use of segmented environments and real-time anomaly detection cut service downtime by 87% compared to industry averages.”
New threat, new mindset
Cyberattacks are moving from instant penetration to complex models that adapt continuously, creating a much different risk.
In response, CFOs are collaborating across the org chart to develop defense strategies fast against malicious or rogue AI agents.
Guarding against AI-led threats requires CFOs to adopt a new mental model for internal control, said Tony Jarjoura, CFO at network security company Gigamon.
“People are still looking for typical phishing links or unrealistic looking videos. They’re not trained to tease out those small ripples. It requires different competencies and controls to prevent, detect and mitigate,” he said.
The CFO still operates like an American football quarterback, orchestrating strategies while others do the technical defense work, he added. “But AI means we have to dive into all sorts of new areas to ensure risk mitigation.”
Jarjoura recommended:
Focus on visibility over agent activities in tools and training. Inventory all your AI tools, including details such as models, connectors, data access, API calls, credentials, and monetary authorities.
Create an AI governance council so functions can articulate their risks and mitigations. Assign individuals to track AI token spend closely, and spot unexplained activity.
But is a committee really the answer? Sure, to monitor the right things are happening. But the real risk and response will be on the ground... Doing things like setting expiry and reaffirmation dates for agents, so nothing runs unrenewed.
Fencing in the risk
In a review of the recent rogue agent incident at Hugging Face, data security and governance provider Varonis said it was the first major case of attacker AI versus defender AI, fighting it out in real time. While robot wars may sound fun, it’s less so when the prize is the keys to your bank account.
To avoid or limit damage in such a scenario, Varonis recommended setting the following guardrails on AI agents:
Limit AI worker privileges to what’s strictly needed.
Keep app permissions isolated, even if they’re on the same server.
Review models and datasets downloaded from any shared server before they touch your infrastructure.
Guy Melamed, CFO of Varonis, said the biggest shift in mindset for CFOs is in understanding that sophisticated threats can now emerge with no external actors, or ill intent.
He recommended prioritizing data protection, regardless of which platform you use. He also recommended that security teams focus on human guardrails too:
As we roll out AI, what are our plans and mechanisms for protecting data?
Who can access documents such as payroll files or unpublished financial statements? How do we put a special perimeter around data with legal exposure; unpublished financials, payroll data, personal information?
If sensitive files were deleted or altered, how would we know?
“Don’t assume security teams have all this tracked and under control. Shockingly, many don’t,” said Melamed.
He also recommended scenario testing new breach types regularly so you can plan for different eventualities.
Constant checking for the earliest possible signs of unusual behavior has also become critical. For example, Hugging Face detected the OpenAI breach using anomaly detection, not a traditional attack alert.
“You can stop rogue agents by using real-time monitoring to constantly compare [their activity] to the rails and policies you’ve set, what those agents can and cannot do,” said Chandra Gnanasambandam, CTO at security platform SailPoint. “The moment you spot drift, disable them automatically. But first, you have to know what agents you have. Most organizations don’t know this.”
What can touch your finance stack?
Discussions in finance are focusing on attackers’ ability to use agent groups to search for weaknesses, share findings, and pivot quickly, said Tina Yeh, chief accounting officer at governance, risk and compliance platform Optro. They could also target your internal agents by misdirecting them, stealing their access, or using them to hide suspicious activity.
One risk is agents and service accounts sprawling unmanaged across your finance stack (a bit like random employees wandering around your bank vault unnoticed, Ed). For example, authentication keys may have continuous access to ERP and bank portals with no second factor, no expiry, and no owner, said Yeh.

AI tools can change behavior over time, quickly. So review them continually, including on any scope change, not just on an update or new release. Listing every tool that’s actually running (not just what’s approved) is dull but essential work.
“You can buy a product to monitor [tools]. But keeping an inventory is unglamorous manual work with no vendor to call. So it gets deferred and the monitoring tool watches an incomplete population,” said Yeh.
Find every tool in use, not just the approved list, and ask what it can reach.
For example, Yeh said finance needs to ask what can each AI tool reach in your ERP, billing system, and bank portals, and who’s in charge of that?
Identify hard to reverse actions, such as changing payment instructions, creating a new beneficiary, or giving an agent access to a sensitive system, said Yeh. Require extra verification or human approval at those points. Separate duties and set transaction limits, time delays for material changes, and escalation paths.
Keep auditable risk-based records of agent actions, such as systems accessed, decisions made, and changes triggered. So when something unusual happens you can see how.
Finally: “We should approve the access, not the tool. Most AI governance I see is a software approval process,” added Yeh. “We’re relying entirely on preventive controls at a moment when attackers have become good at satisfying them.”
How are you defending against AI-led cyber threats? Reply (non-publicly) with your anonymous stories.

Reading the room…
Here are some things you should start doing now to strengthen your tail for growing cyber risks
Fix human access first: Know exactly who can access, change, approve or move money across every critical finance system.
Kill weak access by default: No owner, MFA, minimum privilege, expiry or periodic reapproval? Remove the access.
Then inventory every agent: List every AI agent touching finance, including connectors, credentials, APIs, systems reached and actions it can perform.
Approve authority, not tools: Build access approval rules for humans and agents into new software approval. Approve exactly what each person or agent is allowed to read, change, approve or trigger.
Wall off sensitive data: Tier finance data. Banking, payroll, unpublished results and personal or regulated data should sit behind materially tighter permissions.
Protect irreversible actions: Require human approval for new beneficiaries, bank changes, material payments, payroll changes, unusual journals and similar high-risk actions.
Expire agent access: Every agent should have a named owner, defined purpose and expiry date. No reaffirmation, no continued access.
Monitor behavior continuously: Watch for unusual access, posting, payment or transaction patterns across both humans and agents.
Kill on breach: If predefined limits are breached, suspend access automatically first, then investigate.

Boardroom Brief is presented by The Secret CFO Network
Last week’s Playbook was part two of a month long series on, Inheriting a Shitshow Finance Function … (it’s all about flushing out the hidden problems.)
If you found this helpful, please forward it to your fellow finance leaders (and maybe even your Board). If this was forwarded to you, make sure you receive the next edition by subscribing here.







