The AI Exchange: Innovators in Payment Security Featuring Coalfire

Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchange information about how they are adopting and implementing artificial intelligence (AI) into their organizations.
In this edition of The AI Exchange, Coalfire Vice President, Andy Barratt, offers insight into how his company is using AI, and how this rapidly growing technology is shaping the future of payment security.
How has your AI strategy evolved over the past 12-18 months?
Dramatically! In the last 12 months, we’ve appointed Brad Little as our CEO, who joined us from Google, someone who has incredible passion for AI and Automation having seen the value it can drive firsthand. We then appointed a Chief AI and Data Officer, Dan Massersky, to oversee our AI platform roll out, governance, guardrails, and commitments to our clients. In the way many readers will probably expect from Coalfire, we’re leaning in so that we can support our clients with their AI journeys, too.
What is one AI initiative that has already delivered a measurable impact within your organization, and what made it successful?
One initiative has been the implementation of a standardized agentic platform that allows access to multiple frontier models as well as provide automation harnessing and sandbox capabilities. It still feels like we’re just scraping the surface, but there are many legacy systems that a combined AI/Automation harness can instantly help connect. There are often manual tasks that can quickly be automated without requiring vast amounts of AI, but that the AI provides a natural language interface to solving the problem and then the ability to write code, connect systems, or even what seems like trivial things like build macros for a spreadsheet or analyze disparate data sets.
How are you approaching AI governance, particularly around data privacy and security?
Our Chief AI and Data Officer reports directly to our CEO and updates the Board on our approach and any challenges we face. We want to make sure we are doing the very things we would tell our clients to do, top-down executive sponsorship, with a framework for successful, safe, and well governed use. Team members can’t access the tools without signing up to the acceptable use policy. We have an ongoing governance process to identify AI in other products we use outside our standard agentic platform so that we can manage any contractual obligations to *not* use AI or where required to disclose its use. The approved tool list is managed and reviewed as needed, our legal team is engaged regularly, and the tone from the leadership team is one of responsible execution with our customers at the center of what we do - even if it means they’re opting out of AI usage.
What challenges have become more apparent as AI capabilities have matured?
There are many challenges. Some are just misconceptions or a lack of understanding of how AI models can be deployed, whilst a lot of people have concerns around model prompt injection. We expect to see the harnesses, inference layer, and applications that integrate with them to be the new frontier for application security. These are simply products that have not been present in many enterprises over the last ten years, and as such, the application of security considerations is being overlooked. If you think in very simple terms of the AI Models providing a form of language translation, but the inference/harnesses and tools that send and receive data from the models as the layer the business applications generally integrate with, they could potentially be a gold mine for intruders. As a PFI, over the year I’ve seen some significant threats where internal systems have been used in a ‘living off the land’ type scenario – potentially the inference layers or the harnesses used to integrate with the models will be a great place to manipulate business processes from.
Imagine your underwriting application uses AI to support decision making, for loans or credit – and an intruder, instead of attacking the model looking for personal data, attacks the harness – and just changes the messages back and forth between the application and the harness. The intruder has a direct ability to control fraudulent activity. As these systems get increasingly embedded, we’ll need more consideration into how we verify and establish trust at both the model response and the inference layer so that line of business applications are not subject to interference and manipulation.
What advice would you provide for an organization moving from early AI adoption to broader implementation?
My advice would be to start from the top. Accept you’ve probably got some shadow AI right now that you’re not aware of but build up the governance in a way that allows for robust management while allowing your staff to learn and experiment. If staff have access to great tools and can use them to be more productive, the shadow AI issue becomes less prevalent. In simple terms, people stop paying to use their own tools when their employer provides them with a great stack to work within. If you have access to a good tool set at work, then you have less reason to use your personal one. Once the culture of safe and responsible AI use is intrinsically part of your operating model, sometimes the stick has to join the carrot! Restrict access to shadow AI tools from corporate endpoints to avoid sensitive data leaking to public AI providers and ensuring the corporate instances are used to keep the model usage private.
One other suggestion I’d certainly have for C-level executives is to learn a little about AI architecture. I’m sure many readers will have executives that have been through the ‘client / server, N-tier, cloud native, serverless’ journeys. Those have all had interesting differences that mean we have to rethink the way data is used and how the potential threats manifest. Similarly with AI, we have open-access public implementations. You have harnesses that can talk to public models. There are private implementations possible and a lot of permutations to understand, including completely ‘offline local’ approaches. Each has its own set of considerations for privacy and security.
What AI trend (not limited to payments) are you most excited about?
I’m a lifelong learner, so personally I like the idea that I can use AI to help learn more about areas I’m unfamiliar with. Taking complex material and approaching it with ‘explain it to me like I’m five’, is humbling and rewarding. I’ve seen the positive impact this has on my children during their exam study, working with personal AI assistants if they have struggled with some schoolwork. Simply having an AI assistant break things down into manageable chunks and iterate until they understand is hugely valuable.
What really excites me most in AI is not the chatbot layer. It is the chance to make systems integration practical in places where teams used to decide it was not worth the effort. For years, companies ringfenced legacy platforms behind APIs so newer systems could reach them safely. That worked, but every new integration still felt like a big project. MCP (Model Context Protocol) changes that. It gives systems a standard, secure way to expose functions that agents can discover and use. That means an agent can query an obscure dataset in one platform, act in another, and let a user orchestrate both using natural language queries.
The shift is economic as much as technical. Work that once looked too fiddly, too expensive, or was low on the priority list can now be delivered by an end user (almost!). Teams can move from idea to execution much faster, and that is where I think a lot of the real value in agentic AI will come from.


