Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Governance Framework: How to Build One That Works

An AI governance framework proves itself the first time somebody asks for proof. The gap that sinks most programs sits under the policy, in the layer where nobody can say which identities reach sensitive data through an AI tool. Ownership, approval paths, control mapping, and live access visibility are what separate a working framework from a well-formatted document, and right now most organizations are missing at least one of the four. AI reaches most organizations through several doors at once.

Microsoft Entra ID monitoring: Detecting suspicious activity

Entra ID monitoring correlates sign-in, audit, and privileged-role activity to expose suspicious identity changes while evidence still exists. Native controls leave gaps in retention, licensing, and correlation, so resilient teams export data, baseline admin behavior, and connect to Entra ID, Privileged Identity Management (PIM), OAuth, Conditional Access, and on-premises Active Directory events in a single workflow.

AI Governance Auditing for Security and IT Teams

AI governance auditing distinguishes between a documented policy and a working control. The audit traces one AI output back through the identity that invoked it, the data it reached, the guardrail that applied, and the record retained afterward. Most programs fail because access is ineffective: nobody can say which identities access sensitive data through an AI assistant, let alone prove the limit is held.

To self-host or not to self-host your password manager

For an individual, self-hosting a password manager is rarely realistic. Most people don't run servers, handle patching, or manage uptime, so a cloud vault ends up being the only practical choice. For an organization, self-hosting becomes a real decision, one your security and IT teams can make deliberately. And once you can choose, you also take on the risks and the responsibility that come with that choice.

Threat Lab Quarterly: August 2026

Netwrix formed a dedicated in-house Security Research team on July 15, 2025, led by Huy Kha, Director of Security Research. The team includes Senior Staff Security Researcher Darryl Baker, a recognized authority on Active Directory and identity security. They research identity, data security, AI, and cloud threats, with the goal of translating security research into practical improvements across Netwrix's product portfolio.

The AI challenge most companies don't have

A few months ago, I attended a GC AI Summit hosted by Harvard Law School. As expected, there was plenty of discussion about AI tools, governance frameworks, emerging regulations, and the future of the legal profession. One topic of discussion stood out above the others: Most organizations only need to think about how they deploy AI, whereas we have to think about how we deploy AI and how we develop AI.

What is DLL hijacking, and why your new AI plugin might be the easiest way in

DLL hijacking is a decades-old Windows vulnerability class (Mitre Att@ck T1574) getting new life from AI plugins bolted onto legacy desktop apps. Attackers plant a malicious DLL where a vulnerable app will load it instead of the real one, inheriting that app's privileges. To detect it, watch for DLLs loaded by name from writable folders. To prevent it, you have to fix the app's load-order logic or blocking untrusted DLLs at the endpoint.

Netwrix Auditor named to two 2026 Capterra Shortlists

Netwrix Auditor earned a spot on the 2026 Capterra Shortlist for Cybersecurity Software and Compliance Software, plus a 2026 Software Advice FrontRunners placement. The recognition is grounded in 200+ verified reviews, with a 4.5 out of 5 rating and 95% positive feedback. Auditor is used by professionals across 13,000+ organizations, including 120+ Fortune 500 companies, who use it to unify visibility across hybrid IT environments and produce audit-ready evidence in real time.

Intune still can't bare-metal image a device, and other things nobody told IT

Organizations pushed toward Intune are hitting the same wall regardless of industry or size. Intune doesn't manage servers, can't do bare metal imaging, still lacks the OU-style hierarchy and delegation Group Policy admins are used to, and covers a fraction of the settings Group Policy has supported for 20 years, though that gap has narrowed. That's why so many IT teams are stuck running Group Policy and Intune side by side years past their planned cutover.