The Agentic Edge is a Tenet Security interview series where we sit down with security leaders to hear what they’re actually seeing, building, and worrying about as AI agents move into production. In this episode, we talk with Ravi Nori, Head of Cybersecurity at Gopuff.
For the video version, click here.
Introduction
Question: Please introduce yourself
I’m Ravi Nori. I’m the head of cybersecurity at Gopuff, so I handle all aspects of cyber here for the company.
Before that, most of my experience has been defense and aerospace. Predominantly in respect to cybersecurity, I have a strong aviation based background. I’ve worked in really highly regulated industries. Gopuff is my first startup, and first retail experience. It’s been markedly two different environments, but Gopuff as a retail consumer, very front facing, is doing really well. Generates $1.8 billion worth of business here in the US and UK. Presented a lot of challenges as well too. It’s been a great ride here for almost five years.
The CISO Role
Question: What’s the thing that mosr surprised you about the CISO role?
The job is more political than it is technical. It’s more organizationally based than it is really making sound technical decisions. If I was to pass on lessons learned, I think the mistake that a lot of security leaders make is not understanding the business deeply, not understanding operations.
For example, because I have to do PCI audits, I go out to the physical stores that we have. We own two liquor store chains, huge here in the US, Beverages and More, and Liquor Barn. Getting the opportunity to go out into those stores and talk to managers and talk to employees is vital to understanding the business. On the Gopuff side, I’ve gone to the fulfillment centers and done the same thing, talking to the staff in the back stocking the shelves and making sure that we have enough product. But also the drivers, understanding what their experiences are when they do deliver. My wife and I are avid Gopuff customers. I think that’s very, very important. There’s not one facet of the business that I’ve not touched.
I drew that from my experiences in defense where I work with soldiers in the field. Or in aviation, going on the plane, seeing our products installed, working with installers, working with the mechanics, understanding how the aviation protocols work at even a physical level. I think that’s really, really important. That’s something that I see lacking in the industry. There’s always context to whatever technology you bring in. That will shape and define how successful you are in the company.
Framing Risk to the Board
Question: How are you framing agentic AI risk for executive leadership?
One is to understand, and this goes back to the political, that we are not gonna be blockers of adding agentic AI or third party gen AI tools to the company. I think that’s very, very key. One, for a personal reason, is that I’m using these tools at scale. I’m also building MCP servers for personal use. I would hope to deploy a personally built cloud agent in my personal environment. There are very useful tools. It’s been the most helpful, I would say, for my job.
It’s very important that you embrace new technology and you look forward to how we can best use it. But I do have a job, I need to make sure that we’re doing it securely. The main thing is to do it from the customer perspective. Our customers expect a secure experience. They don’t want their PII, PCI data compromised.
I don’t pitch it from a fear mongering aspect, or “hey, if we don’t do this, doomsday’s coming”. That’s not a very good way of doing it. I also try to pick technologies that will add some other core benefits beyond just security and monitoring. This is why I love Tenet. Tenet provides a different level of workflow on the AI agents that we build. If engineering embraces these tools, they can work with it to make their development better.
Friction Between Security to Engineering
Question: How do you deal with the friction between security to engineering? Do you have tips for other CISOs dealing with the same issue?
Trying to get buy-in first is one thing, but sometimes that’s not available to you. Then I think it’s understanding what the technical integration would mean. Would it affect other groups, do I need to bring in other groups to do the integration? That shapes the types of technologies to try to bring in. That kind of lends me towards SaaS based solutions, agentic based solutions, solutions that are working passively in the background that don’t require a lot of technical integration between cross groups. I don’t have to bring in DevOps and the guys who are handling payment schemes, etc., into these conversations.
Tenet has done a really great job in making that integration seamless. Being at the API base. It was very, very easy to integrate, it took minutes. That shapes the technology I bring in. But that comes into me understanding the business, me understanding how this organization works, how to get buy-in, and three, having a strong technical understanding of what works for us and what doesn’t.
So if it required me installing an agent, for example, into our subscriptions, I always say no. Because yes, I can do that integration, but I don’t want to. One, it’s complex. It’s a layer of complexity that you don’t need anymore.
And then understanding our budget constraints, which I’m intimately aware of. As a budget holder, I have to be aware of the resistance that I’m going to face. What teams like finance and legal wanna know is, hey, what ROI am I getting from this? Part of the ROI is, am I getting the right customer support? Is it easy to integrate, and does it affect other teams at scale? If I can give a positive answer for those three criteria, I will more than likely get buy-in for the product.
Agentic Risk Categories
Question: Which agentic risk category do you think the industry is most focused on, and which is it most underestimating?
I’m gonna quote Tenet again because I’m not an AI expert. Working with the Tenet team and getting so technical and doing the integration, helped me understand AI and what the risks are to our business. For me, it doesn’t really matter what it is at scale, it’s what is relevant for Gopuff. In the end that’s all I care about.
What I would say is I was really surprised at the volume and sophistication of prompt injection attacks. And the fact that people are trying it, it’s not just a bot. These are actual persons trying to do this on our app, that are using our app most likely as consumers, just to see. It is hard to tell what’s outta curiosity, or were they really trying to damage our mobile app. But they are doing it. I think that was shocking, to see the level and sophistication of those attacks.
The leads who are leading engineering, when Nevo and Barak were able to present that data to them, they were blown away at the amount that was happening. The industry as a whole needs to acknowledge that these things are happening at scale. If you don’t have guardrails around it within the onset of your development, you should be asking up front. For example, we’re using 3rd-Party Customer Service Agents. What are they doing from a security standpoint? The answer is really not much. They don’t have those guardrails in place to maybe prevent somebody from actually doing a prompt request that has some malfeasance to it on the onset.
Maybe they need to be doing more on protecting the data that they log. And ensuring that they’re redacting certain types of PII and PCI information, which they’re probably not. Don’t just assume that the agentic AI companies that you’re working with to develop these agents are actually doing their due diligence. That’s probably the biggest takeaway that I have gotten out of this. It was shocking.
Opinion on AI & Security
Question: Have you changed your mind about anything in the last 12 months when it comes to AI and security?
I would say I have gotten more educated. From that statement I made before, we do need another third party tool to come in and at least help us with our assumptions, that hey, when we sign a contract with somebody, maybe we should have asked those questions up front. That was something that normally I would look at contractual terms sent from legal. Okay, they’re not gonna take our data. But maybe as the CISO I should have asked a few more questions, now that we’ve actually had some direct experience. And not assume that those third parties are going to do secure due diligence. Maybe they shouldn’t, because that’s not the focus of what they do. I do get familiar with technologies like Tenet that are doing just that, making sure those guardrails are in place. Working with Tenet and some other technologies that I’ve been able to bring in, it’s gonna force me to ask more pointed questions before we sign contracts with people.
Simply, you’re (third party) taking log data from us, obviously for every transaction that comes in, any interaction with the customer. What are you doing with that log data? One of the things that Tenet observed is that people, in their frustration of not getting their order, are putting their credit card data in full. Now that data is stored on the 3rd-Party Customer Service Agents side in a log file, but we are responsible for that data because the 3rd-Party CS Agents. is in our stack. In the end, we own that data. The 3rd-Party CS Agents don’t redact that data, or that sensitive information. In the end, we’re the ones who are gonna suffer for that. It’s a brand risk for us.
It’s really, really important to have those conversations up front. What are you doing with log data, which nobody really thinks about. From a developer standpoint, you’re looking at it to solve problems. As a security professional, I’m gonna assume that you’re gonna redact that data in the logs, but maybe I shouldn’t have made that assumption. We should never make those assumptions. We should always be paranoid as far as monitoring the type of data that these companies take.
Advise to CISOs
Question: If you were advising a CISO that their organization is deploying autonomous agents, what are the first three things you’d tell them to do?
Understand, before you deploy, why you’re deploying it. What is that agent going to do? What systems is it going to interact with? AI hasn’t changed the way security is asking the same fundamental questions. The fundamental questions are the same. You’re still asking questions around data connections, public access, access control, the who, what, and where. None of that changes. It’s just that now you’re applying it to AI. AI makes things faster, makes more information available at a quicker rate, but the fundamental questions don’t change. I would say CISOs maintain that same level of discipline on AI.
Before you bring in new technology, make sure that’s really helping your business case. Why are you bringing this autonomous agent in? What is that agent gonna be doing? What workflow are you trying to optimize? Is it really helping your business? You don’t have to do it from the security mindset. You need to do it from a business mindset, along with your technology partners, the CTO, the founders, the CEOs, legal. CISOs are in a unique position that you have to look at everything, including financial. What value is this agent bringing into the org?
When you can answer the business case, then you can go, okay, now you can start getting into the weeds. What type of data is the system accessing, or is the agent accessing? Where’s that data going? What is that agent gonna be doing with that data? How do I ensure, like I brought the example of the logs when you’re logging activity, that certain sensitive information is going to be redacted from log files. It’s the same question I would ask for any technology I bring in here. Where’s that data going? Where does it live? Where does it reside? What am I doing with it? How am I securing it? How are you helping me secure it? If you’re not helping me secure it, what should I be securing?
Getting into those fundamentals, making sure the use cases are met from a business standpoint and then from a technical standpoint with the security context, are the two things I would advise that you do. You should be asking the same questions about any technology you bring in. That doesn’t change even if it’s AI based.
Thanks to Ravi for joining The Agentic Edge with so much honesty and a unique perspective.
Are you a security leader seeing the agentic front lines up close? We’d love to feature you. Reach out!