Hygiene, endpoint visibility and operational discipline are critical prerequisites for AI readiness

Hygiene, endpoint visibility and operational discipline are critical prerequisites for AI readiness

CIOs need to know that traditional patching and vulnerability management cycles are increasingly unable to keep pace with infrastructure changes.

By on

Artificial intelligence is forcing enterprise leaders to revisit their infrastructure operations, a part of IT that has received comparatively little attention over the past decade.

In a conversation with iTNews Asia, Nathaniel Callens, independent cybersecurity analyst, and Satyen Desai, Regional Vice President, ASEAN at Tanium, both said that enterprises and CIOs need to go back to basics, as many organisations tend to focus on AI models and copilots while neglecting and overlooking the operational foundations needed to deploy AI securely and at scale.

Both believe infrastructure hygiene, endpoint visibility and operational discipline are becoming the defining factors of AI readiness, particularly as AI agents begin acting autonomously across enterprise environments.

"The quality of the underlying environment matters again. For 10 years, the prevailing assumption was that abstraction layers, cloud, SaaS and APIs would paper over infrastructure neglect. They did not. They hid it. AI workloads run on the same endpoints, identities and networks the industry has been under-investing in, and they expose every gap with unforgiving speed,” Callens said.

AI is shining a light on technical debt

According to Callens, many organisations deprioritised infrastructure hygiene while focusing on digital transformation initiatives. "Hygiene was unfashionable because it was unglamorous. Patching, asset accuracy, configuration drift and identity cleanup never made the cover of an annual report," he said.

Recent industry data cited by the speakers shows that 43 percent of organisations report that more than 10 percent of their endpoints are unknown, unmanaged or non-compliant. "The cracks were always there, AI just put a spotlight on them and removed the option to look away,” he added.

Callens said that many enterprises continue to approach AI readiness as a technology purchasing exercise rather than an operational one. “Most enterprises I speak with in APAC have a clear answer on which model they want to deploy and a much fuzzier answer on whether their endpoints, identity hygiene and change management discipline can support agents acting on their behalf,” he explained.

He also noted that many organisations have well-defined AI strategies but far less confidence in the operational maturity that creates imbalance as AI agents move beyond content generation into executing actions across enterprise environments.

Visibility outweighs model capability

According to Desai, the larger AI risk lies in organisations lacking real-time visibility into their technology estates. He said many enterprises have enthusiastically invested in copilots, AI agents and proof-of-concept deployments without first establishing complete visibility.

Before scaling AI initiatives, he recommends organisations focus on three priorities:

● Building a real-time inventory of every endpoint, server and workload including shadow IT.

● Eliminating accumulated patching and configuration drift.

● Consolidating fragmented IT and security tools into a unified operational platform.

The boards moving fastest on AI are the ones whose CIOs have already done the unglamorous work of infrastructure hygiene.

- Satyen Desai, Regional Vice President, ASEAN at Tanium

AI is shrinking the response window

Both speakers pointed to the changing threat landscape as another reason operational maturity has become increasingly important. Recent advances in AI-assisted exploit generation have significantly reduced the time between vulnerability disclosure and weaponisation.

Callens pointed to Anthropic's recently demonstrated Mythos Preview, which showed dramatic improvements in autonomous exploit development capabilities.

The vulnerability-to-exploit window has collapsed from more than two years to a single day.

- Nathaniel Callens, independent cybersecurity analyst

He also said that every enterprise he had worked with carries debt accumulated over years of acquisitions, cloud migrations and tooling sprawl. Once organisations allow AI agents to act within enterprise environments, previously tolerated weaknesses become far more significant. "Every shortcut, every unpatched system and every undocumented dependency becomes a potential incident,” he explained.

Desai said traditional patching and vulnerability management cycles are increasingly unable to keep pace. He also noted that only a few organisations can deploy more than 90 percent of critical patches within 24 hours, making continuous endpoint management increasingly important.

He recommends organisations to move beyond periodic maintenance towards continuous endpoint management. "Culturally, it means IT operations and security stop working from different dashboards and different SLAs. The CIO and CISO share one view of the estate, one set of priorities and one accountability for outcomes," he said.

Operationally, routine activities such as patching, configuration management and exposure remediation should become increasingly automated, while human oversight remains for higher-risk decisions.

Infrastructure discipline becomes the differentiator

As foundation models continue converging in capability, both experts believe sustainable competitive advantage will shift away from the AI models themselves. Instead, success will increasingly depend on operational excellence.

"The organisations that win will be the ones whose endpoints, identities and workloads are visible, current and well governed. Most enterprises will consume frontier AI models from providers rather than build their own. The durable advantage sits in the operational estate those models act upon,” Desai said.

Callens believes the industry may ultimately look back on this period as the point where enterprise IT management fundamentally changed.

"The old definition of IT management was service availability, ticket throughput and project delivery. But now it is about operating an environment that can be trusted to make autonomous decisions safely.”

As enterprises move beyond AI experimentation towards production deployments, both speakers said that infrastructure discipline is becoming a foundational requirement rather than a back-office concern.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
© iTnews Asia
Tags:

Most Read Articles