惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
CERT Recently Published Vulnerability Notes
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
V
Visual Studio Blog
Stack Overflow Blog
Stack Overflow Blog
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Tor Project blog
P
Proofpoint News Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Latest news
Latest news
L
LINUX DO - 热门话题
罗磊的独立博客
T
Tenable Blog
The Hacker News
The Hacker News
美团技术团队
N
Netflix TechBlog - Medium
V
Vulnerabilities – Threatpost
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
博客园 - 司徒正美
Jina AI
Jina AI
Cyberwarzone
Cyberwarzone
云风的 BLOG
云风的 BLOG
S
Secure Thoughts
Cloudbric
Cloudbric
S
Security @ Cisco Blogs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
Spread Privacy
Spread Privacy
U
Unit 42
雷峰网
雷峰网
C
CXSECURITY Database RSS Feed - CXSecurity.com
Webroot Blog
Webroot Blog
爱范儿
爱范儿
博客园 - 【当耐特】
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
P
Palo Alto Networks Blog
Google Online Security Blog
Google Online Security Blog
The Last Watchdog
The Last Watchdog
博客园 - 聂微东
Help Net Security
Help Net Security
Hacker News: Ask HN
Hacker News: Ask HN
F
Full Disclosure
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
S
Security Affairs
Project Zero
Project Zero

PCI Perspectives

Mapping PCI DSS v4.0.1 to the NIST Cybersecurity Framework 2.0 2026 North America Community Meeting Agenda Highlights Meet the Council’s New Head of Business Operations and Risk Management The AI Exchange: Innovators in Payment Security Featuring PCA Cyber Security Enhance Your Community Meeting Experience with Interactive Workshops Bring PCI SSC Training to Your Organization with the New Training Venue Host Program The AI Exchange: Innovators in Payment Security Featuring Utimaco Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Sharon Gai Welcome Our Newest Associate Participating Organizations The AI Exchange: Innovators in Payment Security Featuring SecurityMetrics PCI SSC Publishes New Guidance on Compensating Controls and the Customized Approach Spotlight On: Dreamplug Technologies Private Limited (CRED), a New Principal Participating Organization Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1 The AI Exchange: Innovators in Payment Security Featuring In-Solutions Global Ltd Coffee with the Council Podcast: Nominate Now for the Global Executive Assessor Roundtable (GEAR) PCI SSC Publishes PCI PTS HSM v5.0 Request for Comments: PCI Secure Software Lifecycle Standard v2.0 Spotlight On: Worldline, a New Principal Participating Organization Coffee with the Council Podcast: Stronger Together – The Value of Participating with PCI SSC The AI Exchange: Innovators in Payment Security Featuring Dreamplug Technologies Private Limited (CRED) Level Up Your Payment Security Expertise with PCI SSC Knowledge Training PCI SSC Launches Enhanced Language Microsites for Global Audience Exhibit at or Sponsor the 2026 Community Meetings Spotlight On: Stripe, a New Principal Participating Organization The AI Exchange: Innovators in Payment Security Featuring Toast, Inc. Coffee with the Council Podcast: A Panel Discussion on Cryptography The AI Exchange: Innovators in Payment Security Featuring Flywire Spotlight On: Amazon, a New Principal Participating Organization Welcome Our Newest Associate Participating Organizations The AI Exchange: Innovators in Payment Security Featuring Checkout.com Coffee with the Council Podcast: PCI SSC Publishes First-Ever Annual Report The AI Exchange: Innovators in Payment Security Featuring Bank of America Request for Comments: PCI Card Production and Provisioning Physical and Logical Security Standards v3.0.1 Spotlight On: Futurex, a New Principal Participating Organization The AI Exchange: Innovators in Payment Security Featuring Soft Space PCI Security Standards Council Publishes First-Ever Annual Report Coffee with the Council Podcast: PCI SSC Releases Version 2.0 of the PCI Secure Software Standard PCI SSC 2025 Community Meetings Now Available on Global Content Library PCI SSC Releases Version 2.0 of the PCI Secure Software Standard 2026 PCI SSC Training Schedule Announced Spotlight On: Reflectiz, a New Principal Participating Organization The AI Exchange: Innovators in Payment Security Featuring Jscrambler Meet the Council’s New Client Engagement Operations Director The AI Exchange: Innovators in Payment Security Featuring SISA Meet the Council’s New Director, Training Programs Request for Comments: PCI Key Management Operations (KMO) v1.0 Standard PCI SSC Publishes Mobile Payments on COTS (MPoC) Guidance Document The AI Exchange: Innovators in Payment Security Featuring Block, Inc. Request for Comments: PCI PTS HSM v5.0 Coffee with the Council Podcast: Nominate Your Company for the Council’s Next Brazil Regional Engagement Board 2025 Asia-Pacific Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring Elavon Inc. Coffee with the Council Podcast: Meet the New Regional Director of Japan and South Korea, Junichi Tsuboi Internal Security Assessor (ISA) Training Case Study: WestJet Sneak Peek: 2025 Europe Community Meeting Speakers AI Principles: Securing the Use of AI in Payment Environments The AI Exchange: Innovators in Payment Security Featuring Cloud Security Alliance Beware of PCI DSS Compliance Certificates Meet the Council’s New Regional Director, Europe PCI SSC Releases New Guidance on Authentication and Cryptography Welcome Our Newest Associate Participating Organizations Sneak Peek: 2025 North America Community Meeting Speakers Coffee with the Council Podcast: Meet This Year’s Asia-Pacific Community Meeting Keynote Speaker, Sharon Gai The AI Exchange: Innovators in Payment Security Featuring Salesforce
The AI Exchange: Innovators in Payment Security Featuring PROSA
Alicia Malone · 2026-07-10 · via PCI Perspectives

Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchange information about how they are adopting and implementing artificial intelligence (AI) into their organizations.  

In this edition of The AI Exchange, PROSA Chief Information Security Officer, Valther Galván Ponce de León, offers insight into how his company is using AI, and how this rapidly growing technology is shaping the future of payment security. 

How has your AI strategy evolved over the past 12-18 months?

Over the past 12–18 months, our AI strategy has evolved from exploration to a more practical, responsible, and security-driven adoption model. In cybersecurity, we have seen that AI is no longer only an emerging capability; it is becoming an important enabler for improving visibility, prioritizing risk, and supporting faster decision-making.

A key part of this evolution has been strengthening our use of AI-enabled security, analytics, observability, and risk management capabilities. These technologies help organizations identify patterns, improve context, reduce manual effort, and support security teams in detecting and responding to potential threats more effectively.

For us, the main change has been moving from asking “what can AI do?” to asking “where can AI help us make better security decisions?” We are focused on applying AI to support threat detection, risk prioritization, operational visibility, secure access, and cybersecurity resilience, while maintaining appropriate governance and human oversight.

AI provides speed, scale, and context, but cybersecurity still requires judgment, accountability, and a clear understanding of business impact. 

What is one AI initiative that has already delivered a measurable impact within your organization, and what made it successful?

One AI initiative that has delivered meaningful impact is the use of AI-supported security monitoring and response capabilities within our cybersecurity operating model. These capabilities have improved how security information is analyzed, correlated, and prioritized, allowing teams to focus on events that may pose a higher risk.

The impact has been reflected in better visibility, faster analysis of potential incidents, and more efficient response processes. Instead of relying only on manual review or isolated alerts, AI-supported analytics can help identify patterns, reduce noise, and provide better context for decision-making.

What made this initiative successful was not only the technology itself, but the way it was implemented. We aligned AI-enabled capabilities with clear cybersecurity use cases, strengthened monitoring and response processes, and kept human validation as part of the workflow.

In my opinion, this balance is essential. AI can help teams move faster and make better informed decisions. Still, final judgment should remain with experienced security professionals who understand the environment, the risk, and the potential business impact. 

How are you approaching AI governance, particularly around data privacy and security? 

Our approach to AI governance is based on responsible adoption. Since we operate in a highly sensitive environment, especially in the payments industry, we cannot treat AI only as an innovation tool. It must be evaluated with the same discipline that we apply to cybersecurity, data protection, regulatory compliance, and operational risk.

From a privacy and security perspective, our focus is on defining clear rules for how AI can be used, what types of information may be processed, and which use cases require additional review before implementation. We are especially careful with confidential information, customer data, payment-related data, and sensitive operational information.

For us, data minimization is very important. AI tools and AI-enabled capabilities should use only the information necessary for a specific purpose, under appropriate controls.

We are also approaching AI governance through access management, vendor risk management, monitoring, policy definition, and human oversight. AI can bring significant benefits to cybersecurity and operations, but it must be managed in accordance with clear security, privacy, and governance practices.

In my opinion, AI should help improve detection, visibility, analysis, and decision-making, but it should not remove accountability from the people and teams responsible for security. 

What challenges have become more apparent as AI capabilities have matured?

As AI capabilities have matured, one of the biggest challenges has been moving from isolated AI-enabled capabilities to a more integrated and adaptive cybersecurity model. Many technologies now include strong AI and analytics features, but the real value comes when those capabilities can work together, share context, and support faster, more coordinated decisions.

In practice, this is not only a technology challenge. It requires consistent data quality, clear ownership of security signals, strong governance, integration between processes, and well-defined response workflows.

Another important challenge is avoiding overreliance on AI. As detection, analytics, and automation improve, it can be tempting to assume that technology will always interpret risk correctly. In reality, AI still requires governance, tuning, validation, and human judgment. False positives, incomplete context, data silos, and inconsistent policies can limit the effectiveness of AI-enabled cybersecurity.

For me, the main lesson is that AI maturity is not just about adopting more advanced tools. It is about building the discipline to connect people, processes, data, and technology within a security architecture that adapts as threats evolve.

This is where concepts such as adaptive cybersecurity and cybersecurity mesh become very relevant. They encourage organizations to think beyond individual controls and focus on a more coordinated, flexible, and risk-based security model. 

What advice would you provide for an organization moving from early AI adoption to broader implementation? 

I recommend moving from experimentation to implementation with a clear strategy, not only with enthusiasm for technology. Early AI adoption is useful for understanding capabilities, but broader implementation requires governance, prioritization, risk management, and strong alignment with business and security objectives.

The first step should be to identify use cases where AI can deliver real value with manageable risk. In cybersecurity, this may include threat detection, alert prioritization, vulnerability management, user behavior analytics, incident response support, operational visibility, and risk analysis.

However, organizations should avoid implementing AI everywhere at once. It is better to scale based on proven results, clear metrics, and lessons learned from initial pilots.

I would also recommend building AI governance from the beginning. This includes defining what data can be used, how privacy and security will be protected, how vendors will be evaluated, how outputs will be validated, and where human review is required.

As AI becomes part of a broader cybersecurity model, integration becomes critical. The value is not only in having AI-enabled capabilities, but in connecting those capabilities so they can provide useful context and support coordinated decisions.

Organizations should invest in people and processes as much as in technology. AI can improve speed, visibility, and analysis, but it still depends on teams that understand the risks, the business environment, and the right response.

Successful broader implementation comes from balancing innovation with governance, automation with human judgment, and technology with a clear security strategy. 

What AI trend (not limited to payments) are you most excited about?  

The AI trend I am most excited about is Agentic AI, especially its potential to transform cybersecurity and operations.

I see Agentic AI as the next step beyond traditional AI assistants or copilots. Its value lies not only in analyzing information but also in helping reason through workflows, recommending actions, coordinating tasks, and supporting process execution under defined controls.

In cybersecurity, this is especially relevant. Security teams work with a large number of signals across different environments, systems, identities, applications, and business processes. Agentic AI has the potential to help connect those signals, accelerate investigation, prioritize risks, and recommend response actions with more context.

This is particularly valuable in an adaptive cybersecurity model, where organizations need to respond quickly as threats evolve.

What matters most is using Agentic AI responsibly. The objective should not be unrestricted autonomy but controlled, governed assistance. In my opinion, the real value will come from combining automation with expert judgment.

Agentic AI can help reduce repetitive work, accelerate analysis, and improve decision-making, while security professionals remain accountable for final decisions.

For me, this trend has the potential to make organizations more proactive, resilient, and adaptive, not only in payments but across many industries where security, trust, and operational continuity are critical. 

View More Content on Artificial Intelligence

Learn More About PROSA