Skip to main content
Right of Boom

Our Speakers

An Uncompromising Roster of Experts.
Our speakers bring unfiltered, tactical insights forged in the crucible of real-world incident response.

Back to all speakers
Eric Sundt

Eric Sundt

Director of Cybersecurity and Compliance Services

Moore Computing

Eric Sundt is the Director of Compliance Services at Moore Computing, an MSP based in St Louis, Missouri. Eric has been in IT for 20 years, and specifically the MSP world for 15 years. His journey has included everything from IT support to cybersecurity governance and MSP business management, with several certifications along the way. This has developed him into a multi-disciplinary IT/cybersecurity strategist and business advisor who seeks to use the full breadth of his experience to inform his daily efforts on behalf of his company and its customers.

At Moore, Eric’s focus is on building healthy cybersecurity programs for Moore and its customers, largely using NIST 800-171 / CMMC and the CIS controls as foundational frameworks. Eric believes healthy cybersecurity results in healthy compliance, so he aims to think creatively and strategically about how best to build and protect modern information technology systems, especially as we incorporate AI.

Sessions

Modern AI presents us with a difficult "form versus function" paradox. It presents in the *form* of traditional software, yet carries out the non-deterministic *function* of a human worker. Securing AI strictly according to its form creates a dangerous control gap, leaving "overqualified" models capable of writing exploits or bypassing sandboxes even if they’re only assigned to simple administrative tasks. With motivations closely mimicking those of a human toddler and wide-ranging capabilities beyond the most brilliant prodigy, AI presents a unique sort of Insider Threat.

To address this security gap, this talk presents a Least Capability model. Least Capability builds on Least Privilege and Least Functionality by restricting what an AI tool inherently knows how to do. Grounded in Sounil Yu’s DIKW framework insights and in lessons from the history of training AI models, Least Capability aims to maximize AI's capacity for good while minimizing the possibilities of negative impact.

This session details how to operationalize Least Capability in practice in order to strip away unnecessary model capabilities and neutralize agentic threats by design. We will consider a variety of topics, including how to:

  • Apply traditional Human Resources controls to AI
  • Create "job descriptions" for purpose-built AI usage
  • Deploy technical and structural controls such as Dual-LLM topologies, tool-limited AI Agents, and more
  • Foster effective auditing and "reset" options for AI models
  • Ask questions of vendors providing AI functionality
  • Guide MSP customers through these same considerations
  • Save money on AI implementation