A number of reports and surveys have been published over the past year highlighting the growing gap between the increasing complexity of modern cyber threats and organizations’ ability to secure their environments against them.
For example, in one report last year,
BigID found that almost 40% of organizations surveyed admitted to lacking tools to protect AI-accessible data and only 6% had an advanced AI security strategy or an AI trust, risk, and security management (TRiSM) framework, “
signaling widespread unpreparedness for AI-driven threats.”
In its
2025 Readiness Report, multinational IT infrastructure services provider
Kyndryl found that only 31% of 3,700 business leaders surveyed feel completely prepared to protect their organizations against AI-related and other external risks security risks – up only a little from the 29% who said the same thing the year before – and 82% experienced an cyber-related outage last year.
In addition, 31% of customers cited regulatory or compliance concerns as a top barrier limiting their company’s ability to scale their technology investments.
This month, Kyndryl is making moves to help enterprises shore up their defenses and ensure they comply with the growing number of regulations. The services provider last week
introduced its policy-as-code capabilities to enable organizations to scale their agentic AI initiatives for complex and highly regulated environments.
A day later, the firm
launched its cloud-based Kyndryl Intelligent Recovery Service (KIRS) solution that is integrated with Kyndryl Bridge – its AI-powered platform – and automates recovery processes and provides visibility across both hybrid and multi-cloud environments.
Helping with Mitigation, Recovery
In their readiness report, Kyndryl executives wrote that business leaders said upgrading their IT infrastructure helps mitigate external business risks and regulatory pressures and brings efficiency and innovation benefits.
“Modern cyber resilience strategies and new technologies such as AI depend on a foundational tech and data stack,” they wrote. “Reinforcing this foundation is essential to building trust, increasing business agility, maintaining uptime and defending against disruption.”
The company’s policy-as-code capability fits in with this. According to
Patrick Gormley, Kyndryl’s global data science and AI consult lead, policy as code is the “practice of converting an organization’s rules, policies and compliance requirements into machine-readable code so AI systems can follow them automatically. This breakthrough innovation directly addresses the top enterprise concern, especially for those in highly regulated industries, about AI: the organization’s ability to execute workflows that require regulatory compliance and maintain trust.”
Guardrails for AI
The code prevents unauthorized actions and creates guardrails for AI to operate within, which leads to consistent interpretations of policy and offer traceable and explainable reasons, he
said in an online interview.
“People oversee all activities related to these processes,” Gormley said. “This makes policy as code particularly valuable in heavily regulated industries, such as financial services, healthcare and government. Policy as code helps enable these industries to realize the full benefits of AI and agentic AI by reducing the risk of the types of compliance failures that damage reputations and incur heavy financial penalties.”
Kyndryl’s policy-as-code strategy includes a range of capabilities for agentic AI governance, from ensuring agents only execute permitted actions and are enforced by pre-defined policies and blocking AI hallucinations to logging every agent action and decision and enabling human supervision through a dashboard that makes sure agents align with policies.
“The bottom line is that an AI agent, by design, is unable to act outside the parameters of its allowed operations,” Gormley said. “And the beauty of the capability is that it also enables system observability and accurate record keeping.”
Addressing 'Dual Resilience Challenge'
Kyndryl’s KIRS solution is aimed at what
Paul Savill, global practice leader for cybersecurity and resiliency for network and edge at Kyndryl, calls the “dual cyber resilience challenge” of quickly recovering from disruptions while managing a complex regulatory landscape. This is done through automated recovery workflows and real-time visibility.
Organizations get real-time insights into recovery objectives, system health, and resiliency capabilities and includes unified dashboard to drive the needed central visibility into the progress of recoveries as well as compliance metrics for governance and oversight. It works for cloud platforms, containerized workloads, and databases, according to the services provider.
Kyndryl executives called out a number of industries where the service works well, including retail and its point-of-sales systems, inventory management tools, and loyalty platforms, healthcare organizations with various hospitals and clinics that have strict recovery time objectives and regulatory requirements, and financial services, which need to protect data and transaction systems.
Another sector is manufacturing and energy, which their operational technology (OT) and Internet of Things (IoT) platforms.