HomeRisk ManagementsMore than 75% of Organizations Face Microsoft 365 Governance Challenges

More than 75% of Organizations Face Microsoft 365 Governance Challenges

Published on

spot_img

Rising Governance Incidents Amid Increased AI Adoption: Findings from ShareGate

In a revealing report by ShareGate, it has been estimated that a staggering 77% of organizations globally encountered at least one governance incident related to Microsoft 365 over the past year. This concerning statistic highlights a growing sense of overconfidence in AI controls, which has led to the emergence of new risks within enterprises.

To gather these insights, ShareGate conducted two extensive surveys encompassing nearly 1,800 IT professionals and leaders across nine countries. The findings were presented in their second annual report, titled “State of Microsoft 365.” This report aims to shed light on the current state of governance practices surrounding Microsoft 365, particularly in the context of the increasing integration of AI technologies.

Among the organizations that experienced governance incidents, significant issues were prevalent. A notable 38% acknowledged that they had inadvertently retained access for former employees or guests, while 35% faced gaps in audits or compliance. Moreover, 26% reported instances of sensitive information being exposed to unauthorized individuals. ShareGate identified these disruptions as primarily arising from poor visibility into systems, an overestimation of the effectiveness of existing governance strategies, and a prevailing skills gap in AI governance.

In light of these findings, it is particularly noteworthy that full deployments of Microsoft Copilot have nearly doubled within the past year. The report indicated that these deployments have surged from 29% to an impressive 56% of organizations utilizing Copilot. Significantly, around 28% of these organizations are now running three or more AI tools. This rapid adoption has seemingly outpaced the ability of many organizations to maintain proper governance frameworks.

A critical point raised in the report is that many enterprises still rely on outdated practices, such as point-in-time audits, to monitor their governance environments. Two-thirds (65%) of the respondents revealed that incidents are frequently only identified post-factum, often during quarterly audits or through user complaints. In contrast, only a third (35%) of organizations employ proactive monitoring and automated alerting systems, highlighting a substantial lag in adopting modern governance strategies.

AI as a Catalyst for Increased Risk

The swift integration of AI into organizational frameworks has further compounded risks associated with governance. As a striking statistic, 22% of the organizations reported that expenses related to AI have consumed more than a fifth of their IT budgets. This figure rises to 32% among organizations that have implemented Copilot fully. While many businesses express confidence in their governance models, a surprising 93% believe their frameworks are adequately prepared for the challenges posed by AI. Paradoxically, 29% of these same businesses have encountered issues where sensitive internal data was inadvertently exposed by Copilot or other AI tools, underscoring a concerning disconnect.

This dissonance may be partly attributed to a deficit in AI governance expertise, which ranks as a top concern for 37% of respondents, alongside issues related to data quality and security. A paramount solution highlighted by IT professionals is the need for improved controls surrounding AI agents, with a considerable 34% considering this as the most significant factor to alleviate governance challenges. This is followed by the necessity of executive buy-in (20%) and automated remediation mechanisms (18%), while only 3% mentioned that additional budget funding could resolve these issues.

Richard Harbridge, the principal industry advisor at ShareGate, provided insights on the current environment: “Most of the tenant environments I look at aren’t broken; they just don’t know what’s happening within them. Teams feel confident because nothing has surfaced yet, but that doesn’t mean there’s nothing wrong.” He pointed out that the gap between the absence of news and the absence of problems is where governance incidents typically reside, complicating matters further when multiple AI tools are involved. Harbridge emphasized that rather than increasing diligence or expanding teams, organizations should invest in tools and processes that reveal and remedy issues promptly—preferably within the first week rather than waiting for months.

As organizations continue to adapt to the changing landscape brought about by AI and evolving governance requirements, the findings of the ShareGate report serve as a crucial reminder. Continuous vigilance and proactive strategies are essential to mitigate emerging risks and ensure effective governance in an increasingly complex technological environment.

Source link

Latest articles

Hackers Exploit Check Point VPN Remote Code Execution and Management Zero-Day in Attacks

Check Point Warns of Critical Vulnerabilities Impacting VPN and Security Management Products Check Point has...

Data Quality Surpasses Skills as the Primary Challenge in Threat Hunting

Data Quality Emerges as Primary Challenge for Threat Hunting Teams, Surpassing Skills Shortages Data quality...

CISA Offers OT Recovery Guidance via CI-Fortify

Business Continuity...

More like this

Hackers Exploit Check Point VPN Remote Code Execution and Management Zero-Day in Attacks

Check Point Warns of Critical Vulnerabilities Impacting VPN and Security Management Products Check Point has...

Data Quality Surpasses Skills as the Primary Challenge in Threat Hunting

Data Quality Emerges as Primary Challenge for Threat Hunting Teams, Surpassing Skills Shortages Data quality...