HomeCyber BalkansSurvey Reveals Poor Monitoring of Employees' Shadow AI Usage

Survey Reveals Poor Monitoring of Employees’ Shadow AI Usage

Published on

spot_img

In the ever-evolving landscape of cybersecurity, organizations are increasingly confronting a persistent challenge: the human element. While cybersecurity professionals diligently work to safeguard their networks and protect sensitive data, employees often remain the weakest link in this intricate security chain. Time and again, individuals inadvertently expose their organizations to risk by clicking on malicious links within emails, recycling weak passwords, sharing confidential information, and committing various other missteps that savvy threat actors are quick to exploit.

The introduction of generative AI tools promised enhancements in productivity and efficiency but simultaneously created a new frontier laden with security risks. As employees begin to embrace these unsanctioned AI tools, the potential for security breaches escalates at an alarming pace and scale, making it increasingly challenging for organizations to maintain oversight.

Recent findings from a comprehensive Bitdefender survey that included over 1,200 cybersecurity professionals underscore the gravity of the situation. A startling 47% of respondents admit to lacking complete visibility into the AI tools employed by their workforce. This lack of oversight not only raises red flags about potential security vulnerabilities but also highlights a significant disconnect between the perspective of company leaders and frontline workers. While 58% of IT and security managers claim to have comprehensive knowledge of AI usage within their organizations, only 46% of operational staff concur, indicating that many companies may underestimate the security threats stemming from unsanctioned AI.

Reflecting on these vulnerabilities, the Bitdefender report articulates a poignant assertion: “This isn’t a technology problem alone; it’s also a governance vacuum.” The term “Shadow AI” has emerged to describe the phenomenon where unauthorized AI tools proliferate within organizations, a situation akin to the longstanding issue of “shadow IT.” However, Shadow AI presents its own unique challenges, being considerably more difficult to detect with a far greater potential for data leakage.

In light of these developments, security leaders are faced with the challenge of addressing Shadow AI. Chase Cunningham, a notable expert in zero-trust security and chief strategy officer for Demo-Force, emphasizes that imposing a blanket ban on AI use may exacerbate an already precarious situation. He argues that a policy simply stating, “Do not use generative AI,” falls short of being an effective strategy and more often drives usage into clandestine realms, where security teams find it difficult to garner visibility.

Cunningham advocates instead for a more nuanced approach, suggesting that organizations should focus on understanding how employees are utilizing AI technologies. By identifying which unsanctioned AI applications employees are engaging with and the motives behind their usage, companies can develop governance policies that promote responsible AI adoption. This approach shifts the focus from prohibition to education, cultivating an environment where employees feel encouraged to use AI tools safely and responsibly rather than resorting to secretive use.

In Cunningham’s words, “Organizations can’t govern what they can’t see.” This statement underscores the need for enterprises to foster a culture of transparency and communication when it comes to AI use. While internal messaging often motivates employees to adopt AI for increased business efficiency, it is equally vital to highlight the associated risks. Erich Kron, a CISO advisor at security awareness training firm KnowBe4, emphasizes that discussions surrounding AI should not only highlight its benefits—such as aiding in report generation or code writing—but also address the potential pitfalls, including data leaks and unexpected outcomes like model hallucinations, in ways that resonate with employees across all technical levels.

Merely raising awareness about the risks associated with Shadow AI won’t suffice, according to industry analysts. The insights from the Bitdefender survey reveal a pressing need for organizations to obtain better visibility into the AI tools used by employees. Rik Turner, an analyst at Omdia, articulates that organizations successfully managing such risks will likely maintain an up-to-date inventory that distinguishes between sanctioned and unsanctioned generative AI services, thus facilitating effective governance.

Cunningham reinforces this sentiment, stressing the importance of both visibility and governance. He cautions against attempts to outright ban AI usage, suggesting instead a strategy to curtail invisible and indiscriminate use, as well as limiting access to only what is necessary for task completion.

As organizations navigate this intricate landscape, the balance between embracing AI technology for productivity and maintaining robust cybersecurity measures is ever more crucial. The challenge lies not only in implementing policies but cultivating a culture where responsible AI use becomes commonplace and integral to daily operations.

Craig Galbraith, a seasoned journalist and founder of Galbraith Multimedia, highlights the importance of these insights within the technology sector. His work emphasizes the need for a proactive approach to cybersecurity risks associated with emerging technologies, ensuring that organizations remain resilient in the face of evolving threats.

Source link

Latest articles

UNC6671 Vishing Group Rebrands Following Millions in Gains

Vishing Extortion Group UNC6671 Continuously Rebrands to Evade Detection and Strengthen Operations A notable and...

DEF CON Diaries #2: Tips for Staying Calm and Collected

During the much-anticipated Black Hat and DEF CON conferences, attendees can expect a vibrant...

18-Year-Old Linux Kernel SCTP Vulnerability Allows Attackers to Gain Root Access and Escape Containers

Discovery of SCTPhantom: A High-Severity Linux Kernel Vulnerability The cybersecurity community has identified a significant...

Behavioral Biometrics: Detecting Nonhuman Threat Actors

AI as a Cybersecurity Game Changer: The Emergence of Mythos and AI-Enabled Attacks In recent...

More like this

UNC6671 Vishing Group Rebrands Following Millions in Gains

Vishing Extortion Group UNC6671 Continuously Rebrands to Evade Detection and Strengthen Operations A notable and...

DEF CON Diaries #2: Tips for Staying Calm and Collected

During the much-anticipated Black Hat and DEF CON conferences, attendees can expect a vibrant...

18-Year-Old Linux Kernel SCTP Vulnerability Allows Attackers to Gain Root Access and Escape Containers

Discovery of SCTPhantom: A High-Severity Linux Kernel Vulnerability The cybersecurity community has identified a significant...