Leading by Example: Cybersecurity Leader Uploads Sensitive Files to AI
When Even Cyber Experts Leak Data to AI: The Hidden Risks of Public LLMs
This past summer, a senior cybersecurity official in the US made a critical mistake: he inadvertently leaked critical government documents to the public version of ChatGPT. Luckily, he had implemented sufficient security measures to prevent any major data breaches from happening.
However, the lesson learned is quite alarming. What are the chances that your own employees are not making the same mistake with your own critical business data?
The ‘Reason’ Behind Such a ‘Mistake’
This type of data leak is hardly ever done out of malicious intent. What your own employees are trying to accomplish is to work more efficiently and effectively. What your own employees are unaware of is that such a commonly used AI is not secure simply because it is used by many. There is a fundamental distinction between public and private AI that is not well understood.
The Reality of Public AI Tools
When information is provided to public AI tools, that information is often provided to the company that operates those tools to improve their models.
It is not a breach, nor is it a hack. It is, in fact, in direct alignment with the Terms of Service.
The moment that sensitive information is provided, your organization loses all control over that information and risks it being accessed by others.
Building a Safe AI Culture
While placing an AI prohibition on page 53 of an employee handbook might be an ‘attempt’ at security, it will not stop an organization from being exposed in the real world. To protect an organization without hindering AI development, there must be an active ‘guardrails’-based approach:
Awareness Training: Your organization can provide your employees with basic training on how public LLMs function, why there are restrictions, and what information is off-limits.
Provide Alternatives: Employees are like water. Employees will go where it is easiest. Your organization must provide approved, private AI tools. If you can make these tools easy, you can build security into your organization.
How We Can Help: AI Security & Training
Embracing the pace of AI adoption does not have to come at the cost of your data’s security. As your cybersecurity ally, we can help you follow clear guidelines, deploy secure private LLMs, and provide your team with the training they need to confidently use AI technology safely and effectively.
Connect with our advisory team today to see how we can help secure your organization’s AI adoption.
