A featured contribution from Leadership Perspectives, a curated forum for insurance leaders, nominated by our subscribers and vetted by the Insurance Business Review Editorial Board.

MEM

Tim Myers, CISO | Director, IT Security & Operations

Are You Flying Blind? The Consequences Of Unmonitored AI Usage

Tim Myers

Tim Myers

Cybersecurity Governance Authority

Tim Myers serves as CISO and Director of IT Security & Operations at MEM. He leads cybersecurity strategy, information security and technology operations, strengthening organizational resilience through risk management, regulatory compliance and proactive security practices that safeguard critical systems, data and business operations.

As a cybersecurity professional, what keeps you up at night? You’ve locked down the workstations and servers, you have a solid vulnerability management program, you perform penetration tests every month, you’ve segmented your network, you have immutable storage and offsite backups, you’ve outsourced your “Manage, Detection, and Response” (MDR platform, and your annual assessment(s) are pleasing to your board of directors.

What about Artificial Intelligence (AI)? Are you caught up in endless discussions and meetings talking about options and next steps? Do you have a policy and training that everyone has signed as “read or completed”? Maybe the answer is to block everything AI. Is that realistic? Do you really want to “just say no”? How about we just pick one and tell everyone that’s the one they must use? Many organizations are wrestling with these and other related questions as the AI landscape continues to expand, shift, and seemingly move under our feet every day.

Employee curiosity and organizational preparedness are pressing against each other and creating a significant data security risk. A recent study suggests that 93% of companies have already begun using AI tools, sometimes with personal accounts, while they do not understand the risks. 70% of IT leaders have identified “unauthorized” AI tools within their organization. “Shadow AI is here!”

Monitoring Matters Most

Are you monitoring or blocking AI usage? Do you know what is being asked of the AI tools? If you’re not monitoring, blocking, or do not know what is being asked (prompted), you are likely to have sensitive data leakage occurring.

There needs to be a correlation between the use of AI and AI usage monitoring.

The risk of leaking sensitive data when you are not monitoring the usage creates quite a dilemma with your Compliance department and violates data privacy regulations. How do you stay in compliance with state statutes when you are leaking data but can’t report what has been leaked?

Leaking sensitive data isn’t your only risk. If you are allowing the use of “unapproved AI tools”, you may be exposing your organization to “backdoors” that exist, putting your corporate network at risk.

How about the potential for hallucinating responses from AI tools? Have your employees been trained how to examine AI responses for accuracy, or are you running the risk of AI response usage that can lead to damaged client trust and legal liability?

Perhaps there needs to be a correlation between the use of AI and AI usage monitoring. You shouldn’t allow one without the other.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.