{"id":4499,"date":"2024-07-17T10:31:48","date_gmt":"2024-07-17T15:31:48","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/orgs-are-finally-making-moves-to-mitigate-genai-risks"},"modified":"2024-07-17T10:31:48","modified_gmt":"2024-07-17T15:31:48","slug":"orgs-are-finally-making-moves-to-mitigate-genai-risks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/17\/orgs-are-finally-making-moves-to-mitigate-genai-risks\/","title":{"rendered":"Orgs Are Finally Making Moves to Mitigate GenAI Risks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt8d83dd54d2fa910a\/6696ff66be53992fc73efeb0\/genai_IrenaR_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many enterprise security teams finally appear to be catching up with the runaway adoption of AI-enabled applications in their organizations, since the public release of ChatGPT 18 months ago.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A new analysis by Netskope of anonymized AI app usage data from customer environments showed substantially more organizations have begun using blocking controls, data loss prevention (DLP) tools, live coaching, and other mechanisms to mitigate risk.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Keeping an Eye on What Users Send to AI Apps\">Keeping an Eye on What Users Send to AI Apps<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Most of the controls that enterprise organizations have adopted, or are adopting, appear focused on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/generative-ai-has-its-risks-but-the-sky-isn-t-falling\" rel=\"noopener\">protecting against users sending sensitive data<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 such as personal identity information, credentials, trade secrets, and regulated data \u2014 to AI apps and services.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Netskope&#8217;s analysis showed that 77% of organizations with AI apps now use block\/allow policies to restrict use of at least one \u2014 and often multiple \u2014 GenAI apps to mitigate risk. That number was notably higher than the 53% of organizations with a similar policy reported in Netskope&#8217;s study last year. One in two organizations currently block more than two apps, with the most active among them blocking some 15 GenAI apps because of security concerns.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The most blocked GenAI applications do track somewhat to popularity, but a fair number of less popular apps are the most blocked [as well],&#8221; Netskope said in a blog post that summarized the results of its analysis. Netskope identified the most-blocked applications as presentation maker Beautiful.ai, writing app Writesonic, image generator Craiyon, and meeting transcript generator Tactiq.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Forty-two percent of organizations \u2014 compared to 24% in June 2023 \u2014 have begun using DLP tools to control what users can and cannot submit to a GenAI tool. Netskope perceived the 75% increase as an indication of maturing enterprise security approaches to addressing threats from GenAI applications and services. Live coaching controls \u2014 which basically provide a warning dialog when a user might be interacting with an AI app in a risky fashion \u2014 are gaining in popularity as well. Netskope found 31% of organizations have policies in place to control GenAI apps, using coaching dialogs to guide user behavior, up from 20% in June 2023.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Interestingly, 19% of organizations are using GenAI apps but not blocking them, which could mean most of these are &#8216;shadow IT&#8217; [use],&#8221; says Jenko Hwong, cloud security researcher with Netskope Threat Labs. &#8220;This stems from the improbability that any security professional would permit unrestricted use of GenAI applications without implementing necessary risk mitigation measures.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Mitigating Risks With Data From GenAI Services Not Yet a Focus\">Mitigating Risks With Data From GenAI Services Not Yet a Focus<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Netskope found less of an immediate focus among its customers on addressing risk associated with the data that users receive from GenAI services. Most have an acceptable use policy in place to guide users on how they must use and handle data that AI tools generate in response to prompts. But for the moment at least, few appear to have any mechanisms to address potential security and legal risks tied to their AI tools spewing out factually incorrect or biased data, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/researchers-show-how-to-use-one-llm-to-jailbreak-another\" rel=\"noopener\">manipulated results<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, copyrighted data, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/chatgpt-hallucinations-developers-supply-chain-malware-attacks\" rel=\"noopener\">completely hallucinated responses<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ways that organizations can mitigate these risks is through vendor contracts and indemnity clauses for custom apps and enforcing the use of corporate-approved GenAI apps with higher quality datasets, Hwong says. Organizations can also mitigate risks by logging and auditing all return datasets from corporate-approved GenAI apps, including timestamps, user prompts, and results.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Other measures security teams can take include reviewing and retraining internal processes specific to the data returned from GenAI apps, much like how OSS is part of every engineering department&#8217;s compliance controls,&#8221; Hwong notes. &#8220;While this isn&#8217;t currently the primary focus or the most immediate risk to organizations compared to the sending of data to GenAI services, we believe it&#8217;s part of an emerging trend.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The growing attention that security teams appear to be paying to GenAI apps comes at a time when enterprise adoption of AI tools continues to increase at warp speed. A staggering 96% of the customers in Netskope&#8217;s survey \u2014 compared to 74% in June 2023 \u2014 had at least some users using GenAI apps for a variety of use cases, including coding and writing assistance, creating presentations, and generating images and video.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Netskope found the average organization currently to be using three times as many GenAI apps and having nearly three times as many users utilizing them, compared to just one year ago. The median number of GenAI apps in use among organizations in June 2024 was 9.6, compared to a median of 3 last year. The top 25% had 24 GenAI apps in their environments, on average, while the top 1% had 80 apps.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ChatGPT predictably topped the list of the most popular GenAI app among Netskope&#8217;s customers. Other popular apps included Grammarly, Microsoft Copilot, Google Gemini, and Perplexity AI, which interestingly was also the 10th most frequently blocked app.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u201cGenAI is already being <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/gen-ai-tools-will-permeate-all-areas-of-the-enterprise\" rel=\"noopener\">used widely across organizations<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and is rapidly increasing in activity,&#8221; Hwong says. &#8220;Organizations need to get ahead of the curve by starting with an inventory of which apps are being used, controlling what sensitive data is sent to those apps, and reviewing [their] policies as the landscape is changing quickly.\u201d<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/orgs-are-finally-making-moves-to-mitigate-genai-risks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Many enterprise security teams finally appear to be catching up<\/p>\n","protected":false},"author":12,"featured_media":4500,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4499","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/orgs-are-finally-making-moves-to-mitigate-genai-risks.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4499","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4499"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4499\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4500"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4499"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4499"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4499"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}