LinkedIn    Facebook    Twitter    Youtube   
LinkedIn    Facebook    Twitter    Youtube   
Category :  

Is ChatGPT the new security risk?

By Tarsus Distribution

While ChatGPT is an incredible and disruptive technology that appears to answer practically any question an individual might ask, it appears to leave C-suite executives and compliance officers with even more questions.

In essence, ChatGPT is a natural language processing chatbot that is fuelled by AI technology which enables users to have human-like conversations and more. It can answer questions, and help users with tasks, such as composing emails, writing essays, and even code. Users can even ask it to role-play and review a business proposal as if it were an investor from Shark Tank, for example.

Covered in this article

Not without limitations
Nobody really knows
Ask the right questions
Having the right policies in place
Vendor-related issues
Having the right skills
No need to panic

Not without limitations

However, although it appears very impressive, ChatGPT has its limitations. There are well-documented issues with accuracy, and OpenAI has admitted the tool has “limited knowledge of world events after 2021”.  As such, it tends to fill in replies with incorrect data if there is not enough information available on the subject in question. Various ethical considerations still remain in the grey zone, such as plagiarism and the use of intellectual property without specific consent.

Other limitations include its inability to answer questions that are worded in a certain way, as it requires specific phrasing to understand the question being asked clearly. Another, and more serious, limitation is a lack of quality in the chatbot’s responses, which while often plausible, can sometimes make no real sense, or are repetitive and vague.

It is no surprise then, that business leaders are asking themselves questions, such as how they should govern the use of ChatGPT, and in fact any of the many next-generation AI tools that are popping up all over the place, even within their own businesses.

Moreover, they are questioning how they can guard against new risks posed by bad actors using weaponised AI against them, and how they can monitor and manage the risks of vendors and third-party partners within their supply chain using these tools. Adding to the problem, is that many professionals and leaders don’t fully understand what these risks are, or comprehend their implications, in the first place.

Nobody really knows

It has become clear that AI will change the business world, because it’s impossible that technology that is so powerful and easy to use will not have a profound impact on corporate operations, risks, and governance.

Likewise, chief information security officers (CISO) and other practitioners in the areas of cybersecurity and risk will have a pivotal role to play in helping organisations navigate these challenges.

However, beyond that, the answers to the questions that ChatGPT poses are anyone’s guess, and CISOs will need to be prepared to find these answers as the technology advances and is adopted into the enterprise.

Ask the right questions

How can they do this? By asking themselves and their organisations a lot of questions, the first of which should be whether or not they have the appropriate oversight structures in place.

When it comes to AI, the fundamental challenge is governance, and businesses must find a way to manage how AI is studied, developed, and employed within the company.

Senior management and the board need to establish some sort of governance over the use and development of AI, otherwise employees might be left to their own devices, leaving the enterprise open to a proliferation of risks.

Having the right policies in place

The next step is having basic policies that formalise governance principles for AI. Following this, the business must implement more precise policies and procedures that staff members and other third parties need to follow.

For instance, if senior management unveils bold ambitions for using generative AI to automate interactions with customers, for example, the company should follow up with policies that dictate how particular business units can attempt to integrate AI into their operations.

In highly regulated industries such as financial services or healthcare, entities might want policies that prohibit any rolling out of AI initiatives until dedicated teams have had the opportunity to thoroughly test those systems for security and compliance risks.

Vendor-related issues

At this juncture, companies should also start to consider vendor-related challenges more thoroughly. For instance, does the organisation want its vendors to disclose whether or not they are using AI when processing data or transactions on the company’s behalf?

Similarly, do they require a security assessment before buying any AI tools from a vendor? Policies are needed to address these and other challenges, and companies must work closely with procurement teams to ensure policies are clearly understood and are integrated into operations.

Having the right skills

Companies also need to ask themselves whether or not they have the right skills to manage AI-enabled work on a regular basis, and if so, do they have the defined necessary roles and responsibilities to put AI ambitions into practice?

Different skills are needed to assess the security risks of an AI implementation, to carry out IT audits, and to test software code for new products that have been developed by ChatGPT, for example.

This element is particularly challenging, as organisations will need to design entirely new workflows in ways that are unfamiliar and far-reaching.

No need to panic

Importantly, businesses need to realise there’s nothing to panic about. At its heart, AI is just another new technology, much like the rise of the internet back in the 1990s, or the cloud in the 2010s.

Yes, it raises a slew of security, operational, and compliance issues that companies haven’t even considered yet, but CISOs are becoming equipped with the tools and skills needed to work through these issues and find solutions that meet their company’s needs.

They may well have to depend heavily on frameworks such as the National Institute of Standards and Technology (NIST), and others that are being developed specifically for AI. They will need to augment their capabilities in areas of policy management, risk assessment, monitoring, and training. And they’ll need support from the board, the C-Suite, management, and other stakeholders, to ensure the process is managed properly and that goals align with the company’s vision.

Is ChatGPT the new security risk?

By Tarsus Distribution

While ChatGPT is an incredible and disruptive technology that appears to answer practically any question an individual might ask, it appears to leave C-suite executives and compliance officers with even more questions.

In essence, ChatGPT is a natural language processing chatbot that is fuelled by AI technology which enables users to have human-like conversations and more. It can answer questions, and help users with tasks, such as composing emails, writing essays, and even code. Users can even ask it to role-play and review a business proposal as if it were an investor from Shark Tank, for example.

Covered in this article

Not without limitations
Nobody really knows
Ask the right questions
Having the right policies in place
Vendor-related issues
Having the right skills
No need to panic

Not without limitations

However, although it appears very impressive, ChatGPT has its limitations. There are well-documented issues with accuracy, and OpenAI has admitted the tool has “limited knowledge of world events after 2021”.  As such, it tends to fill in replies with incorrect data if there is not enough information available on the subject in question. Various ethical considerations still remain in the grey zone, such as plagiarism and the use of intellectual property without specific consent.

Other limitations include its inability to answer questions that are worded in a certain way, as it requires specific phrasing to understand the question being asked clearly. Another, and more serious, limitation is a lack of quality in the chatbot’s responses, which while often plausible, can sometimes make no real sense, or are repetitive and vague.

It is no surprise then, that business leaders are asking themselves questions, such as how they should govern the use of ChatGPT, and in fact any of the many next-generation AI tools that are popping up all over the place, even within their own businesses.

Moreover, they are questioning how they can guard against new risks posed by bad actors using weaponised AI against them, and how they can monitor and manage the risks of vendors and third-party partners within their supply chain using these tools. Adding to the problem, is that many professionals and leaders don’t fully understand what these risks are, or comprehend their implications, in the first place.

Nobody really knows

It has become clear that AI will change the business world, because it’s impossible that technology that is so powerful and easy to use will not have a profound impact on corporate operations, risks, and governance.

Likewise, chief information security officers (CISO) and other practitioners in the areas of cybersecurity and risk will have a pivotal role to play in helping organisations navigate these challenges.

However, beyond that, the answers to the questions that ChatGPT poses are anyone’s guess, and CISOs will need to be prepared to find these answers as the technology advances and is adopted into the enterprise.

Ask the right questions

How can they do this? By asking themselves and their organisations a lot of questions, the first of which should be whether or not they have the appropriate oversight structures in place.

When it comes to AI, the fundamental challenge is governance, and businesses must find a way to manage how AI is studied, developed, and employed within the company.

Senior management and the board need to establish some sort of governance over the use and development of AI, otherwise employees might be left to their own devices, leaving the enterprise open to a proliferation of risks.

Having the right policies in place

The next step is having basic policies that formalise governance principles for AI. Following this, the business must implement more precise policies and procedures that staff members and other third parties need to follow.

For instance, if senior management unveils bold ambitions for using generative AI to automate interactions with customers, for example, the company should follow up with policies that dictate how particular business units can attempt to integrate AI into their operations.

In highly regulated industries such as financial services or healthcare, entities might want policies that prohibit any rolling out of AI initiatives until dedicated teams have had the opportunity to thoroughly test those systems for security and compliance risks.

Vendor-related issues

At this juncture, companies should also start to consider vendor-related challenges more thoroughly. For instance, does the organisation want its vendors to disclose whether or not they are using AI when processing data or transactions on the company’s behalf?

Similarly, do they require a security assessment before buying any AI tools from a vendor? Policies are needed to address these and other challenges, and companies must work closely with procurement teams to ensure policies are clearly understood and are integrated into operations.

Having the right skills

Companies also need to ask themselves whether or not they have the right skills to manage AI-enabled work on a regular basis, and if so, do they have the defined necessary roles and responsibilities to put AI ambitions into practice?

Different skills are needed to assess the security risks of an AI implementation, to carry out IT audits, and to test software code for new products that have been developed by ChatGPT, for example.

This element is particularly challenging, as organisations will need to design entirely new workflows in ways that are unfamiliar and far-reaching.

No need to panic

Importantly, businesses need to realise there’s nothing to panic about. At its heart, AI is just another new technology, much like the rise of the internet back in the 1990s, or the cloud in the 2010s.

Yes, it raises a slew of security, operational, and compliance issues that companies haven’t even considered yet, but CISOs are becoming equipped with the tools and skills needed to work through these issues and find solutions that meet their company’s needs.

They may well have to depend heavily on frameworks such as the National Institute of Standards and Technology (NIST), and others that are being developed specifically for AI. They will need to augment their capabilities in areas of policy management, risk assessment, monitoring, and training. And they’ll need support from the board, the C-Suite, management, and other stakeholders, to ensure the process is managed properly and that goals align with the company’s vision.

Is ChatGPT the new security risk?

Intelligent Edge
Shawn 23, Jun 2022 0
By Tarsus Distribution While ChatGPT is an incredible and disruptive technology that appears to answer practically any question an individual might ask, it appears to leave C-suite executives and compliance officers with even more questions. In essence, ChatGPT is a natural language processing chatbot that is fuelled by AI technology which enables users to have […]
Read More05, Jul 2023

Why collaboration is a game-changear

Intelligent Edge
Shawn 23, Jun 2022 0
By Tarsus Distribution Collaboration is a golden buzzword companies love to use. Transformation is the challenge that inspires collaboration.  But how do you use it effectively in a workplace that is still finding its post-pandemic-feet? Here's what you need to know. When collaboration becomes part of your work culture, something transformative happens. Suddenly, different minds […]
Read More15, Jun 2023

Respect - A strategy for building relationships effectively

Intelligent Edge
Shawn 23, Jun 2022 0
By Shirlinia Martin  While work ethic, empathy, good communication, and trust are all critical attributes for business leaders, respect remains the most important. Any entity that does not promote an environment of mutual respect will experience high employee churn and a resulting lack of critical skills. In fact, without respect and appreciation, any business’s human […]
Read More15, May 2023

Safeguard your systems with Disaster Recovery as a Service

Intelligent Edge
Shawn 23, Jun 2022 0
By Werner Herbst, General Manager: Enterprise Today, technology is integral to practically every part of a business. However, the more we depend on our hardware, networks, and applications, the more catastrophic it can be if they fail us. This is why every business needs a plan in place to rapidly restore and recover IT systems […]
Read More05, May 2023

Building a sustainable business culture

Intelligent Edge
Shawn 23, Jun 2022 0
By Gary Pickford In the last decade, sustainability has become an increasingly integral part of doing business in any industry. For companies to balance their financial, social, and environmental risks, with their obligations and opportunities, sustainability has to be top of mind, instead of a grudge, tick-box exercise. The aim of any sustainable business strategy […]
Read More28, Apr 2023

Effective collaboration is enabled by technology

Intelligent Edge
Shawn 23, Jun 2022 0
By Tarsus Distribution Much like communication, collaboration has undergone a major paradigm shift since the global COVID-19 pandemic sent workforces home to work almost overnight. In the past, if an employee needed to collaborate, they would have had to set up a meeting, and get all the necessary people around a table. No longer. The […]
Read More31, Mar 2023

Businesses with an adaptive culture stay current and future-orientated

Intelligent Edge
Shawn 23, Jun 2022 0
By Johannes Groenewald, General Manager If the past few years have shown us anything, it’s that the ability of any organisation to adapt is a true competitive advantage. Adaptability means that a business that can evolve with the times, and do it successfully, is open to new ideas, and doesn't get stuck in the "that's […]
Read More30, Mar 2023

Taking the stress out of financial year end

Intelligent Edge
Shawn 23, Jun 2022 0
By Rialda Piek, Financial Manager There’s no doubt that financial year-end (FYE) can be a stressful time for businesses of every size. This is particularly true in South Africa, where many companies align their financial year-end with the South African Revenue Service’s (SARS) personal tax year dates, which sees their financial year-end fall on the […]
Read More24, Mar 2023

CX is key to driving revenue growth

Intelligent Edge
Shawn 23, Jun 2022 0
By Marilyn Patterson, Demand Generation Manager As a hot topic, it’s not surprising that prioritising customer experience (CX) continues to be a top strategic objective in businesses hungry for that competitive edge.  CX not only encompasses the entirety of the customer’s experience with your business, throughout all aspects of the buyer’s journey, it also includes […]
Read More27, Feb 2023

How to demonstrate real value when selling ICT services

Intelligent Edge
Shawn 23, Jun 2022 0
By Lizelle Le Roux, Business Unit Manager: Product The days of simply selling products or solutions are over for ICT distributors. Leading entities today understand that services are the lifeblood of any good partner. Providing services places customers in a position where they can deliver more effectively to their customers. In turn, this brings value […]
Read More23, Feb 2023

Addressing cloud security and privacy challenges

Intelligent Edge
Shawn 23, Jun 2022 0
By Alan Hawkins, GM: Cyber-Security and Software Hyperscale public cloud providers have the economies of scale and in-house expertise to secure their data centres to an extent no small and medium business (SMB) could hope to achieve. Even so, SMBs need to be aware of the growing number and rising complexity of the security risks […]
Read More16, Feb 2023

Creating a futuristic roadmap for today’s retailers

Intelligent Edge
Shawn 23, Jun 2022 0
By Tarsus Distribution Entities in every sector face a critical need to overhaul their IT architecture and operating models to keep up with a constantly evolving landscape. In fact, digital technologies have become a key element across every vertical, and nowhere is this more relevant than in the retail sector, which is facing its own […]
Read More19, Jan 2023

Improving the learning experience for students and teachers

Intelligent Edge
Shawn 23, Jun 2022 0
By Tarsus Distribution For all organisations, digital transformation has become key to success, or even survival, as, over the past few years, businesses had to act quickly during the global pandemic, and move all their operations online. In essence, digital transformation is about digitising and modernising systems. Operations are streamlined and more efficient, data is […]
Read More19, Jan 2023
Tarsus_logo
LinkedIn    Facebook    Twitter    Youtube   
Subscribe to our news
[class^="wpforms-"]
[class^="wpforms-"]