As balancing between harnessing the potential of generative artificial intelligence (genAI) and mitigating its risks becomes a challenge for many organizations, educating and training the workforce on how to use genAI tools safely plays a critical role, Trellix CEO Bryan Palma told SDxCentral.
Palma categorizes the security impact of genAI into three categories:
- Positive uses in defense: GenAI tools can enhance protections, aiding in tasks like script writing and environment management for security teams.
- Malicious uses by adversaries: These same tools can accelerate criminal activity, making adversaries more skilled, faster, and more cost-effective.
- Employee misuse and data leaks: Employees using genAI tools could be at risk of misuse and exposure of sensitive company information.
To ensure the safe use of genAI tools, the responsibility shouldn't fall solely on security teams, but on every member of the organization.
That’s why Palma emphasizes the need to make sure employees understand the varying levels of information sensitivity within an organization.
“If I'm just making a meeting agenda, go ahead and use ChatGPT. If I'm doing a public presentation, no problem at all. But if I'm working with the IP of the company, I want to be super careful, because once I put it in there, I don't know how it's being controlled,” he said.
In addition, organizations should educate their workforce to be aware of phishing and other fraudulent activities that are becoming more sophisticated and advanced with genAI tools.
How to deploy workforce education on genAI security risks?Companies should integrate education on genAI risks into their existing cybersecurity training and certification programs, Palma suggests.
This computer-based training, typically conducted annually, should now include information on tools like ChatGPT to cover its benefits, risks, and company policies regarding the use of such genAI tools.
“I think the best way to do it is to have a policy and a regulated standard and then have some standardization,” Palma said. For instance, companies should procure enterprise licenses for approved genAI tools and allow IT teams to assess and ensure their security. This strategy is preferable than blocking these tools, as employees might seek unapproved alternatives, he added.
“If you get people aware and you have a strong training policy and protocols, most of the people at the company are going to want to protect the company,” Palma said. “But if they don't know, they may [misuse] it unintentionally.”
How Trellix educate its workforce on genAIAt Trellix, cybersecurity training is an annual mandate, now including the genAI module for awareness, technology and protection policy education and the company plans to expand it, Palma said.
Even though Trellix employees in general have more security knowledge than a traditional company, there is always uncertainty.
He suggests using simulations, similar to those used in phishing-prevention training. “I signed so many DocuSigns that sometimes I have to slow down and be like, OK, they may be tricky, but that that just makes you more aware.”
“If you can create a competition around it or give people some training but make it fun, then that'll get them more educated about how to use it right, and what the benefits are,” Palma said.
“I also think proactively saying at Company X, this is how we think about genAI and we use this platform, our IT team has vetted it, it's safe, here's how you use it, here's the type of data that can go in it. Those types of things I think is the way to get a change in your protection from your people,” he added.
Advice to fellow CEOsPalma's advice to fellow CEOs is to treat genAI as a business initiative that needs the right resources and a new capability that requires communication and training.
“It requires protections, but ultimately, it's an incredibly powerful tool that all businesses need to be using in their business,” Palma said. “It's kind of like the old analogy of a car. A car goes fast, but it has brakes. That's how they should be thinking about it: you've got to have some clear policies, and standards in approach and you've got to train people. ”
“I don't think blocking it is the right answer and I just don't think that is a viable, long-term plan,” Palma said.
Comments