• About
  • Subscribe
  • Contact
Friday, May 9, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Technology Data Protection

GenAI use in enterprise prompts inclusion of AI in security arsenal

FutureCISO Editors by FutureCISO Editors
September 27, 2023

Photo by Tara Winstead from Pexels: https://www.pexels.com/photo/an-artificial-intelligence-illustration-on-the-wall-8849295/

Share on FacebookShare on Twitter

A new survey by Gartner suggests that 34% of organisations are either already using or implementing artificial intelligence (AI) application security tools to mitigate the accompanying risks of generative AI (GenAI).

The Gartner Peer Community survey was conducted from April 1 to April 7 among 150 IT and information security leaders at organisations where GenAI or foundational models are in use, in plans for use, or being explored.

The survey revealed that 26% are currently implementing or using privacy-enhancing technologies (PETs), ModelOps (25%) or model monitoring (24%) (see Figure 1).

Figure 1. Organisations using or planning to use tools to address risks related to generative AI (Percentage of Respondents)

Source: Gartner Peer Community (September 2023)

“IT and security and risk management leaders must, in addition to implementing security tools, consider supporting an enterprise-wide strategy for AI TRiSM (trust, risk and security management),” said Avivah Litan, distinguished VP analyst at Gartner.

Avivah Litan, Gartner

“AI TRiSM manages data and process flows between users and companies who host generative AI foundation models and must be a continuous effort, not a one-off exercise to continuously protect an organisation.”

Avivah Litan

IT is ultimately responsible for GenAI security

While 93% of IT and security leaders surveyed said they are at least somewhat involved in their organisation’s GenAI security and risk management efforts, only 24% said they own this responsibility.

Among the respondents who do not own the responsibility for GenAI security and/or risk management, 44% reported that the ultimate responsibility for GenAI security rested with IT. For 20% of respondents, their organisation’s governance, risk, and compliance departments owned the responsibility.

Related:  AI plays a pivotal role in combat against cyber risks

Top-of-mind risks

The risks associated with GenAI are significant, continuous and will constantly evolve. Survey respondents indicated that undesirable outputs and insecure code are among their top-of-mind risks when using GenAI:

  • 57% of respondents are concerned about leaked secrets in AI-generated code.
  • 58% of respondents are concerned about incorrect or biased outputs.

“Organisations that don’t manage AI risk will witness their models not performing as intended and, in the worst case, can cause human or property damage,” said Litan. “This will result in security failures, financial and reputational loss, and harm to individuals from incorrect, manipulated, unethical or biased outcomes. AI malperformance can also cause organisations to make poor business decisions.”

Tags: Artificial IntelligenceGartnergenerative AI
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • DDoS attacks surge in Asia Pacific, claims Cloudflare
  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025
  • New standard for cybersecurity at the storage layer
  • Cybersecurity challenges persist despite improved defenses

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl