Governments need to strengthen cyber defense for the AI ​​era, and need to go back to basics

AI Basics


Meeting room laptop work desk globe

Virojt Changeencham/Getty Images

The government will hope to go on a more attention path in the adoption of artificial intelligence (AI), particularly Generated AI (GEN AI). This should include strengthening cyber defense as AI technology continues to evolve. That means it's time to revisit the basics.

Both private and public sector organisations are concerned about security and ethics in the adoption of Gen AI, but the latter have higher expectations about these issues, Capgemini's Asia-Pacific CEO Olaf Pietschner said in a video interview.

Also: AI risks are everywhere – and now MIT is adding them all to one database

The government is more risk-averse and, implicitly, has higher standards for governance and guardrails required for Gen AI, Pietschner said. They need to provide transparency about how decisions are made, but that requires that the AI-driven process have a level of explanation, he said.

Therefore, he added that public sector organizations are less resistant to problems such as hallucinations and false and inaccurate information generated by AI models.

It focuses on the fundamentals of modern security architectures, says Frank Briguglio of SailPoint Technologies, public sector identity security strategist for identity and access management vendors.

When asked what AI adoption would change for the public sector, Briguglio pointed out the need to insert the necessary controls to protect data and prevent it from being exposed to AI services that reduce the internet for training data.

Also: Can the government turn AI safety talk into action?

In particular, managing online identity requires a paradigm shift, says Eduarda Camacho, COO of Identity Management Security vendor. She added that not only using multifactor authentication, but also relying on the native security tools of cloud service providers is not enough.

Furthermore, it is not sufficient to apply strong protections to privileged accounts only, Camacho said in an interview. This, she added, has made it more complicated to establish an identity, in particular, along with the emergence of AI generals.

Also: Most people worry about deepfakes and overestimate their ability to find them

Like Camacho, Briggulio supports the merits of an identity-centric approach. He said that from a privacy and security perspective, he would ask the organization to classify where all data resides and protect it accordingly.

They need to be able to apply the policy to the machine in real time. This also has access to data, he said in a video interview. Ultimately, he said that all attempts to access a network or data are assumed to be adversarial, highlighting the role of zero trusts that can potentially compromise corporate systems.

The attributes or policies that grant access must be accurately verified and governed, and business users must be confident in these attributes. The same principle applies to data and organizations that need to know where data resides, how it is protected, and who can access it, Briguglio pointed out.

Also: IT leaders fear they are being affected by the tech infrastructure in a hurry to adopt Gen AI

He added that identity needs to be reassesed throughout the workflow or dataflow. Here, the reliability of the credentials is reassessed as it is used to access or transfer data, including who it is transferred to.

Camacho emphasizes the need for businesses to establish a clear identity management framework. She said that access management doesn't differ based solely on the role of users. Companies urged them to invest in strategies that assume that all identities within an organization are privileged.

Assuming that all identities can be compromised, she added that the emergence of Gen AI will only increase this. Organizations can preempt robust security policies and implement the necessary internal change management and training, she noted.

And the IBM research shows that business leaders have lost faith in it. This is the reason

This is important for the public sector, especially as more governments are beginning to deploy GEN AI tools in work environments.

In fact, a survey by Capgemini, which voted 1,100 executives around the world, found that 80% of government and public sector organisations have increased their investment in Gen AI over the past year. Approximately 74% have described the technology as being transformative in helping drive revenue and innovation, with 68% already working on some GEN AI pilots. However, only 2% have enabled GEN AI features in most or all features or locations.

Also: A clear roadmap lacking in AI governance and overall corporate recruitment

98% of organizations in this sector allow employees to use Gen AI to some extent, while 64% have implemented guardrails to manage such use. Another 28% have limited such use to research notes from the employee group, Capgemini, who have chosen such use, and 46% have developed guidelines for responsible use of Gen AI.

However, when asked about concerns about ethical AI, 74% of public sector organizations pointed to a lack of confidence that GEN AI tools are fair, while 56% expressed concern that bias in the GEN AI model could have embarrassing consequences when used by customers. Another 48% highlighted the lack of clarity in the underlying data used to train GEN AI applications.

Focus on data security and governance

As things stand, the focus on data security has increased as more government services become digitalized and more risk of being exposed to online threats.

Last month, Singapore's Ministry of Digital Development and Information (MDDI) revealed that there was a government-related data incident in 2023. The ministry believes that more government services have increased to higher data usage as they are digitalised for citizens and businesses.

Additionally, we recognize the need for more government officials to report the incident, saying MDDI may have contributed to the increase in data incidents.

Also: The AI ​​Gold Rush makes basic data security hygiene important

In its annual update on the efforts made by Singapore's public sector to protect personal data, MDDI said 24 initiatives have been implemented in the past year between April 2023 and March 2024. These include a sector's central privacy toolkit that anonymizes 20 million anonymous documents and supports over 20 public sector Gen AI use cases.

The government's data loss protection (DLP) tools have been further improved. This works to prevent accidental loss of classification or sensitive data from government networks and devices.

All eligible government systems use central account management tools that automatically remove unwanted user accounts, MDDI said. This reduces the risk of unauthorized access by executives who leave their role, as well as the risk of threat access that uses dormant accounts to perform exploits.

Also: Safety guidelines provide the first layer of data protection needed with the AI ​​Gold Rush

As digital services adoption grows, there is a higher risk from data exposure, due to human surveillance or security gaps in technology, Pietschner said. As crowd halts are exposed, things go crazy, he said, organizations are trying to drive innovation faster and adopt technology faster.

He explains that it emphasizes the importance of using modern IT tools and adopting robust patch management strategies, and that older technologies still pose the highest risk for businesses.

Briguglio added that it also shows the need to adhere to the basics. Don't deploy security patches and kernel changes without regression testing or testing them in sandboxes first, he said.

Also: IT leaders fear that they are being affected by the tech infrastructure in a hurry to adopt Gen AI

The governance framework that guides organizations on how to respond in the case of a data incident is equally important, Pietschner added. For example, he said that public sector organizations are transparent and it is essential to disclose violations, so citizens know when their personal data will be made public.

He said that the governance framework must be implemented in Gen AI applications as well. This should include policies to guide employees regarding the recruitment of GEN AI tools.

However, another Capgemini survey that surveyed 1,098 senior executives and 1,092 software experts around the world found that 63% of public sector organizations have yet to determine a governance framework for software engineering.

Nevertheless, 88% of software experts in the sector use at least one GEN AI tool that is not officially approved or supported by the organization. This figure is the highest of all verticals voted in a global study, Capgemini noted.

That shows governance is important, Piechener said. He said that using fraudulent GEN AI tools allows developers to inadvertently expose internal data that should be protected.

He noted that some governments could create customized AI models to add layers of trust and monitor their use. This will help employees use only authorized AI tools to protect the data used.

Also: Transparency is extremely lacking amid growing interest in AI

More importantly, he said public sector organizations can eliminate biases and hallucinations in AI models, and that necessary guardrails should be arranged to mitigate the risk of these models generating responses that are inconsistent with government values ​​and intentions.

He added that the zero trust strategy is easier to implement in the public sector with a higher level of standardization. For example, government services often share standardized procurement processes, making it easier to make zero trust policies easier.

In July, Singapore announced plans to release technical guidelines to enhance security of AI tools and systems, and provide “practical measures.” The voluntary guidelines aim to provide references to cybersecurity experts seeking to improve the security of AI tools and can be adopted along with existing security processes implemented to address the potential risks of AI systems, the government said.

And how is Singapore creating more comprehensive AI?

Gen AI is evolving rapidly, and Briguglio said that everyone still doesn't fully understand the true power of technology and how it can be used. It seeks organizations that include public sector organizations that plan to use GEN AI in their decision-making process, and ensure that there is human surveillance and governance to manage access and sensitive data.

“As we build and mature these systems, we need to be sure that the controls we place around the AI ​​General are appropriate for what we are trying to protect,” he said. “You need to remember the basics.”

However, AI can work with humans to better defend against enemies who apply the same AI tools in attacks, said Eric Trexler, the US public sector business lead at ParaAlto Networks.

Also: AI is changing cybersecurity, businesses must awaken to threats

Proper checks and balance are required as mistakes can occur. When done correctly, AI can help organizations keep up with the speed and volume of online threats, Trexler explains in detail in a video interview.

Recalling his previous experience running a team that conducted malware analysis, he said automation provided speed to catch up with his enemies. “We don't have enough people and we have some tasks that make the machines better,” he pointed out.

AI tools, including Gen AI, can “find needles in the haystack.” This is something that can be a struggle when the amount of security events and alerts can bump into millions of people every day. AI can search for markers or indicators across an array of multifaceted systems that collect data, creating an overview of events.

Also: Artificial Intelligence, Real Anxiety: Why Stop worrying and love AI

Trexler also recognized that things could still be wrong and emphasized the importance of establishing necessary frameworks such as governance, policies, playbooks and more to mitigate such risks.





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *