More than one-third of sensitive business information input into generative AI apps is regulated personal data: Netskope Threat Labs – CRN

AI For Business


Netskope, the leader in Secure Access Service Edge (SASE), released new research showing that regulated data – data that organizations are legally obligated to protect – accounts for more than one-third of sensitive data shared with generative AI (genAI) applications, posing a potential risk of costly data breaches for businesses.

New research from Netskope Threat Labs reveals that three-quarters of companies surveyed currently completely block at least one genAI app, reflecting enterprise technology leaders' desire to limit the risk of sensitive data exfiltration. However, less than half of organizations have data-centric controls in place to prevent sensitive information from being shared in input queries, and most organizations are lagging behind in adopting the advanced data loss prevention (DLP) solutions required to safely enable genAI.

Using a global dataset, researchers found that 96% of enterprises currently use genAI, a figure that has tripled in the past 12 months. On average, enterprises are currently using nearly 10 genAI apps, up from 3 last year. And the top 1% of adopters are using an average of 80 apps, up from 14. Along with increased usage, enterprises have seen a surge in proprietary source code sharing within genAI apps, accounting for 46% of recorded data policy violations. These changing trends complicate how enterprises manage risk and require more robust DLP efforts.

The security and data loss control nuances that organizations are applying are positive signs of proactive risk management. For example, 65% of companies have now implemented real-time user coaching to guide users' interactions with genAI apps. Research shows that effective user coaching plays a key role in mitigating data risks, with 57% of users changing their behavior after receiving a coaching alert.

“Securing genAI requires further investment and increased attention. Use of genAI is pervasive in the enterprise and shows no signs of slowing down anytime soon.” James Robinson, Chief Information Security Officer, Netskope“Companies need to be aware that genAI output can accidentally expose sensitive information, spread misinformation or introduce malicious content. A robust risk management approach is needed to protect data, reputation and business continuity.”



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *