Urgent.News

What's breaking now, across thousands of outlets.

AI

AI deployments bring with them risks companies are ill-prepared for — analysts

Enterprises that have been rapidly adding AI tools and services into their workflows are often not prepared for the internal and external threats that could expose weaknesses in their systems, analysts said. “I don’t think they are ready,” said Pete Shoard , chief of research for cybersecurity at Gartner. “I think the underlying thing here is that we’ve been doing the same thing for so long — and…

AI deployments bring with them risks companies are ill-prepared for — analysts

As businesses rapidly integrate AI tools into their operations, they often find themselves unprepared for the potential internal and external risks that come with these deployments, according to cybersecurity analysts. Pete Shoard, Gartner's chief research officer for cybersecurity, emphasized that companies have been operating in the same manner for too long, and it is time for a change.

External threats, such as sensitive data leakage to large language models (LLMs) or uploading sensitive files to public repositories like GitHub, pose significant risks. Pete Shoard pointed out that hard-coded secrets being uploaded through vulnerable applications to GitHub can create avenues for attackers to gain access to a company.

Peter Nost, a senior analyst at Forrester, noted that AI is enhancing various stages of threat detection and response, enabling organizations to proactively identify and address potential vulnerabilities. However, this shift towards a more proactive approach has not been evenly adopted across all companies. Jack Gold, a principal analyst at J. Gold Associates, highlighted that smaller and medium-sized businesses (SMBs) tend to lag behind larger organizations in terms of cybersecurity readiness, as they often lack the necessary resources and budget to invest in robust security solutions.

Gold emphasized that many companies are more focused on implementing barriers to protect against security impacts rather than actively seeking out potential threats. The increasing reliance on AI agents also contributes to technical debt, as more and more agents are generated and deployed, potentially introducing new attack surfaces and security challenges.

As a result, companies are seeking external services to help them identify and mitigate these risks. Established vendors like Palo Alto Networks and CrowdStrike offer comprehensive solutions, while smaller firms specialize in specific areas such as network monitoring or cloud monitoring. Some innovative products, like Thinkst Canary, utilize honeypotting technology to attract attackers and gain insights into their tactics.

Despite the availability of advanced threat detection tools, remediation remains a challenge for many organizations, as they tend to prioritize careful consideration and patching of identified issues over automated solutions.

Written by urgent.news from Computerworld's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at computerworld.com →

More in AI

More from Wednesday 26 August →