AI agents are on the loose....is your security organization ready?
In Part 3 of our conversation with Tim Freestone, Chief Strategy Officer at Kiteworks, we dig into the findings of the company's fifth annual Data Security and Compliance Risk Survey -- and the numbers are sobering. Eighty percent of organizations experienced a security or AI incident in the past year. Sixty-three percent of those incidents produced a compliance consequence. And half of organizations still cannot produce a complete AI data access audit record within one business day.
Watch The Full Episode Here!
The Growing AI Governance Gap
Tim highlighted the significant findings from KiteWorks' fifth annual data security and compliance risk survey. Alarmingly, 80% of organizations reported a security or AI incident in the past year, with 63% of those incidents leading to compliance consequences. This paints a stark picture of the current landscape where organizations struggle to keep pace with the sophistication of AI-enabled threats while maintaining adequate governance.
Tim emphasized that "AI governance is ultimately a business responsibility requiring stronger board-level AI literacy". The gap between threats and defenses is widening, and organizations must prioritize both AI literacy and robust audit trails to navigate this complex environment.
Insights on Spending and Maturity
Interestingly, Tim pointed out that organizations with the largest security budgets are not necessarily the ones achieving the highest maturity scores in their security posture. He noted, "A lot of this comes down to buying technology without understanding how to leverage it." The skills gap in cybersecurity and data governance remains a significant hurdle.
Organizations often invest heavily in tools without the necessary expertise to utilize them effectively, resulting in wasted resources and missed opportunities for improvement.
The Importance of Collaboration
During our conversation, we discussed how the traditional silos between cybersecurity and compliance teams are beginning to erode. Tim remarked, "There's collaboration that needs to happen", as the lines between these disciplines blur in the face of new technological challenges. This collaboration is vital for creating a unified approach to data governance and compliance, ensuring that organizations can respond effectively to threats.
Acknowledging the Blind Spots
Tim also shared insights on the blind spots many organizations face regarding AI risks. He stated that "Aha moments come from first-hand experiences and media reports of breaches". Organizations must be proactive in understanding their exposure to AI risks, rather than waiting for incidents to occur before taking action.
As the landscape continues to evolve, it's crucial for leaders to recognize the importance of integrating AI governance into their overall security strategy.
