One thing to remember is the security industry is making money when you’re afraid.
So the actual risk for a business your size is not a hacker on a computer saying I’m in or whatever. It’s an employee clicking a bad link or pasting client data into a free online AI tool.
So here’s the good news. The stuff that works best costs almost nothing. Truthfully, I don’t even think you need to spend a dime.
Train your team on phishing
Here is what phishing means. It basically means people trying to trick you trying to get access to your computer by pretending to be someone.
You want to audit your tools that you’re using and you want to audit exactly how your company and your employees approach these phishing scams and what their training level is on that.
You will see more social engineering when AI comes out, so be prepared.
Turn on two-factor authentication
I know it’s annoying, but it’s genuinely one of the best things you can do security wise. Turn on multi-factor authentication.
Give your team the right AI
So the answer isn’t banning AI, it’s giving your team the right version of it.
If they don’t need access, you shouldn’t give them access. But if they do have access, they should have a strong filter on what’s allowed in.
Put a dumb bouncer in front of your AI
And what I’ve been doing with my AI systems is we run through, I’ve mentioned this before, but a dumb bouncer idea. So you have a less complicated AI at the front of each message, right? It reads emails, it reads incoming messages. And it strips out all the parts that might be toxic, like install this software, transfer money here, stuff like that.
So having a two-tiered approach there is really smart. I think that when you have a smart AI running your company or doing work for you, you don’t want to expose that same AI to someone who can potentially socially misdirect them.