0861 887 788

AI has changed industries, workflows, and the rules of how we work. It has also changed the threat landscape. Phishing emails now look legitimate. Deepfakes can make it difficult to tell what is real and what is fake. Social media is flooded with AI-generated content and automation. Think of AI like a car: it can be used to do great things, but in the wrong hands, it can also cause damage.

The opportunities and productivity that AI unlocks for us today are endless. We can communicate with it as if it were a colleague or assistant. We can build agents to automate repetitive tasks. We can even instruct it to help with almost anything we need, short of actually making us tea. The point is that AI is not something to fear; it is something to encourage. Across industries, organizations are building AI plans to automate processes, boost productivity, and enable their users. But are they doing it safely? Is the data they input protected?

There is a saying that goes: if something is free, you are the product. Users are joining open AI platforms and using free versions everywhere. Unless your company governs which platforms are appropriate and which are not, users will choose whatever is easiest. With paid AI services like Microsoft Copilot, you have more control over how the platform handles your data. In the case of Copilot, once the subscription is assigned to your users, the platform works within your organizational data boundaries rather than relying on random public data. When a user uploads data, it remains within your organization, which helps reduce the risk of data being used to train external AI models.

The ugly side of AI appears when sensitive company data is shared with AI platforms without proper control or consent. If an AI tool is prompted correctly and has access to exposed information, it could potentially surface internal data, financial details, or other confidential content. That is why organizations need to decide which AI model they trust, pay for the right licences, and put governance around its use. Work with trusted ICT partners, secure your data, and make AI adoption a controlled business decision rather than a free-for-all.

Now for what is probably my favourite part of AI, although not necessarily the good part: how are threat actors using AI today? Threat actors have become smarter over the years, and they have fully adopted AI to speed up attacks. Phishing emails can look like legitimate messages. Even a remote employee may appear legitimate until the laptop arrives and they start accessing organizational data. A great example is a case from last year where a large technology company employed an individual in Japan. The individual went through a series of interviews, appeared on camera, matched the expected voice, and had credentials that checked out. The company signed an employment contract and shipped the employee’s kit. Everything went well for the first few weeks, until the company’s MDR solution detected that the employee was accessing organizational data unrelated to their role. After an investigation, the MDR provider concluded that the individual was never real. A very convincing “person” had been created using AI. They also discovered that a VPN had been installed on the device with a backdoor to South Korea. Fortunately, the threat actor was stopped before any damage could be done.

The moral of the story is simple: AI can help organizations build speed, improve productivity, and automate repetitive work. But it can also be used to support cyberattacks, including ransomware campaigns that organizations may not see coming.

Stay safe. Govern your AI usage. Protect your data.