Transcript
I'm very pleased to be joined by Matt Locke, Field CTO at Varonis. Really good to see you, Matt. Thank you for having me. So we're talking about securing sensitive data in the age of AI, and you've just released a report, The State of Data Security. It reveals some alarming figures. 99% of organizations have sensitive data exposed to AI tools. So what does that tell us about the state of AI security today? Yeah, it's an alarming stat, so nothing that comes as any surprise, really. I think, more than anything, it highlights the speed of which AI is being adopted, and the lack of progress with traditional IT security functions. A lot of companies are realizing now that to roll out AI, it's going to highlight issues and risks that perhaps they've been ignoring and not addressing for years, and AI is fundamentally bringing that to the forefront. I want to dig deeper for a bit. So why do so many organizations find themselves in this sort of vulnerable position? Yeah, well, it's because traditionally, organizations don't adopt a data-centric focus on security. I think too many organizations are still looking at perimeter-based security, maybe trusting internal employees, and unfortunately, AI will utilize all of the permissions that an employee has, and if they're not addressed, if they're open, if they're exposed, inevitably, AI will utilize all of that. Yeah. Well, we hear a lot about shadow IT, but what about shadow AI? It's becoming a growing concern, employees using apps without approval. What makes this such a big risk to manage, I suppose, a difficult risk, and what are the other risks that companies are taking on? Yes, of course. It's a massive blind spot for a lot of companies. I think AI, particularly Gen AI, the co-pilots, the GPTs, they are incredibly consumer-friendly. They're designed to be consumer-friendly. I think in our personal lives, we're using them more and more, and so it's inevitable, I think, that individuals are going to start realizing that they can be more productive, get things done using AI. Lack of investment or focus in organizations means that they run the risk of these tools being used. There's no software needed. There's no logon needed. You can open up a browser and start using AI, and the risks are potentially huge. There is no real visibility of what's going on. Employees don't really understand the risks of putting sensitive information into AI. We've seen it before where PII, source code, are being uploaded into these AI tools to be able to make them more effective, and that information is gone. It's lost. Unfortunately, once it's left, it's very hard to retrieve and get it back. It's inevitable that those models will start to use that sensitive information to train themselves and get better. As organizations really think about providing these tools to the employees, they will find a way, and they will start to use them. We've heard about shadow IT for a long time. Shadow AI really is a massive risk to a lot of companies, and so they need to think about making it available, thinking about sanctioned AI. At least they have some chance of having some visibility, some control, and some governance about how they're being used. I want to ask you about automating data controls because many organizations still hesitate in racing automation. Why do you think this is? What's in their way? Well, there's a number of reasons. I think if you speak to an IT security team, they would happily, readily admit that automation is going to make things like data security challenges that much easier, but there's the worry and the risk of having any adverse effects. IT typically don't want to be seen as the bad guys. If I remove access from a particular file, or a site, or a particular data set from an employee and they can't perform their job, they can't share it, they can't process, then IT really are going to face the wrath of that organization. Automation has somewhat been a bit of a terrifying aspect for a lot of companies. They'd like to have change control. Really it comes down to a lack of visibility, a lack of context. I think if organizations want to tackle, for example, AI security and data security, they need to have context of what's important, what's sensitive. They need to be able to get high levels of confidence that these automation policies are going to do what they need to do. They're not going to have an adverse impact. Maybe start by running it in order only mode. Maybe thinking about running some policies around low-risk environments, just removing superfluous access or stale accounts. IT can run low-level automation policies to gain confidence, but most importantly, they can then take that information and share it with the C-level, the board, to show them the gains that they've made in reducing risk. There has been no impact on the business. It's about building confidence. I think with the sprawl of data that we have nowadays and the amount of permissions that have been generated all the time, it's inevitable that we have to adopt a level of automation. I think we're getting there slowly, but it's about context, it's about visibility, and it's about confidence on anything. Who owns the data in the organizations that you work with? What are the patterns you're seeing there and who owns it currently, but also who should own the data? It really depends on who you ask. I think most organizations realize now that the business owns the data. Can provide the frameworks to make sure that it's procured and provisioned and managed and backed up and all that stuff, but I think they recognize that the business do own the data. The business understands the value of the data. They should ideally understand who should have access to it. There's a whole educational thing that we need to keep doing to explain the risks of making mistakes and oversharing, but fundamentally, it is the business that own the data. There are more risks introduced with that type of thing. The business really want to adopt an open model of a collaboration and sharing. If you ask the business to decide who gets access, they'll be very willing to make sure everybody can do their job. You speak to IT and they're very much from a compliance, a security, a risk perspective, they want to lock it down. It's a happy medium. How do you strike that balance? How do you strike that balance? A lot of it is education. It's really about implementing guardrails, fundamentally. I think with the move to collaboration platforms, for example, as we all went into lockdown, the adoption of collaboration made these businesses function during that time. In essence, what we did is we made the decision somewhat unknowingly to allow the business to make decisions on who get access to data. IT relinquished that control. We're not getting it back anytime soon, but the business want to implement guardrails. They want to say, you can share and you can collaborate and do the productivity gains that you're seeing, but we're going to put some policies in place just to protect you, us, the business, our customers, our clients. If somebody shares something really sensitive, financial information or credential information with the whole organization, we're going to take that away. We're going to lock that down. We're not going to come and step on your toes and take away all of that productivity that we've become used to. Yeah, there has to be an educational piece, there has to be some guardrails, but we also have to trust the business that they know who should have access to it. We've spoken a lot about the risks of AI, but I want to end on a positive note. Have you got examples of organizations actually getting AI adoption right? Yes, absolutely. There are examples. Thank God there are examples. I think what is common amongst the organizations that have done this is that they have adopted a data-centric view to applying security controls. They're looking at things like policy-based access, so making decisions to say, well, marketing can have access to collateral about proposals and things they want to put on, but they can't have access to the PII. It makes it a little bit easier to then adopt things like AI solutions. Companies that are readily adopting these technologies are doing it successfully in a way where they understand what information can be fed into these platforms, they're ensuring that LLMs or whatever models they're building aren't learning from data sets they shouldn't be learning from, there's a lot of visibility, there's governance in place, there are committees set up to ensure that it's being used properly. It's about safely adopting these new technologies. They are going to be part and parcel of what we do in the future. The companies that don't typically do so well are the ones that say, no, we're not using it, we're locking it down, and then shadow AI creeps in, and then before you know it, information is leaking before you even think about rounds of actually securing it. It's those organizations that take a data-centric, policy-based approach that are actually reaping the rewards of running AI. Well, Nat, this has been really insightful. Thank you so much for sharing your expertise today. No problem. Thank you very much. I've been speaking with Matt Lark of Varonis, and for ISMG, I'm Anna Delaney.