Daily News
Generative AI surge: Cybersecurity challenges prompt urgent reassessment for enterprises
Published
3 years agoon

A recent study by Menlo Security sheds light on the escalating cybersecurity challenges faced by enterprises due to the burgeoning growth of generative AI, urging businesses to swiftly reassess their security strategies. Tools like ChatGPT have become an integral part of daily workflows, and the seamless integration of AI into work routines prompts a call for heightened security measures.
Andrew Harding, VP of Product Marketing at Menlo Security, emphasised the need for a balanced approach, stating, “Employees are integrating AI into their daily work. Controls can’t just block it—but we can’t let it run wild either.”
Harding highlighted the consistent rise in generative AI site visits and power users within enterprises, emphasising the persistent challenges faced by security and IT teams. The report indicates a surge of over 100% in visits to generative AI sites within enterprises in the last six months, accompanied by a 64% increase in frequent generative AI users.
However, the study underscores that despite commendable efforts by organisations to implement security policies around generative AI usage, the prevailing domain-by-domain approach proves insufficient.
Harding cautioned that this piecemeal tactic struggles to keep pace with the continuous emergence of new generative AI platforms. The report revealed an 80% spike in attempted file uploads to generative AI sites over six months, a direct consequence of added functionality, posing a significant risk beyond potential data loss.

Researchers warn of amplified phishing scams, as generative AI may enhance the sophistication of phishing attacks. Harding suggests the need for real-time phishing protection to prevent AI-powered phishing incidents. The rise of generative AI, exemplified by tools like ChatGPT, has been meteoric.
OpenAI’s GPT-1 in 2018 marked the beginning, followed by Google Brain’s PaLM in 2022 with 540 billion parameters. The debut of OpenAI’s ChatGPT in 2022 ignited a global frenzy, leading to widespread integration into daily workflows.
However, the rapid assimilation of generative AI tools introduces overlooked risks for businesses. These systems are only as secure, ethical, and accurate as the data used to train them.
Generative AI models draw training data from vast sections of the public internet, lacking comprehensive control over the content ingested. This poses a potential threat, especially if proprietary information is inadvertently posted online, making it accessible to the models.
To strike a balance between security and innovation, experts recommend a multi-layered approach.
Harding suggests implementing measures such as copy-and-paste limits, security policies, session monitoring, and group-level controls across generative AI platforms.

The lessons from past technological inflection points, such as cloud, mobile, and web technologies, underscore the need for organizations to adapt security strategies to align with evolving technology paradigms.
With the exponential adoption of generative AI, businesses face a crucial juncture where security strategies must rapidly evolve to prevent these technologies from spiraling out of control.
As Harding aptly cautions, “There’s been consistent growth in generative AI site visits and power users in the enterprise, but challenges persist for security and IT teams.” Businesses must find the delicate equilibrium between security and innovation to navigate the evolving landscape of generative AI.