Why The Safest AI Teams Report The Most Incidents
Article excerpt
Highlighted: the sentence this signal was extracted from
By Heather Ceylan, Forbes Councils Member. Heather Ceylan is the Chief Information Security Officer at Box, where she leads the global information security program and strategy. In security, the metric I distrust most is a low incident count. A quiet quarter can mean the controls are working. Or it can mean that we weren't looking in the right places. Telling those two apart has always been part of the job, but with AI moving into every corner of the business, it has become more important than ever. Earlier this year, my team at Box, working with Harris Poll, surveyed 1,640 IT decision-makers about how they're deploying AI . Nearly half said an AI tool had already exposed information someone wasn't supposed to see, and one in six called the incident significant. But the more interesting detail is which companies reported it. The organizations furthest along with AI - the ones running agents across the business - reported more incidents, not fewer. Sixty percent of the most mature reported an exposure event, compared with 46% of the least mature. That's easy to misread as the leaders having weaker controls than everyone else. A more careful read is that they're running more agents across more systems, so there's more that can go wrong and they're far better at spotting it when it does. The difference is visibility. More than a quarter of the least mature organizations had...
Keep reading with a free account
The rest of this article, and every signal for Box, is in your free account.
