Generative AI Adoption Raises Security Concerns in Workplaces, New Research Reveals

A recent report by IT software firm Ivanti has highlighted increasing security concerns linked to the adoption of generative AI (GenAI) in the workplace. The findings indicate that while the use of advanced AI technologies promises to enhance digital employee experiences (DEX), they also introduce significant risks that demand urgent attention.

The research, which surveyed over 20,000 IT professionals, executive leaders, office workers, and security experts worldwide, found that 86% of IT professionals believe poor digital experiences prompt employees to adopt unsafe workarounds. Such workarounds often involve using unsanctioned devices and AI tools, increasing the vulnerability of company data to security breaches, data privacy violations, and other legal issues.

Significantly, the report revealed that three-quarters of global knowledge workers currently utilise GenAI tools. However, a staggering 81% of these workers have not received any formal training in their use. Moreover, 15% of employees admitted to using unauthorised AI tools, highlighting a critical oversight in organisational security protocols.

Mike Riemer, Ivanti’s Field Chief Information Security Officer (CISO), summarised the issue succinctly: “Although harmless in the moment, employees typically opt for convenience and put security on the back burner." He further stressed the importance of employers understanding their employees' workplace behaviours to implement security measures that reduce the temptation for unsafe practices.

The report also underscored the importance of balancing robust security with user experience. Riemer elaborated, “Strong security shouldn’t come at the cost of user experience, as it is integral to maintaining both security and productivity.” The findings stress that by focusing on user experience in the design of security measures, companies can significantly reduce the chances of employees bypassing established protocols in favour of more convenient, though less secure, methods.

A concerning trend identified in the report is the widespread use of personal devices to access work networks. Half of the surveyed office workers admitted to this practice, with 32% indicating their employers were unaware. This practice can introduce significant vulnerabilities, particularly where employees bypass official security measures.

Furthermore, despite the well-documented benefits, only 62% of the surveyed companies use virtual private networks (VPNs) or zero-trust solutions to restrict network access and protect sensitive information. Even more concerning is that only 57% employ multi-factor authentication, a basic yet vital component of modern cybersecurity practices.

Additionally, the report found that security leaders are frequently excluded from DEX investment decisions. Only 38% of companies consult their CISO on DEX strategy, investment, and planning, despite the potential for these tools to significantly enhance both security and user experience.

Looking ahead, Ivanti recommends that businesses not only focus on integrating security and privacy consideration into their DEX strategies but also ensure basic internet hygiene practices are rigorously followed. This includes widespread utilisation of VPNs, zero-trust solutions, and multi-factor authentication. The integration of these measures would help mitigate the risks introduced by the adoption of generative AI tools and policies that do not fully consider the employee's digital experience.

With these insights, organisations have clear indicators of the steps necessary to protect company data while leveraging technology to enhance employee productivity. The onus is on businesses to navigate this balancing act efficiently and effectively, ensuring that security measures support rather than hinder the digital employee experience.

Source: Noah Wire Services