New cybersecurity guidance for artificial intelligence (AI) systems was issued jointly by the U.S. Cybersecurity and Infrastructure Security Agency, the FBI, the National Security Agency’s Artificial Intelligence Security Center, and cybersecurity agencies of Australia, New Zealand, the U.K., and Canada. The Guidelines, Deploying AI Systems Securely: Best Practices for Deploying Secure and Resilient AI Systems, are particularly notable because they focus on best practices for organizations that deploy AI developed by a third party rather than targeting developers of AI systems.
Resource Search
The U.S. Securities and Exchange Commission (SEC) released the Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rules in August 2023, requiring registrants to provide and report timely information about their cyber risk so that investors can make informed investment decisions. With the rules in place, the SEC expects that companies will apply materiality considerations for cybersecurity incidents as they would be applied regarding any other risk or event—through the lens of the reasonable investor.
Despite cybersecurity being noted as a top priority according to PwC’s 2024 Global Digital Trust Insights survey of 3,876 business and tech executives at the largest global companies, the actual progress on improving security is sluggish, even stagnant. By making one or two bold moves to put security at the epicenter of innovation, the top companies are positioning themselves for greater productivity and faster growth as they dive into new technologies with confidence that they are well protected.
The evolution of cybersecurity threats is increasing at a rapid pace and becoming more sophisticated as they leverage the same advanced technologies and methodologies as cyber defense tools. No longer are cyberattacks focused primarily on financial incentives, they are also aiming at maximizing operational disruption.
The tech industry has been undergoing a difficult period. Economic instability, high inflation, and rising interest rates have prompted tech companies to reevaluate their business strategies, adjust their growth plans, and revisit their staffing models. At the same time, there have been remarkable advancements with generative artificial intelligence (AI) taking center stage and ushering a new era of technology. This acerating pace of tech innovation continues to introduce new business opportunities across industries.
The cyber landscape is always evolving and requires proactive diligence, effective controls, and regular education to significantly reduce the risks. While the volume and complexity of threats continue to grow, experts agree that businesses can significantly reduce their exposure—and costs, if a breach occurs—by following some well-vetted best practices. This list of such practices begins with setting a strong governance framework and is underpinned by continual awareness and education.
The use of artificial intelligence (AI) continues to spread with a staggering speed as it reshapes industries through improved efficiency, productivity, and decision-making. However, the meteoric rise and adoption of AI technology—including ChatGPT—can overshadow some valid concerns around security and privacy. Addressing those concerns, this report offers insights from industry use cases for AI and delves into the cybersecurity risks, privacy regulations and compliance, mitigation strategies, and immediate actions that security teams can take to mitigate the risk from generative AI.
The internet and specifically e-commerce has grown exponentially over the last 30 years, incorporating nearly every aspect of trade. As a result, industries and governmental agencies have blossomed to ensure cybersecurity, expending over $150 billion annually to combat this persistent threat. As this market segment continues to expand, crippling cybersecurity intrusions have increased dramatically affecting nearly every sector including finance, health care, infrastructure, and defense systems.
By now, most organizations have implemented mandatory annual cyber awareness training for their employees, covering topics such as phishing and social engineering attacks. While this education is thwarting cybercrime, it is only part of robust defense strategy. In looking back at the state of cyber in 2022 and highlighting important developments, we also look ahead at what is next in building cyber resilience that will require additional defensive measures and documentation.
Cyber threats and fraud schemes are designed to infiltrate and compromise your business. By using this cybersecurity resource guide and taking proactive actions to prevent cyber threats, you can strengthen your defensive strategy. This guide includes: Cyber Fraud Overview Recommendations and Resources Quick Reference Guide for Employees Cybersecurity Checklist