Monthly Archives: September 2023

Cloud Security – A Shared Responsibility

While cloud computing is now a common way to provision computing resources and outsource IT functions, security can be a (perceived) obstacle to adoption. Cloud security can be a shared responsibility, however, between the customer and provider. Read on to learn more about what to expect from a current or prospective provider, and what you can do yourself to stay secure.

 

 Cloud Security and Why it Matters

 

Cloud computing, although providing multiple benefits, also presents security concerns. With compute resources available through the Internet, the greater amount of data moving between networks and devices, data which can be lost or stolen. Cloud security is a combination of technology, processes and policies that can keep your applications and data safe, reliable and available. Who ensures this, your company or the provider?

 

Cloud Security a Shared Responsibility

 

The answer is, both. In general, the provider provides and maintains the infrastructure, and the company looks after the data and applications “in” the cloud. How much responsibility either party assumes depends on the type of platform used. For instance, for Infrastructure as a Service (IaaS), the provider furnishes just that – infrastructure–and your company needs to manage the security of its own data and applications.  Other platforms like PaaS and SaaS provide more oversight. Sometimes the CSP will also offer data storage and monitoring. Top providers may even offer security-by-design or layered security as well as network monitoring and identity access management. 

 

Your Company’s Role

 

In general, a provider that handles more of the functions also protects more. Beginning with Infrastructure as a Service (IaaS), you secure data, applications, and control over your virtual network. With Platform as a Service (PaaS) you still handle data and applications and user access. Software as a Service (SaaS) allows you to outsource applications while still maintaining oversight of user access. Your company may need to employ multi-factor authentication for access control and train workers in password procedures. 

 

Considerations When Seeking a Provider

 

When evaluating a cloud service provider, security is critical. Does your current or prospective provider offer network monitoring? One of the concerns about cloud is lack of visibility regarding who attempts to access your network; how does the provider address this? With more scrutiny of data handling and more stringent regulations, assuring that your provider follows the same regulations you do is vital. 

 

Cloud computing, even with its benefits, carries security risks. To learn more about developing your cloud security strategy, contact your trusted technology advisor today.

How Will Your Business Use Artificial Intelligence?

Artificial Intelligence seems to be the hot topic nowadays, in the business world and the world at large. Many of us use the technology, whether we know it or not. Visitors to a website see that chat window pop up, and it seems like a real person is on the other end. Because of AI, it is often a chatbot simulating personal interaction. With the rollout of Generative AI in the form of ChatGPT, previously unknown possibilities have arisen. Artificial Intelligence has the potential to boost business productivity but also carries risk. Read on to learn more about how to harness this technology for the benefit of your business while considering risks of its use.

 

ChatGPT Has Started a New Conversation

 

Recently, CompTIA published a blog post about how generative IT has created great potential to enhance everything we do, but also brings up serious questions. The article cites questions for business leaders to ask. One is, can you harness AI to improve your operations and offerings, and should you? What benefits does AI offer, and what risks? And what do customers want? As with all tech innovations, considering business goals first is key, and how the technology can be implemented to achieve these goals. One theme that stands out from the article: proceed, but with caution.

 

Benefits Come with Considerations

 

Some members of the CompTIA board of directors cite specific ways they’ve benefited from AI technology. For example, one is able to upload documents like contracts and let AI find any red flags ahead of time, reducing legal costs. Or an email scheduling app can remind a user of upcoming appointments, almost in the same way a human would. Perhaps AI could be used on a video call to summarize main points and come up with directions for what to do next. With AI, especially applications like ChatGPT, come different considerations.

 

Potential Risks of Generative AI 

 

According to Scott Barlow, one of the authors, “previous technologies helped organizations to grow faster and scale. AI will take that to the next level and enable everyone to be more productive.” He goes on to say that it comes with more risks than other applications. Errors, or “hallucinations” can happen, where the accuracy of the model deteriorates. One model’s ability to respond correctly to math questions dropped from 93% to 30%, according to Barlow. Aside from this, data may be biased, leading the algorithm to generate content that may unfairly exclude others. And how transparent is the model’s process of generating the result? Explainability is another issue–how did the large language model (LLM) used find the result it did. 

 

One of the big risks is security. For starters, even though AI has potential to spot threats, it could also enable even an amateur hacker to write malware into code and distribute it via a sophisticated phishing email, or simply find other ways to intrude into your company’s network. Companies will need to consider access controls, such as which LLMs they allow their workers to use. Additionally, this use needs to be protected by a firewall and must not access an organization’s intellectual property. Protecting customers’ personally identifiable information is also paramount. Artificial intelligence also has the potential to value efficiency over interacting with people, another thing to think about preventing. While people enjoy using AI in the form of ChatGPT and what it generates, they still need to interact with a human. Or they need to be given that choice. 

 

While AI’s capabilities and potential are exciting, we still need to proceed carefully and watch out for risks. For further guidance, contact your trusted technology advisor today.