Ivanti CISO Takes on AI Security, Governance and Talent Gap

However, the speed at which organisations are deploying AI is causing problems. Companies are losing sight of regulation and employee training, while security measures are being overlooked. 

Organisations are adopting AI without understanding its risks. At the same time, government frameworks are fragmented and failing to keep pace. This creates a gap between innovation and oversight, where AI systems are used without accountability.

Lack of regulation leads to a lack of AI transparency. Ivanti found that among people who use generative AI tools at work, nearly a third (32%) keep their AI use completely hidden from management. Employees could be sharing company data, without malicious intent but with real consequences.

Therefore, organisations must encourage transparency by building a culture of trust. Rather than prohibiting AI use, leaders should assess which platforms meet security standards and provide trusted sanctioned options. Reduced friction for initial testing, while maintaining a secure environment, can help reduce shadow AI use.

At Ivanti, we are trying to do just that. We have established an AI Governance Council – a cross-functional group designed to define acceptable and prohibited use cases. 

We’ve also implemented different tiers of oversight based on the use case, giving employees a path to submit AI tools for review, alongside practical guidelines. The goal isn’t to slow innovation, but to enable it responsibly.

Is the future of cybersecurity talent defined by a blend of technical expertise and AI fluency? 

Ultimately, being able to understand and utilise AI effectively will become a core requirement for all cybersecurity talent alongside technical expertise. Businesses must take responsibility in ensuring employees are trained to develop these hybrid skills.

As AI is embedded across security operations, cybersecurity professionals will be expected to work confidently alongside these systems rather than treat them as optional tools. 

But that isn’t to say that core security skills will become redundant. Employees must still be able to understand networks, systems and identify vulnerabilities.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *