Restricting GenAI Copilots with Securiti’s Jack Berkowitz
Jack Berkowitz, chief data officer (CDO) for Securiti, explains why many organizations are not allowing employees to turn on generative artificial intelligence (AI) copilots for fear of losing control of sensitive data.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Jack Berkowitz, who's the Chief Data Officer for security, and we're talking about, well, copilots, some folks are turning them off and other folks never turned 'em on in the first place.
And a lot of it has to do with security. Hey, Jack, welcome to the show. Anyway.
Good to see you. So what are you seeing going on here? Is it maybe only in regulated industries that are people turning these things off?
Or are there more concerns at work here because people are kind of starting to really understand where that data's flowing? Yeah, I, I thought, and we thought at the beginning it was about regulated industries, you know, fears about, you know, different sort of regulations coming down, but it turns out it's across the board. Uh, what people are starting to see is, is not so much the problem of hallucinations, which is a concern, but it's really, you know, data that they thought was secured, actually getting exposed inadvertently through copilots.
And so it really comes into sort of a data governance and data rights issue, And exposed to what exactly, or is the concern that is exposed to the LLM that, um, it might some days show up in some sort of training and output in the future? Or is it more about it's exposed simply because it's moving across, um, some sort of network? It's really the latter, right?
Uh, exposed because it's, it's available inside the system, and if you had hunted for it, maybe you had the rights to go see certain things, whether it's HR data or, you know, company financial data or whatever. It happens to be business plans, but now it's at the fingertips of everybody inside the company or everybody who has access to the chat bot. And suddenly, you know, people are asking for information and it's, it's being a great co-pilot.
It's giving it to 'em. Uh, it's just maybe the original intent wasn't for them to have it. So this is like that scenario where everybody's suddenly asking, um, you know, uh, chat GPT how much their boss makes, right?
Yeah, exactly. I mean, that's the, that's the outer extreme that everybody thinks about. Mm-Hmm.
But, uh, you know, it could be very sensitive things, you know, um, could be about mergers and acquisitions can be about, operations can be about, you know, suppliers, all sorts of different things can be end up getting exposed. Mm-Hmm. Um, there's solutions to this, right?
Um, you know, if anybody had ever set up, you know, very clean, uh, data repositories, well then maybe that's the solution. But, but nobody's really done that. So it's really about going back to all that unstructured content, those documents, those emails, those slack messages, and cleaning up, uh, the permissions accr.
And it takes some work. Will people do that work for the benefits of Gen ai or will they sit there and say, that's just too big a lift for that effort and, you know, 'cause the truth of the matter is data hygiene's been, shall we say, uh, limited over the last few decades. Yeah, exactly.
You know, if you think about 20 years ago, everybody had Documentum installed and that was the ultimate data hygiene, and nobody wanted to do it 'cause it was too much of a heavy lift. Um, I don't know. I mean, we've heard about people asking for better NDAs.
We've heard other companies say, you know what? We're just all gonna operate at a certain level and let it go. I think it's depends on that risk profile of the company and what they're concerned about.
Um, you know, and it, and, and it is, right? It's, it's just like any sort of privacy or data security. There's always a, a trade off between, you know, what's the benefit that you want to give versus what's the permissions you're giving.
You know, like when you're on Amazon, you're giving it permissions to look at what your, what your shopping history is and everything else to get you better product recommendations. Uh, so there is always this trade off that people either consciously or subconsciously make, and companies are gonna be making that same trade off as to move forward. Is it too much to ask individuals to just be careful with the data that they're gonna expose through these copilots?
Or is, um, you know, just the fact of the matter is that the average person just isn't gonna, you know, think about that until it's too late? Yeah, I think it's really the latter, right? And unfortunately, uh, you know, you'll find instances where people will expose information and then use it for whatever reason that, uh, that they have, right?
And, and that can create some, some situations, um, you know, either that are embarrassing or that are legal, or that are, are, you know, certainly, uh, uh, not great for the business. Mm-Hmm. And I think EPA exposes, uh, an uncomfortable truth.
I think a lot of organizations and people go to work for them and they start to refer to, you know, the company's data, but a lot of times that data, they're just stewards of other people's data that they've been entrusted to use. And maybe we are a little too cavalier with the way we think about data, and that's now manifesting itself here in the age of copilots. Yeah, I, I think you really hit it on the head.
Uh, I've worked, uh, prior to joining security, I worked at a Fortune, uh, 500, you know, really dealing with a lot of personal information before that. I think we originally met when I was at Oracle, and you deal with lots of different data and, you know, building the ability to respect that data into the culture of, of companies is really important. And, you know, every day you, you hear about things, but then once you're inside the wall and you just walk around and you know, you can observe whether or not a company has that culture of, of really protecting their consumer or not.
Right? Um, and you can see it in five minutes when you walk through the holes, halls of any company can tell. Um, and so, uh, it's super important that that culture starts at the top and everybody understands it.
Mm-Hmm. Will this ultimately force us to go revisit a lot of these data management and hygiene issues that we've ignored for a long time? Because, um, usage of AI will come probably with some additional regulations as we go forward, but, um, I wonder if we're having a moment, as they say.
Yeah, I think so. I mean, if you look at it though, it, it's really tied to business benefit. If the businesses or the organization see a benefit, then they'll do the ig.
You know, you look at the explosion of data tools over the past eight or 10 years, you know, now we have lake houses and all this piping and everything. People are spending billions of dollars to get their structured data under control managed permissioned because there's a huge advantage or a huge business benefit they had. We're gonna see the same thing happen with this gen ai, uh, uh, revolution.
When people start to realize the business benefit, they realize that if I do the proper data governance, I do the proper security, then I can take advantage of it. And that business benefit for certain use cases already, we're seeing, you know, outweighs things. 8% gain in revenue, uh, through using some of these gen AI tools.
Well, you know, for a lot of companies, that's two or three years of sales growth. And if you think about it in that terms, and, oh, well now what do I need to do that the CEO will understand that, the board will understand that, and you'll start to see that as data hygiene, uh, improvements coming rapidly. And I think, you know, we at security, but also a lot of other companies are working on tooling and capabilities that can allow companies to use this stuff in a, in a more safe and a better way.
And does this surface a problem that at least in my mind, is kind of as old as time when it comes to it, but we've never really established who's responsible for data. Uh, a lot of times the IT folks will look at data and to them it's all the same because it's just more data moving through the applications. And the business side is the side that understands the nominal value of the data and what data actually is relevant and what data is sensitive.
So I feel like these two groups have never quite aligned on how to actually, No, it's, you're, you're spot on. It's always been a tennis game, right? Uh, and so you either had the centralized IT group or you had, oh, well just put, give it to everybody.
We saw that in bi, right? Give Tableau to everybody or centralize it all with SAP or business objects, right? Um, but really what you're gonna need is, is this sort of hybrid approach where the business is taking the decisions about, you know, the meaning of the data or the quality of the data or whatever.
And the IT organization, the security organization, or in the case for me, chief data organization, is actually enabling that through the right tooling, through the right policies, and through the right communication cultural change Among organizations that you have seen that have reached that level of maturity. What was it that kind of tipped it finally? I mean, 'cause a lot of organizations, I think there's people inside them that all have the right notion in their mind, but getting the organization to become that, um, data aware and, and reach that higher level of, uh, I don't know, hierarchy on Maslow's thing or whatever it is when it comes to data management.
Yeah, yeah. What, what, what, what gets 'em there, there, Yeah. See, it's, it's really about clarity of the mission, right?
Clarity of the mission about what they're trying to achieve. Um, you know, when you look at certain companies and you read their 10 Ks these days, you know, intuits 10 K is beautiful, uh, in terms of their, their mission, right? And then when you see that, then, then you can understand how all those data assets start to come together.
And then the mission clear for everybody. If the mission isn't super clear, then, then the behaviors and the systems and intra company in fighting as to who controls what and who seek decision, sort of always over, over overruns things. So I think, um, being crisp about how data is meaningful to the organization, and even more importantly, being crisp about how data is important to the customers or the consumers that you serve.
'cause at the end of the day, we all serve somebody, right? If you're a hospital system, you're serving patients. If you're, if you're a bank, you're serving consumers, maybe you're serving other banks, you know, all of that needs to be really crisp about the fact that it's there and that, you know, we are custodians, but here's the mission we're trying to fulfill for the those people or, or those organizations.
And if you're clear about it, then everything can fall in line. So, coming back full circle though, um, I may have issued an edict that says the thou shall not use the copilots, but there's always been this shadow IT issue running around. So how do I kinda, you know, get everybody to, who will probably nod their head and then go home and log in and use chat GBT to get something done?
Yeah, I think, I think at the end of the day, we, we want people to use, use the systems, right? I, I don't think blocking these systems makes a heck of a lot of sense. I think we want people to use 'em, but we wanna give them the tools and the abilities to do that.
So if you're a company that's concerned about your, you know, the use of it or, or, or, or you know, data being exposed, there's tools that you can use today to be able to deal with that. If you're building your own chat bots and a lot of places to do for specific use cases, there's things like LM firewalls that you can put in place that can help check your policies. So I think it's investing in the frameworks to allow your, your team to use these tools as opposed to just say, block it, you know, everybody's gonna go home and use it, right?
And before you know it, it's, it's gonna permeate everything. So it's better to know what people are doing and to help them do it, as opposed to trying to restrict them. Right?
And worst yet, instead of being behind a corporate firewall, they're sitting at home on consumer grade PCs and routers and, um, and loading up sensitive data. I mean, what, what Could happen? Yeah, exactly.
Exactly. You know, it's, it's like a hacker's, uh, delight if, if that's happening. So, All right, folks, you heard it here.
It's not so much that we can stop progress, it's coming. We just have to figure out how we're gonna apply some adult supervision and make to make it all work. Hey, Jack, thanks for being on the show.
Thanks, Mike. Great to be here. All right.
And back to you guys in the studio.