Is AI changing the governance culture?


Tam Finans CTO Yasin Çarkcı answered the question, “Is AI changing governance culture?”

Çarkcı stated:

“This topic, in fact, is being addressed as if artificial intelligence has become a hype lately. AI is indeed a hype right now, but when combined with cybersecurity, it’s a topic that, while entertaining, also carries risks for cybersecurity professionals. In my own experience, in 2018-19, AI was a simple element we used to make our work a little more efficient, to increase productivity, and it didn’t add many risks to our work processes. But recently, especially with the arrival of agents and LLMs, AI has started to pose a serious risk. We are both defending against AI and trying to understand offensive practices with AI and LLMs. Actually, I somewhat separate security and cybersecurity into ‘before AI’ and ‘after AI’. What were we doing before AI? We are doing the same thing now.” If we want to protect data, we use DLP; if we don’t want it to leak, we prevent it with DLP. If it’s going to leak, it happens somehow. We try to make it meaningless data by at least masking or hashing it. We log inputs and outputs. We try to make correlations. We create microsegmentation, layered architecture, and security architectures. These existed before artificial intelligence and still exist with artificial intelligence. However, with artificial intelligence, my perspective on governance has changed significantly. Financial institutions that take this seriously were complying with governance, either necessarily or willingly. But with artificial intelligence, you have to comply with these concrete rules set by the policymakers. Since there is no book on this, or if there is, it is not widely applied, and the rules are not clear at this stage, we have started to give importance to the governance side internally and have started to implement it. We have started to develop an internal governance policy that evolves with the interaction of artificial intelligence. The policy or policies we have developed here, or the policies that other institutions will develop, are actually based on a very simple logic. Now, artificial intelligence exists, that’s true, but there’s also human intelligence. First of all, it’s crucial to raise awareness among people within this governance framework. We need to establish well-defined rule sets. Artificial intelligence itself is both the creator and the solver of the problem. By incorporating artificial intelligence into governance and leveraging its power, we can create transparent policies, revealing decision-makers, decisions made, and implementers in a transparent manner, thereby minimizing risks. In this way, by combining the power of governance with the power of artificial intelligence, and by raising awareness among people, we ensure that AI is used more effectively, healthily, and safely from our perspective. We also establish the secure architecture that we should implement by default, thus combining AI and governance to create a healthy and reliable ecosystem. This is what needs to be done and what will be done. Of course, the most important point here is that CISOs and security policy developers need to be much more dynamic and proactive than they were 10 years ago. We’re not talking about technologies or structures that change every year or two. We’re talking about constantly changing things; a rule that’s A when we go to bed at night becomes B in the morning. Those who adapt quickly are the ones who can somehow apply these rules and governance policies to their own organizations, or even write these rules themselves. That’s what we’re trying to do at Tam Finans. Thank you.

Artificial Intelligence and Cybersecurity: Risks and Opportunities

Artificial intelligence has revolutionized many sectors in recent years, leading the way in technological advancements. However, this rapid development has created both opportunities and risks in the field of cybersecurity. While AI offers cybersecurity experts more effective defense mechanisms, it also allows malicious actors to develop new attack methods. This article will discuss the impact of AI on cybersecurity, the challenges encountered in this field, and potential future developments.

The Role of AI in Cybersecurity

AI plays a significant role in cybersecurity by accelerating data analysis, threat detection, and response processes. Its capacity to quickly process large datasets allows for the early detection of potential threats and enables proactive measures against them. This is critical, particularly for enhancing security in large-scale networks and complex systems.

Risks Arising from AI

The use of AI in cybersecurity also brings new risks. Malicious actors can create vulnerabilities by manipulating AI algorithms or using this technology to develop their own attack strategies. This requires cybersecurity professionals to constantly be vigilant against new threats.

AI and Governance

For AI to be used effectively in cybersecurity, governance policies also need to be updated. Organizations should adopt a dynamic and proactive approach to adapt to the innovations brought by AI. This requires considering not only the technological infrastructure but also the human factor.

Human Factor and Awareness

The human factor is crucial for the success of AI-powered cybersecurity strategies. Raising awareness among employees and users is a critical step for the effective implementation of security policies. Training and awareness programs can increase the effectiveness of AI-powered security solutions.

The Future of AI and Cybersecurity

Developments in the field of AI and cybersecurity will accelerate even further in the future. This means both new opportunities and new challenges. Organizations must develop flexible and innovative strategies to adapt quickly to these changes. While artificial intelligence has the potential to revolutionize cybersecurity, careful planning and implementation are necessary to fully utilize this potential.

Conclusion

Artificial intelligence presents itself as a technology that offers both opportunities and risks in the field of cybersecurity. For this technology to be used effectively, organizations need to update their governance policies and consider the human factor. While artificial intelligence has the potential to revolutionize cybersecurity, careful planning and implementation are necessary to fully utilize this potential. In the future, advancements in artificial intelligence and cybersecurity are expected to accelerate, and flexible and innovative strategies must be developed to adapt quickly to these changes.

Share:

About the Wise