International Cyber Expo International Cyber Expo
  • About Us
Friday, 2 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Shadow AI and the permissions problem: what to check before handing AI the keys

by Lara Joseph
October 2, 2026
in Featured
Shadow AI and the permissions problem: what to check before handing AI the keys
Share on FacebookShare on Twitter

AI tools have moved from novelty to daily habit with remarkable speed, and for many people they are now as much a part of the working day as email. For Corey Nachreiner, CSO at WatchGuard Technologies, that makes a few simple questions more urgent than ever. “People are already using AI for everyday questions, work tasks, and highly personal conversations. Before you type, stop and ask: What am I sharing? Who might see it? What is this tool allowed to do for me? Those questions matter more as AI moves beyond chat and starts taking actions on our behalf.”

Jack Cherkas, Global Chief Information Security Officer at Syntax, believes this year’s campaign is well timed to prompt that reflection. “Cybersecurity Awareness Month is usually a reminder to get the fundamentals right and that is still absolutely critical,” he says. “This year, however, the National Cybersecurity Alliance has adopted the theme, ‘Don’t Make It Easy for Them,’ and that message should also prompt organizations to look at a growing source of risk: artificial intelligence (AI).”

“As organizations and individuals adopt AI, we need to remember that AI is not just another technology. It has the potential to be transformational,” Cherkas continues. “It can hold accounts and permissions, see whatever you give it access to and take actions on your behalf. Many organizations and individuals have never considered the implications of these actions.”

Handing over your privilege

Nachreiner warns that the convenience of connecting AI assistants to personal and corporate accounts comes with a significant trade-off. “When we give an AI agent access to our email, files, calendars, financial information, or other accounts, we are giving it our privilege,” he says. “If someone gets access to that AI account or its credentials, they may be able to do almost anything we can do. That makes AI accounts an increasingly attractive target for threat actors.”

His advice is to treat those accounts with the seriousness they deserve. “Protect them like your primary email or bank account. Turn on multi-factor authentication, be skeptical of unexpected links and login requests, and pause before you share sensitive information or approve a connection.”

Cherkas frames the same challenge as a simple test that should be applied before any AI tool is switched on. “So, as the world embraces AI, we must determine three things before access is granted: what it can see, what it can do and who is responsible for it.”

The AI nobody chose

For organisations, the picture is complicated by the sheer number of routes through which AI enters the business. “For businesses, the issue is shadow AI,” says Nachreiner. “It is not just the chatbot someone opens in a browser. It’s also the plug-in, extension, or integration that gets added without security knowing.”

Cherkas goes further, pointing out that some AI arrives without anyone actively adding it at all. “And we also must remember that, in many cases, AI appears even when we never chose it. It’s in the tool approved three years ago that quietly shipped an AI-infused update, the browser extension or the application add-in,” he says. “Some AI adoption arrives without a decision, and the things nobody decided on are the things nobody is watching.”

Visibility first

Both experts agree that organisations cannot govern what they cannot see. “Security doesn’t exist without visibility,” says Nachreiner. “Organisations need to know which AI tools are in use, where their data is going, and what permissions those tools have.”

He highlights encrypted traffic as a particular blind spot. “Our latest research found that 95% of malware arrived over encrypted TLS traffic, yet only 20% of deployed devices inspect that traffic. As more workplace activity and more AI integrations operate through encrypted channels, organisations cannot assume that encrypted means safe.”

From there, Nachreiner sets out a clear order of priorities. “It is visibility first, then policy, then enforcement. So, teams can decide what is allowed, what needs to be turned off, and where controls need to be applied,” he says. “Implementing Shadow AI policies and safeguards is critically important, and something that we have done successfully at WatchGuard to protect our own employees, customers and partners.”

For Cherkas, the effort required is modest compared with the risk of doing nothing. “‘Don’t Make It Easy for Them’ is the right tagline for this year. For organizations, that means adopting AI in a pragmatic, secure and responsible manner. For individuals, it means 10 minutes in your settings. Neither is hard. Both are overdue for many.”

ShareTweet
Previous Post

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

Recent News

Shadow AI and the permissions problem: what to check before handing AI the keys

Shadow AI and the permissions problem: what to check before handing AI the keys

October 2, 2026
Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

Cybersecurity Awareness Month: AI agents are users too, and they need governing like it

October 2, 2026
Malicious Email Could Hijack AI Agent and Access Connected Accounts

Malicious Email Could Hijack AI Agent and Access Connected Accounts

October 2, 2026
RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant

October 1, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol