Your Organization's AI Is Going To Change Your Cybersecurity's AI
Our remit in behavioral cybersecurity is to focus you on what's actually under your control. That's how you manage risk in your own career and through your cybersecurity program. The most basic thing you control is your attention. Every culture encodes this in its language: you focus attention, you pay attention, you make attention. It's a limited resource. Managing it is a form of risk management.
That's why a recent post from Microsoft's Jaime Teevan, Seven Predictions, is worth your team's time. She maps out how AI is about to change the shape of work itself. All of her points are interesting, though three in particular struck us as having cybersecurity implications.
We'd add one thing she doesn't say directly: each of these shifts is also an invitation for the AI-SOC function to integrate across the enterprise, rather than sit off to the side as a standalone process. Each prediction changes what you're responsible for protecting. Here's how we'd translate those predictions into risk terms.
Reading becomes asking; writing becomes answering
Teevan's point is that AI-mediated interaction reveals something documents never could: not just whether someone engaged with content, but what they were trying to learn when they did. That's a meaningful upgrade in organizational visibility, and a new category of sensitive data.
The risk: the questions your employees ask an AI system are, in aggregate, a map of what the organization doesn't yet understand, including where its security gaps are. Who has access to that map, how long it's retained, and whether it's query-able by people outside the original context are all governance questions your access-control policy probably doesn't cover yet.
The audience talks back
Group work does its best thinking not when one expert holds the floor, but when participation is even and perspectives are diverse. AI tools built for synthesis rather than broadcast will start surfacing the range of views in a room, not recording or averaging views into a single message.
The risk: an always-on aggregator of "what people actually think" is also an always-on record of dissent, disagreement, and internal politics with named individuals. That's a career-development risk for the people whose unfiltered views get captured, and a data-handling risk for whoever owns the system doing the capturing. At the very least, people need room to change their mind as they develop.
We'll start to cache human thought
This is the one we'd flag. Teevan describes a system that looks across everything an employee is working on, anticipates what a task will need, and quietly assembles the answer before the person gets stuck by pulling together things the person already said elsewhere as well as resources the person didn't anticipate needing.
The risk: this is intrinsically a data-retention and cross-context-access system approach. For a cybersecurity program, that's not a hypothetical "interconnection risk," it's a specific, answerable question: which systems can this AI read from, which can it write to, and does your current access model even have a concept of "this AI acting on behalf of this employee, across these three tools"? Most don't yet.
The through-line
Each of these predictions moves the organization's real attention, and real risk, outside the tools built to track it. As AI reshapes what work is, career-development risk (again), systems-access risk, and cross-system interconnection risk stop being separate categories and start becoming the same everyday work risk, just distributed across a much larger surface.
Here is how she wraps up her post: Attention really is all you need. The catch is that ours runs out.
Pay attention to how that AI-related attention shift lands on your team before it lands on your incident log.
Ask us how you can co-create the role of cybersecurity in the AI-augmented workplace.
(image credit: User:Kalan, CC BY 3.0 <https://creativecommons.org/licenses/by/3.0>, via Wikimedia Commons)

Comments
Post a Comment