Shadow AI in SOCs: A Growing Threat to Security Operations
Shadow AI has become a significant problem in security operations centers (SOCs), where analysts are using personal chatbots to quickly decode and analyze scripts, log lines, and other incident data. However, this convenience comes with a cost: sensitive information is being leaked into these unapproved tools, which can be used by attackers to gain valuable insights into the company's systems.
According to IBM's research, employees use AI tools that their company has not approved at an alarming rate, with nearly half of all generative AI users accessing these tools through personal accounts. The cost of a data breach involving heavy shadow AI use is around $670,000 more than the average breach.
The security teams themselves are also vulnerable to this problem, as they are under pressure to quickly analyze and resolve incidents. Analysts may rely on unapproved AI tools for their verdicts, which can lead to mistaken conclusions and a wrong path being taken in an investigation.
IBM's approach to addressing this issue is to provide approved AI channels that are fast enough to use, teach analysts what sensitive information should never leave the environment, and monitor data flow instead of chasing banned tools. The company has built its own approved path at scale through its IBM Consulting Advantage platform, which puts AI assistants powered by Watson x into the daily workflow.