Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Trusted workflows, AI tools, and the insider risk gap teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Insider risk is moving into everyday workflows, with blocked activity rising in Microsoft and Google sites, AI tools concentrating around ChatGPT and Read.ai, and text, screenshots, and USB emerging as common movement channels, according to Safetica’s Data Protection Trends report. The governance gap is no longer perimeter blocking, but consistent control over data-in-use across approved collaboration tools.

NHIMG editorial — based on content published by Safetica: Insider

By the numbers:

Questions worth separating out

Q: How should security teams govern AI-powered insider threats?

A: Treat AI-powered insider threat as an identity governance problem first.

Q: Why do screenshots and plain text files matter in insider risk programmes?

A: Because they often indicate that users are repackaging sensitive information to bypass controls or to move it through a channel the policy does not understand.

Q: How can security teams tell whether DLP is actually reducing risk?

A: Look for better prioritisation of high-value data, fewer noisy alerts, and clearer visibility into which identities can reach sensitive content.

Practitioner guidance

  • Map sensitive-data movement across approved channels Inventory where confidential data actually moves across browser, web apps, cloud storage, email, chat, AI tools, screenshots, and USB, then apply the same policy logic where the work occurs.
  • Treat AI prompts and pasted text as governed inputs Classify AI tools as data-handling workflows, then define what content can be pasted, summarised, or generated in each population.
  • Correlate screenshots, text files, and USB use Use one detection view for .txt creation, screenshot activity, and external USB events so the same user behaviour can be tracked across repackaging paths.

What's in the full report

Safetica's full report covers the operational detail this post intentionally leaves for the source:

  • Quarter-over-quarter channel breakdowns showing where blocked activity is actually rising across the environment
  • Policy violation tables for web, email, instant messaging, and USB that help teams compare channel pressure
  • App-category and file-extension trend data that show how users repurpose content in practice
  • Behavioural observations that help security teams distinguish friction from intent

👉 Read Safetica's Data Protection Trends report on insider risk and data movement →

Trusted workflows, AI tools, and the insider risk gap teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16618
 

Insider risk is becoming a workflow governance issue, not a perimeter problem. When web apps, email, chat, and AI tools become the main movement paths, the question is no longer whether an app is trusted. The question is whether the organisation can apply differentiated rules to trusted tools based on identity, role, and data type. That is a control design issue, not an endpoint-only problem. Practitioners should read this as a push toward contextual policy enforcement.

A question worth separating out:

Q: What is the difference between blocking a channel and governing data movement?

A: Blocking a channel is a blunt control that stops one route. Governing data movement means understanding which users, content types, and workflows are acceptable across all the places work happens, so the organisation can reduce risky handling without forcing people into another workaround.

👉 Read our full editorial: Insider risk is shifting into trusted workflows and AI tools



   
ReplyQuote
Share: