¡La inscripción ya está abierta para SASE Week 2023! Inscríbete en la lista de invitados.

  • Servicio de seguridad Productos Edge

    Protéjase contra las amenazas avanzadas y en la nube y salvaguarde los datos en todos los vectores.

  • Borderless SD-WAN

    Proporcione con confianza un acceso seguro y de alto rendimiento a cada usuario remoto, dispositivo, sitio y nube.

La plataforma del futuro es Netskope

Intelligent Security Service Edge (SSE), Cloud Access Security Broker (CASB), Cloud Firewall, Next Generation Secure Web Gateway (SWG) y Private Access for ZTNA integrados de forma nativa en una única solución para ayudar a todas las empresas en su camino hacia el Servicio de acceso seguro Arquitectura perimetral (SASE).

Todos los productos
Vídeo de Netskope
Borderless SD-WAN: el comienzo de la nueva era de la empresa sin fronteras

Netskope Borderless SD-WAN offers an architecture that converges zero trust principles and assured application performance to provide unprecedented secure, high-performance connectivity for every site, cloud, remote user, and IoT device.

Leer el artículo
Borderless SD-WAN
Adopte una arquitectura de borde de servicio de acceso seguro (SASE)

Netskope NewEdge es la nube privada de seguridad más grande y de mayor rendimiento del mundo y ofrece a los clientes una cobertura de servicio, un rendimiento y una resiliencia incomparables.

Más información sobre NewEdge
NewEdge
Tu red del mañana

Planifique su camino hacia una red más rápida, más segura y más resistente diseñada para las aplicaciones y los usuarios a los que da soporte.

Obtenga el whitepaper
Tu red del mañana
Netskope Cloud Exchange

Cloud Exchange (CE) de Netskope ofrece a sus clientes herramientas de integración eficaces para que saquen partido a su inversión en estrategias de seguridad.

Más información sobre Cloud Exchange
Vídeo de Netskope
Cambie a los servicios de seguridad en la nube líderes del mercado con una latencia mínima y una alta fiabilidad.

Más información sobre NewEdge
Lighted highway through mountainside switchbacks
Habilite de forma segura el uso de aplicaciones de IA generativa con control de acceso a aplicaciones, capacitación de usuarios en tiempo real y la mejor protección de datos de su clase.

Descubra cómo aseguramos el uso generativo de IA
Habilite de forma segura ChatGPT y IA generativa
Soluciones de confianza cero para implementaciones de SSE y SASE

Más información sobre Confianza Cero
Boat driving through open sea
Netskope hace posible un proceso seguro, rápido y con inteligencia cloud para la adopción de los servicios en la nube, las aplicaciones y la infraestructura de nube pública.

Más información sobre soluciones industriales
Wind turbines along cliffside
  • Recursos

    Obtenga más información sobre cómo Netskope puede ayudarle a proteger su viaje hacia la nube.

  • Blog

    Descubra cómo Netskope permite la transformación de la seguridad y las redes a través del servicio de seguridad (SSE).

  • Eventos & Workshops

    Manténgase a la vanguardia de las últimas tendencias de seguridad y conéctese con sus pares.

  • Seguridad definida

    Todo lo que necesitas saber en nuestra enciclopedia de ciberseguridad.

Podcast Security Visionaries

Leveling Up the SASE Conversation
Robert Arandjelovic and Gerry Plaza sit down to chat with Max Havey about how embracing a SASE journey can help bring networking and security teams closer together.

Reproducir el pódcast
Leveling Up the SASE Conversation
Últimos blogs

Cómo Netskope puede habilitar el viaje de Zero Trust y SASE a través de las capacidades del borde del servicio de seguridad (SSE).

Lea el blog
Sunrise and cloudy sky
SASE Week 2023: Your SASE journey starts now!

Únase a nosotros para la cuarta SASE Week anual, del 26 al 28 de septiembre.

Registrarse
SASE Week 2023
¿Qué es Security Service Edge (SSE)?

Explore el lado de la seguridad de SASE, el futuro de la red y la protección en la nube.

Más información sobre el servicio de seguridad perimetral
Four-way roundabout
  • Nuestros clientes

    Netskope da servicio a más de 2.000 clientes en todo el mundo, entre los que se encuentran más de 25 de las 100 empresas de Fortune

  • Soluciones para clientes

    Le apoyamos en cada paso del camino, garantizando su éxito con Netskope.

  • Comunidad de Netskope

    Aprenda de otros profesionales de redes, datos y seguridad.

  • Formación y certificación

    La formación de Netskope le ayudará a convertirse en un experto en seguridad en la nube.

Ayudamos a nuestros clientes a estar preparados para cualquier situación

Ver nuestros clientes
Woman smiling with glasses looking out window
El talentoso y experimentado equipo de servicios profesionales de Netskope proporciona un enfoque prescriptivo para su exitosa implementación.

Más información sobre servicios profesionales
Servicios profesionales de Netskope
La comunidad de Netskope puede ayudarlo a usted y a su equipo a obtener más valor de los productos y las prácticas.

Acceder a la Netskope Community
La comunidad de Netskope
Asegure su viaje de transformación digital y aproveche al máximo sus aplicaciones en la nube, web y privadas con la capacitación de Netskope.

Infórmese sobre Capacitaciones y Certificaciones
Group of young professionals working
  • Empresa

    Le ayudamos a mantenerse a la vanguardia de los desafíos de seguridad de la nube, los datos y la red.

  • Por qué Netskope

    La transformación de la nube y el trabajo desde cualquier lugar han cambiado la forma en que debe funcionar la seguridad.

  • Liderazgo

    Nuestro equipo de liderazgo está firmemente comprometido a hacer todo lo necesario para que nuestros clientes tengan éxito.

  • Partners

    Nos asociamos con líderes en seguridad para ayudarlo a asegurar su viaje a la nube.

Apoyar la sostenibilidad a través de la seguridad de los datos

Netskope se enorgullece de participar en Vision 2045: una iniciativa destinada a crear conciencia sobre el papel de la industria privada en la sostenibilidad.

Descubra más
Apoyando la sustentabilidad a través de la seguridad de los datos
La más Alta en Ejecución. Más Avanzada en Visión.

Netskope ha sido reconocido como Líder en el Gartner® Magic Quadrant™ de 2023 en SSE.

Obtenga el informe
Netskope ha sido reconocido como Líder en el Gartner® Magic Quadrant™ de 2023 en SSE.
Pensadores, constructores, soñadores, innovadores. Juntos, ofrecemos soluciones de seguridad en la nube de vanguardia para ayudar a nuestros clientes a proteger sus datos y usuarios.

Conozca a nuestro equipo
Group of hikers scaling a snowy mountain
La estrategia de venta centrada en el partner de Netskope permite a nuestros canales maximizar su expansión y rentabilidad y, al mismo tiempo, transformar la seguridad de su empresa.

Más información sobre los socios de Netskope
Group of diverse young professionals smiling

Cloud and Threat Report: AI Apps in the Enterprise

azul claro más
This report examines how organizations are balancing the benefits of AI tools while also managing the associated risks, highlighting an increasingly popular strategy that involves DLP and interactive user coaching.
Dark cloud over the sunset
9 minutos de lectura

Aspectos destacados del informe

test answer
  • AI app use in the enterprise is increasing exponentially, up 22.5% over the past two months.
  • ChatGPT is the most popular AI app in the enterprise and Google Bard is the fastest growing AI app in the enterprise, both by a large margin.
  • Source code is posted to ChatGPT more than any other type of sensitive data, at a rate of 158 incidents per 10,000 enterprise users per month.
  • Attackers are creating AI app scams and phishing sites to try to capitalize on the hype surrounding ChatGPT.
  • DLP and user coaching are the most popular types of controls enterprises use to enable AI app use while preventing sensitive data exposure.

Executive Summary

sdofjsfojefgejelosij

The conversation around AI often centers on existential questions, such as the potential opportunities and threats AI may bring to humanity. Yet, organizations worldwide and their leaders are dealing with a more immediate concern: How can they use AI apps safely and securely?

Organizations strive to leverage AI applications to enhance operations, improve customer experiences, and facilitate data-driven decision-making. The key is to do this while ensuring safety and security. However, the main security hurdle lies in how some users might employ these applications.

Take ChatGPT, for example, which can be used to review source code for security flaws or assist in editing written content. ChatGPT was used to edit this very executive summary. Inevitably, some individuals will upload proprietary source code or text containing regulated data or intellectual property. The challenge lies in deterring such behavior without hindering the wider organization’s productivity. An outright block on AI applications could solve this problem, but would do so at the expense of the potential benefits AI apps offer.

As we continue to be surrounded by the hype centered on the possibilities of AI, it is evident that ChatGPT and other AI apps are on their way to becoming mainstays in the enterprise. Among Netskope customers, their popularity is growing exponentially, expected to double within the next seven months if they continue to grow at the current rate. This report delves into the rising prominence of AI applications in enterprises, outlines associated risks, including data leaks and potential attacker activity, and proposes strategies for safely and securely integrating ChatGPT and other AI tools in the enterprise setting.

AI Apps Growing in Popularity

The number of users accessing AI apps in the enterprise is growing exponentially. Over the past two months, the percentage of enterprise users accessing at least one AI app each day has increased by 2.4% weekly, for a total increase of 22.5% over that time period. At the current growth rate, the number of users accessing AI apps will double within the next seven months. Over the same time period, the number of AI apps in use in the enterprise held steady, with organizations with more than 1,000 users averaging 3 different AI apps per day, and organizations with more than 10,000 users averaging 5 AI apps per day. At the end of June, 1 out of 100 enterprise users interacted with an AI app each day.

AI app popularity based on number of enterprise users

The most popular enterprise AI app by a large margin is ChatGPT, with more than 8x as many daily active users as any other AI app. ChatGPT has been the center of much hype for the past six months and is also very versatile, likely contributing to its popularity. The next most popular app is Grammarly, which focuses exclusively on writing assistance. Bard, Google’s chatbot, comes in just below Grammarly. All other AI apps combined (of which we are tracking more than 60, including Jasper, Chatbase, and Copy.ai) are less popular than Google Bard.

Most popular AI apps by percentage of total daily AI users

Over the past two months, the fastest growing AI app in the enterprise was Google Bard. Although it still lags far behind ChatGPT in popularity, Google Bard is currently adding users at a rate of 7.1% per week, compared to 1.6% for ChatGPT. At their current rates, Google Bard is poised to catch up to ChatGPT in just over a year. However, as the AI app space is very dynamic, we expect to see many more changes during that time which will disrupt the current growth rates.

Netskope Threat Labs tracks the popularity of AI apps in enterprise environments, rather than the overall popularity of the apps among consumers. For example, while ChatGPT popularity skyrocketed among consumers before cooling off in June, its adoption in the enterprise has been more measured and continues to increase exponentially. The remainder of this report highlights some of the reasons for the measured increase, which include risks of data leakage and controls around its use.

Fastest growing AI apps by number of active daily users added weekly

AI Risks - Sensitive Data

This segment focuses on ChatGPT, the leading AI app in the enterprise by a large margin. An average ChatGPT user interacts with the app by posting 6 prompts daily. The activity level varies by user, with the top 10% of users posting 22 prompts and the top 1% posting 68 prompts daily. For every 10,000 users, an organization can expect around 660 daily prompts to ChatGPT. But the real question lies in the content of these prompts: Are they harmless queries, or do they inadvertently reveal sensitive data?

A Netskope study revealed that source code was the most frequently exposed type of sensitive data, with 22 out of 10,000 enterprise users posting source code to ChatGPT per month. In total, those 22 users are responsible for an average of 158 posts containing source code per month. This trend is not entirely unexpected, considering ChatGPT’s ability to review and explain code and pinpoint bugs and security vulnerabilities. While these services are beneficial, sharing confidential source code with ChatGPT introduces risks including potential data breaches, accidental data disclosure, and legal and regulatory risks.

Users posting sensitive data per 10,000k enterprise users per month

Compared to source code, posts containing other forms of sensitive data are relatively less common. For every 10,000 enterprise users, there are typically 18 incidents of sharing of regulated data (encompassing financial data, healthcare information, and personally identifiable information) on a monthly basis. Intellectual property (excluding source code) is rarer still, with an average of 4 incidents per month for every 10,000 users. Interestingly, passwords and keys also appear among the sensitive data types shared, usually embedded in source code. Despite its relative infrequency (about 4 incidents per 10,000 users monthly), this practice serves as a crucial reminder to software engineers about the risks of hard-coding secrets into source code.

Incidents of users posting sensitive data per 10,000k enterprise users per month

Opportunistic Attackers

With all the hype surrounding ChatGPT and AI apps in general, it is unsurprising that scammers, cybercriminals, and other attackers would attempt to exploit the hype for illicit gains. This is common practice with attackers. For example, the Netskope Threat Labs Cloud and Threat Report from Spring 2023 highlighted attackers attempting to capitalize on the Russo-Ukrainian war, the earthquake in Turkey and Syria, and the collapse of Silicon Valley Bank. The hype and popularity of ChatGPT draws the attention of attackers and scammers because of the large target pool and potential for profit, combined with the varied proficiency of users on the platform.

Throughout the first half of 2023, Netskope Threat Labs has tracked multiple phishing campaigns, malware distribution campaigns, and spam and fraud websites seeking to capitalize on the ChatGPT hype. Netskope Threat Labs is even tracking multiple ChatGPT proxies, sites that appear to offer the benefit of free, unauthenticated access to the chatbot, but at the cost of revealing all your prompts and responses to the proxy operator.

A ChatGPT proxy where the proxy operator sees all prompts and responses

A ChatGPT proxy where the proxy operator sees all prompts and responses

 
In total, Netskope Threat Labs is currently tracking more than 1,000 malicious URLs and domains seeking to capitalize on the ChatGPT and AI hype. The number alone is a reminder of the importance of using a multi-layered approach to protect users from attackers attempting to capitalize on the hype and popularity surrounding any significant event or trend. Such an approach should include domain filtering, URL filtering, and content inspection to protect against both known and unknown attacks.

Enterprise Controls

While a common practice when ChatGPT was first gaining popularity was for enterprises to block the chatbot altogether, organizations have since come to terms with the fact that ChatGPT and other AI apps can offer advantages to the organization, including enhancing operations, improving customer experiences, and facilitating data-driven decision-making. Instead of blocking ChatGPT, organizations have transitioned to a more permissive model that typically includes a combination of DLP and user coaching. DLP can be used to identify potentially sensitive data being posted to AI apps, including ChatGPT, and user coaching can leave the ultimate decision of whether or not to proceed with a prompt to the user.

Organizations placing controls around ChatGPT

The specific controls around ChatGPT vary by industry vertical. Overall, financial services, healthcare, and technology companies have led the charge in implementing controls around ChatGPT. However, the approach each industry has taken varies significantly. In financial services and healthcare, both highly regulated industries, nearly 1 in 5 organizations have implemented a blanket ban. No users are allowed to use ChatGPT. In the technology vertical, only 1 in 20 organizations have implemented a blanket ban. Instead 1 in 4 organizations are using DLP controls to detect specific types of sensitive information (especially source code) being posted to ChatGPT. Furthermore, 1 in 5 technology organizations implement real-time user coaching to remind users of company policy and the risks that come along with ChatGPT and other AI apps. Ultimately, more organizations are likely to adopt DLP controls and real-time user coaching over time to enable the use of AI apps like ChatGPT while safeguarding against unwanted data exposure.

Type of ChatGPT controls by industry vertical

Recomendaciones

Safely enabling the adoption of AI apps in the enterprise is a multifaceted challenge. It involves identifying permissible apps and implementing controls that empower users to use them to their fullest potential while safeguarding the organization from risks. This section includes general technical recommendations for organizations aiming to safely enable AI apps. For more detailed information about how Netskope can help, please refer to the ChatGPT and Generative AI Data Protection solution brief.

→ Regularly review AI app activity, trends, behaviors, and data sensitivity, to identify risks to the organization.

→ Block access to apps that do not serve any legitimate business purpose or that pose a disproportionate risk. A good starting point is a policy to allow reputable apps currently in use while blocking all others.

→ Use DLP policies to detect posts containing potentially sensitive information, including source code, regulated data, passwords and keys, and intellectual property.

→ Employ real-time user coaching (combined with DLP) to remind users of company policy surrounding the use of AI apps at the time of interaction.

Block opportunistic attackers attempting to take advantage of the growing popularity of AI apps by blocking known malicious domains and URLs, and inspecting all HTTP and HTTPS content.

→ Use Remote Browser Isolation (RBI) technology to provide additional protection when there is a need to visit websites in categories that can present higher risk, like newly observed and newly registered domains.

→ Ensure that all security defenses share intelligence and work together to streamline security operations. Netskope customers can use Cloud Exchange to share IOCs, import threat intel, export event logs, automate workflows, and exchange risk scores.

Acerca de este informe

Netskope Threat Labs publishes a quarterly Cloud and Threat Report to highlight a specific set of cybersecurity challenges. The purpose of this report is to provide visibility into cybersecurity risks that AI apps present and how organizations are managing those risks. The analysis presented in this report is based on a study of millions of users from thousands of organizations worldwide, for the period starting May 1, 2023 through June 30, 2023. Stats are reflection of attacker tactics, user behavior, and organization policy. Information presented in this report is based on anonymized usage data collected by the Netskope Security Cloud platform relating to a subset of Netskope customers with prior authorization.

Netskope Threat Labs

Staffed by the industry’s foremost cloud threat and malware researchers, Netskope Threat Labs discovers, analyzes, and designs defenses against the latest web, cloud, and data threats affecting enterprises. Our researchers are regular presenters and volunteers at top security conferences, including DEF CON, Black Hat, and RSA.

azul claro más

Informes de nube y amenazas

El informe Netskope Cloud and Threat Report ofrece una visión única sobre la adopción de aplicaciones en la nube, los cambios en el panorama de las amenazas en la nube y los riesgos para los datos de la empresa.

Storm with lightning over the city at night

Acelere su estrategia de seguridad con el líder en SASE.