ネットスコープは2024年Gartner®社のセキュリティ・サービス・エッジ(SSE)のマジック・クアドラントでリーダーの1社として評価されました。 レポートを読む

閉める
閉める
  • Netskopeが選ばれる理由 シェブロン

    ネットワークとセキュリティの連携方法を変える。

  • 導入企業 シェブロン

    Netskope は世界中で 3,000 を超える顧客にサービスを提供しており、その中にはフォーチュン 100 企業の 25 以上が含まれます

  • パートナー シェブロン

    私たちはセキュリティリーダーと提携して、クラウドへの旅を保護します。

実行能力とビジョンの完全性において
最上位の評価

ネットスコープが2024年Gartner®社のセキュリティ・サービス・エッジ(SSE)のマジック・クアドラントで3年連続リーダーの1社として評価された理由をご覧ください。

レポートを読む
Netskope、2024年ガートナー®マジッククアドラント™セキュリティサービスエッジ部門でリーダーに選出 メニューのグラフィック
私たちは、お客様が何にでも備えることができるように支援します

お客様について
窓の外を見て微笑むメガネをかけた女性
Netskopeのパートナー中心の市場開拓戦略により、パートナーは企業のセキュリティを変革しながら、成長と収益性を最大化できます。

Netskope パートナーについて学ぶ
色々な若い専門家が集う笑顔のグループ
明日に向けたネットワーク

サポートするアプリケーションとユーザー向けに設計された、より高速で、より安全で、回復力のあるネットワークへの道を計画します。

ホワイトペーパーはこちら
明日に向けたネットワーク
Netskope One プラットフォームの紹介

Netskope One は、SASE とゼロトラスト変革を可能にする統合型セキュリティおよびネットワーキング サービスを提供するクラウドネイティブ プラットフォームです。

Netskope One について学ぶ
青い照明の抽象画
セキュアアクセスサービスエッジ(SASE)アーキテクチャの採用

Netskope NewEdgeは、世界最大かつ最高のパフォーマンスのセキュリティプライベートクラウドであり、比類のないサービスカバレッジ、パフォーマンス、および回復力を顧客に提供します。

NewEdgeの詳細
NewEdge
Netskope Cloud Exchange

Netskope Cloud Exchange (CE) は、セキュリティポスチャに対する投資を活用するための強力な統合ツールを提供します。

Cloud Exchangeについて学ぶ
Netskopeの動画
  • セキュリティサービスエッジ製品 シェブロン

    高度なクラウド対応の脅威から保護し、あらゆるベクトルにわたってデータを保護

  • Borderless SD-WAN シェブロン

    すべてのリモートユーザー、デバイス、サイト、クラウドへ安全で高性能なアクセスを提供

  • Secure Access Service Edge シェブロン

    Netskope One SASE は、クラウドネイティブで完全に統合された単一ベンダーの SASE ソリューションを提供します。

未来のプラットフォームはNetskopeです

インテリジェントセキュリティサービスエッジ(SSE)、クラウドアクセスセキュリティブローカー(CASB)、クラウドファイアウォール、セキュアウェブゲートウェイ(SWG)、およびZTNAのプライベートアクセスは、単一のソリューションにネイティブに組み込まれており、セキュアアクセスサービスエッジ(SASE)アーキテクチャへの道のりですべてのビジネスを支援します。

製品概要はこちら
Netskopeの動画
Next Gen SASE Branch はハイブリッドである:接続、保護、自動化

Netskope Next Gen SASE Branchは、コンテキストアウェアSASEファブリック、ゼロトラストハイブリッドセキュリティ、 SkopeAI-Powered Cloud Orchestrator を統合クラウド製品に統合し、ボーダレスエンタープライズ向けに完全に最新化されたブランチエクスペリエンスを実現します。

Next Gen SASE Branchの詳細はこちら
オープンスペースオフィスの様子
SASEアーキテクチャの設計 For Dummies

SASE設計について網羅した電子書籍を無償でダウンロード

電子書籍を入手する
最小の遅延と高い信頼性を備えた、市場をリードするクラウドセキュリティサービスに移行します。

NewEdgeの詳細
山腹のスイッチバックを通るライトアップされた高速道路
アプリケーションのアクセス制御、リアルタイムのユーザーコーチング、クラス最高のデータ保護により、生成型AIアプリケーションを安全に使用できるようにします。

生成AIの使用を保護する方法を学ぶ
ChatGPTと生成AIを安全に有効にする
SSEおよびSASE展開のためのゼロトラストソリューション

ゼロトラストについて学ぶ
大海原を走るボート
NetskopeがFedRAMPの高認証を達成

政府機関の変革を加速するには、Netskope GovCloud を選択してください。

Netskope GovCloud について学ぶ
Netskope GovCloud
  • リソース シェブロン

    クラウドへ安全に移行する上でNetskopeがどのように役立つかについての詳細は、以下をご覧ください。

  • ブログ シェブロン

    Netskope がセキュリティ サービス エッジ (SSE) を通じてセキュリティとネットワークの変革を実現する方法を学びます

  • イベント&ワークショップ シェブロン

    最新のセキュリティトレンドを先取りし、仲間とつながりましょう。

  • 定義されたセキュリティ シェブロン

    サイバーセキュリティ百科事典、知っておくべきすべてのこと

「セキュリティビジョナリー」ポッドキャスト

On Patents, Trolls, and Innovation
In this episode host Emily Wearmouth chats with Suzanne Oliver, an intellectual property expert, and Krishna Narayanaswamy, co-founder and CTO of Netskope, about the world of patents.

ポッドキャストを再生する
On Patents, Trolls, and Innovation
最新のブログ

Netskope がセキュリティ サービス エッジ (SSE) 機能を通じてゼロ トラストと SASE の導入をどのように実現できるかをご覧ください。

ブログを読む
日の出と曇り空
SASE Week 2023年:SASEの旅が今始まります!

第4回 SASE Weekのリプレイセッション。

セッションの詳細
SASE Week 2023
セキュリティサービスエッジとは

SASEのセキュリティ面、ネットワークとクラウドでの保護の未来を探ります。

セキュリティサービスエッジの詳細
4方向ラウンドアバウト
  • 会社概要 シェブロン

    クラウド、データ、ネットワークセキュリティの課題に対して一歩先を行くサポートを提供

  • リーダーシップ シェブロン

    Netskopeの経営陣はお客様を成功に導くために全力を尽くしています。

  • カスタマーソリューション シェブロン

    お客様の成功のために、Netskopeはあらゆるステップを支援いたします。

  • トレーニングと認定 シェブロン

    Netskopeのトレーニングで、クラウドセキュリティのスキルを学ぶ

データセキュリティによる持続可能性のサポート

Netskope は、持続可能性における民間企業の役割についての認識を高めることを目的としたイニシアチブである「ビジョン2045」に参加できることを誇りに思っています。

詳しくはこちら
データセキュリティによる持続可能性のサポート
思想家、建築家、夢想家、革新者。 一緒に、私たちはお客様がデータと人々を保護するのを助けるために最先端のクラウドセキュリティソリューションを提供します。

当社のチーム紹介
雪山を登るハイカーのグループ
Netskopeの有能で経験豊富なプロフェッショナルサービスチームは、実装を成功させるための規範的なアプローチを提供します。

プロフェッショナルサービスについて学ぶ
Netskopeプロフェッショナルサービス
Netskopeトレーニングで、デジタルトランスフォーメーションの旅を保護し、クラウド、ウェブ、プライベートアプリケーションを最大限に活用してください。

トレーニングと認定資格について学ぶ
働く若い専門家のグループ

クラウドと脅威レポート: 企業における AI アプリ

ライトブループラス
This report examines how organizations are balancing the benefits of AI tools while also managing the associated risks, highlighting an increasingly popular strategy that involves DLP and interactive user coaching.
夕焼けに暗い雲
9 min read

Report Highlights リンク リンク

test answer
  • AI app use in the enterprise is increasing exponentially, up 22.5% over the past two months.
  • ChatGPT is the most popular AI app in the enterprise and Google Bard is the fastest growing AI app in the enterprise, both by a large margin.
  • Source code is posted to ChatGPT more than any other type of sensitive data, at a rate of 158 incidents per 10,000 enterprise users per month.
  • Attackers are creating AI app scams and phishing sites to try to capitalize on the hype surrounding ChatGPT.
  • DLP and user coaching are the most popular types of controls enterprises use to enable AI app use while preventing sensitive data exposure.

Executive Summary リンク リンク

sdofjsfojefgejelosij

The conversation around AI often centers on existential questions, such as the potential opportunities and threats AI may bring to humanity. Yet, organizations worldwide and their leaders are dealing with a more immediate concern: How can they use AI apps safely and securely?

Organizations strive to leverage AI applications to enhance operations, improve customer experiences, and facilitate data-driven decision-making. The key is to do this while ensuring safety and security. However, the main security hurdle lies in how some users might employ these applications.

Take ChatGPT, for example, which can be used to review source code for security flaws or assist in editing written content. ChatGPT was used to edit this very executive summary. Inevitably, some individuals will upload proprietary source code or text containing regulated data or intellectual property. The challenge lies in deterring such behavior without hindering the wider organization’s productivity. An outright block on AI applications could solve this problem, but would do so at the expense of the potential benefits AI apps offer.

As we continue to be surrounded by the hype centered on the possibilities of AI, it is evident that ChatGPT and other AI apps are on their way to becoming mainstays in the enterprise. Among Netskope customers, their popularity is growing exponentially, expected to double within the next seven months if they continue to grow at the current rate. This report delves into the rising prominence of AI applications in enterprises, outlines associated risks, including data leaks and potential attacker activity, and proposes strategies for safely and securely integrating ChatGPT and other AI tools in the enterprise setting.

AI Apps Growing in Popularity リンク リンク

The number of users accessing AI apps in the enterprise is growing exponentially. Over the past two months, the percentage of enterprise users accessing at least one AI app each day has increased by 2.4% weekly, for a total increase of 22.5% over that time period. At the current growth rate, the number of users accessing AI apps will double within the next seven months. Over the same time period, the number of AI apps in use in the enterprise held steady, with organizations with more than 1,000 users averaging 3 different AI apps per day, and organizations with more than 10,000 users averaging 5 AI apps per day. At the end of June, 1 out of 100 enterprise users interacted with an AI app each day.

AI app popularity based on number of enterprise users

The most popular enterprise AI app by a large margin is ChatGPT, with more than 8x as many daily active users as any other AI app. ChatGPT has been the center of much hype for the past six months and is also very versatile, likely contributing to its popularity. The next most popular app is Grammarly, which focuses exclusively on writing assistance. Bard, Google’s chatbot, comes in just below Grammarly. All other AI apps combined (of which we are tracking more than 60, including Jasper, Chatbase, and Copy.ai) are less popular than Google Bard.

Most popular AI apps by percentage of total daily AI users

Over the past two months, the fastest growing AI app in the enterprise was Google Bard. Although it still lags far behind ChatGPT in popularity, Google Bard is currently adding users at a rate of 7.1% per week, compared to 1.6% for ChatGPT. At their current rates, Google Bard is poised to catch up to ChatGPT in just over a year. However, as the AI app space is very dynamic, we expect to see many more changes during that time which will disrupt the current growth rates.

Netskope Threat Labs tracks the popularity of AI apps in enterprise environments, rather than the overall popularity of the apps among consumers. For example, while ChatGPT popularity skyrocketed among consumers before cooling off in June, its adoption in the enterprise has been more measured and continues to increase exponentially. The remainder of this report highlights some of the reasons for the measured increase, which include risks of data leakage and controls around its use.

Fastest growing AI apps by number of active daily users added weekly

AI Risks - Sensitive Data リンク リンク

This segment focuses on ChatGPT, the leading AI app in the enterprise by a large margin. An average ChatGPT user interacts with the app by posting 6 prompts daily. The activity level varies by user, with the top 10% of users posting 22 prompts and the top 1% posting 68 prompts daily. For every 10,000 users, an organization can expect around 660 daily prompts to ChatGPT. But the real question lies in the content of these prompts: Are they harmless queries, or do they inadvertently reveal sensitive data?

A Netskope study revealed that source code was the most frequently exposed type of sensitive data, with 22 out of 10,000 enterprise users posting source code to ChatGPT per month. In total, those 22 users are responsible for an average of 158 posts containing source code per month. This trend is not entirely unexpected, considering ChatGPT’s ability to review and explain code and pinpoint bugs and security vulnerabilities. While these services are beneficial, sharing confidential source code with ChatGPT introduces risks including potential data breaches, accidental data disclosure, and legal and regulatory risks.

Users posting sensitive data per 10,000k enterprise users per month

Compared to source code, posts containing other forms of sensitive data are relatively less common. For every 10,000 enterprise users, there are typically 18 incidents of sharing of regulated data (encompassing financial data, healthcare information, and personally identifiable information) on a monthly basis. Intellectual property (excluding source code) is rarer still, with an average of 4 incidents per month for every 10,000 users. Interestingly, passwords and keys also appear among the sensitive data types shared, usually embedded in source code. Despite its relative infrequency (about 4 incidents per 10,000 users monthly), this practice serves as a crucial reminder to software engineers about the risks of hard-coding secrets into source code.

Incidents of users posting sensitive data per 10,000k enterprise users per month

Opportunistic Attackers リンク リンク

With all the hype surrounding ChatGPT and AI apps in general, it is unsurprising that scammers, cybercriminals, and other attackers would attempt to exploit the hype for illicit gains. This is common practice with attackers. For example, the Netskope Threat Labs Cloud and Threat Report from Spring 2023 highlighted attackers attempting to capitalize on the Russo-Ukrainian war, the earthquake in Turkey and Syria, and the collapse of Silicon Valley Bank. The hype and popularity of ChatGPT draws the attention of attackers and scammers because of the large target pool and potential for profit, combined with the varied proficiency of users on the platform.

Throughout the first half of 2023, Netskope Threat Labs has tracked multiple phishing campaigns, malware distribution campaigns, and spam and fraud websites seeking to capitalize on the ChatGPT hype. Netskope Threat Labs is even tracking multiple ChatGPT proxies, sites that appear to offer the benefit of free, unauthenticated access to the chatbot, but at the cost of revealing all your prompts and responses to the proxy operator.

A ChatGPT proxy where the proxy operator sees all prompts and responses

A ChatGPT proxy where the proxy operator sees all prompts and responses

 
In total, Netskope Threat Labs is currently tracking more than 1,000 malicious URLs and domains seeking to capitalize on the ChatGPT and AI hype. The number alone is a reminder of the importance of using a multi-layered approach to protect users from attackers attempting to capitalize on the hype and popularity surrounding any significant event or trend. Such an approach should include domain filtering, URL filtering, and content inspection to protect against both known and unknown attacks.

Enterprise Controls リンク リンク

While a common practice when ChatGPT was first gaining popularity was for enterprises to block the chatbot altogether, organizations have since come to terms with the fact that ChatGPT and other AI apps can offer advantages to the organization, including enhancing operations, improving customer experiences, and facilitating data-driven decision-making. Instead of blocking ChatGPT, organizations have transitioned to a more permissive model that typically includes a combination of DLP and user coaching. DLP can be used to identify potentially sensitive data being posted to AI apps, including ChatGPT, and user coaching can leave the ultimate decision of whether or not to proceed with a prompt to the user.

Organizations placing controls around ChatGPT

The specific controls around ChatGPT vary by industry vertical. Overall, financial services, healthcare, and technology companies have led the charge in implementing controls around ChatGPT. However, the approach each industry has taken varies significantly. In financial services and healthcare, both highly regulated industries, nearly 1 in 5 organizations have implemented a blanket ban. No users are allowed to use ChatGPT. In the technology vertical, only 1 in 20 organizations have implemented a blanket ban. Instead 1 in 4 organizations are using DLP controls to detect specific types of sensitive information (especially source code) being posted to ChatGPT. Furthermore, 1 in 5 technology organizations implement real-time user coaching to remind users of company policy and the risks that come along with ChatGPT and other AI apps. Ultimately, more organizations are likely to adopt DLP controls and real-time user coaching over time to enable the use of AI apps like ChatGPT while safeguarding against unwanted data exposure.

Type of ChatGPT controls by industry vertical

推奨 事項 リンク リンク

Safely enabling the adoption of AI apps in the enterprise is a multifaceted challenge. It involves identifying permissible apps and implementing controls that empower users to use them to their fullest potential while safeguarding the organization from risks. This section includes general technical recommendations for organizations aiming to safely enable AI apps. For more detailed information about how Netskope can help, please refer to the ChatGPT and Generative AI Data Protection solution brief.

→ Regularly review AI app activity, trends, behaviors, and data sensitivity, to identify risks to the organization.

→ Block access to apps that do not serve any legitimate business purpose or that pose a disproportionate risk. A good starting point is a policy to allow reputable apps currently in use while blocking all others.

→ Use DLP policies to detect posts containing potentially sensitive information, including source code, regulated data, passwords and keys, and intellectual property.

→ Employ real-time user coaching (combined with DLP) to remind users of company policy surrounding the use of AI apps at the time of interaction.

Block opportunistic attackers attempting to take advantage of the growing popularity of AI apps by blocking known malicious domains and URLs, and inspecting all HTTP and HTTPS content.

→ Use Remote Browser Isolation (RBI) technology to provide additional protection when there is a need to visit websites in categories that can present higher risk, like newly observed and newly registered domains.

→ Ensure that all security defenses share intelligence and work together to streamline security operations. Netskope customers can use Cloud Exchange to share IOCs, import threat intel, export event logs, automate workflows, and exchange risk scores.

このレポートについて リンク リンク

Netskope Threat Labs publishes a quarterly Cloud and Threat Report to highlight a specific set of cybersecurity challenges. The purpose of this report is to provide visibility into cybersecurity risks that AI apps present and how organizations are managing those risks. The analysis presented in this report is based on a study of millions of users from thousands of organizations worldwide, for the period starting May 1, 2023 through June 30, 2023. Stats are reflection of attacker tactics, user behavior, and organization policy. Information presented in this report is based on anonymized usage data collected by the Netskope Security Cloud platform relating to a subset of Netskope customers with prior authorization.

Netskope Threat Labs リンク リンク

業界屈指のクラウド脅威およびマルウェア研究者を擁するNetskope Threat Labs は、企業に影響を与える最新のウェブ、クラウド、データの脅威を発見、分析し、防御策を設計します。 当社の研究者は、DEF CON、Black Hat、RSAなどのトップセキュリティカンファレンスで定期的にプレゼンターやボランティアを務めています。

ライトブループラス

クラウドと脅威のレポート

The Netskope Cloud and Threat Report delivers unique insights into the adoption of cloud applications, changes in the cloud-enabled threat landscape, and the risks to enterprise data.

Storm with lightning over the city at night

SASEのリーダーと共にセキュリティ対策を強化する