Although AI is currently in control of the boardroom agenda, a discussion on the latest The Security Strategist podcast suggests that enterprises might be posing the wrong first question.
The real AI problem isn't just how many AI models an enterprise can deploy, but whether the data that powers the AI model is protected, can be recovered, is affordable, and is, in fact, usable.
Chris Steffen, Host and Vice President of Information Security at Enterprise Management Associates (EMA), is joined by Randy De Meno, Vice President of Business Development and responsible for the Microsoft practice at CrashPlan, on The Security Strategist podcast. They claim that data strategy should come before AI strategy since enterprises are facing rising storage costs, token sprawl and ever more complex cloud environments.
How AI Spending Exposes a Data Protection Problem
This is a time when businesses are generating and keeping large amounts of data. Steffen, when considering the discussions that took place at Black Hat and DEF CON, stated that data protection, cost and governance had become major concerns within the industry.
He said that data is being generated at an exponential rate and asked how it would be protected, what would be done with it, and how it would be paid for.
De Meno said the discussion on data should begin with the measures being taken to protect it. “This includes M365 and Google Workspace. While the two maintain their SaaS applications effectively up and running, that's their primary focus.”
However, he adds that Microsoft 365 is likely the most attacked environment. “While they do a great job of keeping that service up and running. That’s the responsibility of the customer.”
Most enterprises say that they are using AI and deploying AI to make their products easier to use is not a fair argument.
“If you had to use AI simply to make your product easier, it probably wasn’t easy to work with to begin with,” voices De Meno.
AI may satisfy a checkbox for most enterprises. However, CrashPlan enables conversational AI so users can directly query the data they’re protecting from various locations. It has been established that the data is often more valuable and more relevant than traditional social media feeds or news feeds.
Therefore, what truly matters is what an enterprise does with the protected data. De Meno tells Steffen that that's a paradigm the backup space will go through in the next five years. “What location? How granular can I search for data?” are some key questions that will be voiced.
Time vendors like CrashPlan allow customers to work impactfully with that protected data. “Just don't have it out there being a cold copy waiting for restore. Let's do something with it,” De Meno says. “That's one of the evolutions of AI. We just happen to be at the leading edge of it, enabling customers to interact with their protected data.”
Another issue was raised about storage space during the conversation with Steffen.
Especially for enterprises whose setup is based on Microsoft 365 and Google Workspace, the question of the cost of cloud storage is becoming increasingly imperative.
De Meno claimed that for many years businesses had been encouraged to put ever greater amounts of data into SaaS platforms, only for them then to have to deal with rising storage and overage charges as these environments grew.
He said that some customers are now being charged annual overage fees amounting to seven figures and eight figures, while some enterprises have come up with bills of about one million dollars a year.
China Rewrites AI Export Rules
Beijing weighs limits on model weights, data and chip designs, signaling a new phase in state control of advanced AI capabilities.
This has turned data archiving from a simple IT routine into a financial matter for the top level of management.
The problem goes beyond that of storage since the same data is now being used by AI systems, adding another level of cost and risk.
Steffen referred to "token sprawl" as an increasing worry for CFOs, since companies found that their AI usage could very quickly go beyond the budgets that had initially been allocated.
As De Meno pointed out, the key issue is whether all that use of AI is truly necessary.
He asked, "What proportion of that use of tokens was justified? And what percentage of it could have simply been replaced by a search on Google or Bing?"
The podcast also points out a more fundamental issue, namely that businesses are having difficulty linking their AI spending to tangible improvements in productivity.
Steffen gave an example of an enterprise in which token spending rose by 50 per cent while productivity only increased by five per cent. This gap might soon become harder to justify.
CrashPlan Guide: Are you Headed for a Microsoft 365 Storage Overage?
Designing Truly Resilient Stacks
Use lessons from humanitarian crises to engineer graceful degradation, offline capability and human-centred availability into core platforms.
Can the Data Be Recovered?
The discussion eventually comes back to a question often asked: How easy is it to recover? According to De Meno, this ought to be one of the first questions that executives ask when they are assessing backup, archiving and data protection strategies.
“You have the multinational with data sovereignty, and data must remain within country boundaries. That means you must ensure your software solution can do that,” De Meno tells Steffen.
When it comes to talking about protection or backup or archiving, the first and most important question De Meno would ask C-suites: “How easy is it to recover?”
“Are you expanding your user community capabilities, or how can your user community do a self-service recovery?” He adds, “How simple is it for them to find the data?”
That is important since people generally don't remember the exact name of a SharePoint document or the specific location of a given file. Search should take into account the way in which people actually use information.
Overall, AI security must begin with data security. Enterprises can make heavy investments in AI models, applications and infrastructure; much of that investment will be based on an unstable foundation if the underlying data is not protected, governed and recoverable.
As De Meno pointed out, enterprises might now have considerable theoretical value derived from AI even if they fail to safeguard the data which those systems rely on.
For C-suites, the next stage in the discussion about AI might therefore be less concerned with pursuing the most recent model and more focused on determining whether the enterprise knows where its data is, what it costs, who can access it, and whether it can retrieve it when needed. Token sprawl is not the answer.
Yahoo’s Missed Google Moment
Examines how refusing to buy Google, major data breaches and poor capital allocation turned an internet leader into a cautionary case study.
Takeaways
- Data protection should start with how you're safeguarding your data.
- AI is being used to enable better interaction with protected data.
- Enterprises are facing unexpected costs due to SaaS storage overages.
- Effective data archiving can lead to significant cost savings.
- Token sprawl is increasing exponentially, impacting budgets.
- Understanding the shared responsibility model is crucial for data security.
Chapters
00:00 Introduction to Data and AI Challenges in Cybersecurity
01:23 Crash Plan's Role in Data Resiliency and AI
03:49 The Cost of SaaS Storage and Data Overages
07:31 The Evolution of Backup and Data Usage with AI
12:29 The Impact of Token Sprawl on AI and Budgeting
18:57 Understanding the Shared Responsibility Model in Cloud Security
23:28 Making Data Easy to Find and Use
24:52 Closing Remarks and Future Outlook
For more information on how enterprises can tackle data recovery, visit crashplan.com.
Comments ( 0 )