Navigating AI Integration and Cybersecurity Risks in Modern Organizations

Dr. Hadas Tamam Ben Avraham of Ono Academic College discusses the governance of AI in organizations, addressing Shadow AI, risk management, and integrated cybersecurity training.

Source
Navigating AI Integration and Cybersecurity Risks in Modern Organizations
Photo: צילום: Walla.co.il

Organizations hold vast amounts of data, yet they often struggle to extract actionable insights in time to make critical decisions. Artificial intelligence tools offer the capability to rapidly analyze data, identify patterns, and assist employees with time-consuming tasks. For management seeking to improve services, streamline processes, or make decisions under uncertainty, this represents an opportunity that is difficult to ignore.

However, these tools do not operate in a vacuum. They ingest organizational data, generate answers that employees may rely on, and sometimes integrate into workflows without any prior decision on how to validate the outcomes. Cybersecurity is already recognized as a significant risk that management and boards of directors must oversee. The adoption of AI introduces new challenges: what data is transferred to these tools, who can access it, and what happens when an erroneous analysis becomes the basis for a decision.

"When an organization considers adopting AI, I suggest starting with workflow processes," says Dr. Hadas Tamam Ben Avraham, Vice Dean and Head of the Cyber Security Risk Management Research Institute at Ono Academic College. "Where is the bottleneck? Which decision can be improved through data analysis? What is truly needed to help employees? Only after understanding the need can an organization select a tool, determine what data is appropriate to share, and establish how results will be verified."

The Unauthorized Usage Operating Outside Work Plans

Alongside planning for future deployment, organizations must evaluate what is already happening today. An employee seeking to summarize a document, a manager utilizing a tool for data analysis, and a team member drafting a customer response via AI may view these actions as a standard way to execute their daily work. It is not always clear to them whether the tool has been officially approved or whether the information they inputted is sensitive.

Concerns regarding privacy violations and data exposure lead some organizations to completely prohibit the use of AI tools. According to Tamam Ben Avraham, while this concern is justified, an outright ban risks leaving the core issue unaddressed. If employees still require these tools, some will continue to utilize them outside official organizational systems.

This phenomenon is known as Shadow AI—the unauthorized or unmonitored use of artificial intelligence tools for work purposes. "Specifically when you close the issue with a sweeping ban, you risk losing visibility into what is actually happening," she notes. "The employee wants to solve a problem. The organization must provide a viable path to do so, while clarifying what data may be shared, which tools are permissible, and when AI output requires human review."

She emphasizes that mapping must include both existing usages and the business needs they serve. This allows distinctions to be made between a tool assisting an employee in drafting a draft versus a tool influencing a decision concerning a customer, employee, or business operation. These are distinct use cases requiring varying levels of governance.

Erroneous Decisions Are Not Always Cyber Incidents

Utilizing AI intersects risks that should not be conflated. Inputting personal data into an external tool raises privacy and information security questions. Relying on flawed analysis triggers issues of oversight and professional accountability. A decision made without transparent rationale may necessitate legal and managerial review. Frequently, several of these challenges manifest within a single event.

"Not every failure in AI utilization is a cyber attack," emphasizes Tamam Ben Avraham. "However, those who focus exclusively on the technological side may overlook the impact on decisions, just as those who focus solely on policy may fail to understand how the system operates. Therefore, continuous dialogue is required among technology, privacy, legal, and management professionals."

Responsibility for this governance extends up to executive management and the board of directors. Management must determine where AI serves a genuine need, procure appropriate tools and policies, and ensure oversight for sensitive applications. The board of directors must supervise how the organization identifies and manages these associated risks.

"A board member does not need to know how to build a model," states Tamam Ben Avraham. "They do need to know where AI is deployed within the organization, what data enters these tools, who verifies the outputs, and what management will do if a discrepancy arises. These are questions pertaining to organizational oversight."

Diverse Professions, A Common Lexicon

This transformation creates a demand for professionals possessing multidisciplinary expertise. Cybersecurity specialists are required to understand how to protect AI systems and the data traversing them. Privacy, legal, and risk management professionals must evaluate novel applications and translate risks into actionable policies. Managers and directors must understand enough to make informed decisions and exercise oversight. None of these stakeholders can operate in isolation.

This exact imperative underpins the Master of Business Administration (MBA) program specializing in Cybersecurity & AI Security at Ono Academic College. The specialization integrates management education with technological and practical knowledge, offering two distinct tracks tailored for different professional trajectories.

The Incident Response (IR) track is designed for individuals seeking to deepen their expertise in the technological and operational aspects of cybersecurity and AI system protection, including hands-on laboratory environments. The Governance, Risk, Compliance & Privacy (GRC&P) track focuses on risk and crisis management, data privacy, regulatory compliance, and leading responsible AI utilization within organizations, incorporating training for an AI Officer (AIO) certified by the Information Technology Association.

In addition to track-specific studies, the program offers elective courses for Data Protection Officer (DPO) certification and cyber-expert board directors. Both tracks converge in cyber crisis management simulations, where technological and managerial personnel must collaborate under real-time operational conditions.

"We want a business manager to speak the language of cybersecurity and articulate the business implications of system data to the executive team, while ensuring managers know how to pose the correct questions," Tamam Ben Avraham concludes. "As AI integrates into an increasing number of workflows, the capacity to bridge these domains becomes an inherent part of professional competence for anyone utilizing a computer."

Related News