Navigating AI Safely in Your Small Business: an AI Cybersecurity Perspective

A number of other interesting AI cybersecurity issues are hitting our radar as customers begin taking advantage of new AI tools in their small businesses.

Aaron Willis
Cybersecurity
Data Security
Navigating AI Safely in Your Small Business: an AI Cybersecurity Perspective

Earlier this year, in our Forensic Update Webinar, we predicted that AI tools would become capable of rapidly creating complex, malicious code to steal credit cards and other data.  

While we are certainly seeing that prediction come true, a number of other interesting AI security issues are hitting our radar as customers begin taking advantage of new AI tools in their small businesses.

Why should I care about using Artificial Intelligence safely? 

Based on data collected from customers, the SecurityMetrics Forensic Team predicts that “with the help of AI tools, even script kiddies could rapidly create complex completed code that can steal credit card data. For example, AI is being used to create malware for more obscure languages (e.g., Golang, Swift) and generating ecommerce skimmers.” 

This means that navigating AI safely is more important than ever. 

Stories about Artificial Intelligence from the Forensic Field

Recently, a small merchant used AI to help generate an ecommerce solution for selling their products and services. Much to their dismay, soon after, they experienced a data breach that included theft of customer data and credit card loss. During the forensic investigation, our team discovered random directories and scripts were being dynamically created during the checkout process. 

While not seemingly malicious or dangerous, these curious directories and code artifacts made little sense in the context of a well-thought-out and secure checkout process. If nothing else, they provided potential threat actors with an incredible amount of surface area to try attacking. The large number of directories and scripts popping in and out of existence made it extremely time-consuming and complicated to find the source of the data breach. 

Additionally, none of the customer’s limited IT staff could shed any additional light on what the scripts were doing or why they were necessary. It was just something the AI did. Rather than continue a costly investigation through this bizarre eCommerce solution, it was more cost-effective for the merchant to just start over with a proven eCommerce platform; a very costly lesson both in time and capital resources.

Can I use Artificial Intelligence in my shopping cart code?

Certainly, AI is also being used by bad guys to create malware in obscure languages quickly or to generate ecommerce skimmers, ransomware, and other evil contrivances, but its ease of use for good guys can also be that proverbial two-edged sword. 

It might sound very tempting to use AI to whip up some JavaScript and PHP code to get a custom shopping cart done for your website and skip that $99 monthly fee for a hosted checkout solution.  

However, the cost of a mandated forensic investigation after a hacker powns your shopping cart might prove $99 a month for a proven secure platform is a real bargain, especially if you do not have a skilled IT team on staff.

Key takeaway: It's crucial for small businesses to understand that while AI can do some amazingly cool and helpful things, it still has a long way to go before it is a replacement for competent and skilled human expertise, especially in sensitive areas where HIPAA and PCI DSS standards apply.

Examples of Artificial Intelligence (AI)

Artificial intelligence is quickly becoming widely utilized by small businesses. Examples of legitimate business uses include:

  • Intelligent and helpful chatbots
  • Facial recognition
  • Content creation and editing
  • Marketing ideas and other research
  • Analytics
  • Process automation (offloading boring or tedious tasks)
  • Improving blogs, essays, and white papers
  • Detecting changes in social media algorithms
  • Writing code for just about any type of application you can dream up

AI can and will be a game-changer for many small businesses with limited time and budget. In the hands of skilled users, AI can save a lot of time and money, and can even help small business get a bit of competitive leverage. But it's essential to use it cautiously, and knowledgeably.  

The Importance of Using Artificial Intelligence Safely

Using AI in small businesses with caution and skill is crucial for several reasons.

  1. Data Security: AI systems often handle sensitive customer and business data. Without proper safeguards, these systems can be vulnerable to cyberattacks, leading to data breaches and financial losses.
  2. Accuracy and Reliability: AI algorithms can sometimes produce inaccurate or biased results. Careful implementation and oversight are necessary to ensure that AI tools provide reliable and fair outcomes, avoiding decisions that could negatively impact the business or its customers.
  3. Compliance with Regulations: Many industries have strict data protection and privacy regulations. Using AI without understanding these regulations can result in non-compliance, leading to legal consequences and hefty fines.
  4. Resource Management: Implementing AI can be resource-intensive. Small businesses need to ensure they have the necessary technical expertise and financial resources to deploy and maintain AI systems effectively.
  5. Customer Trust: Customers expect businesses to protect their data and use technology responsibly. Mismanagement of AI can lead to breaches of trust, harming the business's reputation and customer relationships.
  6. Operational Efficiency: While AI can automate and optimize many business processes, improper use can lead to inefficiencies and errors. Skilled implementation ensures that AI enhances productivity rather than creating additional problems.
  7. Competitive Advantage: When used correctly, AI can provide a competitive edge by improving decision-making, enhancing customer experiences, and streamlining operations. However, careless use can negate these benefits and put the business at a disadvantage.
  8. Ethical Considerations: AI systems can perpetuate biases present in their training data. Businesses must use AI ethically, ensuring that it does not reinforce harmful stereotypes or unfair practices.
Cautious and skilled use of AI helps small businesses maximize benefits while minimizing risks, ensuring that AI contributes positively to their growth and success.

The Basic Do's and Don'ts for Avoiding AI Cybersecurity Threats in the Workplace

To make AI usage safer in the workplace, small businesses should:

  • Always Review AI-Generated Code: AI-generated code should always be reviewed and tested to identify potential security vulnerabilities.
  • Educate the Team: Providing comprehensive training on AI usage and cyber security best practices can mitigate many risks. The free SecurityMetrics Academy is a good resource for staff training.
  • Implement Data Protection Measures: Utilize encryption techniques and access controls to safeguard sensitive information processed by AI systems.
  • Regularly Update and Patch AI Systems and Tools: Apply timely updates and patches to AI software to stay vigilant against vulnerabilities.
  • Collaborate Between IT and Security Teams: Foster communication and collaboration between IT professionals and cybersecurity experts to ensure safe AI usage.
  • Leverage AI Responsibly: Use AI to enhance productivity and decision-making while maintaining human oversight to mitigate bias and ensure ethical use. Also, double check generated content does not accidentally violate somebody else’s work or intellectual property.
  • Adhere to PCI Requirements: Protect cardholder data by maintaining PCI compliance and adhering to privacy regulations.

Things to avoid when using AI include:

  • Relying Solely on AI for Coding and Cybersecurity: Never implement AI-generated code in a production environment without skilled review.
  • Downloading Third-Party AI Models Without Vetting: Exercise caution to avoid introducing security vulnerabilities or biases.
  • Assuming AI is Foolproof: Human oversight is essential to detect and correct potential errors or biases in AI-generated content and code.
  • Neglecting AI Training and Maintenance: Regularly train AI to understand the network and update models to avoid outdated results.
  • Overlooking the Importance of Human Expertise: Human expertise remains crucial for guiding AI deployment and ensuring alignment with organizational goals.
  • Assuming AI can do more than it can: While AI is certainly powerful in some things, it is more of a force multiplier.

See also: SecurityMetrics PCI Guide

Crafting an AI Strategy

Small business owners often wear multiple hats, including using AI to craft emails, generate ad copy, or create website code. While AI can be helpful, there are pitfalls to avoid. A solid AI strategy can mitigate many risks. 

Matthew Heffelfinger, Director of the SecurityMetrics Threat Intelligence Center, advises providing employees with AI guidelines and creating a formal AI acceptable use policy. 

Key topics to consider in an AI-acceptable use policy include:

  • Generative AI Code Cybersecurity Risks: AI can assist in coding but may produce code with security vulnerabilities. A solid IT team can fortify cyber defenses to prevent hacker access.
  • Preventing Bias and Biased Results: AI algorithms often reflect the worldview of their creators, leading to biased outcomes. It's essential to recognize AI's limitations and ensure responsible use with human oversight.
  • Creating a Comprehensive Cybersecurity Plan: Prioritize cybersecurity by training AI with comprehensive company information. A competent IT team plays a pivotal role in building and supervising AI models to align with cybersecurity objectives.

A skilled writer can use AI to craft an excellent article or blog quickly. An unskilled writer might be able to get some content out using AI, but it will not be great quality writing and will probably sound just like an AI wrote it. Probably not the look your company is going for.  

The same is true for a skilled coder, IT person, analyst, marketer, or blogger. AI is at a point where it can help you do your job in more productive and creative ways. It cannot do your job or somebody else’s job that you don’t want to hire, although it will certainly try. However, you will pay the bill when it fails.  

Mitigating eCommerce Risks with AI Tools

E-commerce shopping carts are inherently high-risk. High-value data such as customer information and credit card data are present in those shopping carts, even if only for a small moment. This makes shopping carts, even for small merchants, a desirable target for data thieves. 

SecurityMetrics' Shopping Cart Inspect tool combines forensic tools with human analysis to identify malicious or suspicious issues. This service analyzes your checkout process and identifies problematic scripts and processes for further inspection. 

We are researching and implementing AI to help us in our investigations. AI allows us to quickly detect suspicious and malicious activity that may be present in the hundreds of thousands of lines of code that are often present in a checkout session. This process used to take many man-hours to achieve. Using AI, our hope is to cut this process down to minutes.

Commercial cybersecurity AI tools are quickly becoming available that can help small businesses with tedious tasks such as log monitoring, threat detection, and many other IT chores. 

We encourage small business owners to get familiar with what is happening with these types of applications, but to exercise restraint and wisdom in their implementation and not to incorporate these tools until both you and them are ready to do so safely and securely. 

Conclusion: Making AI Work For Small Businesses

Prioritizing cybersecurity can be challenging for small businesses, but even basic cybersecurity hygiene and a proactive approach to defending websites can go a long way. For assistance with cybersecurity, small businesses can reach out to SecurityMetrics experts or consult resources like their incident response plan blog.  

We hope you are also researching and learning about ways AI can help you in your business processes. Artificial Intelligence is an exciting and game-changing technology. But as with all new advances, it comes with a new set of problems and challenges. We must learn to implement AI responsibly and alongside skilled experience so that AI does not come back to bite us with catastrophic failures from poorly executed plans. 

The old adage is truer than ever. To err is human. To really screw things up, you need a computer.

Join Thousands of Security Professionals.

Subscribe Now

Get the Guide To PCI Compliance

Download

Get a Quote for Data Security

Request a Quote