Author Archives: BobSulli

The State of Cybersecurity Insurance Adoption

The cost of a single data breach, ransomware attack or other security incident can adversely impact the most solid financial balance sheet. The growing threat from sophisticated cybercriminals targeting organizations of all sizes elevates cybersecurity insurance from an IT security concern to a critical business priority, demanding the attention of senior leadership and boards of directors. But what are the limitations of these cybersecurity policies and what are the benefits and hurdles to purchasing a policy that protects organizations? In the event of a cyberattack, how satisfied are organizations with their insurers’ response? Sponsored by Recast Software, the purpose of this research is to address these questions and help organizations prepare for the purchase of insurance.

It’s about the money. Respondents do not expect any decrease in cyber risks targeting their organizations. Instead, according to 75 percent of respondents, their organizations’ exposure will increase (47 percent) or at best stay the same (28 percent). As cyberattacks increase in severity and sophistication, the potential for a significant financial consequence is becoming more likely. According to 61 percent of respondents, the average total financial impact of all security exploits and data breaches experienced by their organizations since purchasing insurance averaged $21 million.

The top two reasons for purchasing insurance are the increasing number of cybersecurity incidents (41 percent of respondents) and concerns about the financial impact (40 percent of respondents). According to the research, 65 percent of respondents say their organizations are purchasing limits between $6 million to more than $100 million. However, 50 percent of respondents say it is difficult to comply with insurers’ requirements. More than 51 percent of respondents say insurers require regular scanning for vulnerabilities that need to be patched.

Ponemon Institute surveyed 631 IT and IT security practitioners in the United States who are familiar with cyber risks facing their companies and have knowledge about their organizations’ use of cybersecurity insurance. Seventy-six percent of respondents say their organizations have completed the purchase and 24 percent of respondents say their organizations are in the process.

 

In this section, we provide an analysis of the research. The complete findings are presented in the Appendix of this report. The report is organized according to the following topics.

 

  • What keeps organizations’ IT security posture from being strong?
  • How helpful is cybersecurity insurance in protecting organizations from adverse financial consequences?
  • Dealing with the hurdles organizations face when purchasing cybersecurity insurance

 What keeps organizations’ IT security posture from being strong?

 Technology and governance challenges are affecting the ability to improve organizations’ security posture. Less than half (49 percent) of respondents rate their IT security posture in terms of its effectiveness at mitigating risks, vulnerabilities and attacks across the enterprise as very effective. The primary reasons are the ineffectiveness of security technologies and the complexity of the IT security environment.

Other challenges that need to be addressed are having a complete inventory of third parties with access to their sensitive and confidential data, keeping senior management up to date about threats facing their organizations and convincing management that cyberattacks are a significant risk.

Understanding the level of cyber risk is important because organizations realize cyber threats are not decreasing. Sixty-three percent of respondents say they assess the level of cyber risk to their organizations. According to 75 percent of respondents, cyber risks will increase (47 percent) or stay the same (28 percent).

The internal assessments are informal (23 percent) or formal (21 percent). However, 37 percent of respondents say their organizations do not do any type of assessment (21 percent) or rely on intuition of gut feel (16 percent). Only 19 percent hire an independent third party to conduct the assessment.

How helpful is cybersecurity insurance in protecting organizations from adverse financial consequences?

 Cybersecurity insurance can improve organizations’ security posture. As reported, 76 percent of respondents have completed the purchase of cyber insurance. On average, these organizations have held their policies for two years, which gives them an understanding of the benefits and effectiveness of cyber insurance.

Almost half (49 percent) of respondents say following the purchase of cybersecurity insurance their cybersecurity posture improved greatly or significantly. However, 48 percent of these respondents changed insurance companies. The primary reasons for the change were the cancellation of the policy or the high expense.

Since purchasing cybersecurity insurance, the threats to organizations did not decrease. While only 27 percent of respondents say cyberattacks have increased and only 17 percent of respondents say their IT security costs have increased,  45 and 44 percent of respondents say cyberattacks and IT security costs have stayed the same.

Forty-three percent of respondents say cyber insurance coverage is sufficient with respect to coverage terms and conditions, exclusions, retentions, limits and insurance carrier financial security. Sixty-seven percent of respondents are extremely satisfied (23 percent), very satisfied (21 percent) or satisfied (23 percent) with coverage.

The financial consequences of all security exploits and data breaches experienced since the purchase of insurance averages $21 million, which includes all costs including out-of-pocket expenditures such as ransomware, consultant and legal fees, indirect business costs such as productivity losses, diminished revenues, legal actions, customer turnover and reputation damage. Sixty-one percent of respondents experienced a significantly disruptive security exploit or data breach since the purchase of cybersecurity insurance.

Fifty-three percent of respondents say their organizations filed a claim following the incident and an average of 46 percent of the losses were covered or approximately $9.7 million. When asked how satisfied their organizations were with the insurance company’s response to the claim, less than half (46 percent of respondents) were very or highly satisfied with the response.

And 65 percent of respondents say their organizations have experienced cyberattacks such as ransomware or denial of service and 61 percent of respondents say cyberattacks have resulted in the misuse or theft of business confidential information, such as intellectual properties.

Dealing with the hurdles organizations face when purchasing cybersecurity insurance

 Insurance companies’ assessment of organizations’ security posture is mainly focused on the existence of an adequate budget. Only half (50 percent) of respondents say the insurance company assesses their security posture. If they do, it is to determine if there is adequate budget (65 percent of respondents). Other factors included are evidence of security and training programs conducted (52 percent of respondents), effectiveness of incident response team (45 percent of respondents) and ability to detect and prevent cyberattacks (45 percent of respondents).

To read the rest of this report, visit the ReCastSoftware.com website

Taylor Swift, the FCC deepfake ban, and why you are the last (only?) line of defense

Twitter (X) briefly blocked Taylor Swift searches in reaction to deepfake posts. A good, if brutal, response.

Bob Sullivan

Hold on tight, fellow humans, there’s artificial turbulence ahead.  Like it or not, the time has come to stop believing what you see, what you hear, and perhaps even what you think you know. Reality is indeed under attack and it’s up to us to preserve it.  The only way to beat back this futuristic nightmare is with old-fashioned skepticism.

Lately, it feels like all anyone wants to talk about is AI and how it’s going to make life much easier for criminals, and much harder for you.  I’ve annoyed several interviewers recently by saying I don’t believe the hype. There is not an avalanche of voice-cloning criminals out there manipulating victims by creating fake wailing kids claiming to need bail money.  The so-called grandparent scam has operated successfully for many years without AI.  But I think that misses the point. First of all, as many journalists have demonstrated (even me!) it’s trivial to create deepfakes now. An expert cloned my voice for $1. But more important, a recent offensive, vile Taylor Swift deepfake was viewed 47 million times before it was removed from most of social media.  This kind of violation is here, today, and it’s going to be very hard to stop.

There are celebrated efforts, of course. The FCC just made voice cloning in scams explicitly illegal, which is certainly welcome, but if FCC efforts to stop robocalling are a guide, AI scams won’t be stopped by this. There are also some high-tech efforts to separate what’s real from what’s fake, and that’s also welcome. Watermarking — even in audio files — can be used by software to declare items as AI-generated, so our gadgets can tell us when a Joe Biden video has been manipulated. Naturally, I wish tech companies had built such safety tools into their AI-generating software in the first place, but this kind of retrofitting is what we’ve come to expect from Big Tech.

I don’t have high hopes that an “AI-generated” label on a negative presidential candidate video is going to do much to stop the coming attack on reality, however. I’m afraid to say this, but it’s true: the problem, dear Brutus, lies not in our stars but in ourselves.

I am the last person to lump responsibility for the failures of billion-dollar tech companies onto busy human beings.  And that’s not what I’m doing here. I still want tech workers to speak up when managers ask them to make tools that can be used to hurt people. I still want regulators to staff up and lock down companies that behave recklessly.  But when it comes to defending reality, the truth is, we are on our own right now.  Human beings are going to have to develop radical inquisitiveness when it comes to things we see, hear, and feel while interacting with technology.

This is going to be hard. Many of us want to see a video of our least-favorite politician looking stupid.  A large number want to see “exclusive” video of famous people in….candid…moments.  We would love for them to contact us directly and offer to be our friend, or even our lover.

We have to help each other learn to resist these base urges, to choose reality over this dark fantasy world that’s being foisted on us.

As if often the case with tech crises, this problem isn’t really new.  Marketers have always manipulated consumers. Propagandists have always lied to populations.  Many dark periods of history can be blamed on large groups failing to exercise proper skepticism, their prejudices and predispositions used against them.  What’s different about our time is the scale.  As we learned back in 2016, a room full of typists half-way around the world can persuade thousands of Americans to attend real-world rallies. The tools for liars and criminals are very powerful; we have to respond with equal force.

I recently interviewed Professor Jonathan Anderson, an expert in artificial intelligence and computer security at Memorial University in Canada, about this problem, and he’s persuaded me that humans must react by adjusting to this new “reality” of un-reality.  We must stop believing what we see and hear. And there is precedence for this.  At the dawn of photography, many people believed that photos couldn’t lie.  Most folks now know that it’s trivial to manipulate images, perhaps even on a subconscious level. If you see something that doesn’t look right — a man’s head on an animal’s body — your first instinct is to react as if Photoshop is the culprit.  Hopefully, we’ll all engage in a learning curve now where this is how we react to any media that’s unexpected, be it a fake desperate child, a celebrity asking to meet with us, or a politician doing something foolish.

My fear is that people will still believe what they want to believe, however.  A “red” person will believe only “blue” fakes, and vice versa.  And that, in my view, is the greatest threat to reality right now.

The growing risk of payment transaction fraud

Business payment transactions are massive. In 2020, business transactions in the US alone were $23 trillion. By 2028, the value of business transactions worldwide is expected to increase to $200 trillion[1]. Such growth should make increasing the security of business payment transactions a priority.

The objectives of this research, conducted by Ponemon Institute and sponsored by Creednz, are to understand the vulnerabilities in organizations’ current payment transaction processes and if controls in place are effective in mitigating the risk. We surveyed 659 professionals in finance, accounting, treasury and risk and compliance. All respondents are familiar with their organizations’ approach to managing payment transaction fraud.

A key takeaway from this research is organizations’ lack of confidence in their existing controls and the ability to keep enough staff to address the risk of payment transaction fraud. Eighty-eight percent of respondents say their organizations had at least one payment transaction fraud in the past two years. The average cost of these incidents was $149,225. Seventy-six percent of respondents say it took more than a month to more than a year to discover and remediate these incidents.

As payment transactions grow, fraud is expected to increase. Fifty-four percent of respondents say fraud will increase significantly (23 percent) or increase (31 percent). The primary reasons are the increasing sophistication of fraudsters (59 percent), lack of resources and technology systems to proactively identify accounts payable/receivable fraud (56 percent), and vulnerabilities in business processes (53 percent).

“A manual process leads to fraud, and those that get blamed are the ones who literally clicked the ‘send’ button,” said Creednz Co-founder and CEO Johnny Deutsch. “It makes no sense in today’s world that technology isn’t being utilized and applied to prevent this in the first place. Creednz was built from the ground up to give finance teams the tools to fight back and protect against payment fraud and safeguarding corporate finances.”

The following findings indicate why payment transaction fraud is a growing risk

 Finance and Treasury may be considered most responsible for preventing fraud, but IT security/SecOps is in the accountability hot seat. Finance and Treasury are most responsible according to 17 percent and 13 percent of respondents. Most accountable for reducing payment transaction fraud is IT security/SecOps (34 percent of respondents),

Confidence in banks and current controls to prevent payment transaction fraud is low. Only 32 percent of respondents are confident or very confident that their banks would verify and stop a suspicious transaction and only 30 percent of respondents have confidence in their current controls.

IT security/SecOps and IT operations are most likely to get fraud-related alerts from their banks. IT security/SecOps (67 percent of respondents) and IT operations (55 percent of respondents) are most often notified about payment transaction fraud. Fifty-two percent of respondents say Finance and 37 percent of respondents say Treasury are likely to get fraud alerts. As discussed, IT security/SecOps is the function considered most accountable for preventing fraud.

Most organizations have experienced at least one payment transaction fraud incident in the past two years. Eighty-eight percent of respondents say their organizations had at least one payment transaction fraud incident in the past two years. More than half (51 percent) of respondents say their organizations had at least four incidents.

The average cost of these incidents (not including internal investigations, legal fees and fines and loss of shareholder confidence) was $149,225. Seventy-six percent of respondents say it took more than a month to more than one year to discover and mitigate these incidents.

Following the fraud, the primary step taken was to invest in technologies. Sixty-five percent of respondents say their organizations purchased technologies to reduce the time it takes to detect the fraud and technologies that would prevent business transaction fraud (63 percent of respondents). Only 44 percent of respondents say the fraud was immediately reported to senior management.

Concerns about the organization’s ability to be good custodians can damage reputations. The number one negative consequence following the fraud incident was damage to the organization’s reputation with business partners and consumers (60 percent of respondents). This is followed by non-compliance with regulations (51 percent of respondents) and loss of shareholders’ confidence (46 percent of respondents).

Keeping staff is the number one challenge to mitigating payment transaction fraud. Staff shortages (56 percent of respondents), the inability to systematically control risks created by third parties or vendors (54 percent of respondents, and the worry that staff would leave in the event of payment transaction fraud (51 percent of respondents) are the top challenges.

Organizations (69 percent of respondents) are most likely to use bank account access privileges to minimize payment transaction fraud.  User entitlements determine the level of banking application access. A user must be entitled to account access to perform tasks. Unless a user is given full entitlements, each account user is to have access and level of access that is defined when entitlements are granted.

Sixty-four percent of respondents say their organizations conduct a daily review and approval of all outgoing payment transactions, 61 percent of respondents say their organizations have added ACH blocks or ACH filters and 60 percent of respondents use multi-factor authentication.

Perceptions about the security of banking relationships from 46 percent of respondents who are in Corporate Finance and Treasury.

Almost half (48 percent) of corporate finance and treasury respondents say their organizations have bank accounts outside the US and Canada. Seventy-five percent of these respondents have a minimum of 21 to more than 50 bank accounts and 48 percent say these accounts are located outside of North America. Seventy-seven percent of respondents say bank accounts are located in EMEA, 69 percent of respondents say LATAM and 64 percent of respondent say Asia-Pac.

Review of user entitlements is not frequent. Sixty-one percent of respondents say their organizations review user entitlements. However, almost half (47 percent) of respondents say these reviews occur annually (23 percent) or as needed (24 percent). In addition, organizations are not auditing bank accounts as often as they should. Fifty-five percent of respondents say their organizations are auditing bank accounts to verify such factors as permissions, stale users and signatory rights policies. However, 68 percent of these respondents say they only conduct the audits quarterly (28 percent), annually (19 percent) or as needed (21 percent).

The inability to know all users with entitlement privileges is the most significant challenge to managing user entitlement privileges, according to 40 percent of respondents. Forty-one percent of respondents say there is no formal process to monitor changes to their user bank account entitlement process and 36 percent of respondents say monitoring is only done as needed. Only 23 percent of respondents say IT security is relied upon to monitor changes. Other challenges not as significant are the lack of information related to signatory rights (28 percent of respondents) or the inability to conduct regular reviews (27 percent of respondents).

The findings from all respondents are shown below.

Most organizations are concerned about potential fraud when making payments to third parties and vendors outside the US and Canada. Fifty-nine percent of respondents say payments are made to overseas organizations and 76 percent of respondents say they are concerned or very concerned about the potential of fraud when making payments to these regions. Of the 59 percent of respondents making payments overseas, 70 percent of respondents say payments are made to third parties in EMEA, 65 percent of respondents say LATAM and 55 percent of respondents say Asia-Pac.

The results of risk assessments determine how many payment policies are applied. Sixty-one percent of respondents say payment policies are applied consistently without consideration of risk, location and the length of time the relationship has lasted. However, 39 percent of respondents say payment policies are not applied consistently. If payment polices are not applied consistently, 58 percent say payment policies differ based on risk assessments. This is followed by 45 percent of respondents who say application policies are based on location of vendor/third party/contractor.

Most organizations are using a third-party service to validate bank account details. Only 36 percent of respondents say their organizations validate bank account details all the time. If they do validate, 64 percent of respondents say they use a third-party service. This may be due to the challenge of not having enough staff dedicated to mitigating payment transaction fraud. Forty-nine percent of respondents say a phone call is made to validate vendor bank account details.

Sixty-two percent of respondents say email is used to exchange account details with vendor’s/third parties/contractors and 59 percent of respondents use a more secure exchange through a vendor portal.

Concern about the corruption of the payment file is the reason many respondents are not confident in their vendor management vetting process. Fifty-two percent say possible corruption of the payment file and 48 percent of respondents say it is human error that the third-party vetting process is not reducing the risk of payment transaction fraud.

To read the full report, visit the Creendnz.com website

What self-checkout failures can teach us about artificial intelligence

Bob Sullivan

We all want tech to solve the world’s most vexing problems, and we’ve all spent time with tech that hasn’t lived up to its promises. The printer that lets us down as we’re rushing to a meeting. The concert ticket app that suddenly fails as we’re trying to get into a show. The helpful website customer chat tool that only knows how to say, “I’m sorry you’re having trouble.”  Tech might feel like the solution to every challenge; clearly, it’s not.  And it often creates as many problems as it solves.

And that takes me to self-checkout lines at retail stores.  We’ve all seen them work; we’ve all seen them fail.  I want people to remember this as we race headlong into the AI world.

There have been a flurry of articles recently about the failed experiment of self-checkout. How big stores are backsliding on kiosk installations. How consumers have come to realize they are doing extra work, often enduring extra frustration, and not getting anything for their trouble. How lack of human beings at store exists contribute to shoplifting.

People in the industry say these comments are overblown. But there is no denying; self-checkout is often a headache. And it gets no beta-test bye from me. We’ve been forcing people to find the code for green peppers (organic or not?) since the 1990s.  That’s a generation of shoppers’ time to work out the kinks.

I know many of you love running into a drugstore and running out with one tube of toothpaste without having to wait for a store clerk to take your money and make your change.  As usual, my criticism is not sweeping or all-inclusive.  Quite the contrary. I want people to remember that new technologies should be implemented without forcing people to abandon old ways.  The solutions tech offers are never all-inclusive.  There are compromises to be made. There are exceptions to be handled. The obvious solution for stores is to have a better mix of human clerks and self-checkout machines.

Unfortunately, that mix is hampered by the Trojan horse fighting all good technology implementations — above all, cost cutting. See, self-checkout is really about minimizing minimum wage employees, not getting the best out of a new human invention. In a capitalist society, that pressure will always exist. But even here, this approach is short-sighted and doesn’t pencil out.  There is evidence that labor cost savings from self-checkout are erased by increased shoplifting.  And we’ve all seen stores that end up hiring nearly as many self-checkout hand-holders as they had cashiers.

So when we introduce new tech, blended, human-friendly solutions should be the first impulse, not a last resort. After 9/11, there was so much talk (and snake oil) around facial recognition.   Most of those implementations failed spectacularly, and we found that talented, attentive security guards are better at keeping us safe.  Slowly, airport security tech has gotten better, and it can now stand alongside human talent to protect our flights.  But any rush to find a gadget cure-all is doomed to fail.

Here’s another example I’ve thought about often. Not long ago, many believed virtual reality would soon be ubiquitous.  Today, you barely hear the term. Creating a fully immersive experience that fools the mind turns out to be incredibly hard. But augmented reality — where repair instructions project over a technician’s genuine eyesight as they try to complete a tricky repair — has great potential.  In a similar way, self-driving cars are a pipe dream.  But driver assistance technology is here today, works incredibly well, and holds the promise of soon dramatically reducing car accidents.

So as artificial intelligence continues to creep into our offices and our consumer products, let’s make sure people are leading the way, not forced to follow it. Otherwise, we’ll end up like so many consumers, standing in line, waiting for someone to come verify our driver’s license so we can buy cooking wine.

 

Cyber Insecurity in Healthcare: The Cost and Impact on Patient Safety and Care 2023

A strong cybersecurity posture in healthcare organizations is important to not only safeguard sensitive patient information but also to deliver the best possible medical care. This study was conducted to determine if the healthcare industry is making progress in achieving these two objectives.

With sponsorship from Proofpoint, Ponemon Institute surveyed 653 IT and IT security practitioners in healthcare organizations who are responsible for participating in such cybersecurity strategies as setting IT cybersecurity priorities, managing budgets and selecting vendors and contractors.

The report, “Cyber Insecurity in Healthcare: The Cost and Impact on Patient Safety and Care 2023,” found that 88% of the surveyed organizations experienced an average of 40 attacks in the past 12 months. The average total cost of a cyber attack experienced by healthcare organizations was $4.99 million, a 13% increase from the previous year.

Among the organizations that suffered the four most common types of attacks—cloud compromise, ransomware, supply chain, and business email compromise (BEC)—an average of 66% reported disruption to patient care. Specifically, 57% reported poor patient outcomes due to delays in procedures and tests, 50% saw an increase in medical procedure complications, and 23% experienced increased patient mortality rates. These numbers reflect last year’s findings, indicating that healthcare organizations have made little progress in mitigating the risks of cyber attacks on patient safety and wellbeing.

According to the research, 88 percent of organizations surveyed experienced at least one cyberattack in the past 12 months. For organizations in that group, the average number of cyberattacks was 40. We asked respondents to estimate the single most expensive cyberattack experienced in the past 12 months from a range of less than $10,000 to more than $25 million. Based on the responses, the average total cost for the most expensive cyberattack was $4,991,500, a 13 percent increase over last year. This included all direct cash outlays, direct labor expenditures, indirect labor costs, overhead costs and lost business opportunities.

At an average cost of $1.3 million, disruption to normal healthcare operations because of system availability problems was the most expensive consequence of the cyberattack, an increase from an average of $1 million in 2022. Users’ idle time and lost productivity because of downtime or system performance delays cost an average of $1.1 million, the same as in 2022. The cost of the time required to ensure the impact on patient care was corrected increased from an average of $664,350 in 2022 to $1 million in 2023.

“While the healthcare sector remains highly vulnerable to cybersecurity attacks, I’m encouraged that industry executives understand how a cyber event can adversely impact patient care. I’m also more optimistic that significant progress can be made to protect patients from the physical harm that such attacks may cause,” said Ryan Witt, chair, Healthcare Customer Advisory Board at Proofpoint. “Our survey shows that healthcare organizations are already aware of the cyber risks they face. Now they must work together with their industry peers and embrace governmental support to build a stronger cybersecurity posture—and consequently, deliver the best patient care possible.”

The report analyzes four types of cyberattacks and their impact on healthcare organizations, patient safety and patient care delivery:

Cloud compromise. The most frequent attacks in healthcare are against the cloud, making it the top cybersecurity threat, according to respondents. Seventy-four percent of respondents say their organizations are vulnerable to a cloud compromise. Sixty-three percent say their organizations have experienced at least one cloud compromise. In the past two years, organizations in this group experienced 21 cloud compromises. Sixty-three percent say they are concerned about the threat of a cloud compromise, an increase from 57 percent.

Business email compromise (BEC)/spoofing phishing. Concerns about BEC attacks have increased significantly. Sixty-two percent of respondents say their organizations are vulnerable to a BEC/spoofing phishing incident, an increase from 46 percent in 2022. In the past two years, the frequency of such attacks increased as well from an average of four attacks to five attacks.

Ransomware. Ransomware has declined as a top cybersecurity threat. Sixty-four percent of respondents believe their organizations are vulnerable to a ransomware attack. However, as a concern ransomware has decreased from 60 percent in 2022 to 48 percent in 2023. In the past two years, organizations that had ransomware attacks (54 percent of respondents) experienced an average of four such attacks, an increase from three attacks. While fewer organizations paid the ransom (40 percent in 2023 vs. 51 percent in 2022), the ransom paid increased nearly 30 percent from an average of $771,905 to $995,450.

Supply chain attacks. Organizations are vulnerable to a supply chain attack, according to 63 percent of respondents. However, only 43 percent say this cyber threat is of concern to their organizations. On average, organizations experienced four supply chain attacks in the past two years.

As in the previous report, an important part of the research is the connection between cyberattacks and patient safety. Following are trends in how cyberattacks have affected patient safety and patient care delivery.

  • It is more likely that a supply chain attack will affect patient care. Sixty-four percent of respondents say their organizations had an attack against their supply chains. Seventy-seven percent of those respondents say it disrupted patient care, an increase from 70 percent in 2022. Patients were primarily impacted by delays in procedures and tests that resulted in poor outcomes such as an increase in the severity of an illness (50 percent) and a longer length of stay (48 percent). Twenty-one percent say there was an increase in mortality rate.
  • A BEC/spoofing attack can disrupt patient care. Fifty-four percent of respondents say their organizations experienced a BEC/spoofing incident. Of these respondents, 69 percent say a BEC/spoofing attack against their organizations disrupted patient care, a slight increase from 67 percent in 2022. And of these 69 percent, 71 percent say the consequences caused delays in procedures and tests that have resulted in poor outcomes while 56 percent say it increased complications from medical procedures.
  • Ransomware attacks can cause delays in patient care. Fifty-four percent of respondents say their organizations experienced a ransomware attack. Sixty-eight percent of respondents say ransomware attacks have a negative impact on patient care. Fifty-nine percent of these respondents say patient care was affected by delays in procedures and tests that resulted in poor outcomes and 48 percent say it resulted in longer lengths of stay, which affects organizations’ ability to care for patients.
  • Cloud compromises are least likely to disrupt patient care. Sixty-three percent of respondents say their organizations experienced a cloud compromise, but less than half (49 percent) say cloud compromises disrupted patient care. Of these respondents, 53 percent say these attacks increased complications from medical procedures and 29 percent say they increased mortality rate. 
  • Data loss or exfiltration disrupts patient care and can increase mortality rates. All organizations in this research had at least one data loss or exfiltration incident involving sensitive and confidential healthcare data in the past two years. On average, organizations experienced 19 such incidents in the past two years and 43 percent of respondents say they impacted patient care. Of these respondents, 46 percent say it increased the mortality rate and 38 percent say it increased complications from medical procedures. 

Other key trends in cyber insecurity

Concerns about threats related to employee behaviors increased significantly. Substantially more organizations are now worried about the security risks created by employee-owned devices (BYOD), an increase from 34 percent in 2022 to 61 percent of respondents. Concerns about BEC/spoof phishing increased from 46 percent to 62 percent in 2023.

Disruption to normal healthcare operations because of system availability problems increased to $1.3 million from $1 million in 2022. Users’ idle time and lost productivity because of downtime or system performance delays averaged $1.1 million. The cost of the time taken to ensure impact on patient care was corrected increased to $1 million in 2023 from $664,350 in 2022.

Accidental data loss is the second highest cause of data loss and exfiltration. Accidental data loss can occur in many ways, such as employees misplacing or losing devices that contain sensitive information, or mistakes made when employees are emailing documents with sensitive information. Almost half of respondents (47 percent) say their organizations are very concerned that employees do not understand the sensitivity and confidentiality of documents they share by email.

More progress is needed to reduce the risk of data loss or exfiltration. All healthcare organizations in this research have experienced at least one data loss or exfiltration incident involving sensitive and confidential healthcare data. The average number of such incidents is 19.

Cloud-based user accounts/collaboration tools that enable productivity are most often attacked. Fifty-three percent of respondents say project management tools and Zoom/Skype/video conferencing tools at some point were attacked.

Organizations continue to deploy a combination of approaches to user access and identity management in the cloud (56 percent of respondents). These include separate identity management interfaces for the cloud and on-premises environments, unified identity management interfaces for both the cloud and on-premises environments, and deployment of single sign-on.

The lack of preparedness to stop BEC/spoof phishing and supply chain attacks puts healthcare organizations and patients at risk.  While BEC/spoof phishing is considered a top cybersecurity threat, only 45 percent of respondents say their organizations include steps to prevent and respond to such an attack as part of their cybersecurity strategy. Similarly, only 45 percent say their organizations have documented the steps to prevent and respond to attacks in the supply chain. Malicious insiders are seen as the number one cause of data loss and infiltration — however, only 32 percent say they are prepared to prevent and respond to the threat. 

The primary deterrents to achieving an effective cybersecurity posture are a lack of in-house expertise, staffing and budget. Fifty-eight percent of respondents, an increase from 53 percent in 2022, say their organizations lack in-house expertise and 50 percent say insufficient staffing is a challenge. Those citing insufficient budget increased from 41 percent to 47 percent in 2023.

Security awareness training programs continue to be the primary step taken to reduce the insider risk. Negligent employees pose a significant risk to healthcare organizations. More organizations (65 percent in 2023 vs. 59 percent of respondents in 2022) are taking steps to address the risk of employees’ lack of awareness about cybersecurity threats. Of these respondents, 57 percent say they conduct regular training and awareness programs. Fifty-four percent say their organizations monitor the actions of employees.

The use of identity and access management solutions to reduce phishing and BEC attacks has increased from 56 percent of respondents in 2022 to 65 percent in 2023. The use of domain-based message authentication (DMARC) increased from 38 percent in 2022 to 43 percent in 2023.

To read the full report, download it from Proofpoint’s website.

Someone made a deepfake of my voice for a scam! (With permission…)

Bob Sullivan

“I need help. Oh my God! I hit a woman with my car,” the fake Bob says. “It was an accident, but I’m in jail and they won’t let me leave unless I come up with $20,000 for bail …Can you help me? Please tell me you can send the money.”

It’s fake, but it sounds stunningly real. For essentially $1, using an online service available to anyone, an expert was able to fake my voice and use it to create telephone-ready audio files that would deceive my mom.  We’ve all heard so much about artificial intelligence – AI – recently. For good reason, there have long been fears that AI-generated deepfake videos of government figures could cause chaos and confusion in an election.  But there might be more reason to fear the use of this technology by criminals who want to create confusion in order to steal money from victims.

Already, there are various reports from around North America claiming that criminals are using AI-enhanced audio-generation tools to clone voices and steal from victims. So far, all we have are isolated anecdotes, but after spending a lot of time looking into this recently, and allowing an expert to make deepfakes out of me, I am convinced that there’s plenty of cause for concern.

Reading these words is one thing; hearing voice clones in action is another. So I hope you’ll listen to a recent episode of The Perfect Scam that I hosted on this for AARP.  Professor Jonathan Anderson, an expert in artificial intelligence and computer security at Memorial University in Canada, does a great job of demonstrating the problem — using my voice — and explaining why there is cause for … concern, but perhaps not alarm.  His main suggestion: All consumers need to raise their digital literacy and become skeptical of everything they read, everything they see, and everything they hear. It’s not so far-fetched; many people now realize that images can be ‘photoshopped’ to show fake evidence.  We all need to extend that skepticism to everything we consume. Easier said, than done, however.

Still, I ponder, what kind of future are we building? Also in the episode, AI consultant Chloe Autio offers up some suggestions about how industry, governments, and other policymakers can make better choices now to avoid the darkest version of the future that I’m worried about.

I must admit I am still skeptical that criminals are using deepfakes to any great extent. Still, if you listen to this episode, you’ll hear Phoenix mom Jennifer DeStefano describe a fake child abduction she endured, in which she was quite sure she heard her own child’s voice crying for help.  And you’ll hear about an FBI agent’s warning, and a Federal Trade Commission warning.  As Professor Anderson put it, “based on the technology that is easily, easily available for anyone with a credit card, I could very much believe that that’s something that’s actually going on.”

 

Preparing for a Safe Post Quantum Computing Future: A Global Study

Sponsored by DigiCert, the purpose of this research is to understand how organizations are addressing the post quantum computing threat and preparing for a safe post quantum computing future. Ponemon Institute surveyed 1,426 IT and IT security practitioners in the United States (605), EMEA (428) and Asia-Pacific (393) who are knowledgeable about their organizations’ approach to post quantum cryptography.

Quantum computing harnesses the laws of quantum mechanics to solve problems too complex for classical computers. With quantum computing, however, cracking encryption becomes much easier, which poses an enormous threat to data security.

That is why 61 percent of respondents say they are very worried about not being prepared to address these security implications. Another threat of significance is that advanced attackers could conduct “harvest now, decrypt later” attacks, in which they collect and store encrypted data with the goal of decrypting the data in the future (74 percent of respondents). Despite these concerns, only 23 percent of respondents say they have a strategy for addressing the security implications of quantum computing.

The following findings illustrate the challenges organizations face as they prepare to have a safe post quantum computing future. 

Security teams must juggle the pressure to keep ahead of cyberattacks targeting their organizations while preparing for a post quantum computing future. Only 50 percent of respondents say their organizations are very effective in mitigating risks, vulnerabilities and attacks across the enterprise. Reasons for the lack of effectiveness is that almost all respondents say cyberattacks are becoming more sophisticated, targeted and severe. According to the research, ransomware and credential theft are the top two cyberattacks experienced by organizations in this study.

The clock is racing to achieve PQC readiness. Forty-one percent of respondents say their organizations have less than five years to be ready. The biggest challenges are not having enough time, money and expertise to be successful. Currently, only 30 percent of respondents say their organizations are allocating budget for PQC readiness. One possible reason for not having the necessary support is that almost half of respondents (49 percent) say their organization’s leadership is only somewhat aware (26 percent) or not aware (23 percent) about the security implications of quantum computing. Forty-nine percent of respondents are also uncertain about the implications of PQC.

Resources are available to help organizations prepare for a safe post quantum computing future. In the last few years, industry groups such ANSI X9’s Quantum Risk Study Group and NIST’s post-quantum cryptography project have been initiated to help organizations prepare for PQC. Sixty percent of respondents say they are familiar with these groups. Of these respondents, 30 percent say they are most familiar with the ANSI X9’s Quantum Risk Study Group and 28 percent are most familiar with NIST’s industry group.

Many organizations are in the dark about the characteristics and locations of their cryptographic keys. Only slightly more than half of respondents (52 percent) say their organizations are currently taking an inventory of the types of cryptography keys used and their characteristics. Only 39 percent of respondents say they are prioritizing cryptographic assets and only 36 percent of respondents are determining if data and cryptographic assets are located on-premises or in the cloud.

Very few organizations have an overall centralized crypto-management strategy applied consistently across the enterprise. Sixty-one percent of respondents say their organizations only have a limited crypto-management strategy that is applied to certain applications or use cases (36 percent) or they do not have a centralized crypto-management strategy (25 percent).

Without an enterprise-wide cryptographic management strategy organizations are vulnerable to security threats, including those leveraging quantum computing methods. Only 29 percent of respondents say their organizations are very effective in the timely updating of their cryptographic algorithms, parameters, processes and technologies and only 26 percent are confident that their organization will have the necessary cryptographic techniques capable of protecting critical information from quantum threats.

While an accurate inventory of cryptographic keys is an important part of a cryptography management strategy, organizations are overwhelmed keeping up with their increasing use. Sixty-one percent of respondents say their organizations are deploying more cryptographic keys and digital certificates. As a result, 65 percent of respondents say this is increasing the operational burden on their teams and 58 percent of respondents say their organizations do not know exactly how many keys and certificates they have.

The misconfiguration of keys and certificates and the ability to adapt to cryptography changes prevents a cryptographic management program from being effective. Sixty-two percent of respondents say they are concerned about the ability to adapt to changes in cryptography such as algorithm deprecation and quantum computing. Another 62 percent are concerned about the misconfiguration of keys and certificates. Fifty-six percent are concerned about the increased workload and risk of outages caused by shorter SSL/TLS certificate lifespans.

To secure information assets and the IT infrastructure, organizations need to improve their ability to effectively deploy cryptographic solutions and methods. Most respondents say their organizations do not have a high ability to drive enterprise-wide best practices and policies, detect and respond to certificate/key misuse, remediate algorithm remediation or breach and prevent unplanned certificates.

Crypto Centers of Excellence (CCOEs) can support organizations’ efforts to achieve a safe post quantum computing future. A CCOE can help improve operational cryptographic processes and increase an organization’s trust environment. They do require advanced technologies and expertise in cryptography to maintain secure operations and comply with applicable regulations. Most organizations in this research do plan on having a CCOE. However, currently only 28 percent of respondents say their organizations have a mature CCOE that provides crypto leadership, research, implementation strategy, ownership and best practices. Another 28 percent of respondents say they have a CCOE, but it is still immature.

Hiring and retaining qualified personnel is the most important strategic priority for digital security (55 percent of respondents). This is followed by achieving crypto-agility (51 percent of respondents), which is the ability to efficiently update cryptographic algorithms, parameters, processes and technologies to better respond to new protocols, standards and security threats, including those leveraging quantum computing methods.

 To read the key findings in this report, click on DigiCert’s website

Robot fear is approaching 1960s-levels; that might be a distraction

Bob Sullivan

When I logged onto a Zoom meeting recently, I was offered the chance to let the company use some kind of whiz-bangy AI magic that would summarize the meeting for me.  Cool? Maybe. Artificial intelligence? Not by my definition. New? Not really.  New name? Absolutely

I’m sure you’ve had this experience a lot lately.  “AI-powered” marketing-speak is everywhere, sweeping the planet faster than dot com mania ever did.  In fact, it’s come so fast and furious that the White House issued an executive order about AI on Monday. AI hasn’t taken over the planet, but AI-speak sure has. It’s smart to worry about computers taking over the world and doing away with humanity, but I think marketing hype might be AI’s most dangerous weapon.

Look, chatbots are kind of cool and impressive in their own way. New?  Well, as consumers, we’ve all been hijacked by some “smart” computer giving us automated responses when we just want a human being at a company to help us with a problem. The answers are *almost* helpful, but not really.  And chatbots … are…not really new.

I like to remind people who work in this field — before “the Cloud” there were servers.  Before Web 3.0 there was the Internet of Things, and before that, cameras that connected to your WiFi.  Before analytics, and AI, there was Big Data.  Many of these things work better than they did ten or twenty years ago, but it was the magic label — not a new Silicon Valley tech, but a new Madison Avenue slogan — that captured public imagination.  Just because someone calls something AI does not make it so.  It might just be search, or an updated version of Microsoft Bob that isn’t terrible.

I don’t at all mean to minimize concern about tech being used for evil purposes.  Quite the opposite, really. If you read the smartest people I can find right now, this is the concern you’ll hear.  It’s fine to fret about ChatGPT Jr., or ChatGPT’s evil half-brother, making a nuclear bomb, or making it substantially easier to make a nuclear bomb. We’ve been worried about something like that since the 1950s and 60s.  And we should still be concerned about it. But that’s not happening today.

Meanwhile, tech (aka “AI”) is being used to hurt people right now. There’s real concern all the focus on a sci-fi future is taking attention away from what needs to be done to reign in large technology companies right now.

Big databases have been used to harm people for a long time.  Algorithms decide prison sentences — often based on flawed algorithms and data.  (Yes, that is real!) Credit scores rule our lives as consumers. The credit reports on which they are built are riddled with errors. And as people seem to forget, credit scores did virtually nothing to stop the housing bubble.  I just read that credit scores are at an all-time high, despite the fact that consumer debt is at very high levels — and, in a classic toxic combination — interest rates are also very high. So just how predictive are credit scores?

I know this — Folks looking to regulate AI/Big Data/algorithmic bias haven’t done nearly enough research into the decades-long battle among credit reporting agencies, consumer advocacy groups, and government regulators.  Hint: It’s not over.

There is a lot to like in the recent AI executive order.  I’ve long been an advocate that tech companies should include “abuse/harm testing” into new products, the way cybersecurity teams conduct penetration testing to predict how hackers might attack. Experienced, creative technologists should sit beside engineers as they dream up new products and ponder: “If I were a bad person, how might I twist this technology for dark uses?”  So when a large tech firm comes up with a great new tool for tracking lost gadgets, someone in the room will stop them and ask, “How do we prevent enraged ex-partners from using this tech to stalk victims?” Those conversations should be had in real-time, during product development, not after something is released to the world and is already being abused.

Today’s executive order calls for red-teaming and sharing of results with regulators.   In theory, such reports would head off a nuclear-bomb-minded bot at the pass.  Good.  I just hope we don’t race past algorithmic-enhanced racial discrimination in housing decisions — which happens today, and has been happening for decades.

The best piece I read on the executive order appeared in MIT Technology Review — a conversation with Joy Buolamwini, who has a new book out titled  Unmasking AI: My Mission to Protect What Is Human in a World of Machines.  She’s been ringing the alarm bell on current-day risks for nearly a decade

For something that’s a more direct explanation of the order, read this piece on Wired.  

This is a link to the White House fact sheet about the executive order. 

 

 

 

Cost Of Insider Risks Global Report — 2023

Ponemon Institute is pleased to present the findings of the 2023 Cost of Insider Risks: Global study. Sponsored by DTEX, this is the fifth benchmark study conducted to understand the financial consequences of insider threats caused by careless or negligent employees or contractors, criminal or malicious insiders or credential thieves.  As revealed in this research, organizations face increasing costs to respond to insider security incidents. Moreover, the time to contain an incident has not improved  — it takes an average of 86 days to contain. In 2022 the time to contain the incident was 85 days. Only 13 percent of incidents were contained in less than 31 days.

This cost study is unique in addressing the core systems and business process-related activities that drive a range of expenditures associated with a company’s response to insider negligence and criminal behaviors. In this research, we define an insider-related incident as one that results in the diminishment of a company’s core data, networks or enterprise systems. It also includes attacks perpetrated by external actors who steal the credentials of legitimate employees/users (i.e., imposter risk).

The first study was conducted in 2016 and focused exclusively on companies in North America. Since then, the research has been expanded to include organizations in Europe, Middle East, Africa and Asia-Pacific with a global headcount of 500 to more than 75,000. In this year’s study, we interviewed 1,075 IT and IT security practitioners in 309 organizations that experienced one or more material events caused by an insider. A total of 7,343 insider incidents are represented in this research.

The most prevalent insider security incident is caused by careless or negligent employees.

According to the findings, 55 percent of incidents experienced by organizations represented in this research were due to employee negligence and the average annual cost to remediate these incidents was $7.2 million. Not as frequent are incidents involving criminal or malicious insiders (25 percent of incidents) and credential theft (20 percent of incidents). However, the average cost per these incidents are more costly at $701,500 and $679,621, respectively.

As shown in this research, the cost of insider risk varies significantly based on the type of incident. The activities that drive costs are monitoring & surveillance, investigation, escalation, incident response, containment, ex-post analysis and remediation.

The following are the most salient findings from this research.

 The negligent insider is the root cause of most incidents. The average number of negligent insider incidents is 14 in this year’s study. There are a variety of reasons employees can put their organizations at risk. These include not ensuring their devices are secured, not following the company’s security policy, forgetting to patch and upgrade to the latest version.

 Malicious insiders accounted for an average of 6.2 incidents and the average cost per incident of $701,500.  In the context of this research, malicious insiders are employees or authorized individuals who use their data access for harmful, unethical or illegal activities. Because of their potentially wider access to an organization’s sensitive and confidential data, malicious insiders are harder to detect than incidents caused by external attackers or hackers.

 Credential theft incidents average $679,621 per incident. The intent of the credential thief is to steal users’ credentials that will grant them access to critical data and information. These attackers commonly use phishing.

 Insider security incidents are increasing.  According to the 2023 research, 71 percent of companies are experiencing between 21 and more than 40 incidents per year. This is an increase from 67 percent in 2022 of companies having between 21 and more than 40 incidents.

Privileged access management (PAM) and user training and awareness are shown to reduce the cost of insider risk. The research analyzed the impact security technologies and activities can have on reducing costs. PAM can save an average of $5.9 million. User training and awareness programs can save $5.4 million and SIEM reduces the cost by $4.3 million.

Disruption or downtime and direct and indirect labor represent the most significant costs when dealing with insider threats. Investments in technology, which includes the amortized value and licensing for software and hardware that are deployed in response to insider-related incidents is the third most significant cost.

Companies spend the most on containment of the insider security incident. An average of $179,209 is spent to contain the consequences of an insider threat. The least amount of average cost is for escalation $29,794 and monitoring and surveillance is $33,596. Incidents that took less than 30 days to contain had the lowest average total cost of activities at $11.92 million. In contrast, average activity costs for incidents that take more than 90 days is $18.33 million.

North American companies are spending more than the average cost on activities that deal with insider threats. The total average cost of activities to resolve insider threats over a 12-month period is $16.2 million. Companies in North America experienced the highest total cost at $19.09 million. European companies had the next highest cost at $17.47 million.

Financial services and services have the highest average activity costs. The average activity cost for financial services is $20.68 million and services is $19.63 million.

Organizational size affects the cost. The cost of incidents varies according to organizational size. Large organizations with a headcount of more than 75,000 spent an average of $24.60 million over the past year to resolve insider-related incidents. To deal with the consequences of an insider incident, smaller-sized organizations with a headcount below 500 spent an average of $8 million.

Interviews with participants in this research revealed the following insights into insider threats.

In addition to determining the cost of insider threats for companies in this research, we interviewed participants about their experiences with the threat and what they are doing to reduce risks.

The insider threat continues to pose the greatest threat to organizations. Fifty-five percent of insider risks were caused by employee negligence. Of these organizations, 75 percent of respondents say the most likely cause of insider threat is a negligent insider who caused harm through carelessness or inattentiveness (15 percent), a mistaken insider who caused harm through a genuine mistake (35 percent), or an outsmarted insider who was exploited by an external attack or adversary (25 percent).

Sales and customer service are the roles or function that poses the greatest insider risks (48 percent and 47 percent, respectively). Functions that pose the least risk are IT and legal third-party contractor, 23 percent and 29 percent, respectively).

Malicious insiders were most likely to email sensitive data to outside parties (67 percent). They are also very likely to access sensitive data not associated with the role or function (66 percent) and scanning for open ports and vulnerabilities (63 percent).

Cloud and IoT devices are most likely to be the channels where insider-driven data loss occurred (59 percent and 56 percent, respectively. Less likely are corporate-owned endpoint (41 percent) and BYOD endpoints (43 percent). IoT and cloud are the channels organizations are of most concern (65 percent and 61 percent, respectively).

Malware and social engineering attacks were most likely to cause a non-insider attack that caused a data breach 56 percent and 53 percent, respectively. In the past 12 months, 58 percent of organizations had a minimum of two non-insider attacks which caused a data breach. Malware is considered the most important attack to prevent (65 percent of organizations).

More organizations believe the use of AI and machine learning is important to reducing insider threats.   Sixty-four percent of respondents believe AI and machine learning is essential (33 percent) or very important (31 percent) to preventing, investigating, escalating, containing and remediating insider incidents. This is a significant increase from 54 percent of organizations in 2022. Sixty-one percent say automation is essential (38 percent) or very important (23 percent) to managing insider risks.

Reduction in incidents is the top metric for measuring the success of insider risk efforts and programs (50 percent). This is followed by assessment of insider risks (40 percent) and length of time to resolve the incident (38 percent)

Five signs that your organization is at risk

  • Employees are not trained to fully understand and apply laws, mandates, or regulatory requirements related to their work and that affect the organization’s security.
  • Employees are unaware of the steps they should take at all times to ensure that the devices they use—both company issued and BYOD—are secured at all times.
  • Employees are sending highly confidential data to an unsecured location in the cloud, exposing the organization to risk.
  • Employees break your organization’s security policies to simplify tasks.
  • Employees expose your organization to risk if they do not keep devices and services patched and upgraded to the latest versions at all times.

To read the full report, visit the DTexSystems.com website.

A warning from historians: AI is going to create a lot of ‘sh*& jobs’

Bob Sullivan

We’ve all had the maddening experience of being shuttled off to a mindless chatbot when we need real customer service help. Few things can raise your blood pressure like a nonsensical automated response designed as a stall tactic when you have a real crisis on your hands.

I hope you all realize this is the world we are hurling madly towards with all the mindless promotion of AI we’ve seen lately. Since the advent of automated voice response systems, consumers have been swearing into their phones while corporations have engaged in a cynical race to the bottom. Make cost centers like customer service cheaper, and profits increase. Make consumers capitulate because of artificial, frustrating hurdles, and profits increase. That’s unchecked, broken-market capitalism in action.  Gotcha Capitalism, fueled by bots.  That’s not an opinion, it’s a fact.  Take a flight pretty much anywhere in America now and you’ll see what Big Data, and advanced analytics, and AI, or whatever other fancy tech marketing term you throw at it, has done to us. The race to the bottom is so real that we’ve become numb even to airline crash near-misses.

And so I want to talk today about another crash-landing that’s coming – one that’s predictable, but preventable if we act.

A billion useless people.

Yes, AI is coming for our (good) jobs. And no, despite what some ivory tower economists like to say, it’s not a given that we’ll simply replace those jobs with even better jobs.

A billion useless people was the headline of one of my favorite stories . In it, I discussed a simple dinner-party question: What job do you hope your son or daughter trains for? At least if your sensible parental goal was a comfortable life, that would have been a fairly easy question to answer a generation ago or so, but today? Doctor? Lawyer? Pilot? Professor? Software engineer? Ask a few of them and you might be surprised.

The real cause of tension should be a wide-ranging study conducted by Oxford University I wrote about in a similar piece. The study ranked 700 jobs in terms of their potential for automated replacement or “computerization.” How likely is this kind of worker to be replaced by a robot?  The results were stunning.  Many people like to think fast food workers have the most to lose from robots. In reality, it might be lawyers.  Plenty of today’s high-paying, white-collar jobs are filled with rote tasks that robots are very good at.  Knowledge workers have long convinced themselves they aren’t as replaceable as hamburger chefs. They’re wrong. If you’ve ever been bored at work, there’s a robot coming for your job.

On a micro scale, you should feel personally threatened. On a macro scale, this is a real threat to social order.  A billion useless people are going to get very angry, and the resulting unrest should scare everyone.  We must start thinking now about what to do with people when a large percentage of adults don’t have anything productive to do with their lives.

I wrote all that seven years ago, before ChatGPT was a twinkle in a programmer’s eye. Maybe you think I’m exaggerating, but Goldman Sachs published a report earlier this year estimating that “generative AI could expose the equivalent of 300 million full-time jobs to automation.”

So, this concerning future is coming — fast.  CNBC published a story this week with similar speculation about the future of the job market, and I recommend you read it.  There are some great comparisons in the story from labor market historians. Sure, there will still be some kind of higher-order jobs in a world of AI — someone has to “prompt” ChatGPT, right? — but the scale of job destruction could be immense.  Here’s one comparison offered by  Felix Koenig, assistant professor of economics at Carnegie Mellon University: Just about 100 years ago, audio tracks were introduced into silent movies, putting a generation of local musicians out of work — until then, orchestras would accompany the moving pictures.  Once “talkies” were invented, a single musician could play a soundtrack, that audio could be recorded, and replayed millions of times in theatres around the world — eliminating 99.9% of the jobs for movie musicians.  That one musician is still paid pretty well, but the rest are now out of luck.

And so it will be with AI. On the one hand, there will be a race to get a plumb job as a robot programmer. There could be a few big winners and then a lot of losers. Our economy currently favors that structure, and this is a great risk.

What worries me more is that people will be left to do jobs that are considered too expensive for robot labor.  Garbage collection in messy cities, for example.  Or maybe flipping hamburgers. After all, robots require free health care — they have to be repaired. People don’t. Let’s just call them “sh&t jobs,” which is what Jason Resnikoff, history professor, told CNBC.

This future is not yet written.  Yes, in the past society endured — thrived, really — when physically challenging farm jobs turned into urban paper-pushing jobs.  That kind of retraining doesn’t happen by accident, however.  In between those two events in America, we created a thriving college system and passed the GI Bill so millions could be trained without going into debt.  Today, such a massive initiative seems out of the question.

I believe the coming future offers great possibilities. I think the future will bring revenge of the artists, and revenge of the caring souls.  AI will not create great original art (though it will certainly rip off existing art).  And it will not inspire people recovering from strokes to endure the challenges of physical therapy. Therapists and artists have a bright future. Human inspiration and originality might finally gets its just rewards.  That’s what the Oxford study suggested.

But not everyone can do those things. And we must prepare now for this reality.  AI is as much hype as it is reality — everytime you hear AI, just think “Cloud” or “Internet 3.0” or whatever marketing term you like. But one thing will happen, I promise: corporations will figure out how to drive costs down in the name of artificial intelligence, and the race to the bottom will continue unabated, unless we do something to stop it.  Airlines will keep ripping off consumers until there are rules against it, and until there is real competition.  TV studios will generate boring shows based on search queries unless creativity is protected by labor rules. And so on.

Each time you have an insane interaction with an automated customer service tool, you are seeing a glimpse of the future.  Trust me, this is a future we want to stop before it’s too late.