enterprisesecuritymag

GenAI usage is up. Productivity is elusive.

Enterprise Security Magazine | Monday, August 24, 2026

Is your organization actually more productive?

Most organizations have an idea who's using GenAI but struggle to assess whether employees are using it effectively or generating measurable business impact.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

Join us for our Driving GenAI Effectiveness with Productivity-First Governance webinar to learn the strategies leading organizations are using to safely and effectively scale enterprise GenAI.

During this session, you'll learn:

• The latest enterprise GenAI usage and effectiveness benchmarks

• How to govern innovative MCP/Connector apps such as Claude Cowork

• How to get visibility into the activities of the heaviest users of tokens

• Best practices for implementing productivity-first governance

• A brief demonstration of the NROC Security solution

Register today and learn about the metrics that matter most for measuring GenAI effectiveness and governance strategies that will increase personal productivity AI.

Date: Tuesday, September 22nd

Time: 10:00 am PT | 12:00 pm CT | 1:00 pm ET | 6:00 pm GMT | 8:00 pm EET

Speakers: Larry Bianculli, Managing Partner, Cibernetica Group, Antti Reijonen, Co-Founder and CEO, NROC Security

Register now: https://us06web.zoom.us/webinar/register/WN_CpAL3Kn5RqCJ7xen7EeqWw

More in News

Data sits at the center of modern business. Customer records, financial information, intellectual property and operational data move through systems every day, supporting decisions and keeping organizations running. Protecting that information is no longer only an IT responsibility. It has become part of maintaining trust and business continuity. Data security covers the practices and technologies used to protect information from unauthorized access, misuse, alteration or loss. It includes access controls, encryption, monitoring, identity management, backup strategies and governance. The challenge is becoming more complicated as organizations adopt cloud services, connected applications and remote work environments. Information can now move across multiple systems and locations, making it harder to understand where sensitive data resides and who can access it. For organizations across Latin America, strengthening data security also means accounting for different regulatory environments, business practices and levels of digital maturity. A practical security strategy needs to work within the realities of the organization rather than simply add another layer of technology. Data Visibility Becomes the Starting Point Organizations cannot protect information they cannot properly identify. Understanding what data exists, where it is stored and how it moves through the business is becoming an essential part of security planning. Data discovery and classification can help organizations distinguish sensitive information from less critical records. This allows security teams to focus controls and resources where they matter most. Access management is equally important. Employees, contractors and third-party partners may all require access to business systems, but not everyone needs the same level of access. A least-privilege approach can reduce unnecessary exposure by giving users only the permissions required for their roles. Regular reviews can also help remove outdated access when responsibilities change. These measures may sound basic, but they form the foundation of a stronger data security environment. Sophisticated security tools have limited value when organizations do not understand their data or control who can reach it. Cloud Adoption Changes the Security Equation Cloud computing has made it easier for organizations to access applications and scale digital services. It has also changed how security teams protect information. Data may now be distributed across cloud platforms, business applications and third-party services. Responsibility for protecting it can also be shared between the organization and technology providers. “Data security is increasingly connected to customer trust, regulatory responsibility and business continuity.” This makes configuration and governance particularly important. Misconfigured permissions, unnecessary access and poorly managed accounts can create openings that attackers may exploit. Organizations therefore need security practices that follow data wherever it resides. Traditional perimeterbased approaches are less suited to environments where users, applications and information are constantly moving. Identity has become an important part of this model. Strong authentication, appropriate permissions and continuous monitoring can help organizations maintain control across increasingly distributed environments. People Remain Part of the Security Strategy Technology can block many threats, but employees remain closely connected to data security. Phishing, weak passwords, accidental sharing and poor handling of sensitive information can create vulnerabilities even when technical controls are in place. Security awareness therefore needs to be part of everyday work. Employees should understand what information requires protection, how suspicious activity should be reported and why security policies matter. The most effective programmes tend to avoid treating employees as the problem. Instead, they make secure behavior easier to understand and incorporate into normal workflows. Security teams also need to work closely with business departments. Marketing, finance, human resources and operations may handle different types of sensitive information, each with its own risks. A shared understanding of data responsibility can make security more practical and easier to maintain. Resilience Matters Alongside Prevention Preventing unauthorized access is only one part of data security. Organizations also need to prepare for the possibility that an incident will occur. Backups, recovery procedures and incident response plans can help reduce disruption when information is lost, compromised or made unavailable. Recovery strategies need to be tested rather than left as documents that exist only for compliance purposes. Monitoring also plays an important role. Unusual login activity, unexpected data transfers and other abnormal behavior can provide early indications of a security problem. Artificial intelligence is increasingly being used to support this work. AI can help security teams examine large volumes of activity and identify patterns that may deserve attention. Human judgment remains essential. Security professionals need to determine whether an alert represents a genuine threat and decide how the organization should respond. Security Becomes Part of Business Strategy Data security is increasingly connected to customer trust, regulatory responsibility and business continuity. A security incident can affect more than systems. It can disrupt operations and damage relationships with customers and partners. This makes security a leadership issue as much as a technical one. Executives need visibility into the organization’s most important data, the risks surrounding it and the measures in place to protect it. Security should also be considered when new systems and services are introduced. Building protection into technology decisions from the beginning is generally more effective than attempting to address weaknesses after deployment. For organizations across Latin America, the path forward will depend on combining technology with sound processes and informed employees. No single security product can protect every piece of information or address every threat. Data security is becoming a continuous business discipline. Organizations that understand their information, control access, prepare for disruption and make security part of everyday decisions can create a stronger foundation for digital growth. As businesses become more dependent on data, protecting it becomes inseparable from protecting the business itself. ...Read more
Security operations in Canada are becoming more complex and interconnected as organizations aim to enhance the protection of people, property, and critical assets. While traditional guard duties are still relevant, technology also provides security teams with new tools to track activity, confirm incidents and react to new risks. Video surveillance has evolved from a mere recorder to a video surveillance system that can enable remote monitoring and smart detection. Mobile devices can also enable guards to communicate with control centers and to access incident history and operational instructions. How Are Canadian Security Teams Improving Real-Time Incident Response? Increased surveillance in large or busy facilities is changing with connected surveillance. Increased surveillance in large or busy facilities is changing with connected surveillance. The high-definition cameras can deliver more visual information, and analytics can detect specific activities and alert security staff members. Instead of the guards having to constantly monitor all cameras, technology can be used to focus on events that need a closer look. Human verification will continue to be critical, as alerts can be automated but need interpretation for actions taken. The mobile device is improving communication between guards and security coordinators. Assignments can be sent to the workers' smartphones and dedicated devices, and they can report incidents and share pertinent data from various locations. Digital reporting can provide a more consistent set of records with fewer handwritten records. Supervisors will be able to view information more efficiently and be alert to common problems that might mean changes to patrol routes or procedures. Geofencing and electronic patrol systems provide enhanced visibility into guard activities. Organizations can set up checkpoints and track completion of the patrol on connected devices. These can help through accountability and let the supervisors know if they're being done on the planned security activities throughout large properties. Which Technologies Are Reshaping Security Operations across Canada? Another sector is access control, which is also undergoing great technological advances. Integrated entry systems and biometric verification can help to control access to restricted areas. Access systems can be integrated with security monitoring systems to provide more context when an unusual entry attempt is made. Organizations can then use the access records and video evidence to investigate the event. Video analytics and pattern recognition are other means by which AI is making its way into security workflows. With the proper configuration, data and human oversight, these capabilities can be valuable in spotting unusual activity and prioritizing alerts. There is still a need for trained personnel in security teams to interpret situations and then act accordingly as per the security protocols. ...Read more
Cybersecurity leaders no longer evaluate multi-factor authentication as a narrow login control. It now sits at the center of trust because the network perimeter has been replaced by cloud applications, remote access, mobile users and third-party services. Attackers have adapted. Rather than defeating infrastructure directly, they target the human identity layer through phishing, fake websites, credential reuse, session interception and social engineering. AI has sharpened deception, weakening legacy assumptions about passwords, one-time codes and user vigilance. Traditional MFA can reduce some exposure, but it often preserves the weakness it is meant to protect. A password remains in the path, a user still has to recognize a fraudulent prompt, a code may still be entered into a hostile session and the burden of correctness often sits with the individual. For executives, this is not just a security design problem. It becomes a cost, productivity and confidence problem. Help desks carry reset volume, employees navigate repeated prompts, customers abandon frustrating processes and fraud teams absorb losses when authentication stops at login but fails to control sensitive actions after access is granted. The stronger path removes static credentials from daily use rather than hiding them behind more steps. It should make trust mutual, so the service proves itself to the user before the user approves the session. It should also extend beyond login, because access to payroll, funds transfer, privileged systems or sensitive records requires authorization tied to the verified person, not just an earlier sign-in. Biometric confirmation, device trust, cryptographic validation and context-aware checks matter most when they reduce the chance that a stolen credential, copied website or compromised session can become real damage. Adoption depends just as much on usability. Security teams have spent years asking users to remember, rotate, reset and protect secrets while interpreting security cues under pressure. That model does not scale across banking customers, public-sector users, field employees, shared workstations, legacy applications and VPN access. The right approach should simplify the act of proving identity, accommodate users with different levels of digital confidence and integrate across environments that cannot all be rebuilt. Simplicity is not softness. It is the discipline of reducing unnecessary steps while preserving proof, control and auditability. Executives should also look for coverage that matches enterprise reality. A solution that works only for new cloud applications can leave exposed systems behind. One that requires broad redesign can slow adoption. One that replaces a single password burden with multiple disconnected authentication paths can dilute governance. The benchmark is a consistent identity experience across cloud, desktop, VPN, legacy, shared and constrained environments, backed by implementation support that lets security leaders test, train and expand without disrupting users. Password Free emerges as the premier choice for organizations that want MFA to move from layered passwords toward true password elimination. Its differentiator is full duplex authentication, in which the service validates itself to the user before the user confirms identity through a matched image, short code and biometric approval. That design addresses phishing, imposter websites and one-way code entry. Its website scope reinforces the fit through passwordless authentication, Windows Hello extension and coverage across cloud, desktop, VPN, legacy, shared and air-gapped systems. For buyers prioritizing trust, broad reach and user simplicity, Password Free offers the clearest path forward. ...Read more
A board can receive a long vulnerability report and still lack an answer to the question that matters most. Which exposures can disrupt the business, and which deserve funding now? Security programs often accumulate scanners and assessments without resolving whether controls cover the full environment or materially reduce exposure. Cybersecurity consultancy has to close that gap before it adds more technical work. The buying decision is complicated by a crowded service menu. Penetration testing may be useful, but it is not a substitute for deciding whether identity controls or recovery planning deserve attention first. Without that prioritization, assessment activity can outpace risk decisions. Useful advisory work begins by mapping the business before prescribing an exercise. Infrastructure coverage matters, but conversations with finance, legal, technology and business owners can expose obligations that a system inventory misses. Contractual duties and regulatory requirements can change the priority of a weakness that looks routine in isolation. Threat modeling should connect plausible events to business impact rather than elevate every vulnerability equally. That gives executives a defensible basis for deciding where limited security budgets belong. Board reporting needs a different language from technical remediation. Vulnerability scores may help security teams order work, yet they rarely tell directors what a weakness could mean for revenue, service continuity, contractual exposure or customer commitments. A consultant should convert technical findings into business risk, then make the decision path visible. Risk registers become especially useful when management accepts exposure or delays remediation. The record preserves ownership and gives leadership something concrete to revisit rather than allowing unresolved findings to disappear into technical backlogs. “Outsourced CISO’s work converts technical findings into business risk and records accepted exposure in a risk register, giving leadership a clearer basis for security decisions.” Assessment depth should follow the problem, not the consultant’s service catalog. A vulnerability scan and a red-team exercise answer different questions. Cloud providers and external technology partners can also change where exposure sits, making a familiar assessment inadequate for the actual environment. Executives need advice on whether an assessment fits the risk, along with a realistic view of the effort required. Overspending on an elaborate exercise can be as unhelpful as running a light assessment against the wrong risk. The engagement model also has to fit staffing economics. A company may need senior security leadership every week without enough work or budget to justify a full-time CISO. Virtual leadership can address that gap if it preserves ownership between meetings and maintains follow-through when recommendations are not adopted. Culture matters here. Security advice that ignores how managers communicate or approve change can stall even when the technical recommendation is sound. Outsourced CISO fits that buying logic through a virtual CISO model that begins with stakeholder conversations and a broad review of the business environment. It maps business threats against systems and obligations, then helps determine which security assessment is appropriate rather than defaulting to a fixed exercise. Its work converts technical findings into business risk and records accepted exposure in a risk register, giving leadership a clearer basis for security decisions. The consultancy also extends this governance approach to AI agents by discovering their presence and maintaining records of each agent’s owner and authorized permissions. Changes outside those boundaries triggers alerts for review. For firms that need senior security judgment without a full-time hire, that combination makes Outsourced CISO a practical choice for ongoing cybersecurity guidance. ...Read more

Weekly Brief