The cybersecurity landscape has changed significantly in the past couple of years due primarily to the maturation of artificial intelligence models. Threat actors have leveraged AI models to expose vulnerabilities and infiltrate networks faster while improving the sophistication of phishing attempts and credential harvesting.
An alarming example of this is that researchers using a powerful AI model were able to crack years-long security measures within a few days. Data loss prevention is a multi-pronged effort that involves both technology departments in general and each of us as end-users of computing devices.
Individual access to sensitive information is a key factor in data loss, whether in the form of a data breach or a data leak.
Data breaches
A data breach is when a threat actor gains unauthorized access to sensitive information, typically by infiltrating a device or network. One of the most common methods of initial exploitation is social engineering via phishing attacks to harvest credentials and access end-user devices.
Another highly common method of entry is through unpatched, therefore vulnerable, hardware and software platforms. A sharp increase in zero-day vulnerabilities (hardware and/or software that is actively exploited before a patch for the vulnerability is available) has been noted over the past few years, partly driven by the increased use of AI models in engineering attacks.
These two problems—weak or stolen credentials and unpatched systems—are often used in conjunction to gain access to sensitive information. As a matter of note, there has also been an increase in supply chain compromises, whereby a breach of one software system used by an organization leads to the breach of another system within the same organization.
Prevention measures
- Use passwords that are lengthy, complex, randomly generated, and are not duplicated or reused. A password manager platform can assist with all these metrics and store passwords securely.
- Use and/or implement single sign-on when it is available. Additionally, enable and use multi-factor authentication on any platform that supports it.
- Install security patches when available. When your operating system prompts you to restart,do so as quickly as possible.
- Phishing recognition is paramount. Do not engage in emails or texts from unknown or unverified users. Never click links or input credentials.
Data leaks
A data leak is when an end-user unintentionally exposes sensitive information, typically by sharing data in an unsecure or unsafe manner. A common exposure occurs via cloud-based document storage providers and the ability for individuals to share those documents with other internet-connected users.
An increasingly common exposure risk is AI chatbots that use provided data to grow and trainv a large language model. Several of these chatbots may meet privacy policies for logged-in users, while not protecting information willingly given to the chatbot.
Another common issue is sensitive information being relayed via email, as there is a notable difference between encryption in transit and encryption at rest. Potentially less common but high-risk nonetheless are A.) connecting to unencrypted, public Wi-Fi networks while working with sensitive information and B.) storing sensitive information on local devices or external drives.
Prevention measures
- Minimize the use of individualized sharing permissions in cloud-based storage platforms and avoid sharing to “anyone with the link.” When multiple documents need sharing with multiple users, create a shared space where permissions can be set once to avoid oversharing to the internet at large.
- Use AI chatbots appropriate for and contained within your work domain (e.g. Gemini or Copilot) as opposed to using chatbots that use your data to grow their LLM.
- Emails containing sensitive information should have added encryption via the email platform or a third-party platform that is company-provided.
- Avoid connecting to public Wi-Fi networks; use a company VPN or a hotspot.
- Avoid storing sensitive information on your local or external storage devices.
- Do not share credentials or access codes, and do not write down passwords (use a password manager).
Data loss prevention
The human role in data loss prevention is critical, and understanding the difference between data breaches and data leaks can help ensure that preventative measures are implemented and maintained. A final recommendation is to maintain a clear separation of your work-related accounts and activities from your personal accounts and activities.
Technology departments must be intentional with implementations that can prevent exposure, while individuals must be diligent in recognition and cautious in the use and management of their access to sensitive information.
Every user granted access to any amount of sensitive information should follow basic policies and procedures to ensure a safe and secure environment that prevents data loss.





