Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Artificial Intelligence - Walking the AI Security and ROI Tightrope
Artificial Intelligence Articles Business and Policy Security

Walking the AI Security and ROI Tightrope

Joe LoganBy Joe LoganAugust 17, 20266 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Walking the AI Security
Share
Facebook Twitter LinkedIn Email Copy Link
AI Summary

This piece examines the tension between rapid AI innovation and the need for rigorous security and responsible use.

It offers guidance for leaders on defining use cases, managing risk, measuring ROI, and building the cultural foundations required to adopt AI safely and effectively.

Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Organisations across every sector are accelerating their adoption of generative AI, driven by board-level expectations for rapid innovation and measurable business value. Yet the same boards are equally insistent that AI initiatives must not compromise security, privacy, or regulatory compliance, and not lead to runaway cost. 

This dual mandate has placed CIOs and security leaders in a difficult position: they must move quickly enough to capture competitive advantage while ensuring that AI systems remain tightly governed, well-validated, and aligned with enterprise risk tolerance. Increasingly, these professionals need to find a way to effectively address both challenges at once – and successfully walk the AI security and ROI tightrope.

A minefield of risks to navigate

Today’s AI risks translate into an array of real-world consequences: corporate information leakage, regulatory penalties, reputational damage, contractual liability, and financial exposure.

One of the primary risks is an access management challenge: preventing sensitive information from reaching individuals or systems that should not have access to it. As organisations integrate generative AI into workflows, more data is transferred into AI platforms, creating additional exposure points. Each AI provider becomes another vendor whose controls, contractual commitments, and data-handling practices must be scrutinised.

The rise of agentic AI compounds these data security and privacy risks. Autonomous or semi-autonomous agents can perform tasks, trigger workflows, and access data without direct human oversight. This opens the door to unintended actions – an AI agent operating outside its scope or accessing restricted data – and these missteps can occur at unprecedented speed and scale.

Striking the right balance

The instinct to “lock everything down” in response to potential AI risk is understandable, but counterproductive. A system locked down to the point of impenetrability has no operational value. This is part of the security/ROI tightrope that must be walked and the balance that must be struck.

The right approach is to define AI use cases with great precision, and to understand what data each one requires. For both the organisation and individuals, this means drilling down on what information they absolutely need access to, down to the individual data element, and whether there’s a compelling business need for that access. It’s worth analysing whether the same workflow could be accomplished a different way, without access to that information.

In practice, organisations will likely want to default to “secure” for most AI use cases, and then deliberately determine what must be open and accessible rather than starting with accessibility and then trying to secure it after the fact.

Another part of the solution is creating a cultural shift within the organisation. Organisations need to foster a culture where employees are encouraged to use AI to explore better, faster, and more efficient ways of working – but to also use it thoughtfully and with sound judgment. The old cliches still apply: with great power comes great responsibility.

To help create a culture of responsibility, organisations should make it easy for their end users to “do the right thing” and harder for them to “do the wrong thing”. For instance, providing an enterprise-licensed AI platform encourages employees to stay within approved systems and reduces the likelihood they’ll turn to unsanctioned tools – lowering the chance of shadow AI. 

A framework for measuring success

Concurrent with addressing security concerns, leaders can focus on the ROI side of the equation. Measuring that ROI can be challenging – but fortunately, the upfront work on defining use cases pays dividends on this front as well.

Organisations should define use cases with explicit expectations for cost savings, productivity gains, or other measurable outcomes. If you don’t define what success looks like, you can’t judge what kind of return on investment you received.

Once those success criteria are established, the path forward inevitably involves experimentation, and not every effort will deliver equal returns. There will be successes as well as projects that don’t pan out. 

Identifying the bright spots – the AI use cases that deliver real value and can be replicated across the organisation – accelerates adoption and lifts overall productivity. Just as important is learning from the efforts that don’t deliver as expected. Those outcomes provide the insight needed to refine assumptions, sharpen priorities, and redirect resources.

Early use cases may require meaningful time and attention as employees learn new tools, but the learning curve shortens quickly. Over time, the wins compound, the missteps become instructive rather than costly, and the organisation grows more adept at spotting high value applications.

Keeping an eye on cost

While they’re focusing on ROI, organisations will want to pay attention to one of the elephants in the room when it comes to AI: the compute cost. Each AI interaction consumes tokens, which translate directly into energy usage and financial cost. 

Organisations can reduce waste by educating employees on effective prompting, selecting the right model for the right task, and leveraging in-memory context to minimise unnecessary iterations. 

These practices mirror simple energy-saving behaviours – like turning off lights when leaving a room – but applied to AI usage. Just as on the security front, this educational component and cultural shift can go a long way towards moving ROI in the right direction. Otherwise, organisations might risk seeing the productivity gains on one side of the ROI ledger being nullified by an enormous AI token consumption expense on the other.

A little discernment goes a long way

As AI becomes more deeply embedded in organisational life, discernment is rapidly emerging as one of the most consequential leadership competencies of the AI era.

Discernment means the ability to pause and assess: What are the risks with a particular AI usage? What could go wrong? What does success look like and how can we best position ourselves to build on that success? What are the potential costs or expenses – and are there ways for us to optimize around those factors so that our overall ROI isn’t impacted? 

The security/ROI tightrope is not going away. But with the right approach and a discerning mindset, it is entirely possible to walk it with confidence, enabling organisations to move fast with AI without compromising the business or its reputation.

Joe Logan
Joe Logan

Joe Logan is Chief Information Officer at iManage. He is responsible for the alignment of security, data engineering, and IT, at the company.

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Fake evidence: How generative AI is changing fraud capabilities

    August 14, 20264 Mins Read

    AI-assisted software engineering is creating a new delivery paradox

    July 10, 20267 Mins Read

    What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors

    June 19, 20266 Mins Read
    ISB-Bora-Side-Bar

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}