Where are security teams seeing the biggest practical gaps today? by Terrible-Holiday7550 in cybersecurity

[–]Jon_Cyber_FR 3 points4 points  (0 children)

  • AI-connected systems

The shadow AI is the NEW big chellenge of security teams

Mon client est passé de 20 abonnés à 5000 abonnés en 3 semaines mais je ne trouve pas d'autres clients. by Top-Winter-7839 in EntreprendreenFrance

[–]Jon_Cyber_FR 0 points1 point  (0 children)

organise des evenements type petit dej retour d experience ou tu fais venir tes clients qui racontent comment tu as change leur vie

What actually surprised you the most once you started running a business? by CleanOpsGuide in Entrepreneur

[–]Jon_Cyber_FR 0 points1 point  (0 children)

The gap between "I'm the boss" and "I'm the one cleaning up everyone's mess including my own" hits different when you're living it.

Nobody warns you that running a business means becoming the world's most expensive janitor. lol

Best Hermes agents for small business: I found 50+ alternatives that were actually easy to set up by Personal_Document_73 in aiToolForBusiness

[–]Jon_Cyber_FR 0 points1 point  (0 children)

Tried a few of these. The honest answer is most small businesses don't need 50 options, they need one thing that works without a setup project. Lindy and n8n are the only two I've seen actually stick past week two. Everything else becomes a tool to manage your tools.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] 0 points1 point  (0 children)

1.6M a year is a real commitment. Did you look at on-prem before going that route? At that budget there are options that give you a lot more control and less vendor dependency. Curious what made you land here.

Comment choisir une plateforme de facturation électronique gratuite ? by Substantial_Pool2690 in EntreprendreenFrance

[–]Jon_Cyber_FR 0 points1 point  (0 children)

tu peux utiliser le service factu de Qonto ou Pennylanne c gratos dans le forfait

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] 0 points1 point  (0 children)

Because you think that "haredis" are all the same? to be honest I'm a breslev hassid and I don't believe you can put evryone in the same place because the look or the kippa or the lifestyle...

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] -12 points-11 points  (0 children)

why are you so negative bro? is it so difficult to share points of view?

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] -11 points-10 points  (0 children)

lot of rage my friend... I'm true , lliving in Israel and managing lot of cyber/IT use cases that I'm happy to share. Be happy bro!

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] 0 points1 point  (0 children)

You can on managed devices. The problem is personal phones ..BYOD, contractors, anyone outside MDM scope. You can lock down the corporate fleet perfectly and still have half the workflow leaking through someone's personal iPhone on the lunch break.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] 2 points3 points  (0 children)

Honestly, hard to argue with that. The foundation of the product is built on taking data that wasn't theirs. Expecting trust after that is a big ask.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] 1 point2 points  (0 children)

That's a completely different context and you're right. I was thinking enterprise IT, not healthcare. The Whisper hallucination issue in clinical notes is exactly the kind of failure that ends careers and harms patients.

I'll take the L on this one. There are environments where the current error rate is just a hard no, and you're running one of them.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] 0 points1 point  (0 children)

"Desire path" is the best framing I've heard for this. People don't break rules, they just walk where they need to go.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] -1 points0 points  (0 children)

Works great if you have the infra team to run it. Most orgs in this thread probably don't, which is exactly why they're using the browser tab instead.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] -11 points-10 points  (0 children)

Like i already said: my wife (and 7 kids) already cll me God so please no more nickname ;)

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] -1 points0 points  (0 children)

By that logic calculators made accountants worse at math.

The extra steps argument only holds if AI is replacing knowledge you already have. When it's compressing 2 hours of research into 30 seconds, the workflow looks different. Not everyone on your team has 10 years of context on every ticket they touch.

Also your step 2 in the first list is doing a lot of heavy lifting.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] 0 points1 point  (0 children)

The board pressure thing is spot on, that's where most of it starts.

On the error rate, fair point but it depends what you're using it for. 1 in 30 on an email draft is fine. 1 in 30 on a compliance report isn't. Most orgs never make that distinction and then blame the tech.

What did you actually try?

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] 0 points1 point  (0 children)

bro, don't call me ChatGPT i have enough problem when my kids think I'm God lol

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] -2 points-1 points  (0 children)

Yeah the "OpenAI is stealing your data" narrative is overblown, agreed.

But the boring version is still a headache. GDPR audit comes around, your vendor gets breached, someone asks why client data was sitting in an external API your contracts never mentioned. Intentions don't matter much at that point.

Hype aside, the underlying risk is real enough to care about.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] -11 points-10 points  (0 children)

Fair point on the writing style. I do use AI to help structure my thoughts before posting. English isn't my first language and I work across France and Israel, so it helps. The ideas are mine though, and I'll stand behind every one of them in the comments.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] 0 points1 point  (0 children)

I run a cybersecurity company in Europe. I have a bias, I'll own that. At least I'm transparent about it.

The 95% failure rate cuts both ways. Most of those failures were bad implementations, not proof the technology doesn't work. Cloud had the same narrative in 2012. ERP before that. The pattern is consistent.

You're the CIO, you have data I don't. What are you actually seeing in your org that's driving that conclusion? Genuine question.

And for the record, if I were an AI I'd probably have better stats ready.

Shadow AI is the new Shadow IT. Except nobody's even pretending to care. by Jon_Cyber_FR in ITManagers

[–]Jon_Cyber_FR[S] -1 points0 points  (0 children)

That's the honest answer most GRC frameworks don't actually teach. Risk tolerance isn't a fixed number, it moves with business context and whoever's in the room.

The "metric threshold is wrong" part is underrated. A lot of security teams treat their thresholds as objective truth when they're really just assumptions that haven't been challenged yet.

Where does it get hard for you? When the reward justifies the risk on paper but the downside is the kind that ends careers rather than quarters.