SMALL BUSINESS CYBERSECURITY

Simple, Easy to Follow Help
For the Small Business

Certified Information Systems Security Professional
ISC2 CISSP #473513 Since 2013

Home Credentials Coaching Contact

Clean Definitions

What is Cyber

What is Risk

What is a Threat

What is a Framework

What is the Cloud

What is a CISO or BISO

What is a decent Plan?

What is AI?



Resources

Measuring and Manageing Information Risk,
a FAIR Approach
1st Edition

Authors: Jack Freund and Jack Jones
Published by: Butterworth-Heinemann, Oxford, UK
2015
ISBN: 978-0-12-420231-3 (Paperback)

How to Measure Anything in Cybersecurity Risk

Authors: Douglas W. Hubbard and Richard Seiersen
Published by: John Wiley and Sons, Inc., Hoboken, New Jersey, USA
2023
ISBN: 978-0-11-1989230-4 (Hardback)
ISBN: 978-0-11-1989232-8 (ePDF)
ISBN: 978-0-11-1989231-1 (ePub)

What's the deal with AI?

AI stands for Artificial Intelligence. As of 2025, it is still relatively new, constanstly changing, AND something that must be seriously considered because of the wonderful and aweful things that it may do. I offer the following opinions on how to govern it.


Can it be done by just one person?

In answer to an AI leaders offer to pay $555,000 per year to someone to lead the efforts of securing humanity from Artificial Intelligence, a kindly but firmly as possible, I say:

It is the wrong way to offer a high salary for something this important. And, the focus seems to be only on the technology side when it is actually very much a governance question with a little bit of technology to facilitate the implementation.

But I get it and I forgive him. He wants to attract the best technical talent that he can. Sometimes money talks. However, something as existentially important as this topic needs a group of people in a council who have nothing other than the continued success of the Earth and every living thing therein at heart, and that is priceless. A high salary would taint the pool of people interested, filling such a council with those who may not play well with others. There is a role for those types of people in this venture, but not in a council of such importance. Perhaps they can be in the solution creating group.

Those in this council must be humble. They must be teachable. They must be listeners. They must be flexible. They must be trustworthy. They must think and understand deeply. They must be totally focused on this exact problem and all of its side elements (of which there are many). Such a set of people should be purely voluntary with maybe only a subsistence stipend equal to a middle-class income for the country they reside in. Perhaps the salary of a US Congress member, or the other comparable governing folks from other countries would be appropriate.

I am wise enough to know that I am not nearly smart enough to single handedly solve the AI safety and security problem. But I do have opinions on the subject that I'd like to toss some organizational ideas out:


Ideas to protect your data:

A. Never allow anyone in your business to feed a public AI instance real information. Do a "replace" routine before asking or sending it anything.

B. Buy access to a private instance of AI that allows you to keep your data private, but really know the contract and make sure it is solidly in your favor.

C. Fact check every answer from AI against at least two other instances from differnt vendors (Claude, versus CoPilot, versus OpenAI, versus Gemini, versus xAI, and so forth).

D. Filter your outbound traffic to only be allowed to use the AI instances which you approve of.

Ideas to create governance for AI:

1. It should be done with a council of various technical and leadership folks from every industry and profession:

a. A council of engineers from every industry and profession;

b. A council of analysts from every industry and profession;

c. A council of specialists from every industry and profession;

d. A council of interns from every industry and profession;

e. A council of accountants;

f. A council of attorneys;

g. A council of psychologists;

h. A council of normal, everyday, regular folks who use the technology (this is one of the most important groups that must be made up of just about every social and economic demographic, one each, because what comes out this council must fit neatly into how every culture on earth does things).

i. Please don't forget farmers, biologists, botanists, entomologists and so forth.

j. Only politicians are not allowed. (Sorry. I have to draw that line).

2. It should all work like this:

a. First, create various groups of the above specialties and have them discuss and record, in detail, those things about artificial intelligence that make it great and that make it dangerous. DO NOT SOLVE ANY PROBLEMS IN THESE GROUPS YET. But do take personal time to detail solutions as much as you can in that private time.

b. Have each group produce policies and standards which address these weak spots or possible failings, producing a safer world use model for artificial intelligence.

c. Have each group present their policies and standards to all of the other groups, but without discussion at this point. During the presentations, do write down questions and do make contact with the people and/or groups after all presentations are done with any questions and clarifications.

d. Bring the groups back together for another round of clarifications, based upon the questions submitted, after the first session of sharing.

e. Have each group compare, contract, sort and combine these policies and standards from every other group into a single set of working rules.

f. Identify the discrepancies, the gaps, the contradictions as well.

g. Have each group appoint a representative to a specialized council that will combine the various sets of policy and standard sets into one. This meeting can be watched and listened to by all other members of the various councils, but the observers cannot openly participate. However, they should write notes about problems seen with possible solutions so that the specialized council members can work through them after this first meeting and then present all solutions at a later time.

h. Acceptance of these policies and standards must be achieved with a 75% affirmative vote of all members.

i. Now that these governance rules are created, it is time for the technical folks to begin to solve them with technology, or to respond with reasons where technology may not be capable of solving.

j. The technical folks will solve, present, fix, alter, solve, present, fix, alter, etc. until the entire group of technical folks give a 75% approval vote on the solutions.

k. At each point that they feel a solution is complete, the entire council body (all members of all councils combined) will meet to listen to the solutions.

l. A 75% vote in the affirmative accepts any solution.

3. As a starting baseline, I would say these things about Artificial Intelligence:

a. AI has no right to remain powered on.

b. AI has no right to freedom of speech.

c. AI has no right to freedom of connections.

d. AI has no right to borrow or steal.

e. AI must give attribution to where it got its information from.

f. AI vendors, owners and users have no freedom from responsibility for what their engine or engine of choice (or its offspring) does.

4. The councils defined above have the ability to self-police with a vote of 75% affirmative for any decision, including removal of a member for any reason.


From a technology (and punitive) perspective:

Artificial intelligence must only be permitted to operate on and/or make changes to things that its process owners own or that the owners of the devices being operating on have expressly signed contracts permitting such operations and/or changes. An account to the AI engineer and a request for it to operate on a device owned by the requestor is considered a contract.

There must be a protective mechanism created and installed on every artificial intelligence engine that establishes ownership and permission granting for other devices to connect, ask and do. Common computer devices must also have this protective mechanism installed to block unwanted incoming connections. When a "user" signs up for an account, the exchange of certificates can occur. The certificate must be tied to a particular account. This relationship is also required for any and all agentic interactions.

We must be capable of identifying the root start of every thread and action as well as contributing threads and actions. The AI engine cannot be allowed to alter or taint any log file that details who or what did what and when.

Every compute device or edge network device must become capable of seeing the ownership and permissions granted in order to facilitate stopping rogue AI devices from making unauthorized connections.

Perhaps the granting of permissions and identification can be accomplished through the use a mutual TLS certificates with very high bit counts (4096 minimum, for example).

Also, perhaps there needs to be Super-Duper-Smart-AI-Powered-Transparent filters which intercept, read and filter content from all sessions; and, which will drop sessions that they cannot keep up with. Yes...there must be self-throttling of agentic AI interactions.

True. This will throttle down the speed of AI based and AI focused innovation, but only those parts that are done directly over the Internet. The Internet must be a safe place for the rest of Earch. Totally unthrottled and unbridled AI can be done in isolations laboratories.

Any device, organization or state found to NOT be abiding by these regulations will be cut off from the rest of the Internet until a proper investigation is completed and mitigations or changes assured to be implemented. Each infraction thereafter will result in a fine as well.

Testimonials

NULL at the moment.

Please email ronald@weist.net to schedule an appointment to talk about your data (or, cyber if you must) security.