AIRLINK 80.60 Increased By ▲ 1.19 (1.5%)
BOP 5.26 Decreased By ▼ -0.07 (-1.31%)
CNERGY 4.52 Increased By ▲ 0.14 (3.2%)
DFML 34.50 Increased By ▲ 1.31 (3.95%)
DGKC 78.90 Increased By ▲ 2.03 (2.64%)
FCCL 20.85 Increased By ▲ 0.32 (1.56%)
FFBL 33.78 Increased By ▲ 2.38 (7.58%)
FFL 9.70 Decreased By ▼ -0.15 (-1.52%)
GGL 10.11 Decreased By ▼ -0.14 (-1.37%)
HBL 117.85 Decreased By ▼ -0.08 (-0.07%)
HUBC 137.80 Increased By ▲ 3.70 (2.76%)
HUMNL 7.05 Increased By ▲ 0.05 (0.71%)
KEL 4.59 Decreased By ▼ -0.08 (-1.71%)
KOSM 4.56 Decreased By ▼ -0.18 (-3.8%)
MLCF 37.80 Increased By ▲ 0.36 (0.96%)
OGDC 137.20 Increased By ▲ 0.50 (0.37%)
PAEL 22.80 Decreased By ▼ -0.35 (-1.51%)
PIAA 26.57 Increased By ▲ 0.02 (0.08%)
PIBTL 6.76 Decreased By ▼ -0.24 (-3.43%)
PPL 114.30 Increased By ▲ 0.55 (0.48%)
PRL 27.33 Decreased By ▼ -0.19 (-0.69%)
PTC 14.59 Decreased By ▼ -0.16 (-1.08%)
SEARL 57.00 Decreased By ▼ -0.20 (-0.35%)
SNGP 66.75 Decreased By ▼ -0.75 (-1.11%)
SSGC 11.00 Decreased By ▼ -0.09 (-0.81%)
TELE 9.11 Decreased By ▼ -0.12 (-1.3%)
TPLP 11.46 Decreased By ▼ -0.10 (-0.87%)
TRG 70.23 Decreased By ▼ -1.87 (-2.59%)
UNITY 25.20 Increased By ▲ 0.38 (1.53%)
WTL 1.33 Decreased By ▼ -0.07 (-5%)
BR100 7,626 Increased By 100.3 (1.33%)
BR30 24,814 Increased By 164.5 (0.67%)
KSE100 72,743 Increased By 771.4 (1.07%)
KSE30 24,034 Increased By 284.8 (1.2%)

ISLAMABAD: The federal government has issued an advisory regarding cyber security threat of ChatGPT, while saying that a breach of around 100,000 ChatGPT user accounts on the dark web through an information stealing malware (Raccoon, Vider, Redline) is reported. The advisory further stated that the report about the breach also highlights one of the major challenges of Al-driven projects (including ChatGPT); the sophistication of cyber-attacks.

The government has suggested precautionary measures and cautious use of ChatGPT (at organizational and individual level).

Globally, many organisations are integrating ChatGPT and other Al-powered APIs into their operational flows/information systems. ChatGPT accounts signify the importance of Al-powered tools along with the associated Cyber risks as it allows users to store conversations. In case of breach, access of a user account may provide insight into proprietary information, area of interest/research, internal operational/business strategies, personal communications and software code etc.

The precautionary measures for users include; (1) Do not enter sensitive data into ChatGPT. If essential, ensure to disable the chat saving feature from the platform's settings menu or manually delete those conversations as soon as possible, (2) Use a malware-free/screened system for ChatGPT. An infected system (with information stealer malware) may take snap screenshots or perform key logging, leading to a data leak, (3) ChatGPT/other Al-powered tools and APIs must not be used by users handling extremely sensitive data. Masking of critical information/ dummy data may be utilized where absolutely essential.

For organizations the precautionary measures include, through best practices, organizations can ensure that ChatGPT is used securely and the data is protected. It is also important to note that Al technology is constantly evolving. The key to protection may be that organizations must stay up-to-date with the latest security trends. Few best practices (but not limited to) are as follows:

(1) Conduct Risk Assessment: Before the use of ChatGPT, conduct a comprehensive risk assessment to identify any potential/exploitable vulnerabilities. This will help organizations to develop a plan to mitigate risks and ensure that their data is protected.

(2) Use Secure Channels: To prevent unauthorized access to ChatGPT, use secure channels to communicate with the chatbot. This includes using encrypted communication channels and secureAPIs.

(3) Mechanism to Monitor Access: It is important to monitor who has access to ChatGPT. A mechanism be ensured that access is granted only to authorize individuals. This can be achieved by implementing strong access controls and monitoring access logs.

(4) Implement Zero-Trust Security: Zero-trust security (an approach that assumes that every user and device on a network is a potential threat) be adopted. This means that access to resources should be granted only on a need-to-know basis followed by strong authentication mechanism.

(5) Train the Employees: Employees be trained on use of ChatGPT and the potential risks associated with its use. The employees do not share sensitive data with chatbot and are aware of the potential threat of social engineering attacks.

Copyright Business Recorder, 2023

Comments

Comments are closed.