{"id":39921,"date":"2019-08-05T10:33:14","date_gmt":"2019-08-05T09:33:14","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=39921"},"modified":"2019-08-06T08:39:35","modified_gmt":"2019-08-06T07:39:35","slug":"beyondtrust-ciso-on-conversation-marketing-security-pitfalls-and-best-practices","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/08\/05\/beyondtrust-ciso-on-conversation-marketing-security-pitfalls-and-best-practices\/","title":{"rendered":"BeyondTrust CISO on conversation marketing security pitfalls and best practices"},"content":{"rendered":"\n<p><em>Organisations are increasingly recognising the value of chatbots in providing a positive customer experience. But it is important that security remains top of mind when deploying such tools. Here, Morey Haber, CTO and CISO, BeyondTrust, explores some fundamental security considerations for organisations looking to deploy chatbots and conversation marketing. <\/em><\/p>\n\n\n\n<p>According\nto Gartner\u2019s recent \u2018<em>AI\nand ML Development Strategies\u2019<\/em> study, 40% of organisations cite customer experience (CX) as\nthe number one motivator for use of Artificial Intelligence (AI) technology. <\/p>\n\n\n\n<p>Not surprisingly, across the Middle East, we are seeing enterprises of all sizes, and even several government entities, start rapidly deploying chatbots on their websites, all in an effort to provide customers with faster responses to their queries. <\/p>\n\n\n\n<p>These\nchat applications are designed to field plain text requests from humans that\nare fed into an AI engine, which can provide \u2018smart\u2019, scripted responses to\ninquiries.<\/p>\n\n\n\n<p>As\nthe Machine Learning technology that powers many of these chat applications\ngets smarter, it is going to get increasingly harder for users to determine if\nthey are interacting with a real person or a machine. <\/p>\n\n\n\n<p>As\na case in point, some services classified as \u2018conversation marketing\u2019 may actually\nroute you to the appropriate live person for a more in-depth conversation. But\nwhile we might never know the difference, with a little social engineering, a\nthreat actor can easily determine what is behind the scenes and exploit any IT\nsecurity vulnerability.<\/p>\n\n\n\n<p><strong>Understanding\nthe security implications of chatbots<\/strong><\/p>\n\n\n\n<p>Irrespective of whether it\u2019s a human or machine, there are some inherent security risks in chat-based services. Ironically, while there is a plethora of information available on how to deploy chatbots and the associated benefits, there isn\u2019t the same level of attention and guidance around how to keep it secure for both your organisation and for the end user.<\/p>\n\n\n\n<p>As\na case in point, consider an automated service that is either hosted by the\ncompany itself or connected to a cloud-based AI engine as a service. To\neffectively respond to queries, this service needs to access backend resources.\nThis often means having a database fronted by middleware that allows queries\nvia a secure application programming interface (API). The contents of the\ndatabase will vary from company to company and may include anything from hotel\nreservation information to customer data \u2013 and it may even accept credit card\ninformation.<\/p>\n\n\n\n<p>Here&#8217;s\na checklist of basic security questions to cover before implementing a chatbot\nthat is fully automated and AI-driven:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Is the API connecting your organisation\u2019s website and the chatbot engine secured using access control lists (ACLs)? You can accomplish this by using IP addresses, geofencing, etc.<\/li><li>How do you approach the management of authentications between the systems (webservice, engine, middleware, cloud, etc.)? <\/li><li>How do you apply vulnerability management best practices across the architecture supporting the chatbot? You should also find a way to implement routine penetration testing. <\/li><li>Have you adequately secured privileges\/privileged access and enforced least privilege? <\/li><li>What data can the chatbot query \u2013 is any of it sensitive? Do any specific regulations apply to how this data is collected, stored or handled? For instance, do communications contain information that may warrant extending your scope of regulations, like PCI DSS? Also, will communications \u2018self-destruct\u2019 in accordance with certain regulations?<\/li><li>Is there a process for logging and detecting potential suspicious queries that may be designed to exploit the AI engine or leak data?<\/li><li>Can you mitigate or prevent malware or distributed denial of services (DDoS) that target your service?<\/li><li>Do you ensure end-to-end encryption for all chatbot communication and what protocols are you using?<\/li><\/ul>\n\n\n\n<p>In addition to carefully considering these security implications, organisations should continuously inventory the supply chain based on assets and communications from chatbot, webservice and provider to maintain a risk assessment plan. Any changes can easily affect some of the best practices listed above.<\/p>\n\n\n\n<p><strong>Protecting\nyour employees during conversation marketing<\/strong><\/p>\n\n\n\n<p>In\nconversation marketing, a human is actually responding to the queries via the\nchat window. Several organisations try to make the experience really \u2018authentic\u2019\nand, as a consequence, do not use fake names or pictures for the human chat box\nrepresentative.<\/p>\n\n\n\n<p>However,\nif a company displays the full name of their chat representative inside the\nchat box, with just a little social engineering, a bad actor can easily uncover\ndata about the representative that can be used as part of an exploit. This is particularly\neasy if the representative has a social media profile. So to that end, if you\ndo choose to use conversation marketing, it is critical that you follow a few\nkey security best practices.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>For one, never reveal the employees\u2019 full name and instead use an alias. While this might seem counterproductive (remember the whole making the experience more \u2018authentic\u2019), using the full name or even just the first name and last initial poses a high risk as a little research could uncover personal information about the representative.<\/li><li>If the chat service displays a picture, photo, or avatar of the representative, use a unique image that cannot be found anywhere else on the Internet. The reason \u2013 a simple search by the employee and company name will reveal their social media presence and, if the pictures easily match, you might as well use their full name anyway. You will have done very little to mask their identity and provide protection from a potential social engineering attack at home or at work.<\/li><li>Have a detailed manual in place that clearly states what information the employee can share and what he\/she absolutely cannot \u2013 under any circumstances, irrespective of the inquiry \u2013 during a chat conversation. These guidelines will vary and can include everything from license keys to password resets. Your business will have to establish this list based on the services the chat box provides and any local and industry regulations governing data exposure, particularly across country lines.<\/li><li>Create a formal support and escalation path for inquiries into potentially sensitive information. <\/li><li>Provide regular security training for all chat box representatives so that they know how to recognise a potential attack, how to respond to suspicious requests and how to escalate a situation before it becomes a security incident for your organisation.<\/li><\/ul>\n\n\n\n<p>Let\u2019s\nface it \u2013 when it comes to improving customer service, the benefits of chatbots\nand conversation marketing is undeniable, which means they are here to stay.\nBut these tools do open up another attack vector \u2013 cybercriminals will always exploit\nthe simplest way to compromise an organisation and, unfortunately, humans are often\nthe weakest link.<\/p>\n\n\n\n<p>But\nby assessing the key questions and implementing these best practices, you can enable\na chat service that helps support your business initiatives, without opening up\nunnecessary risks. &nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Organisations are increasingly recognising the value of chatbots in providing a positive customer experience. But it is important that security remains top of mind when deploying such tools. Here, Morey Haber, CTO and CISO, BeyondTrust, explores some fundamental security considerations for organisations looking to deploy chatbots and conversation marketing. According to Gartner\u2019s recent \u2018AI and [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":39957,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6787,5,6,13],"tags":[3211,4853],"class_list":["post-39921","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-transformation","category-enterprise-security","category-insights","category-top-stories","tag-ai","tag-morey-haber"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/39921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=39921"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/39921\/revisions"}],"predecessor-version":[{"id":39923,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/39921\/revisions\/39923"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/39957"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=39921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=39921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=39921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}