ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Balancing trust and security in organisations

Linked InXFacebook

There is a delicate balance between trust and security in any organization. Oseloka Obiora at RiverSafe argues that striking the right equilibrium by implementing policies, training programs, and tools that empower employees while mitigating the risks associated with insider threats is critical to success.

 

Trust is a central factor in building a happy, healthy, and efficient workplace. However, with cyber-security threats becoming increasingly complex and difficult to defend against, businesses are faced with the tough task of balancing trust in their employees and the security of their organisation.

 

As any business leader well knows, employees who believe they are trusted perform better than those who feel micromanaged. Workers who feel empowered to take action, make decisions, and put their ideas out there tend to be happier and more productive in their roles.

 

In fact, research has shown that employees who feel trusted are 260% more motivated to work, have 41% lower rates of absenteeism, and are 50% less likely to look for another job.

 

When it comes to security, however, trust can be a sticky subject. Today, workers across all types of organisations have access to a mammoth range of tools and platforms, and the masses of data contained within them. Keeping these digital environments secure while giving employees access to the resources they need to do their jobs can be a balancing act.

 

Achieving this equilibrium is getting even more challenging, thanks to the growing accessibility and ubiquity of AI.

 

For many businesses, AI has been on a steady, if small-stepping, march into their tech stacks for the past few years. But the recent explosion in the availability and popularity of large language models (LLMs) and generative AI tools like ChatGPT has triggered much discussion around their potential impact on security.

 

The threats posed by untested and unsecured AI tools are already proving a nightmare for businesses to keep track of. The huge market for AI tools makes the security posture of many third-party apps impossible to gauge.

 

Not only are security teams struggling to verify the safety of the tools, but additional security risks can arise due to the quantity of data LLMs ingest and how that data is handled.

 

With new AI tools being rolled out daily, security leaders are being left racing to mitigate potential hazards. Given the complexity of securing these tools and the extent of their use, it’s a near-impossible task.

 

Despite the clear advantages of AI technology, many organisations are concluding that the risks outweigh the benefits. Around two-thirds of UK businesses have already banned, or are considering banning, the use of generative AI tools on company-owned and BYO devices. In 70% of cases, these bans were initiated by concerns from IT department leadership, showcasing the scale of alarm about AI among CIOs, CTOs, and CISOs.

 

But AI isn’t going anywhere. If businesses want to remain innovative and competitive in their markets, they’re going to need to embrace AI sooner rather than later. So where does that leave organisations struggling to balance trust in their employees and their cyber-security position?

 

Navigating these largely uncharted waters will be taxing, but caution and communication are key. Harnessing the benefits of AI without opening up your organisation to risk requires a careful approach—jumping feet-first into new trends isn’t a smart thing to do, but in the long term, neither is closing the door on them completely.

 

Leaders must assess the risks and implement the necessary cyber-protection to ensure the organisation is guarded against these new threats.

 

With cyber-crime on the rise, and AI tools enabling the increased complexity and scale of cyber-threats, approaches like zero trust are gaining traction. Despite the severity of its moniker, such a tactic can be a useful tool within a culture of employee trust.

 

Zero trust is not about eyeing your employees with suspicion or keeping them on a short digital leash. It’s about accepting that no activity within a digital environment can or should be assumed to be innocuous, and by extension, creating a secure and resistant environment by giving no user the benefit of the doubt.

 

Organisations can use zero trust to mitigate at least some AI security risks. By controlling engagement with tools and applications through functionality like identity verification and least-privilege access, security leaders can reduce the attack surface for would-be hackers and cyber-criminals.

 

Security solutions like User and Entity Behaviour Analytics (UEBA) and Security Information and Event Management (SIEM) tools can also help identify unusual and potentially illicit behaviour before it can impact your operations.

 

Although limiting access to the essential tools they need to carry out their work, and tracking their behaviour within a network, may not be welcomed by employees, such tighter security measures are essential. And with proper communication and transparency, businesses can maintain both the trust of their employees and the security of their digital environment.

 

When implementing these kinds of measures, it’s important to make clear that you’re not taking this action because you don’t trust your employees, but because cyber-threats are fast becoming more difficult to protect against.

 

Be transparent and upfront about the dangers and consequences that businesses face, and how these measures will protect employees while allowing them to safely use innovative tools.

 

The bottom line is that even if you can trust that your employees will act appropriately, you simply can’t trust that your business can stay ahead of (and communicate) any developments in cyber-threats quickly enough to mitigate risk.

 

And that’s why trust must go hand-in-hand with robust security measures. Because no matter how much you trust that your employees can do their jobs effectively, you must also have faith in cyber-criminals to do the same. 

 


 

Oseloka Obiora is CTO at RiverSafe

 

Main image courtesy of iStockPhoto.com

Linked InXFacebook
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543