AI Usage Risk
Tracks employee adoption of approved vs unapproved AI tools, prompt hygiene, and exposure of sensitive content to public LLMs.
- Publish approved AI tool list
- Block public LLM domains on managed devices
- Deliver Safe Use of ChatGPT module org-wide
Social Engineering Risk
Measures susceptibility to AI-generated phishing, smishing, vishing, and deepfake impersonation attacks.
- Run quarterly AI phishing simulations
- Enable callback verification for wire transfers
- Train executives on deepfake voice scenarios
Data Leakage Risk
Quantifies likelihood of sensitive data (PII, source code, contracts) leaving the organization via AI tools.
- Deploy DLP rules for AI endpoints
- Audit ChatGPT/Copilot tenant logs weekly
- Mandatory data handling module
Technical AI Security Risk
Application-layer exposure: insecure LLM integrations, prompt injection, RAG poisoning, model supply chain.
- Threat-model every GenAI feature
- Add prompt injection tests to CI
- AppSec training for all engineers
Policy Compliance Risk
Coverage and acknowledgment of AI acceptable use policy across the workforce.
- Require annual AI policy attestation
- Localize policy for EU/APAC
- Tie policy to onboarding
Risk Matrix
Impact vs likelihood — bubble sizes show finding counts
Top Findings
Employees pasting customer data into external AI tools
Customer Support, Sales
Finance team vulnerable to AI-generated invoice fraud
Finance
HR lacks fake candidate / synthetic identity detection training
HR & Recruiting
Engineering team needs prompt injection awareness
Engineering, AppSec
Executives need deepfake verification protocol
Executive Team