Block the prompt, not the work: The end of 'Doctor No'

April 2, 20262 min read1 sources
Share:
Block the prompt, not the work: The end of 'Doctor No'

A familiar character is fading from enterprise security departments: the CISO whose primary function is to say “no.” For years, this “Doctor No” persona blocked new tools like generative AI and unapproved file-sharing services, a practice once seen as the hallmark of a secure posture.

That approach is now becoming a significant business liability. Outright bans on productivity-enhancing tools often fail to stop their use. Instead, employees turn to “shadow IT”—unapproved software and services operating outside of security oversight. This creates unmanaged risks, as sensitive company data can be processed by unsanctioned applications, leading to potential data leakage and compliance failures.

The rapid adoption of generative AI has made the problem critical. Employees using public tools like ChatGPT or DeepSeek to analyze proprietary code or draft strategic documents can inadvertently expose intellectual property. According to a recent analysis, the competitive need for AI-driven efficiency makes a simple blockade untenable, forcing security teams to find a new strategy.

The modern approach shifts from prohibition to secure enablement. Rather than blocking applications entirely, security teams are implementing controls to manage their use. This includes deploying Data Loss Prevention (DLP) solutions that can detect and stop sensitive information from being submitted to public AI prompts. Similarly, Cloud Access Security Brokers (CASBs) provide visibility and policy enforcement for both sanctioned and unsanctioned cloud services, allowing teams to manage risk without stifling innovation.

This evolution recasts security from a simple gatekeeper to a strategic business partner, focused on managing risk while allowing the organization to adopt the tools it needs to succeed.

Share:

// SOURCES

// RELATED

Meta settles bellwether lawsuit alleging addictive design harmed student mental health

Meta's confidential settlement with a Washington school district marks a pivotal moment in the massive litigation against social media's psychological

6 min readMay 24

Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

A sophisticated zero-day attack on Huawei routers allegedly caused Luxembourg's 2023 national telecom outage, raising severe global security concerns.

6 min readMay 23

MiniPlasma Windows 0-day enables SYSTEM privilege escalation on fully patched systems

A newly disclosed 0-day flaw, MiniPlasma, allows attackers to gain full SYSTEM control on patched Windows systems, with a public PoC accelerating risk

6 min readMay 18

The ransomware dilemma: why more than half of security chiefs would pay the price

A new survey reveals 56% of CISOs would consider paying a ransom, highlighting the intense pressure to restore operations despite official guidance.

6 min readMay 16