In this episode of Shh, IT Happens, Eddie Clark of Solve iT and John Ohlwiler of Sentry Technology Solutions are joined by Doug Kreitzberg of SeedPod Cyber to discuss how rapidly growing AI adoption is changing cybersecurity risk, insurance, data governance, and the responsibilities of business leaders.
Employees are already finding ways to use AI to work faster, often before their companies have established policies around which tools are approved or what information can be shared with them. Doug explains why businesses need to put intention behind AI adoption and why cyber insurers are beginning to pay closer attention to AI governance. Some carriers are already introducing exclusions or coverage limitations as they work to understand this emerging risk.
The conversation covers practical ways businesses can get ahead of the problem, including identifying which AI tools employees are using, establishing acceptable use policies, classifying sensitive data, using business-managed AI accounts, and deciding where human oversight is required. Eddie, John, and Doug also discuss why small and midsize businesses increasingly need access to strategic technology expertise as AI, cybersecurity, compliance, and insurance become more closely connected.
In Tool Time, Eddie tackles something almost everyone clicks through without reading: end-user license agreements, or EULAs. The hosts discuss how software agreements can shift responsibility back to the customer and why businesses need to understand their responsibilities for protecting and backing up data stored in platforms such as Microsoft 365 and Salesforce.
Chapter Highlights
00:00 | Welcome to Shh, IT Happens
Veronica introduces the show, Eddie Clark of Solve iT, and John Ohlwiler of Sentry Technology Solutions.
01:39 | AI, Security, and Third-Party Risk
Eddie discusses the rapid pace of AI development and why businesses need technology partners that can keep up as new security risks and vulnerabilities emerge.
04:34 | AI Adoption Without a Plan
Doug Kreitzberg joins the conversation and explains why adopting AI before establishing clear intentions, responsibilities, and guardrails can create unnecessary business risk.
06:37 | Give Your AI a Job Description
Doug compares AI tools and agents to employees. Businesses need to define what they should do, what information they can access, and when human approval is required.
08:20 | How Insurers Are Responding to AI Risk
Doug explains how some insurance carriers are introducing AI-related exclusions and coverage limitations across cyber and other insurance policies.
10:50 | AI Governance and Cyber Insurance
The discussion turns to acceptable use policies, approved AI tools, data access, and the governance practices insurers are beginning to examine.
12:40 | AI Questions Are Coming to Insurance Applications
Doug explains how larger organizations are already seeing more detailed AI governance questions from underwriters and why smaller businesses should expect increased scrutiny as AI risks become better understood.
15:15 | Data Classification Becomes Critical
Eddie and Doug discuss identifying confidential, restricted, and public information so businesses can establish practical controls over what AI systems can access.
18:00 | Finding the Line Between Helpful AI and Business Risk
The group discusses how leaders can balance productivity gains with the need to protect customer information, intellectual property, financial data, and other sensitive information.
20:30 | Does Your Business Need an AI Officer?
Eddie and John discuss emerging AI governance roles and how smaller companies can assign responsibility for AI strategy, security, privacy, and compliance without building a Fortune 1000 executive team.
25:20 | Every Business Is Now a Digital Business
Doug explains why businesses need technology expertise at the leadership table as cybersecurity, AI, data, and business strategy become increasingly connected.
27:45 | Where Should a Small Business Start With AI?
The hosts recommend starting with business goals, educating leadership, identifying existing employee AI use, moving toward company-managed tools, and creating basic guidelines.
32:00 | Practical AI Guardrails for Businesses
Veronica and Doug recap the fundamentals: know what AI is being used, establish approved tools, define what data can be shared, train employees, and bring IT, leadership, and insurance advisors into the same conversation.
34:10 | Tool Time: Read the Fine Print
Eddie explains why businesses should pay attention to software EULAs and how certain agreements can shift responsibility or liability back to customers.
37:30 | Who Is Responsible for Your Cloud Data?
The conversation expands into Microsoft 365, Salesforce, cloud data ownership, backups, and why businesses should maintain an independent strategy for protecting critical information.
39:20 | Final Takeaway: Create the Guardrails Before You Need Them
AI can create significant opportunities for small businesses, but leadership needs visibility, governance, and human oversight so innovation does not quietly create new risk.
This show is brought to you by:
- Solve IT Managed IT and Cybersecurity in Charlotte
- Sentry Technology Solutions in Orlando