Block the prompt, not the work: The end of 'Doctor No'

April 2, 20262 min read1 sources
Share:
Block the prompt, not the work: The end of 'Doctor No'

A familiar character is fading from enterprise security departments: the CISO whose primary function is to say “no.” For years, this “Doctor No” persona blocked new tools like generative AI and unapproved file-sharing services, a practice once seen as the hallmark of a secure posture.

That approach is now becoming a significant business liability. Outright bans on productivity-enhancing tools often fail to stop their use. Instead, employees turn to “shadow IT”—unapproved software and services operating outside of security oversight. This creates unmanaged risks, as sensitive company data can be processed by unsanctioned applications, leading to potential data leakage and compliance failures.

The rapid adoption of generative AI has made the problem critical. Employees using public tools like ChatGPT or DeepSeek to analyze proprietary code or draft strategic documents can inadvertently expose intellectual property. According to a recent analysis, the competitive need for AI-driven efficiency makes a simple blockade untenable, forcing security teams to find a new strategy.

The modern approach shifts from prohibition to secure enablement. Rather than blocking applications entirely, security teams are implementing controls to manage their use. This includes deploying Data Loss Prevention (DLP) solutions that can detect and stop sensitive information from being submitted to public AI prompts. Similarly, Cloud Access Security Brokers (CASBs) provide visibility and policy enforcement for both sanctioned and unsanctioned cloud services, allowing teams to manage risk without stifling innovation.

This evolution recasts security from a simple gatekeeper to a strategic business partner, focused on managing risk while allowing the organization to adopt the tools it needs to succeed.

Share:

// SOURCES

// RELATED

Former ransomware negotiator pleads guilty to working for BlackCat cyber gang

A trusted ransomware negotiator's guilty plea for colluding with the BlackCat gang reveals a shocking insider threat, eroding trust in the cyber respo

6 min readApr 24

Lotus Wiper: A deep dive into the malware targeting Venezuela's energy sector

A new wiper malware, Lotus Wiper, was found targeting Venezuela's energy sector. Our analysis covers its destructive methods and geopolitical implicat

7 min readApr 23

UK regulator launches investigation into Telegram over child safety failures

The UK's communications regulator, Ofcom, has launched a formal investigation into Telegram over its failure to prevent the sharing of CSAM.

6 min readApr 22

UK regulator to probe Telegram, teen chat sites for potential child safety violations

Ofcom launches its first major investigation under the new Online Safety Act, targeting Telegram over allegations of CSAM distribution, setting a majo

6 min readApr 22