Do you know what data is critical to your business?

Notes from our Data Security in the Age of AI roundtable

Artificial Intelligence has moved from something businesses were curious about to something they're actively using. And as we open the door to it, we're also opening the door to our information, including the data that is most sensitive and most critical to how we operate.

That was the question at the heart of a recent roundtable we hosted in partnership with Crayon: do you actually know what data is critical to your organisation?

It's a deceptively simple question, and one a lot of us can't answer as confidently as we'd like.

Why we brought people together

We invited our customers to sit down together and talk openly about how they're using AI in their businesses, and what steps they've taken (and are still taking) to make sure governance and security are considered intentionally rather than bolted on afterwards.

We've been here before

Michael, a Community Lead for Crayon, talked us through how AI has accelerated over the last few years. It's been a game changer, and it's thrown just about everyone into a mode that's equal parts chaotic and curious.

But, as Michael pointed out, we've been here before. Think back to the days before the Cloud and Software-as-a-Service (SaaS) products. I don't remember them myself, but I'm told they were also days of change, discontent, and genuine disbelief that things would ever shift from the status quo. And here we are today.

The point wasn't to downplay the disruption. It was to reframe it. The goal, Michael said, is to create the conditions for better decisions, lower risk, and improved business performance in the age of AI. Not to resist the change, but to meet it well.

Start with the basics: know what you're protecting

The clearest theme of the day was also the most fundamental.

We all know that data feeds our business objectives, whatever they happen to be, whether that's better customer experience (CX), revenue growth, or the ability to innovate. What we don't always know is where our data actually lives, how old it is, how credible it is, or who has access to it. And crucially: what happens if someone who shouldn't have access to it gets it? Are we at risk? Is that data critical to the business?

This is where you start with the basics. Understand what's important to your organisation in terms of data, what's critical, your crown jewels if you will. Because if you don't, business objectives can be impacted, or even severely derailed.

A few questions worth sitting with:

  • What information do we hold, and which of it is genuinely critical? Not everything needs the same level of protection, but you can't make that call until you've mapped it.

  • Where is it stored, and who has access? Data spreads quietly across systems, drives and inboxes. Visibility is the first line of defence.

  • What's our most important intellectual property, and how are we protecting it? For many businesses, this is often the least clearly understood.

Governance and security aren't the brakes, they're the steering

Sometimes the words "governance" or "security", in the context of AI, make people think that everything is coming to a halt.

But that's not quite right. Guardrails might slightly slow the momentum, but they're not an all-out stop. Putting sensible practices around your AI rollouts and usage will actually help accelerate implementation, because it lets you steer AI adoption in a direction that's aligned with your organisation and your objectives (excuse the ongoing car analogies).

Confidence at scale is built on data trust

Here's a tension worth naming. In a Forrester Consulting study conducted for Crayon, one of the top barriers to AI adoption was data privacy and security concerns.

Which is fair enough. Plenty of people are genuinely, and reasonably, concerned.

In our line of work, we hear and see a lot: someone pasting highly sensitive information, such as health data, into a personal ChatGPT account to help summarise it. The intention isn't malicious. But the result is sensitive data quietly leaking out of the organisation, into a tool no one controls.

Which leads to an uncomfortable question that came up more than once: if you're feeding company information into a personal Large Language Model (LLM), are you training your competitor? Data fed into the wrong tool, in the wrong way, doesn't always stay yours.

The takeaway wasn't fear. It was that confidence scaling AI is built on data trust. You move faster when you trust the data you're working with, and when you trust that it's being handled properly.

Culture matters as much as controls

Perhaps the most nuanced part of the discussion was about people, not technology.

Sophie from Humankind brought a great point to the table: another layer of data governance and protection when adopting AI is building a culture of high trust and transparency.

When people understand how their colleagues are using AI, what they've tried, what they've learned, it becomes far easier to have open conversations about what should and shouldn't go into an LLM, especially when confidential data is involved.

The instinct, when AI feels risky, is to lock everything down. But overly stringent AI barriers tend to backfire. If people don't have a safe, sanctioned way to experiment, they'll find their own, and that's how "shadow AI" takes hold, with personal ChatGPT subscriptions and other tools being used quietly, outside anyone's line of sight.

The alternative is a culture that allows for safe experimentation. A few practical threads emerged:

  • Involve your people early. Understanding how AI is actually being used, and what your teams are trying to achieve, is half the battle.

  • Build use cases that make sense for your organisation. Learn from each other, and do it within safe parameters that align with your industry.

  • Create room to experiment, transparently. Clear guardrails, plus enough openness that people feel able to be honest about what they're using and why.

Slow down, just a little

We know AI is being used. The cat is well and truly out of the bag, and there's no end in sight.

The key thing from the day was simply this: slow down, just a little, so you can answer some important questions first.

The themes that came up, pulled together:

  • Start with the basics. Know what you're protecting and what's critical to the business.

  • AI is here. Governance and security aren't there to pull the brakes, they're there to help you steer.

  • Ungoverned data has consequences. Business objectives can be impacted by data no one is watching over.

  • Confidence at scale is built on data trust. You scale faster when you trust your data.

  • Barriers can backfire. Overly stringent AI barriers push people toward shadow AI, and that's how information ends up training someone else's model.

Thank you

It was a really interesting discussion, and we're grateful to Crayon for helping us put it together. To everyone who came along and shared their business insights, thank you. We're glad we got to connect.

If you walked away slightly concerned about answering "no" to any of those questions, like do you actually know where all your data is?, don't worry. That's exactly the kind of thing we can help with.

Get in touch to see how we can help you understand, protect, and get more out of your data. The more you know, the better you'll scale.

Source: Forrester Consulting study conducted for Crayon, "The Future of Operations: Advancing AI-Driven Innovation and Cloud Agility for Small and Medium-Sized Businesses," March 2025.

Next
Next

Recent breaches in Aotearoa: what they mean for New Zealand organisations