cloud security Archives - 麻豆原创 Australia & New Zealand News Center News & Information About 麻豆原创 Tue, 04 Aug 2026 16:57:06 +0000 en-AU hourly 1 https://wordpress.org/?v=7.0.4 Five takeaways on AI governance, trust and innovation /australia/2026/07/07/five-takeaways-on-ai-governance-trust-and-innovation/ Tue, 07 Jul 2026 00:35:23 +0000 /australia/?p=7831 By Marielle Ehrmann, Chief Security Compliance and Risk Officer, 麻豆原创 As AI adoption accelerates, leaders face urgent questions: where is AI being used, what data...

The post Five takeaways on AI governance, trust and innovation appeared first on 麻豆原创 Australia & New Zealand News Center.

]]>

By Marielle Ehrmann, Chief Security Compliance and Risk Officer, 麻豆原创

Image of Marielle Ehrmann, 麻豆原创
Marielle Ehrmann, Chief Security, Compliance and Risk Officer, 麻豆原创

As AI adoption accelerates, leaders face urgent questions: where is AI being used, what data is it touching, who is accountable and what happens when something goes wrong?

Those questions sit at the heart of a recent KBI Media podcast conversation with Marielle Ehrmann, 麻豆原创鈥檚 Chief Security, Compliance and Risk Officer. Her message is clear: done well, AI governance is not a brake on innovation, it is the accelerator.听

For leaders across Australia and New Zealand, that matters now. In many organisations, AI is moving at startup speed while governance is moving at committee speed. According to , nearly all organisations are at least in the process of integrating and scaling AI, yet only around a third have responsible controls in place.听

Here are five takeaways on turning AI governance into a source of trust, resilience and advantage:

1. Boards have moved from excitement to accountability

Not long ago, many boardroom conversations about AI centred on speed: how quickly it could be deployed, where it could drive productivity and how it could create competitive advantage.

Those questions still matter. But, as Ehrmann observed, the conversation has become more sophisticated. Boards are now asking a sharper version of the same question: how fast can we deploy AI without ending up on the front page of the Wall Street Journal?

That shift makes sense.

鈥淎I has moved from being a cool technology experiment to something that can materially impact revenue, reputation, intellectual property, regulatory exposure, but also customer trust,鈥 Ehrmann said.

That is a significant shift. AI is no longer a technology discussion alone. It is a governance, legal, cybersecurity, reputational and business continuity discussion all at once. For leaders, that means AI governance must be elevated beyond a specialist function and treated as a boardroom priority.

2. Good governance is the accelerator, not the brake听

One of the strongest ideas from the conversation is also one of the most important for organisations trying to balance ambition with accountability: governance does not have to slow innovation down.

鈥淕ood governance is really becoming the accelerator pedal, not the brake pedal,鈥 she said.

It is a powerful reframing. Too often, governance is treated as something that arrives after innovation: a checkpoint, a hurdle or a process to be navigated once the exciting work is done. With AI, that approach creates risk. If governance lags too far behind deployment, organisations can quickly lose visibility over where AI is being used, what data it is touching, who is validating outputs and who is accountable when something goes wrong.

Governance, when designed well, creates clarity. It gives teams the confidence to innovate within clear boundaries and helps make AI adoption sustainable.

As Ehrmann put it, 鈥淭he companies that build trust the fastest are often the ones that innovate also the fastest in the long run.鈥

3. AI risk is as much about people as it is about models听

When organisations talk about AI risk, it is natural to focus on the technology itself: the model, the data, the outputs and the architecture. But Ehrmann was clear that the bigger risk often sits somewhere more familiar.

鈥淢ost executives are realising now that the biggest AI risk usually isn鈥檛 the model itself, it鈥檚 the human behaviour around the model,鈥 she said.

That human risk factor is already playing out in practical ways. Employees may paste sensitive information into public AI tools, trust AI-generated outputs too quickly, or move faster than the organisation鈥檚 guardrails allow. For many organisations, AI adoption does not start with a formal strategy. It starts with employees opening a browser tab.

That is why Ehrmann describes the task as giving people 鈥渇reedom within boundaries鈥. Organisations need to give teams room to explore AI and unlock value, while being clear about the limits. That requires policies, education, oversight, data controls and clear accountability for AI risk.

4. Responsible AI is operational discipline, not AI theatre听

There is no shortage of AI strategy decks, transformation slogans or executive panels. But as organisations move from experimentation to scale, Ehrmann suggested it becomes easier to distinguish responsible AI from what she called 鈥淎I theatre鈥.

鈥淵ou can usually spot the difference within the first 15 minutes of a conversation,鈥 she said. 鈥淚f you ask a very simple question on who owns AI risk here, suddenly the room gets quiet.鈥

That question matters because responsible AI must show up in the way an organisation operates. Can leaders say where AI is being used? Do they know what data is involved? Is there a human in the loop validating outputs? Are policies in place? What happens if AI gets something wrong?

鈥淎I governance shows up in operational discipline, not in PowerPoint slides,鈥 Ehrmann said.

Governance claims are easy to make. Proving them is harder. That is where external certification becomes valuable, not as a marketing exercise, but as a discipline that forces organisations to codify, measure and defend their practices against an independent standard.

At 麻豆原创, we were among the first large enterprises to achieve ISO 42001 certification for AI governance in Q3 2025, reflecting the company鈥檚 focus on building trust with customers and helping them adopt AI with confidence.

The broader point for business leaders is clear: responsible AI is not a branding exercise. It is an operational capability.

5. Trust is becoming a competitive advantage听

As AI becomes more embedded in business processes, customers are asking more sophisticated questions. They want to understand how models reach conclusions, how data is protected, how risks are managed and who is accountable.

For Ehrmann, that growing demand for transparency is not something to resist. It is part of what trust now requires.

鈥淭he winning ones will be those who have built governance and can move at the speed of innovation, and that is actually creating trust,鈥 she said.

That idea is especially important as AI governance continues to evolve across jurisdictions. Ehrmann pointed to the need for stronger harmonisation and standardisation across the regulatory landscape, so organisations of all sizes can navigate their responsibilities more clearly.

In the meantime, organisations cannot afford to wait. AI is already moving through the enterprise. The question is whether governance is moving with it.

Moving from AI experimentation to responsible AI at scale听

The pressure to use AI is real. Customers expect faster, smarter experiences, while employees and competitors are moving quickly.

But speed alone is not enough. As Ehrmann put it, innovation gets applause, but good governance keeps you in business.

For organisations across Australia and New Zealand, AI governance is becoming the foundation for trusted innovation: giving people freedom to explore while protecting customers, data, reputation and trust.

Listen to the full podcast to hear more from 麻豆原创鈥檚 Marielle Ehrmann on governing AI with confidence.

The post Five takeaways on AI governance, trust and innovation appeared first on 麻豆原创 Australia & New Zealand News Center.

]]>
How To Build Cloud-First Security Into Your Digital Business /australia/2021/06/28/how-to-build-cloud-first-security-into-your-digital-business/ Mon, 28 Jun 2021 00:51:45 +0000 /australia/?p=4878 Cloud-based software and applications have opened the doors to the flexible working lifestyles like never before. 鈥楪ot internet and a laptop, can work鈥 has become the new mantra for employees across industries globally.

The post How To Build Cloud-First Security Into Your Digital Business appeared first on 麻豆原创 Australia & New Zealand News Center.

]]>
Cloud-based software and applications have opened the doors to the flexible working lifestyles like never before. 鈥楪ot internet and a laptop, can work鈥 has become the new mantra for employees across industries globally.

In response, organisations are revamping increasingly digitalised workforces with a cloud-first security strategy. Whether your organisation has just embarked on a cloud journey, or you鈥檙e looking to update you cloud vendor onboarding process, here are some considerations for building a cloud-first security strategy.

Involve teams company-wide to mitigate security risks

Unlike siloed business systems of the past, cloud security is everyone鈥檚 responsibility. Make sure that leaders understand the risks and cascade expectations across teams accordingly.

At an executive level, sensitive company and customer data and its governance are paramount. Breaches or leaks of sensitive data can destroy trust (and your brand) with millions of existing or potential consumers, and cost millions, if not billions, of dollars in damages to the company.

Technology infrastructure, architecture, and operational data, and its associated maintenance, availability and security are a critical responsibility for the chief information, digital or technology officer. As cloud technology develops and grows, so do the increasingly sophisticated threats, requiring more advanced protection measures. Dedicated internal IT security resources may not be feasible and/or scalable, or a cost-effective option to protect critical cloud systems.

Cloud security also extends to any business unit reliant on cloud software up-time for business-critical applications that serve existing and potential customers, while protecting the company brand and reputation. The financial and legal implications resulting from a lack of data privacy and security can be substantial.

Holistic cloud security and compliance considerations

When considering new cloud vendors, be prepared to sign a non-disclosure agreement before a potential cloud vendor will hand over their sensitive security and technical reports, certifications, and associated documentation. Cloud software and service providers storing and processing sensitive company or customer data should undergo multiple, regular, and globally recognised audits.

Compliance requirements may vary depending on the business functions, data, industry and/or geography. Common global standards for cloud security and service management include BS10012:2017 certification covering data privacy standards, ISO 9001 certification covering quality standards. In addition, ISO 27001 provides a global standard for IT security management practices, and ISO 22301 focuses on the security and resilience of business continuity management processes of the cloud provider.

For example, was one of the first cloud service providers, serving customers such as a national defence agency and financial institutions, and the 18th U.S. company to become ISO 27001 certified (formerly BS7799) in 2004. continues to undergo this and several other external and internal security audits to maintain a high level of certification.

Additional standards to consider include payment card industry (PCI) compliance related to payment data security, and SOC1 and SOC2 Type II reports, which cover compliance of internal controls and security audit reporting, respectively.

Data privacy is a growing area of scrutiny. Depending on the country and jurisdictions you are operating in, there will be local privacy laws which the vendor should comply with. For example, in Australia organisations must comply with Australian Information Privacy Principles. Common privacy product features include data retention (and deletion) procedures, and the general data protection regulation (GDPR), which are applicable to EU citizens regardless of where an organisation is located.

Data should be encrypted when it鈥檚 transmitted over a public network and at rest when being stored in databases. Cloud provider access to data should only be available to a limited, appropriately vetted number of authorised personnel. It is common to request that staff with access to data and data centres undergo appropriate background checks before being given access to customer data. Use industry standard encryption methods for data in transit and at rest.

If data sovereignty is important to your business, be aware of the location and ownership of your cloud provider鈥檚 data centres. Make sure that data centres are Tier 3+ or Level 4 facilities and confirm appropriate disaster recovery and archival/backup practices. Primary production sites should be separate to secondary backup and disaster recovery sites.

Cloud providers often outsource services to third parties for services such as infrastructure. Ask your cloud vendor about their practices, and how they will treat your data with privacy and security.

Mobile security is another consideration. Treat security capabilities of mobile applications with the same level of scrutiny as the vendor鈥檚 web applications, over and above the mobile device鈥檚 local security features such as biometrics.

Cloud security is constantly evolving. Perform continuous security and technical due diligence, as requirements, legislation, and expectations can vary between functionality, industries, and geographies. Above all, manage the integrity, security, and availability of your company and customer data with the same level of rigor as your entire cloud-based business. It鈥檚 the only way to keep pace with your digitalised workforce.

This article also appeared on .

The post How To Build Cloud-First Security Into Your Digital Business appeared first on 麻豆原创 Australia & New Zealand News Center.

]]>