Skip to content

Lack of Transparency on Software and AI Usage Weakens Cybersecurity in SMEs

The bottom line: SMEs cannot track which software and AI tools employees are using, which combined with weak password practices and insecure network behavior creates significant security gaps.

A WatchGuard study shows: Small and medium-sized enterprises only have incomplete knowledge of their digital attack surface and lack adequate control over the application landscape and AI usage of their employees. At the same time, insecure basic practices such as password reuse and unprotected network access continue to spread.

64 percent of surveyed employees use unauthorized AI tools at work. This so-called shadow AI represents a serious control risk because IT and security teams cannot track which tools are being used and what company data is being processed in them. The lack of visibility is compounded by transparency gaps in the overall software landscape: fewer than 30 percent of respondents believe their employer knows exactly which applications are used internally. Almost 40 percent even assume that the company neither fully knows the applications being used nor their actual usage.

In parallel, established security gaps in user behavior remain open. 76 percent use the same password for multiple accounts – a compromise of one access method potentially endangers all services secured with it. 30 percent share passwords with other people. Network usage also shows significant weaknesses: 70 percent work via public WLAN networks, and half access company resources without a VPN. This makes access credentials and data traffic easier to intercept and enables man-in-the-middle attacks. Additionally, 55 percent also use their work devices privately, opening up additional attack vectors through malware, phishing or access to insecure applications.

According to Marc Laliberte, Director of Security Operations at WatchGuard, there is a growing gap between invested security solutions and actual employee behavior. Traditional control mechanisms are not designed for the challenges posed by uncontrolled AI usage and decentralized work. Companies need not only to know which software is installed, but also to be able to track which AI services are being used and whether they are compatible with internal security and data protection requirements.

For many SMEs, it is difficult for in-house IT and security teams to monitor all user risks. Managed service providers can play a supporting role by helping companies detect user risks, implement policies, and provide continuous awareness training. Managing human behavior thus becomes a central requirement when implementing new technologies and promoting decentralized work.


Source: www.it-daily.net · Published July 15, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: