• Link to Instagram
  • Link to LinkedIn
  • Link to Facebook
  • Support
  • Resource Center
  • News & Events
  • Blog
  • Pay Online
Cumulus Global
  • What We Do
    • Managed Cloud Services Provided by Cumulus Global
    • Cloud Computing Security, Privacy, Compliance, & Continuity
    • Collaboration, Productivity, & Transformation
    • Managed Infrastructure & Platforms
  • How We Do It
    • Understand & Assess
    • Cloud Computing Strategy & Planning
    • Cloud Migration & Deployment
    • Cloud Managed Services
    • Service & Support for Cloud and IT Solutions
    • Global Strategic Services
    • Guide, Educate, & Train
  • What We Offer
    • Managed Cloud Services
    • IT Admin, Service, and Support
    • Security CPR® Managed Security
    • Google Cloud Workspace / Education / Chrome / Voice
    • Google Cloud Platform Computing Services
    • Microsoft 365 and Office 365 Managed Services
    • Microsoft Azure
  • Who We Are
    • Our Mission
    • Our Team and Opportunities
    • Our Cloud Computing Partners
    • Our Reviews and Testimonials
    • Our Community
    • Our Sustainability
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Tag Archive for: IT Governance

Posts

9.5 Questions to Answer for a Secure AI Foundation

September 15, 2026/in AI in Google Workspace, Blog, Cybersecurity, General

How to Audit Your Tools and Build a Smart AI Strategy

Written by Allen Falcon, Co-Founder & CEO, Cumulus Global

Officially or not, your team is likely using artificial intelligence (AI) in their day-to-day work. The big question is whether those tools will help or hurt your business. To be truly effective, AI services need to be productive, secure, and affordable. With the AI hype machine pushing tools as quick fixes while businesses grapple with costs, security often gets overlooked.

Building a secure AI foundation protects sensitive information and intellectual property (both yours and your clients’) while preventing the hidden risks of unapproved software. To help you evaluate your current setup, we broke down these 9.5 essential questions into three practical categories.

Key Takeaways

    • ✓Unsanctioned AI tools and personal logins create hidden data risks
    • ✓Setting strict access permissions keeps sensitive files out of public models
    • ✓Human oversight and clear request paths keep daily AI use safe and accountable
    • ✓Audit trails and emergency kill-switches protect your operations during vendor breaches

See: What Is in Use

1) Which AI tools and agents are in use across the business, including those adopted without approval?

Unsanctioned tools hide data movement beyond your control. Adding extra tools can also duplicate capabilities you already have, leading to redundant services and higher costs.

2) Are employees accessing these tools through corporate accounts or personal credentials?

Personal logins mean you have no record of activity or ability to revoke access if someone leaves. You also lose the ability to manage information sharing and everyday workflows.

3) What company information has already been entered into AI tools, and by whom?

Pasting client records, IP, or financial data into public models can trigger immediate compliance violations under HIPAA, PCI, or state privacy laws. You may also violate industry regulations, contractual commitments, and non-disclosure agreements.

Secure: Where the Exposure Lies

4) What systems and records can each tool access, and is that access limited to what the role requires?

Managing individual and team access to information is no longer optional. With AI agents learning from your data, obscurity does not protect sensitive information from being discovered. Tools without proper permissions invite unnecessary exposure, breaches, and data leaks.

5) Have any integrations or connections been added since each tool was approved?

Checking access at implementation will not protect your organization long-term. As AI tools get used, permissions often expand automatically to enable new agents, workflows, and autonomous tasks. Managing AI security requires monitoring these permission changes over time.

6) Do employees know which categories of information should almost never be shared with an AI tool?

Not all information needs heavy locks, but sensitive data should almost never enter public AI systems. Most information falls somewhere in between. Setting clear permissions and data categories protects your organization before data ever leaves your system.

Steer: Who is Accountable

7) Which AI-generated work may be acted upon without human review?

Whether drafting documents or executing autonomous tasks, strict guardrails for human review will prevent costly and embarrassing errors.

8) What is the process when an employee requests a tool that is not yet approved?

A clear request path encourages safe innovation instead of hidden workarounds.

9) Could you demonstrate to a regulator, client, or insurer which AI tools have processed their data?

Having a clear audit trail is critical for maintaining client trust and meeting compliance standards.

Bonus Question

9.5) If a tool or its vendor were compromised, how quickly can you revoke access?

Almost no security setup is completely perfect, which is why having an immediate kill-switch is so important when an AI tool suffers a breach or malfunction.

We Can Help

With security and readiness assessments, and tools and services to monitor and manage security, our team can help you understand your current AI security posture, plan your environment, and deploy productive, secure, and affordable solutions.

Please contact us or meet with a Cloud Advisor to discuss your needs, priorities, and next steps.

Ready to Take the Next Step?

Whether you’re beginning your cloud migration or looking to improve an existing environment, our Cloud Advisors can help.

Schedule a conversation

Allen Falcon

Co-Founder & CEO, Cumulus Global

Allen Falcon co-founded Cumulus Global in 2006 to help small businesses implement enterprise-grade cloud, security, and compliance solutions. Under his leadership, Cumulus Global has grown into a managed cloud services provider supporting more than 1,000 organizations throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-09-15 14:00:572026-09-15 21:34:309.5 Questions to Answer for a Secure AI Foundation

Three Pillars of AI Security for SMBs and Schools

September 10, 2026/in AI in Google Workspace, Blog, Cybersecurity, General

How Small Businesses and Schools Can Protect Sensitive Data While Adopting AI

Written by Allen Falcon, Co-Founder & CEO, Cumulus Global

Artificial Intelligence (AI) is undeniably reshaping how daily work gets done. When used properly, AI tools can help your team draft proposals, analyze spreadsheets, and summarize complex research in seconds.

In fact, nearly 90% of small businesses, local governments, and schools are actively experimenting with modern AI tools. However, many teams are adopting these helpful tools much faster than they are setting up basic rules and security safeguards.

Key Takeaways

    • ✓Adopting AI without governance creates hidden internal security risks.
    • ✓Over 70% of organizations experience data leaks through unauthorized employee prompts.
    • ✓Protecting your data requires a simple, three-part strategy: See, Secure, and Steer.
    • ✓Proper access controls, tool vetting, and activity logging ensure safe, compliant AI usage.

Understanding the Risks

When employees use random online AI tools without guidance, sensitive information can easily leave your organization. Recent research from IT security firm SentinelOne shows that 70% of organizations have experienced internal data leaks through employee prompts. Further, more than 20% of surveyed organizations reported security breaches stemming from authorized or unauthorized AI use.

To protect your organization, your technology must be more than just convenient. These services need to be productive, secure, and affordable.

In previous posts, we discussed how focusing on specific use cases and leveraging built-in features in tools you already own will keep costs down while boosting productivity. Protecting that work requires a simple strategy built on three pillars.

The Three Pillars of AI Security

  See: Bring AI Usage Into Sharp Focus

Most organizations recognize the dangers of Shadow IT (the practice of employees adopting personal or unapproved apps without IT oversight). Shadow AI is the fast-emerging extension of that risk. When team members use personal AI accounts for work tasks, they open your business up to unseen exposure. To manage that risk, you need full visibility into what tools are in play and how your data moves through them.

A strong visibility strategy focuses on a few key practices:

    • Identifying which AI tools your team employs for daily tasks
    • Ensuring that everyone logs in using secure business credentials instead of personal accounts
    • Teaching your team what sensitive business and customer information should never be shared with AI systems

If you do not know what information your team has already shared with AI models, you likely have a hidden risk that needs attention.

 

  Secure: Lock Down Access and Safeguard Data

Before you connect AI models to your company files, your underlying permissions must be tight. AI tools can quickly read and organize whatever data they can access, which means a user might accidentally see restricted files through an AI search prompt.

Securing your data requires a proactive approach to access control:

    • Review user access permissions across all shared folders and cloud drives
    • Understand exactly what information your AI systems can reach
    • Monitor third-party integrations as software updates occur over time

 Steer: Navigate Governance and Chart Your Course

Secure AI lives within clear guardrails. Beyond locking down permissions, you need straightforward policies that guide your team as they use AI.

Setting proper controls involves:

    • Creating a simple process for employees to request new software tools
    • Establishing clear boundaries between automated tasks and work that requires human review
    • Logging system activity so you have clear records if something goes wrong

These guidelines give your team the confidence to use new tools safely while keeping your organization protected.

We Can Help

Through security and readiness assessments, as well as monitoring and management tools, our team can help you understand your current AI security posture, plan your environment, and deploy productive, secure, and affordable solutions.

Contact us or schedule time to connect with a Cloud Advisor to discuss your needs, priorities, and next steps.

Ready to Take the Next Step?

Whether you’re beginning your cloud migration or looking to improve an existing environment, our Cloud Advisors can help.

Schedule a conversation

Allen Falcon

Co-Founder & CEO, Cumulus Global

Allen Falcon co-founded Cumulus Global in 2006 to help small businesses implement enterprise-grade cloud, security, and compliance solutions. Under his leadership, Cumulus Global has grown into a managed cloud services provider supporting more than 1,000 organizations throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-09-10 14:00:462026-09-11 15:08:20Three Pillars of AI Security for SMBs and Schools

Secure Gemini AI in Google Workspace

July 31, 2026/in AI in Google Workspace, Blog, Cybersecurity, General

Three Ways to Protect Company Files When Your Team Uses Gemini AI

Written by Allen Falcon, Co-Founder & CEO, Cumulus Global

Artificial intelligence offers incredible potential for productivity. AI also creates new security challenges.

Follow these three steps to protect and secure information when using Gemini AI in Google Workspace.

Key Takeaways

    • ✓Gemini AI sees what your Workspace settings allow
    • ✓Cleaning up shared files prevents sensitive data leaks
    • ✓Automated onboarding and offboarding keeps permissions accurate
    • ✓Decommissioning inactive accounts closes security gaps and cuts costs

Leaking sensitive, proprietary, or confidential data via AI is easy. An employee may put confidential financial data into a public AI tool, a private AI model, like Gemini AI, might read files that were overshared within your organization, or you may accidentally externally share sensitive information embedded in an internal model.

Gemini AI relies on your existing Google Workspace permissions. If a document is shared too broadly, the AI engine will make that information visible to unauthorized users.

Fortunately, you can secure your sensitive files and establish clear guardrails with a few strategic updates.

Step 1 of 3

Audit Your File Sharing Settings

Unintended file sharing happens quietly in nearly all organizations. Over time, link sharing and external permissions create hidden security risks.

Pay close attention to these common sharing pitfalls that can inadvertently surface confidential data to AI tools:

    • Exposure via Links: “Anyone with the link” settings can expose internal documents to external search engines and public AI crawlers.
    • Sharing to your Domain: Giving permission to your entire domain gives everybody, and every attached service, access to the information.
    • Lingering Access: External sharing permissions granted to contractors often remain active long after their work is complete.
    • Group Over-Sharing: Public Google Groups may inadvertently grant broad access to internal shared drives.

Use an automated tool to scan file, folder, and shared drive permissions against defined policies and compliance guidelines. Put systems in place to monitor and mitigate risks in real-time.

Step 2 of 3

Streamline User Onboarding and Offboarding

Manual IT administration is prone to human error and inefficiency. When employees join or leave, updating access controls requires careful detail.

Establishing automated lifecycle policies helps maintain strict access boundaries at every stage of employment.

    • Automate Onboarding: Add new hires to the correct Google Groups, shared folders, and chat spaces using policy-based automation.
    • Secure Transfers: Transfer file ownership directly to managers or secure shared drives as part of your offboarding workflow.
    • Cleanup Calendars: Remove former staff from internal meetings without disrupting active client appointments.
    • Manage Contacts: Ensure mobile address books remain accurate by clearing out former employees and transferring key business contacts.

Automate these steps to ensure your access controls are up-to-date and Gemini AI only displays sensitive files to authorized team members.

Step 3 of 3

Manage Inactive Accounts and Licenses

Inactive accounts waste budget and create unnecessary entry points for bad actors. Staff members who left months ago should not remain in your user directory.

Put automated management rules in place to ensure that former accounts are properly monitored and decommissioned:

    • Suspension Rules: Establish automated account suspension policies to keep your user directory secure and up-to-date.
    • Inactivity Alerts: Utilize alerts to track and address accounts with no login activity over a 30-day period.
    • License Management: Minimize software expenses and satisfy legal data retention requirements by transitioning offboarded employees to archive licenses.
    • Data Preservation: Safely eliminate paid licenses by transferring essential data into alternate cloud storage options.

Manage user lifecycles to reduce your monthly costs while protecting your company data.

Take the Next Step for Workspace Security

Securing your workspace does not require a complete operational overhaul. Targeted, automated changes create a foundation for strong data governance and reduce operational overhead and risks.

As demonstrated in our recent 3T@3 Series session, automated solutions like Patronum give you the capability to actively monitor and manage permissions and access, streamline your onboarding and offboarding processes, and secure your Google Workspace environment.

Contact us or schedule time to connect with a Cloud Advisor at Cumulus Global to arrange your workspace security review and to explore your options.

Ready to Take the Next Step?

Whether you’re beginning your cloud migration or looking to improve an existing environment, our Cloud Advisors can help.

Schedule a conversation

Allen Falcon

Co-Founder & CEO, Cumulus Global

Allen Falcon co-founded Cumulus Global in 2006 to help small businesses implement enterprise-grade cloud, security, and compliance solutions. Under his leadership, Cumulus Global has grown into a managed cloud services provider supporting more than 1,000 organizations throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-07-31 11:31:542026-07-31 11:39:33Secure Gemini AI in Google Workspace

Recent Posts

  • 9.5 Questions to Answer for a Secure AI Foundation
  • Three Pillars of AI Security for SMBs and Schools
  • Secure Gemini AI in Google Workspace

Featured Blog Topics

  • Artificial Intelligence / AI
  • Managed Cloud Services
  • Cybersecurity

Read

  • Blog
  • Newsletter
  • Microsoft Cloud Monday
  • Google Workspace Wednesday

Watch

  • 3T@3 Series
  • Coffee and Clouds
  • Event Recordings
  • Cumulus Global Channel

Explore

  • Library
  • Events Calendar

Phone / Fax / Email

  • 866-356-1202
  • 508-948-4070
  • info@cumulusglobal.com

Headquarters / Boston

  • Street Address

    4 Bellows Rd / 2nd Floor
    Westborough, MA 01581

  • Mailing Address

    PO Box 1129
    Westborough, MA 01581-6129

Regional Offices

  • Southeast Office

    120 W Trinity Pl
    Decatur, GA 30030

Copyright © 2026 - Cumulus Global | Privacy Policy | Terms of Service | Disclaimer | Website by Cold Spring
Scroll to top Scroll to top Scroll to top