Skip to main content

Fostering trust in the age of misinformation, disinformation, and malinformation

Web Hosting & Remote IT Support

The reality for many organizations is that their employees are already being deceived. So, probably are their customers, their investors, and their board.

For years, the warnings have focused on the impact of deepfakes, such as fake CEOs on video calls, cloned voices authorizing payments, and fraudulent emails.

The tactics themselves are not new, but over the past few years, AI has made them cheaper to produce, harder to spot, and far more convincing within the ordinary flow of business.

It’s this trend that means that the principle of Zero Trust is becoming as relevant to how information is treated as it has been to access.

In cybersecurity, Zero Trust starts from a simple assumption: no user, device, application or request should be trusted by default.

In the age of AI-generated misinformation, businesses need to apply that same mindset to the information that moves throughout their organization.

The new trust crisis

Employees, customers, investors and partners are all making decisions based on what they see, read and hear. If that information is false, manipulated or stripped of context, the consequences can move quickly from confusion to commercial damage. Which is why misinformation, disinformation, and malinformation need to be treated as business risks.

Misinformation – the false content that spreads without deliberate intent – has always been an issue. Disinformation, constructed specifically to deceive, is now easier to manufacture at scale than ever before. And malinformation – true information, often deliberately stripped of context and weaponized – might be the most insidious of the three. A competitor, a criminal group, or an activist campaign no longer needs to breach a network to cause serious damage. They can influence those associated and concerned with an organization simply by shaping what those people see and believe.

What makes this particularly difficult for businesses is that it mirrors something individuals are already struggling with. In an environment saturated with AI-generated content, the habits that people must employ to protect themselves – pause before reacting, questioning the source, verifying before acting – are the same habits that organizations must build into how they operate.

Essentially, the instinct to trust has become a vulnerability. And addressing that requires something closer to a structural response than an awareness campaign.

The importance of verified trust

This is where Zero Trust becomes the strategy. Traditionally, organizations have thought about Zero Trust through the lens of least privilege, ensuring that the right users have access to the right applications, and nothing more. But in an AI-driven information environment, that principle needs to evolve. Businesses can no longer focus just on who is requesting access. They also need to interrogate what information is being used, what action is being taken, and whether the intent behind the action can be trusted.

The next stage is going beyond authentication and investigating authenticity, and asking questions such as “Is this information verified?”, “Is this image real or AI-generated?”, and “Has this content been edited?”. Zero Trust gives businesses a framework for answering those questions. It forces organizations to verify before they act, limit exposure where they can, and reduce the risk of false, manipulated, or decontextualised information moving unchecked through the business.

Standards bodies such as the C2PA (Coalition for Content Provenance and Authenticity) show the direction that this is heading: a future where provenance and integrity are embedded in digital content itself, the same way a padlock in a browser indicates that the connection is secure. Essentially trust won’t be something that businesses need to check for, rather it will be something that travels with the information as provenance feeds verifications. Every piece of content therefore becomes a signal in a continuous trust decision.

Developing Trust in the agentic era

The need to trust intent has become even more pressing as AI agents enter the workplace. These agents will increasingly operate like another person working alongside us, mirroring our behaviors, such as reading documents, interpreting data, making decisions, and acting. The difference, however, is that these non-human identities are moving at machine speed, where human-speed verification has no hope of keeping up.

That means AI agents must be governed through a Zero Trust model from the outset. An agent should not be trusted just because it sits inside the enterprise, has been approved by a user, or is connected to corporate systems. Its identity, permissions, behavior and outputs all need to be continuously validated. Just as importantly, agents should be governed by least privilege, the principle of least information, and least function, granting only the minimum access, data, and capability required for a specific task.

However, these agents create a trust challenge that identity management alone can’t solve. Businesses will need to know whether they are dealing with a human or a machine, whether an agent is behaving responsibly, and whether its actions reflect an organization’s values and boundaries. Effectively, businesses will need to adopt an operating constitution that agents are continuously measured against.

And in this AI era, enterprises must interrogate information, content, intent, behavior, and action in realtime and continuously as identity is generally just checked as front door access. However, given the scale of the task at hand, it will take AI to audit, flag, and govern as needed and keep the chain of trust intact.

Engineering trust into the business

The organizations that succeed will be those that treat trust as something to be engineered, rather than assumed. Misinformation, disinformation, malinformation are security, resilience, and leadership challenges, and AI is making them harder to ignore.

As technology continues to shape how information is created, shared, and acted upon, businesses need to build the same discipline around authenticity that they’ve always applied to access. That means verifying content, questioning intent, and limiting what AI systems can do to what they actually need to do.

Trust can no longer be the default setting. Instead, in today’s operating environment, it must be a decision that’s made continuously, at machine speed, across information, intent, behavior, and action. The good news is that the framework already exists in Zero Trust. What needs to change however is how organizations apply it, broadening the scope to include information, intent, behavior, and action.

We've reviewed, rated, and ranked the best internet security suites.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit



via Hosting & Support

Comments

Popular posts from this blog

These mobile games are just trying to steal your crypto hoard, FBI warns

Web Hosting & Remote IT Support The FBI has warned consumers about a newly-detected, fake "play-to-earn" mobile and online game that tricks victims into depositing cryptocurrency, only to later steal it.  In a public service announcement , the FBI said the elaborate scheme sees scammers first contact the potential victim and try to build a relationship with them.  After a little back-and-forth, the scammers would invite the victim to play an online or mobile game, in which players purportedly earn cryptocurrency rewards in exchange for some activity, “such as growing ‘crops’ on an animated farm” the FBI said.  Depositing cryptos But getting into the “game” isn’t free - the victims must first create a cryptocurrency wallet and deposit some money, which is where the real scam begins. The fraudsters would later also tell the victims that the more funds they deposit, the higher the gains will be. However, as soon as the victim stops depositing additional funds, the...

Want a remote control for your smart home? SwitchBot has made a Matter-compatible one

Web Hosting & Remote IT Support SwitchBot has launched a unique piece of tech capable of controlling smart home devices and infrared appliances. And the best part is you don’t need to connect it to a smartphone or to the internet as it functions perfectly offline.  Aptly named the SwitchBot Universal Remote , it has large spacious buttons, a navigation wheel in the middle, and a 2.4-inch LCD at the top. The company states in their announcement it sought to create a “user-friendly design” that everybody can understand. Now, you can’t just point the Universal Remote at a device and then push a button to issue commands immediately. According to Android Central , you must first choose what you want to control, which can be done by pressing the center red button. Pressing the main button will let you change which group of smart home devices to control.  Universal Remote has launched! 🚀 Consolidate all your remotes, and control everything at home, even #automation! NOW,...