As a security professional within a small or medium-sized business (SMB) grappling with the adoption of Claude, it's crucial to move beyond initial surprises and quickly understand the implications for both business operations and security. The pace of change is swift, and it's essential for security to adapt accordingly. Here are some insights gained from experience and discussions with other leaders in the security field.
Understanding Your Product Choices
Before diving into adoption, it's imperative to clarify your objectives and the specific Claude plan your organization intends to purchase. Each plan comes with different security features; for example, while Single Sign-On (SSO) is available on the Team plan, access to the Compliance API is reserved for the Enterprise plan. Claude Code (Code), Cloud Cowork (Cowork), and Claude Chat (Chat) serve distinct purposes, meaning not every employee will require access to all three.
It’s beneficial to establish an agile approval process to evaluate who genuinely requires a Claude license and for what features. This aims to manage potential security risks effectively. Many employees may engage with “shadow AI tools” independently, further complicating the risk assessment. Reports indicate that as many as half of employees are experimenting with unsigned AI tools. While licensed users might seem like a higher risk, unlicensed users could be experimenting in riskier environments without oversight.
The realm of AI is evolving continuously, and that presents a challenge for those of us in security roles. Updates to Claude occur almost daily, meaning features can change on a whim. Don’t feel pressured to have all the answers or security measures in place immediately; this is a collective learning journey for everyone involved.
Quick Tip: If you're unsure about your Claude plan's features, consult Claude directly. Asking it about functionality can yield clarity, and encouraging team members to explore the information can also lighten your load.
Phased Feature Rollout
A phased rollout of features can diminish security risks, so avoiding enabling everything all at once is advisable. Users may demand full feature access immediately, but it's wise to prioritize and assess risk levels for each feature. Enabling certain functions in Claude might come with warnings, while others might not clearly indicate potential risks.
For effective management, categorizing features by risk is a sound strategy. By creating tranches—such as “enable immediately,” “enable with oversight,” and “postpone until risks are mitigated”—you can create a responsible rollout plan. Reference materials, such as implementation guides, can aid in this process.
Managing API keys is another critical aspect of security. The Anthropic API key should be tightly controlled, as the primary account holder wields significant power over these keys. Understanding the different types of API keys and keeping the processes for issuing them secure is vital, especially when initiating an account.
Quick Tip: Claude has the capability to analyze visual content. If you're wrestling with the implications of a feature's security settings, prompt Claude with a screenshot for a more informed assessment around security policies and compliance.
No Substitute for Human Oversight
It's essential to realize that security generally isn't a built-in feature of Claude products. While Anthropic is working to refine its security offerings, the burden of understanding the risks still falls on your organization. For example, enabling Skills could inadvertently lead to issues like malicious code execution if not monitored carefully. We took the initiative to design a "skills auditor" with Claude Code, allowing us to assess skills based on established security protocols.
Another significant hurdle is the necessary governance over data. The challenge lies not only in what’s fed into Claude, but also in monitoring what comes out. The web search functionality in Cowork is particularly revealing; it may bypass your existing content controls, and the potential for hallucinations—where the AI fabricates information—could lead to significant missteps if users take such outputs at face value.
Quick Tip: Instead of navigating these issues alone, collaborate with existing vendors and security tools to gather insights on emerging uncertainties. They’re adjusting as rapidly as you are and may have useful perspectives to share.
While the dream is for AI to autonomously address security vulnerabilities, navigating implementation choices requires adept decision-making. As an SMB security leader, you're accustomed to agility and quick, informed decision-making. Your expertise positions you well to balance the inherent risks and rewards, paving the way for successful adoption.
This article is published as part of the Foundry Expert Contributor Network.
Interested in joining?