Generative AI's impact on organization structures
The impact of generative AI depends on the current organizational structures. Traditionally, there have been tensions between data science teams and security teams. Data science often needs broad access to data while security strives for a least-privilege approach.
Organizations that follow a methodology of scaling security instead
of consolidating it into a single organizational structure will be
better positioned for success. A scaled approach creates a culture
of security and helps security leaders focus on core issues. One
example of a scaled approach is the
AWS Security Guardians program
An organization can take a similar approach and embed security into its data science teams, called shifting security left. This keeps security close to the work, allowing for fast feedback. When taking this approach, it's important to take the approach of enablement instead of simply blocking work from happening. While it's easier to say "no," a better approach is to think of how to say "yes, but."
Technical organizations that invest in a scaled security approach also see an increase in software delivery velocity, because security reviews are traditionally gatekept by a central team. There is an organizational tax imposed whenever a team moves between organizational structures. This tax can be reduced by keeping a tight feedback loop with security.