Cyber Security in the Age of AI — Five Steps for Protecting Government Data

Oct 31, 2024 | Blog, Uncategorized


City AI Connection is a series of posts on emerging ideas in artificial intelligence, with a focus on government application. These articles are initially shared exclusively with the City AI Connect community and subsequently with a broader audience via the Bloomberg Center for Government Excellence at Johns Hopkins University website, 
govex.jhu.edu. City AI Connect is a global learning community and digital platform for cities to trial and advance the usage of generative artificial intelligence to improve public services. The community is open exclusively to local government employees. To join, visit cityaiconnect.jhu.edu

By Lena Geraghty

As artificial intelligence permeates public sector operations, local governments, with their enormous stores of sensitive information, are facing new digital threats that demand stronger cyber security measures. 

AI relies on large datasets, and improper handling of government data like social security numbers, medical details, and bank account information can lead to breaches of privacy and data misuse. These systems are prime targets for hacking, putting both individual data and public infrastructure at risk. 

 The good news? Many municipalities already take cyber security seriously — 96 percent of respondents to the Public Technology Institute’s 2023 Local Government Cybersecurity National Survey say that their organization provides cyber security training at least once a year. 

You have probably participated in these exercises, like mock phishing attempts and password updates, in your own organization. These essential practices are a solid start but, in the age of AI, are not enough to adequately protect government-owned data. 

As we close out Cyber Security Awareness Month, here are five steps governments can take to build more resilience in their data infrastructure in the age of AI.

Conduct a Risk Assessment — Evaluate where AI solutions are or will be used, especially in high-risk areas like public safety, utilities, or resident services. Test AI solutions using adversarial scenarios to understand how they can be manipulated or evaded by malicious actors. Then, devise a plan to address these issues.

Build a Strong Foundation of Data Governance — Create an information security policy to ensure airtight collection, storage, and processing of data used in AI models and tools. Focus on limiting the amount of personal and sensitive data processed by AI systems to reduce exposure in the event of an attack.

Engage in Regular Audits and Compliance Checks — Partner with third-party experts to conduct periodic security assessments to identify vulnerabilities in AI systems, datasets, or software solutions. Ensure AI solutions comply with relevant data protection regulations and sector-specific laws. Assess vendors and tech providers for security practices, ensuring they meet your institution’s cyber security standards.

Train Staff and Build Awareness  Enhance cyber security training to include AI-related risks. Include tips for recognizing highly realistic and persuasive content created by Generative AI tools. Ensure staff understand the incident response process for AI-related security breaches and can act quickly in the event of an attack.

Engage External Experts and Collaborate — Join intergovernmental forums or networks focused on AI security to share best practices, threat intelligence, and resources. If you are a city government employee, GovEx’s City AI Connect is a great place to start. This field is constantly evolving so partner with cyber security and AI specialists to remain up-to-date on the latest threats and defensive techniques.

Lena Geraghty is a data and government advisor for GovEx. 

 

Four ways to make data work better for residents

Four ways to make data work better for residents

Every single government in the world, from small cities and counties to federal giants, is somewhere on a data journey. The farther they go, the more they’re set up to deliver effective, equitable public services.

Laredo, TX Case Study

Laredo, TX Case Study

The Center for Government Excellence (GovEx) worked with Laredo to establish a data governance structure, increase internal access to data, create data standards for collection and definitions of data, and address staff concerns about data quality, all with a focus on elevating the City’s data practice long term and building staff capacity to take on this work.

Grand Rapids, MI Case Study

Grand Rapids, MI Case Study

Grand Rapids entered into GovEx/WWC engagement to advance its ability to deliver results for its residents by establishing data management practices, in order to bring data and evidence into the decision-making process to increase equity and the quality of life in the City, enabling progress towards the City’s goals and connecting with the community in the process.

Covid-19 Data Is a Mess. We Need a Way to Make Sense of It.

Covid-19 Data Is a Mess. We Need a Way to Make Sense of It.

Our Johns Hopkins University Centers for Civic Impact Executive Director Beth Blauer along with Dr. Jennifer Nuzzo, associate professor of epidemiology at the Johns Hopkins Bloomberg School of Public Health, wrote an op-ed in The New York Times on November 23, 2020.

Banish the thumb drive: a call for better internal data sharing

Banish the thumb drive: a call for better internal data sharing

Some people’s pet peeve is loud chewing; others hate the Oxford comma. Here’s mine: thumb drives.  First of all, can we choose one name for these things? They’re also referred to as “flash drives,” “jump drives,” and “USB drives,” plus a few other names. Let’s choose...

4 Tips to a Clear and Friendly Dashboard

4 Tips to a Clear and Friendly Dashboard

A city dashboard’s primary goal is to give citizens a clear, user-friendly tool to see how well their city is doing. When designing your dashboard, always keep in mind how easy it would be for the average citizen to use. If you include too many factors into your...

So you want to start a data academy…

So you want to start a data academy…

Data can be powerful. But to really harness your data, you need people skilled in analysis, data management, and data-informed decision-making. Many cities are taking that lesson to heart and launching their own data academies to help employees learn to use data better.

GovEx Releases New Smart Cities Guide As Part of Research Collaborative

GovEx Releases New Smart Cities Guide As Part of Research Collaborative

Smart cities projects have proliferated in recent years, and this guide captures some of the best examples around the country along with resources and guidance to help cities understand the foundations of data practices that are necessary for any successful smart cities initiative.

Richmond, VA’s Neighborhood KPIs

Richmond, VA’s Neighborhood KPIs

Richmond is in the process of aligning its priorities, goals, and metrics and has identified 44 KPIs in its seven focus areas to track progress toward the city’s strategic priorities.

Being ‘Sensitive’ about Data Sensitivity

Being ‘Sensitive’ about Data Sensitivity

Open data is great because it’s open. But not all data is meant to be open. A lot of it is “sensitive.” What could be “open data” is often classified as “sensitive data” to protect the personal information and identity of individuals. Sensitive data may be restricted...