Tag Archive for: AI adoption

There’s an old saying that it’s better to be lucky than good. When it comes to protecting your business from cyber threats, that’s a gamble worth retiring.

We prefer a different version: the harder you work, the luckier you get. In cybersecurity, the organisations that look lucky when a major threat makes the news are almost always the ones that invested in operational security best practices long before the headline appeared; unglamorous, consistent work that quietly removes risk before any alert is published.

How AI Has Changed the Cybersecurity Threat Landscape

AI has fundamentally changed the economics of a cyberattack. For years, the raw materials for a breach – old leaked credentials, previously disclosed vulnerabilities, forgotten accounts, unpatched devices – have been sitting in the open. What’s changed is that attackers can now use AI to comb through years of those exposures and test them against live networks at a speed and scale that simply wasn’t practical before.

The FortiBleed activity is a recent example. It wasn’t a single, novel zero-day. It was a systematic recycling of vulnerabilities and credential leaks that were already known and already disclosed – assembled by AI into a working attack against internet-accessible firewalls and VPN gateways. The materials were old. The method was new.

That pattern isn’t unique to one vendor or one product. It’s the shape of the modern threat landscape: the cost of patience has dropped to near zero for attackers, which means the margin for “we’ll get to it eventually” has narrowed considerably for everyone else.

Lucky or Prepared? The Real Difference in Cybersecurity

Here’s the encouraging part. For organisations that had been practising sound operational security, an event like FortiBleed wasn’t an emergency; it was a normal course of business. Review the controls, confirm everything was in order, and move on.

That isn’t luck. It’s the compounding return on consistent work. The teams that hadn’t done the work spent that same week in a fire drill. Same threat, very different week.

The difference comes down to a handful of disciplines that, done routinely, quietly remove most of the risk before any alert is published.

Operational Security Best Practices: The Fundamentals That Work

Operational security isn’t a product you buy. It’s a set of habits you keep. The ones that matter most:

Routine firmware updates.

The devices that run your network – firewalls, switches, access points – need firmware maintained on a schedule, not whenever someone remembers. Outdated firmware is one of the most common ways old vulnerabilities stay exploitable long after a fix exists. If your team discovered FortiBleed through the news rather than through a patch notification, that’s a gap worth closing.

Managed software patching.

Patching should run on a defined cadence and be verified, not assumed. “The update was available” and “the update is installed and the system rebooted” are very different things, and only one of them protects you.

Strong credential management.

Most modern attacks don’t break in, they log in. A business-wide password manager, enforced multifactor authentication (MFA) on every account that matters, and the elimination of generic or default logins close off the easiest path an attacker has. Credentials are the new perimeter; treat them that way.

A minimised attack surface.

Management interfaces shouldn’t be reachable from the public internet. Unnecessary accounts and services should be turned off. Every door you don’t need is one you don’t have to defend.

Routine review of controls.

Security configurations drift over time as people change roles, projects launch, and systems are added. A regular review – confirming that the controls you put in place are still in place and still working – is what keeps a strong posture from quietly eroding.

None of these are exotic. That’s precisely the point. They reward consistency, not cleverness.

Why Operational Security Is Your Best Defence Against AI-Powered Attacks

In an environment where attackers move at machine speed, disciplined operational security may be your single most effective defence – paired with AI-assisted detection and response that can spot and contain trouble at the same pace threats are moving. One side reduces how much can go wrong; the other shortens how long it takes to catch what does.

But tools and tactics only go so far without one more ingredient: treating IT security as a core business competency, with genuine leadership support behind it. Threats like FortiBleed don’t reward the organisations that bought the most software. They reward the ones that operate well, every day – and that takes leadership deciding security is worth doing properly.

Strengthening Your Operational Security With Go West IT

Insisting that security be a core competency doesn’t mean building all of it in-house. The execution and the guidance can be entrusted to a partner who does this work every day – keeping firmware and software current, managing credentials and access, hardening your platforms, and reviewing your controls so nothing drifts.

That’s where Go West IT comes in: helping you put the right fundamentals in place, keep them running, and turn the next industry-wide scramble into a routine exercise.

The harder you work on the fundamentals, the luckier you’ll look when the next threat comes around. We’d be glad to help you do that work.

If you’d like to review where your organisation stands on operational security, we’re here.

Further reading: CISA, “CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure” (June 2026)

Frequently Asked Questions About Operational Security

What is operational security in IT?

Operational security (OpSec) in an IT context refers to the ongoing discipline of maintaining controls that protect a business’s systems, data, and network. This includes routine practices such as firmware and software patching, credential management, MFA enforcement, minimising the attack surface, and regularly auditing that existing controls are still working. Unlike a one-time security audit, operational security is a set of continuous habits – the consistent work that reduces risk before a threat materialises.

What does the FortiBleed vulnerability mean for my business?

FortiBleed refers to a wave of attacks exploiting previously disclosed vulnerabilities in Fortinet devices – particularly firewalls and VPN gateways – combined with leaked credentials. Attackers used AI to systematically test known exposures against live networks. If your business uses Fortinet or similar edge devices and has not applied recent firmware updates or rotated credentials following prior disclosures, it is worth reviewing your posture. CISA published guidance in June 2026 specifically urging organisations to harden Fortinet devices and review credential exposure.

What is the single most important step I can take to improve my business’s cybersecurity right now?

If you’re starting from scratch, enforcing multifactor authentication (MFA) across all key accounts – email, remote access, admin portals – delivers the most immediate reduction in risk. Most successful breaches involve compromised credentials; MFA closes off that path even when a password is known. From there, a structured firmware and patching schedule, combined with a regular review of who has access to what, will address the majority of the remaining exposure.

Once a business starts using paid AI models like OpenAI or Anthropic’s Claude, something predictable happens. Someone – often not a developer by title – builds something. An app. An agent. A workflow that automates a task the team used to dread. And it works. It brings real, measurable value.

That’s the moment the ground shifts. Because in the age of capable AI, we’re all developers now – and AI app hosting is no longer a question just for technical teams. Deciding where your AI-built applications live, who controls them, and how they’re kept secure is a business decision. Getting the answer right early makes everything easier.

Why AI App Momentum Doesn’t Stop at One

Our experience at Go West IT is that once a business sees what’s possible, this doesn’t stay a one-time event. The first useful app inspires the second. A colleague sees it and builds their own. Within a few months, what started as one person’s experiment has become a small portfolio of tools the business is starting to rely on.

That’s really exciting, and it’s also where the important questions begin.

The Right Questions to Ask Before You Host AI Applications

As your team builds more, four questions quickly matter:

  • Where are these apps hosted and who is responsible for keeping them running?
  • Where does the code live, and who controls it if a key person leaves?
  • How do you manage access, is this internal only, or will clients interact with it?
  • How do you ship updates as the app evolves and improves?

These aren’t roadblocks. They’re the sign that something experimental is becoming something real. The businesses that answer them early turn a pile of promising experiments into durable, supportable assets.

How We Host AI-Built Apps at Go West IT: Our Azure Setup

We’re already well down this path internally, and we made a deliberate decision from the start: rather than scatter applications across personal accounts and consumer-grade tools, we’d build on a secure environment we already manage and trust.

In practice, that means:

Hosting in Azure. Our applications run in a managed cloud environment with redundancy, backups, and room to grow – not on someone’s laptop or a free-tier account that disappears when they change roles.

Identity and access through Microsoft Entra ID. Authentication and access management are handled consistently across our applications, so we always know who can reach what – whether the app is internal-only or touches client data.

Code managed in Azure DevOps. Our repositories live there, and we push code from DevOps straight to the application in Azure. That gives us version control, a documented change history, and a clean, repeatable way to ship updates.

The payoff is that as more applications surface – and they will – we’re not reinventing the approach each time. We have a repeatable, supportable process that protects three things at once: operational efficiency (we ship and maintain without chaos), intellectual property (the code your team creates is a business asset, governed like one), and operational security (access, hosting, and change management are controlled by design, not by accident).

How Much Does AI App Hosting Cost? Azure Pricing Explained

One of the most reassuring parts of this conversation is that the costs are knowable and modest relative to the value.

A basic application can run on an Azure Static Web App for approximately $9 per month. A more robust application – one that needs to run in a Linux container, for example – typically lands in the $100 to $200 per month range. Either way, you’re working with predictable monthly recurring costs you can plan around.

That predictability makes return on investment easy to evaluate. It also opens the door to a new metric worth tracking: Return on Tokens – how much did you spend, in AI usage and supporting infrastructure, to build and run that app, and is the value it returns worth it? That’s the difference between ‘we think this AI thing is helping’ and ‘we know exactly what this costs and what it returns.’

Building an AI App Hosting Strategy That Scales

If deciding whether your business is AI-ready was the first step, this is the natural next one: giving the things your team builds a secure, permanent, well-managed home – and a strategy that scales as the next app, and the one after that, arrives.

This is the path we’ve walked ourselves, which is exactly why we can guide you down it. Go West IT can help you stand up a secure hosting and development foundation – Azure for hosting, Entra for identity, Azure DevOps for code, so the value your team is creating with AI becomes something lasting, protected, and supportable.

You’re already building. Let’s make sure what you build has somewhere solid to stand.

If you’d like to talk through a hosting and development strategy for your AI-built applications, we’re here.

Frequently Asked Questions About AI App Hosting

What is the cheapest way to host an AI-built application?

A basic application can run on an Azure Static Web App for approximately $9 per month. This is suitable for lighter tools; internal dashboards, simple agents, or workflow automations that don’t require a dedicated server. More complex applications, such as those that need to run in a Linux container, typically cost $100 to $200 per month. Both options offer predictable monthly costs and enterprise-grade reliability.

What security considerations apply to AI app hosting?

Key areas to address include identity and access management (Microsoft Entra ID handles authentication and controls who can reach each application), code version control (Azure DevOps ensures a documented, repeatable deployment process), and data governance (knowing whether client data or internal data flows through each application and how it is stored and protected). Hosting on a managed cloud platform like Azure also provides redundancy and backup capabilities that consumer-grade tools do not.

What is ‘Return on Tokens’ in AI app development?

Return on Tokens is a metric for evaluating the value of an AI-built application against its actual running costs – including AI model usage fees and hosting infrastructure. It helps businesses move from “we think this is helping” to “we know exactly what this costs and what it returns,” making it easier to prioritize which applications are worth developing and maintaining.

Is your business adopting AI strategically or are employees already using AI tools without clear policies, security controls, or oversight?

Artificial intelligence is no longer something businesses are “thinking about.”

It’s already here.

Employees are using AI tools to write emails, summarize meetings, analyze spreadsheets, generate marketing content, assist with coding, and automate repetitive work. In many organizations, AI adoption is happening faster than leadership realizes.

The challenge is not whether businesses should use AI.

The challenge is whether they are prepared to use it responsibly, securely, and strategically.

As we discussed in AI Conversations Are Accelerating Business Innovation But What Does That Mean for IT Security?, AI adoption is accelerating across nearly every industry. But moving quickly without clear guardrails can introduce operational, compliance, and cybersecurity risks businesses may not fully understand yet.

AI readiness is not about having all the answers.

It’s about asking the right questions early.

1. Who Owns AI Strategy Inside Your Organization?

One of the biggest mistakes businesses make with AI adoption is assuming it will “figure itself out.”

In reality, AI works best when someone is steering the process.  

That does not necessarily mean hiring a Chief AI Officer or building a dedicated AI department.

But businesses should identify:

  • Who evaluates AI tools
  • Who approves use cases
  • Who manages risk discussions
  • Who ensures policies are followed
  • Who measures business value

Without ownership, AI adoption often becomes fragmented.

Different teams begin using different tools independently, sensitive information may be exposed unintentionally, and businesses lose visibility into where AI is being used and why.

The goal is not to slow innovation down.

It’s to ensure adoption happens intentionally.

 

2. Do You Have an AI Use Policy?

Many businesses already have employees using AI tools without any formal guidance.

That creates significant risk.

According to Microsoft Work Trend Index1, employees are often adopting AI tools faster than organizations can establish governance around them.

An AI use policy helps define:

  • Which AI tools are approved
  • What types of data can be used
  • What information should never be entered into AI systems
  • Expectations around human review and accountability
  • Compliance considerations for regulated industries

As outlined in Go West IT’s AI Readiness guidance, organizations should explicitly prohibit employees from inputting confidential client data, financial information, personally identifiable information (PII), or protected health information into consumer-grade AI tools.  

This is especially important for industries like:

  • Financial services
  • Healthcare
  • Legal
  • Accounting
  • Professional services

A simple, readable policy is often more effective than a complicated one no one follows.

3. Are Your Existing Security Controls Ready for AI?

AI adoption introduces new types of security considerations.

Businesses often focus on productivity first and security second.

But AI tools interact with:

  • Cloud platforms
  • Internal documents
  • SaaS applications
  • Sensitive data
  • Identity systems
  • Business workflows

That means AI readiness is closely connected to cybersecurity readiness.

As we explored in Modern Security for the Distributed Workforce, businesses already operate across increasingly decentralized environments. AI expands that complexity further.

Organizations should evaluate whether they have:

  • Multifactor authentication (MFA)
  • Single sign-on (SSO)
  • Identity management controls
  • Data loss prevention policies
  • Endpoint visibility
  • Security monitoring
  • User access governance

Go West IT’s AI Readiness framework also recommends implementing technical guardrails such as SSO integration, input/output restrictions, and controlled AI access layers where appropriate.  

The question is not simply:
“Can employees use AI?”

The better question is:
“Can they use it safely?”

4. Is Your Team Trained to Use AI Responsibly?

AI literacy is quickly becoming a business necessity.

Many employees understand what AI tools can do.

Far fewer understand:

  • What AI should not be used for
  • How hallucinations occur
  • Why outputs require validation
  • How sensitive data may be exposed
  • What ethical concerns exist around AI-generated content

According to IBM AI Insights2, businesses are increasingly integrating AI into operational workflows, making employee understanding and oversight increasingly important.

Training helps close the gap between intention and behavior.

As outlined in Go West IT’s AI Readiness guidance, organizations should provide baseline AI literacy training and reinforce that AI is a productivity tool not an authority. Human review remains essential.  

This is not about fear.

It is about responsible adoption.

5. Are You Measuring Business Value or Just Experimenting?

AI adoption should ultimately support business outcomes.

That could include:

  • Improved efficiency
  • Faster response times
  • Reduced repetitive work
  • Better reporting
  • Operational automation
  • Improved customer experiences

But businesses should still ask:

  • What problem are we solving?
  • How will we measure value?
  • Is this tool improving productivity?
  • Are we reducing risk or introducing it?
  • Is adoption aligned with business goals?

As discussed in Will AI Agents Replace SaaS Applications?, AI is rapidly reshaping how businesses interact with software and workflows. But successful adoption requires intentional planning not random experimentation.

Go West IT’s own AI Readiness framework emphasizes revisiting AI initiatives regularly because the tools, risks, and opportunities evolve quickly.  

AI readiness is not a one-time project.

It’s an ongoing operational conversation.

AI Readiness Is Really About Operational Readiness

The businesses seeing the most success with AI are not necessarily the ones adopting tools the fastest.

They are the ones creating structure around adoption.

That includes:

  • Clear ownership
  • Practical policies
  • Security guardrails
  • Employee training
  • Strategic use-case evaluation

As we discussed in Why Small Businesses Need a Cybersecurity Framework, mature technology strategies are rarely built on isolated tools alone. They are built on structured processes, visibility, and governance.

AI is no different.

Final Thoughts

Most businesses are already exploring AI in some form.

The question is whether that adoption is happening intentionally.

AI readiness does not require perfection. It requires visibility, ownership, training, and thoughtful guardrails that align innovation with security and operational goals.

Because the businesses that benefit most from AI will not simply be the ones that adopt it first.

They will be the ones that adopt it responsibly.

If your organization is beginning to explore AI tools, workflows, or governance strategies, now is the time to start building the foundation for long-term success.

FAQs

1. What does it mean for a business to be AI-ready?

AI readiness means a business has the policies, ownership, security controls, and training needed to adopt AI tools responsibly and effectively.

2. Why do businesses need an AI use policy?

An AI use policy helps define approved tools, acceptable use, data handling expectations, and employee accountability to reduce operational and security risks.

3. What are the biggest AI risks for small businesses?

Common risks include data exposure, compliance issues, inaccurate outputs, shadow AI usage, identity security concerns, and lack of governance.

4. Should employees be trained on AI usage?

Yes. AI literacy training helps employees understand both the benefits and limitations of AI tools, including security, privacy, and ethical considerations.

5. Does AI readiness only apply to large companies?

No. Small and mid-sized businesses are rapidly adopting AI tools as well, making governance, security, and operational readiness important for organizations of all sizes

 

 

Sources:

https://www.ibm.com/think/topics/artificial-intelligence-business-use-cases

https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part

 

The owner of this website has made a commitment to accessibility and inclusion, please report any problems that you encounter using the contact form on this website. This site uses the WP ADA Compliance Check plugin to enhance accessibility.