<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Proton Blog</title><description>News from the front lines of privacy and security</description><link>https://proton.me/</link><language>en</language><feed_url>https://proton.me/feed</feed_url><item><title>Shadow AI is a hidden risk to your business</title><link>https://proton.me/business/blog/shadow-ai</link><guid isPermaLink="true">https://proton.me/business/blog/shadow-ai</guid><description>Learn what shadow AI is, how it exposes business data, how to detect unapproved AI tools, and how to reduce the security and compliance risks.</description><pubDate>Fri, 07 Aug 2026 11:21:34 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI tools are now part of everyday work, helping people summarize meeting notes, draft emails, debug code, analyze spreadsheets, and turn documents into presentations. Used without approval or oversight, however, they can raise serious &lt;a href=&quot;https://proton.me/lumo/ai&quot;&gt;AI privacy&lt;/a&gt; concerns, expose sensitive business information, and leave IT teams unable to see where company data is going.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This guide covers what shadow AI is, how it spreads inside organizations, and the serious risks it creates. We’ll show how to spot unapproved tools and implement practical safeguards to protect your business data — without slowing your team down.&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#what-is&quot;&gt;What is shadow AI?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#shadow-it&quot;&gt;Shadow AI vs. shadow IT&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how&quot;&gt;How does shadow AI happen?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#auto-ai-training&quot;&gt;Does AI automatically train on your data?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#examples&quot;&gt;Examples of shadow AI&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#risks&quot;&gt;What are the shadow AI risks?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#detect&quot;&gt;How to detect shadow AI&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#reduce-risks&quot;&gt;How to reduce shadow AI risks&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#what-to-do&quot;&gt;What to do if sensitive data has already been shared&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#lumo&quot;&gt;A private AI assistant for teams&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;what-is&quot; class=&quot;wp-block-heading&quot;&gt;What is shadow AI?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI is any use of &lt;a href=&quot;https://proton.me/lumo/ai&quot;&gt;artificial intelligence&lt;/a&gt; for work that falls outside a business&amp;#8217;s approved systems and policies. It can involve an unapproved tool, a personal account used for company work, or an approved AI service used with data or for tasks the organization has not authorized.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI often starts with everyday workplace pressures: a tight deadline, the need to find a faster or better way to work, or a tool that is not quite getting the job done. Sometimes, an approved AI tool is available, but people turn elsewhere because they are more familiar with another option.&lt;/p&gt;



&lt;h3 id=&quot;shadow-it&quot; class=&quot;wp-block-heading&quot;&gt;Shadow AI vs. shadow IT&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/shadow-it&quot;&gt;Shadow IT&lt;/a&gt; is the broader term for any software or hardware used without an organization’s approval or oversight. Common examples include personal &lt;a href=&quot;https://proton.me/drive&quot;&gt;cloud storage&lt;/a&gt; used for work, unauthorized messaging apps, and unapproved project management platforms.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI is a specific form of shadow IT involving AI systems and AI-powered features. AI introduces an additional data governance challenge because company information may be submitted to an external system or processed in unfamiliar ways outside the organization’s control.&lt;/p&gt;



&lt;h2 id=&quot;how&quot; class=&quot;wp-block-heading&quot;&gt;How does shadow AI happen?&lt;/h2&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1008&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1008,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA&quot; alt=&quot;A process flow diagram showing how shadow AI happens&quot; class=&quot;wp-post-254799 wp-image-254825&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;62 KB&quot; data-optsize=&quot;16 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;74.4&quot; data-version=&quot;1786093900&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_126,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_430,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_323,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_645,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_860,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_659,c_scale/f_auto,q_auto/v1786093900/wp-pme/how-shadow-ai-happens/how-shadow-ai-happens.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees can enter large amounts of company information into an AI chat window within seconds. Depending on the AI’s settings, the tool may retain the input, share it with other parties (such as &lt;a href=&quot;https://proton.me/blog/data-brokers&quot;&gt;data brokers&lt;/a&gt; or analytics vendors, like in the &lt;a href=&quot;https://proton.me/business/blog/openai-data-breach&quot;&gt;OpenAI breach&lt;/a&gt; case), or use it for targeted ads or model development.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI usually spreads because of a few common organizational gaps.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;No approved alternative&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees are more likely to use shadow AI tools when the business has not provided an approved option A &lt;a href=&quot;https://www.blackfog.com/blackfog-research-shadow-ai-threat-grows/&quot;&gt;BlackFog survey&lt;/a&gt; of 2,000 workers&amp;nbsp; found 49% of employees adopt AI tools without employer approval, 63% think it&amp;#8217;s acceptable to use AI when there&amp;#8217;s no corporate-approved option, and 51% have connected AI tools to work systems without IT&amp;#8217;s knowledge.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Unclear policies&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees may be unsure which tools, tasks, and types of information are permitted. Company guidance may clearly restrict highly sensitive data while saying little about internal meeting notes, draft emails, spreadsheets, source code, or customer conversations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://www.itbrew.com/stories/more-than-one-third-of-it-pros-arent-confident-employees-know-ai-policies&quot;&gt;IT Brew&amp;#8217;s survey&lt;/a&gt; run on 241 IT professionals found that 35% have little to no confidence employees know their company&amp;#8217;s AI usage and data security policies, and only 12% felt “very confident.” A separate &lt;a href=&quot;https://datacentrenews.in/story/over-half-of-firms-lack-clear-ai-policy-as-risks-mount-survey-finds&quot;&gt;WorkNest survey&lt;/a&gt; of 505 HR professionals/employers found 54% of organizations have no AI policy at all, 24% are still developing one, and only 13% have clear, documented rules.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Slow approval processes&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Pressure to meet deadlines can make a lengthy security or procurement review feel impractical. When employees can access a free tool immediately, slow internal processes make unofficial workarounds more likely.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;New AI features in approved software&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A vendor may add generative AI features to an application that has already passed a security review, and the software stays on the approved list even though nobody has assessed how the new feature processes, stores, or shares company data. The employee hasn&amp;#8217;t broken any policy, but the result is the same as the other causes: Company data is now moving through a channel nobody has actually vetted.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Limited awareness of data handling&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees may not know how AI providers like &lt;a href=&quot;https://proton.me/lumo/ai/is-chatgpt-safe&quot;&gt;ChatGPT&lt;/a&gt; and &lt;a href=&quot;https://proton.me/lumo/ai/is-gemini-safe&quot;&gt;Gemini&lt;/a&gt; retain prompts, process uploaded files, use conversations for service improvement, or share data with other providers. They may assume their inputs disappear when they close the browser tab, even when copies remain in account histories, logs, backups, or connected systems.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://www.kolide.com/blog/89-of-workers-use-ai-far-fewer-understand-the-risks&quot;&gt;Kolide&amp;#8217;s report&lt;/a&gt; found that while 89% of employees use AI monthly, only 56% of companies have explained &lt;a href=&quot;https://proton.me/lumo/ai/security&quot;&gt;AI&amp;#8217;s security risks&lt;/a&gt; to staff.&lt;/p&gt;



&lt;h2 id=&quot;examples&quot; class=&quot;wp-block-heading&quot;&gt;Examples of shadow AI&lt;/h2&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Team&lt;/th&gt;&lt;th&gt;Example of shadow AI&lt;/th&gt;&lt;th&gt;&lt;br&gt;Information potentially exposed&lt;/th&gt;&lt;th&gt;Potential impact&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Software development&lt;/td&gt;&lt;td&gt;Pasting internal code into a public chatbot for debugging&lt;/td&gt;&lt;td&gt;Source code, credentials, system architecture, and unreleased features&lt;/td&gt;&lt;td&gt;Proprietary code or secrets may be retained outside company systems&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Product&lt;/td&gt;&lt;td&gt;Uploading a roadmap for summarization&lt;/td&gt;&lt;td&gt;Launch dates, product strategy, pricing, and partner information&lt;/td&gt;&lt;td&gt;Confidential business plans may sit unmanaged on third-party servers&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Marketing and design&lt;/td&gt;&lt;td&gt;Entering campaign plans into an AI writing or design tool&lt;/td&gt;&lt;td&gt;Unreleased products, customer research, brand assets, and audience data&lt;/td&gt;&lt;td&gt;Sensitive campaign information may be processed without legal or security review&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Data analysis&lt;/td&gt;&lt;td&gt;Uploading customer datasets to an external analysis tool&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://proton.me/blog/personal-data&quot;&gt;Personal data&lt;/a&gt;, commercially sensitive records, and confidential insights&lt;/td&gt;&lt;td&gt;Protected or regulated information may be disclosed to unapproved third parties&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Human resources&lt;/td&gt;&lt;td&gt;Using an AI tool to assess applications or summarize interviews&lt;/td&gt;&lt;td&gt;Candidate data, employment information, and assessment criteria&lt;/td&gt;&lt;td&gt;Personnel data exposure may breach GDPR or CCPA&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sales&lt;/td&gt;&lt;td&gt;Uploading call transcripts or account notes for analysis&lt;/td&gt;&lt;td&gt;Customer identities, contract details, pricing, and sales strategy&lt;/td&gt;&lt;td&gt;Customer data exposure may breach GDPR or CCPA&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Customer support&lt;/td&gt;&lt;td&gt;Pasting support tickets into a public chatbot&lt;/td&gt;&lt;td&gt;Customer names, account details, complaints, and correspondence&lt;/td&gt;&lt;td&gt;Retained support records may violate GDPR or CCPA&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Finance&lt;/td&gt;&lt;td&gt;Asking an AI assistant to analyze internal spreadsheets&lt;/td&gt;&lt;td&gt;Budgets, forecasts, payroll information, and transaction records&lt;/td&gt;&lt;td&gt;Financial data may be processed without appropriate safeguards&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Legal&lt;/td&gt;&lt;td&gt;Uploading contracts or case files for summarization&lt;/td&gt;&lt;td&gt;Privileged advice, contractual terms, and client information&lt;/td&gt;&lt;td&gt;Client data misuse may breach GDPR or CCPA and affect privilege&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Leadership&lt;/td&gt;&lt;td&gt;Using an AI service to review board documents or strategic plans&lt;/td&gt;&lt;td&gt;Acquisition plans, internal targets, and executive discussions&lt;/td&gt;&lt;td&gt;Highly sensitive corporate intelligence may become exposed&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;auto-ai-training&quot; class=&quot;wp-block-heading&quot;&gt;Does AI automatically train on your data?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/llm&quot;&gt;Large language models (LLMs)&lt;/a&gt; do not automatically retrain themselves on every prompt in real time, so a conversation won’t inevitably become part of the AI model or appear in another user’s response. However, the level of risk depends on the provider, account type, privacy settings, contract, and how the service has been configured.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An AI provider may retain prompts and uploaded files, make them available for human review, use them to improve its services, or share them with infrastructure and model providers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even when model training is disabled, information may appear in account histories, operational logs, abuse-monitoring systems, backups, browser records, connected services, or third-party integrations. If your content has already contributed to model training, turning off this option won’t make the model forget your past conversations.&lt;/p&gt;



&lt;h2 id=&quot;risks&quot; class=&quot;wp-block-heading&quot;&gt;What are the shadow AI risks?&lt;/h2&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1200&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1200,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA&quot; alt=&quot;A chart that explains the risks of shadow AI&quot; class=&quot;wp-post-254799 wp-image-254849&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;260 KB&quot; data-optsize=&quot;65 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;75&quot; data-version=&quot;1786093960&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1786093960/wp-pme/shadow-ai-risks/shadow-ai-risks.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI can influence decisions, generate customer-facing material, write code, or analyze personal data, all of which create risks extending beyond the security of the tool itself:&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Data breach&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;IBM’s 2025 &lt;a href=&quot;https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications,-97-of-which-reported-lacking-proper-ai-access-controls&quot;&gt;Cost of a Data Breach Report&lt;/a&gt; found that one in five organizations had experienced a &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;breach&lt;/a&gt; linked to shadow AI, yet only 37% had policies designed to manage or detect it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Organizations with high levels of shadow AI faced breach costs averaging $670,000 more than those with little or no shadow AI. Further, incidents involving shadow AI exposed personal information and intellectual property more frequently than the global average.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Exposure of confidential information&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees may share internal documents, source code, financial information, contracts, customer records, product plans, or trade secrets without realizing the AI provider retains their inputs. Even when information is excluded from model training, it can remain exposed to account compromise, security breaches, provider access, insecure integrations, or legal demands.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, &lt;a href=&quot;https://www.forbes.com/sites/siladityaray/2023/05/02/samsung-bans-chatgpt-and-other-chatbots-for-employees-after-sensitive-code-leak/&quot;&gt;Samsung banned ChatGPT&lt;/a&gt; company-wide in May 2023 after employees pasted confidential material into it three times in 20 days, including semiconductor source code, defect-detection algorithms, and a transcribed internal meeting.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Loss of intellectual property&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proprietary knowledge is often a company’s most valuable asset. Uploading code, research, product designs, processes, or strategy documents to an external AI service may conflict with confidentiality agreements or weaken the business’s ability to control that information. An employee may also use AI-generated content without understanding its origins, licensing restrictions, or similarity to third-party material.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Privacy and regulatory violations&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Personal data remains subject to data privacy law when it is processed through an AI tool. Shadow AI can bypass privacy safeguards because the relevant legal teams never know that the processing is taking place. The UK Information Commissioner’s Office warns that AI systems can &lt;a href=&quot;https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-should-we-assess-security-and-data-minimisation-in-ai/&quot;&gt;amplify existing security risks&lt;/a&gt;. Serious GDPR infringements can lead to penalties of up to €20 million or 4% of the organization’s worldwide annual turnover from the previous financial year, whichever is higher.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Insecure integrations and excessive access&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI tools may connect to email, cloud storage, calendars, code repositories, customer databases, and collaboration platforms. Broad permissions, poorly secured APIs, leaked access tokens, malicious browser extensions, and compromised third-party services can expose company systems and data beyond the information entered in a single prompt.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In the &lt;a href=&quot;https://proton.me/business/blog/salesloft-drift-attack&quot;&gt;Salesloft Drift breach&lt;/a&gt;, attackers stole OAuth tokens from Drift, an AI sales-assistant integration, and used them to pull data out of Salesforce instances at more than 700 organizations, including business contacts, API keys, and cloud credentials embedded in support cases.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Prompt injection attacks&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This vulnerability exists in any connected AI system, approved or not — attackers can manipulate an AI system through instructions hidden in documents, webpages, emails, or other content it processes, causing it to reveal information, ignore its original instructions, or take unintended actions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI raises the stakes because an unapproved tool or &lt;a href=&quot;https://proton.me/blog/ai-agent&quot;&gt;AI agent&lt;/a&gt; may never have been assessed for prompt injection or limited to the permissions it needs. If an attack succeeds, security teams may have little visibility into what happened or how to contain it. The consequences are especially serious when the AI agent can access sensitive data or take actions without human review.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Lack of accountability&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI activity often leaves no central audit trail. Security teams may be unable to determine which information was submitted, which model processed it, what output it produced, or how the result influenced a decision. Investigating an error, complaint, &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breach&lt;/a&gt;, or regulatory question becomes much harder without those records.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Unexpected costs and supplier dependence&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Separate subscriptions and API accounts can create duplicated spending across departments. Experimental tools may also become embedded in important workflows before procurement teams have assessed their pricing, reliability, or long-term availability. A free service can become business-critical without a service agreement, continuity plan, or practical way to move the workflow elsewhere.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;detect&quot; class=&quot;wp-block-heading&quot;&gt;How to detect shadow AI&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Shadow AI can be difficult to detect because employees may use personal accounts, browser extensions, embedded AI features, &lt;a href=&quot;https://proton.me/blog/ai-browsers-perplexity-chrome-privacy&quot;&gt;AI browsers&lt;/a&gt;, or tools that blend into normal web traffic. Organizations therefore need visibility into which services are being used and how company data moves through them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Monitoring should remain proportionate and respect employee privacy. The goal should be to identify risky tools and data flows without routinely inspecting the contents of every prompt or conversation.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1200&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1200,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA&quot; alt=&quot;A chart that explains how to detect shadow AI&quot; class=&quot;wp-post-254799 wp-image-254873&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;81 KB&quot; data-optsize=&quot;23 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;71.9&quot; data-version=&quot;1786094058&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1786094058/wp-pme/shadow-ai-detection/shadow-ai-detection.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here are some tips for identifying shadow AI within your organization:&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Create an inventory of AI use&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ask teams which AI tools they currently use, what tasks they use them for, and what prevents them from using approved alternatives. A short survey, interviews with department leads, and a voluntary disclosure period can reveal uses that technical controls miss. Employees are more likely to be honest when the goal is to understand their needs rather than punish early experimentation.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Review network and application activity&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security teams can use network logs, software inventories, and cloud access security tools to identify connections to known AI services. Monitoring can show which services are being accessed and how much data is transferred without capturing the content of every conversation.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Audit browser extensions and plug-ins&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Browser extensions can add AI writing, summarization, translation, meeting, and coding features to almost any workflow. Review which extensions are installed, what permissions they request, and whether they can read webpage content, email, documents, or login information.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Check expenses and procurement records&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employee expense claims, corporate card statements, and procurement records may reveal paid AI subscriptions that have never completed a security review. Repeated payments from different teams can also uncover duplicated tools and unofficial accounts.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Search for unmanaged API keys and integrations&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Review code repositories, secrets managers, cloud environments, billing dashboards, and automation platforms for connections to external AI providers. Unmanaged API keys or unfamiliar usage charges may indicate a prototype, integration, or internal tool that has not been formally approved.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Use data loss prevention controls&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/data-loss-prevention&quot;&gt;Data loss prevention&lt;/a&gt; tools can identify attempts to upload sensitive categories of information such as personal records, credentials, financial data, and source code. Controls should be proportionate and clearly communicated. Employees need to understand what is monitored, why it is necessary, and how to complete legitimate work through approved systems.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Work with employees rather than around them&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Technical monitoring alone will not reveal every instance of shadow AI. Employees may use personal accounts, mobile devices, or tools that appear as normal web traffic. Regular discussions with teams can identify where existing workflows create friction and why employees seek external tools.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;reduce-risks&quot; class=&quot;wp-block-heading&quot;&gt;How to reduce shadow AI risks&lt;/h2&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1200&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1200,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA&quot; alt=&quot;A chart that explains how to reduce shadow AI risk&quot; class=&quot;wp-post-254799 wp-image-254897&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;110 KB&quot; data-optsize=&quot;32 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;71.1&quot; data-version=&quot;1786094119&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1786094119/wp-pme/reduce-shadow-ai-risks/reduce-shadow-ai-risks.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Reducing shadow AI requires practical alternatives, clear policies, appropriate access controls, employee training, and ongoing review. Effective safeguards should support legitimate AI use while keeping company data within approved systems:&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Give employees an approved AI tool&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees are less likely to search for alternatives when you provide&amp;nbsp; a &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt; that meets their practical needs. Any approved tool should offer strong privacy protections, clear data handling terms, appropriate business controls, and enough capability to support common tasks.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Avoid a blanket ban&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A complete ban can push AI use further underground, especially when employees already depend on these tools. Some may move to personal accounts, mobile devices, browser extensions, or less reputable AI services that are harder for the organization to identify.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Create an AI acceptable-use policy&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Use examples based on real workflows. “Do not share sensitive information” leaves too much room for interpretation. A clearer policy might tell employees never to upload customer support exports, source code, contracts, credentials, unreleased financial results, or identifiable employee records to an unapproved service.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Classify data before setting AI rules&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Identify which categories of information are public, internal, confidential, regulated, or highly restricted. Connect each category to permitted AI uses. Public marketing copy may be appropriate for a wider range of tools, while personal data, credentials, trade secrets, and privileged legal material may require a tightly controlled system or be excluded entirely.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Periodically review approved software for new AI features&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An application may process data differently after adding an AI assistant, automatic transcription, content generation, or predictive analysis. Regular vendor reviews can identify these changes and confirm that previously approved tools still meet the organization’s security, privacy, and compliance requirements.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Limit permissions&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Give AI tools access only to the data and systems needed for an approved task. Use company-managed accounts, &lt;a href=&quot;https://proton.me/business/blog/what-is-sso&quot;&gt;single sign-on (SSO)&lt;/a&gt;, &lt;a href=&quot;https://proton.me/blog/what-is-two-factor-authentication-2fa&quot;&gt;two-factor authentication (2FA)&lt;/a&gt;, role-based permissions, and centralized account removal where available. Avoid connecting a &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt; to an entire drive, inbox, or customer database when a narrower source will work.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Set rules by role and use case&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Different teams have different needs and levels of risk. Developers may need API access for testing or prototyping. Marketing teams may need text and image generation. Legal or HR teams may work with information that requires much stronger restrictions. Role-based rules can keep the policy realistic while limiting access to sensitive data and high-risk functions.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Train employees&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees need enough AI literacy to understand both the benefits and limitations of the systems they use. Training should cover &lt;a href=&quot;https://proton.me/lumo/ai&quot;&gt;AI privacy&lt;/a&gt;, confidentiality, hallucinations, bias, intellectual property, prompt injection, human review, and incident reporting. The appropriate training level depends on staff knowledge, experience, and the context in which the AI is used.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Create a simple approval process&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A working process might collect the tool name, intended task, data involved, required integrations, and expected business benefit. Security and legal teams can then approve, restrict, test, sandbox, or reject it based on the actual risk. A long procurement process may encourage employees to find their own workaround. Set a reasonable review target and explain what information is needed to reach a decision.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Keep people responsible for the output&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI-assisted work should have a human owner. Require a review before outputs affect customers, employees, finances, legal decisions, production code, published information, or other high-impact areas. Any person using an AI tool remains responsible for checking its accuracy, appropriateness, confidentiality, and compliance with company policy.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Document important AI-assisted decisions&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Keep a clear record when AI contributes to decisions that affect customers, employees, finances, legal matters, or other high-impact areas. A reliable audit trail supports accountability and helps organizations investigate errors, explain outcomes, and respond to complaints or regulatory questions.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;what-to-do&quot; class=&quot;wp-block-heading&quot;&gt;What to do if sensitive data has already been shared&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Treat an accidental disclosure to an AI tool like any other potential data incident. Move quickly through the following steps.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Identify what was shared:&lt;/strong&gt; Confirm what information was entered or uploaded, which tool and account were used, when the disclosure happened, and who may have had access to the data.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Remove the information where possible:&lt;/strong&gt; Delete the conversation and any uploaded files from the tool. Check the provider’s terms and support options to see whether you can submit a formal deletion request.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Check what the provider may retain:&lt;/strong&gt; Removing a chat from view doesn’t always erase every copy. Review and document what the provider says about operational logs, backups, human review, model training, and deletion timeframes to help determine whether any data may remain.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Secure affected systems:&lt;/strong&gt; Revoke permissions granted to the AI tool or connected plug-ins. Rotate any &lt;a href=&quot;https://proton.me/pass&quot;&gt;passwords&lt;/a&gt;, API keys, access tokens, or other credentials that appeared in the prompt or attached files.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Notify the relevant teams:&lt;/strong&gt; Report the incident to the organization’s security, privacy, legal, or data protection team. They can assess contractual obligations, regulatory requirements, and whether affected customers or partners need to be informed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Learn from the incident:&lt;/strong&gt; Document what happened and use it to improve training, controls, and approved alternatives. Avoid punishing employees who report genuine mistakes, since a punitive response may discourage others from raising future incidents.&lt;/p&gt;



&lt;h2 id=&quot;lumo&quot; class=&quot;wp-block-heading&quot;&gt;A private AI assistant for teams&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lumo for Business gives your team a reliable AI assistant for summarizing documents, analyzing data, reviewing code, drafting content, and exploring ideas while helping your business maintain control of confidential information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt; does not keep logs of conversations or use them to train AI models, and any chat history you choose to save is protected with &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-access encryption&lt;/a&gt;, which means we never have access to your data&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lumo is fully &lt;a href=&quot;https://proton.me/community/open-source&quot;&gt;open source&lt;/a&gt;, built in Europe, and designed to support &lt;a href=&quot;https://proton.me/business/gdpr&quot;&gt;GDPR&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/healthcare&quot;&gt;HIPAA&lt;/a&gt; compliance through Proton’s &lt;a href=&quot;https://proton.me/business/iso-27001-certification&quot;&gt;ISO 27001 certification&lt;/a&gt; and &lt;a href=&quot;https://proton.me/blog/soc-2&quot;&gt;SOC 2 Type II attestation&lt;/a&gt;.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://lumo.proton.me/&quot;&gt;Chat with Lumo&lt;/a&gt;
&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-outlined-purple&quot; href=&quot;https://proton.me/business/lumo/pricing&quot;&gt;Get Lumo for Business&lt;/a&gt;
&lt;/div&gt;





&lt;p class=&quot;wp-block-paragraph&quot;&gt;Giving your team a capable, privacy-focused AI assistant reduces reliance on unapproved tools and helps you keep AI use within systems you oversee.&lt;/p&gt;
</content:encoded><category>For business</category><author>Tom Odlin</author></item><item><title>Vishing attacks: How businesses can defend against voice phishing</title><link>https://proton.me/business/blog/vishing-attacks-business</link><guid isPermaLink="true">https://proton.me/business/blog/vishing-attacks-business</guid><description>Learn what vishing is, why AI voice cloning makes voice phishing harder to spot, and get vishing attack prevention tips for your business.</description><pubDate>Thu, 06 Aug 2026 16:34:06 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vishing, or voice phishing, is a type of &lt;a href=&quot;https://proton.me/business/blog/phishing-attacks&quot;&gt;phishing attack&lt;/a&gt; carried out by phone or voice message – it can be a voice message, a video call, or a phone call. It’s used against businesses and individuals to steal data and money, or launch further scams.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A person’s voice is no longer trustworthy. And with AI voice cloning, attackers can impersonate a family member or a close friend with ease, sounding familiar enough to not raise any suspicion.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI voice cloning makes it more important than ever for businesses to strengthen their defenses against vishing scams. A convincing fake voice can be used to impersonate executives, employees, suppliers, or customers, increasing the risk of fraudulent payments, credential theft, &lt;a href=&quot;https://proton.me/business/blog/account-takeover-attacks&quot;&gt;account takeover&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breaches&lt;/a&gt;, and disruption to internal operations.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Because these attacks can exploit normal business processes and trusted relationships, organizations need verification procedures that do not rely on whether a caller sounds familiar or convincing.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#what&quot;&gt;What is vishing?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how&quot;&gt;How does vishing work?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#ai-vishing&quot;&gt;AI makes vishing harder to detect&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#scenarios&quot;&gt;Common vishing examples targeting businesses&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#credentials&quot;&gt;The credential connection&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#exposed&quot;&gt;Exposed data makes vishing more convincing&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#how-to&quot;&gt;How to verify a suspicious call&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#awareness&quot;&gt;Build vishing awareness around tactics, not scripts&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#after&quot;&gt;What to do after a suspected vishing call&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#proton-pass&quot;&gt;How Proton Pass for Business helps reduce credential risk&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;what&quot; class=&quot;wp-block-heading&quot;&gt;What is vishing?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vishing is a type of &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;phishing&lt;/a&gt; carried out over the phone or through voice messages. Scammers impersonate trusted people or organizations, such as banks, employers, government agencies, or family members, to trick victims into sharing sensitive information, sending money, or taking some other action.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The name comes from “voice” + “phishing.” It is closely related to &lt;a href=&quot;https://proton.me/blog/smishing&quot;&gt;smishing&lt;/a&gt;, which uses SMS or text messages instead of voice calls to carry out similar scams.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Today, vishing can also involve AI voice cloning, which lets scammers imitate a real person’s voice and make the call sound more convincing.&lt;/p&gt;



&lt;h2 id=&quot;how&quot; class=&quot;wp-block-heading&quot;&gt;How does vishing work?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vishing usually works by combining impersonation, &lt;a href=&quot;https://proton.me/blog/what-is-social-engineering&quot;&gt;social engineering&lt;/a&gt;, and urgency. It relies on the pressure of a live conversation to push someone into acting before they have time to verify a request. A caller might pretend to be from IT and ask to confirm a login, pose as a bank employee checking a suspicious transaction, or impersonate a senior executive who urgently needs a payment approved.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unlike &lt;a href=&quot;https://proton.me/business/mail/phishing-email&quot;&gt;phishing emails&lt;/a&gt;, there may be no suspicious link, attachment, or unfamiliar sender address to inspect. The caller may sound calm, convincing, or even familiar, especially if AI voice cloning is involved.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The goal is usually to persuade the victim to reveal credentials or one-time codes, approve a transfer, reset account access, or bypass a normal security process. In a business setting, that could mean tricking finance staff into authorizing a payment, impersonating IT support to collect login details, or convincing an employee to give an attacker access to a company account.&lt;/p&gt;



&lt;h2 id=&quot;ai-vishing&quot; class=&quot;wp-block-heading&quot;&gt;AI makes vishing harder to detect&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Traditional vishing scams often gave themselves away through poor scripts, obvious threats, noisy call centers, or callers who simply did not sound convincing. Some still do. But businesses can no longer treat voice quality, confidence, or familiarity as reliable signs that a call is genuine.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI voice cloning makes it possible to imitate real people closely enough to create believable requests. Attackers can combine a cloned voice with caller ID spoofing and personal details gathered from &lt;a href=&quot;https://proton.me/blog/linkedin-ai-training&quot;&gt;LinkedIn&lt;/a&gt;, company websites, public interviews, social media, or previous data breaches.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That makes familiar voices especially risky as a trust signal. People naturally judge callers by tone, confidence, hesitation, or whether the voice sounds like someone they know. AI can reproduce many of those cues, making an impersonated executive, colleague, vendor, or IT employee sound calm, rushed, authoritative, or concerned.&lt;/p&gt;



&lt;blockquote class=&quot;wp-block-quote is-layout-flow wp-block-quote-is-layout-flow&quot;&gt;
&lt;p class=&quot;wp-block-paragraph&quot;&gt;In 2025, the &lt;a href=&quot;https://www.ic3.gov/PSA/2025/PSA250515&quot;&gt;FBI warned&lt;/a&gt; that malicious actors were using smishing and AI-generated voice messages to impersonate senior US officials, build trust, and try to gain access to personal accounts.&lt;/p&gt;
&lt;/blockquote&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For businesses, attackers do not need a perfect imitation. They only need a call convincing enough to trigger an action, such as approving a payment, sharing a verification code, resetting a password, or changing account access.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That is why sensitive requests should be verified through another trusted channel, even when the caller sounds exactly like someone the employee knows.&lt;/p&gt;



&lt;h2 id=&quot;scenarios&quot; class=&quot;wp-block-heading&quot;&gt;Common vishing examples targeting businesses&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vishing works best when the request feels plausible. Attackers often choose scenarios that fit normal business routines, then add urgency. Here are common vishing examples:&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;IT support impersonation&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One common scenario is IT support impersonation. An employee receives a call from someone claiming to be from the company’s helpdesk, software provider, or security team. The caller may say there is a login issue, an urgent update, suspicious activity, or a migration that requires the employee to confirm credentials or read out a one-time code.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Finance impersonation&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Finance impersonation is another high-risk pattern. A caller pretends to be the CEO, CFO, a senior manager, or a trusted supplier that asks for a payment to be processed quickly. The pressure may be framed as confidential, time sensitive, or linked to a deal, invoice, tax issue, or vendor problem.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Bank fraud calls&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Bank fraud calls are also common. The caller claims to be from the company’s bank and warns about suspicious transactions. The employee is asked to confirm details, approve a security step, move money, or provide information that allows the attacker to access the account later.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Government impersonation&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Government impersonation can affect businesses too. Calls involving His Majesty’s Revenue and Customs (HMRC), the UK’s tax authority, are common enough that HMRC provides a dedicated route &lt;a href=&quot;https://www.gov.uk/find-hmrc-contacts/report-suspicious-hmrc-emails-texts-social-media-accounts-and-phone-calls&quot;&gt;to report suspicious phone calls&lt;/a&gt;. A caller may mention tax deadlines, VAT, payroll, penalties, refunds, or investigations to create urgency.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Supplier and customer impersonation&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There are also supplier and customer impersonation calls. A criminal may pretend to be a vendor changing payment details, a client requesting access to a portal, or a partner asking for a document link. The call may not ask for money immediately. It may only aim to collect information for a later attack.&lt;/p&gt;



&lt;h2 id=&quot;credentials&quot; class=&quot;wp-block-heading&quot;&gt;The credential connection&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vishing often ends at credentials, even when it starts as a conversation. An attacker may ask directly for a password, but many vishing attempts are more subtle. The caller may ask an employee to confirm a username, read out a verification code, approve a &lt;a href=&quot;https://proton.me/blog/what-is-two-factor-authentication-2fa&quot;&gt;two-factor authentication (2FA)&lt;/a&gt; prompt, or log in to a fake portal while the caller stays on the line.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once credentials are exposed, the damage depends on what those credentials can unlock. A reused password can give the attacker access to more than one service, for example. A shared login can make it harder to know who used the account, and a missing 2FA requirement can leave a password as the only barrier. An over-permissioned account can turn one successful call into broader access.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credential hygiene is an essential part of vishing attack prevention. Unique passwords for every service limit how far a stolen password can travel. A business password manager reduces the need for employees to remember or reuse passwords, and a built-in&lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt; password generator&lt;/a&gt;⁠ makes it much easier to create strong, unique passwords for every account. Secure sharing keeps credentials out of calls, chats, and documents. &lt;a href=&quot;https://proton.me/authenticator/&quot;&gt;2FA&lt;/a&gt; adds another barrier when a password is compromised.&lt;/p&gt;



&lt;h2 id=&quot;exposed&quot; class=&quot;wp-block-heading&quot;&gt;Why exposed data makes vishing more convincing&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A vishing call is more persuasive when the attacker already knows something about the business. That information may come from public sources: job titles, suppliers, executives, company structure, press releases, social media posts, conference videos, podcasts, or employee profiles.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It may also come from leaked or stolen data, including email addresses, phone numbers, account details, exposed credentials, or internal documents.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our&lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt; Data Breach Observatory&lt;/a&gt;⁠ shows how exposed data can create risk beyond the original breach. A criminal only needs a phone number, a job title, a vendor name, and an old password to seem credible.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees may have reused details elsewhere, suppliers may have been compromised, or attackers may combine multiple public and leaked sources to build a believable story. In practice, businesses should treat exposed data as fuel for future scams. The more an attacker knows, the less the call sounds random.&lt;/p&gt;



&lt;h2 id=&quot;how-to&quot; class=&quot;wp-block-heading&quot;&gt;How to verify a suspicious call&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you’re suspicious, end the call and verify for yourself whether the request was genuine. Vishing depends on keeping you on the line, encouraging you to answer now and act now. Verification only works when the employee can pause, leave that pressure, and return through a channel the business already trusts.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For any request involving credentials, payments, 2FA codes, remote access, bank details, account recovery, or permission changes, end the call and check the request separately. That may mean calling the person back using the company directory, contacting the bank through the number on its official website, opening an internal IT ticket, or checking supplier details already stored in the company’s records.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The callback number should never come from the caller. Caller ID is not enough either, because numbers can be spoofed. The point is to return to a trusted source, rather than continuing a conversation the attacker may be controlling.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Legitimate executives, suppliers, banks, and IT teams should expect verification for sensitive requests. A caller who becomes aggressive, demands secrecy, or refuses a callback is giving the employee a reason to stop, not a reason to move faster.&lt;/p&gt;



&lt;h2 id=&quot;awareness&quot; class=&quot;wp-block-heading&quot;&gt;Build vishing awareness around tactics, not scripts&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Awareness training for vishing should not only teach people to recognize a list of scam phrases. Scripts change quickly. The manipulation patterns are more stable.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees should learn to recognize the tactics behind the call, not just the script. They also need tactics of their own to fall back on when they’re unsure:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;If a caller makes them feel rushed, anxious, or responsible for fixing something immediately, that is a tactic, not proof of urgency. A caller may claim to be a senior executive, a bank fraud investigator, a tax authority, a supplier, or a security team member. The story can change, but the pressure often looks similar: act now, keep this confidential, trust my authority, and bypass the usual checks.&lt;/li&gt;



&lt;li&gt;Training also needs to include AI voice cloning. The message should be clear without creating panic: a familiar voice is not enough to authorize a risky action. Employees should be taught that they have the right to pause. If a caller asks for a payment, credential, code, access change, or urgent workaround, the safe response is to stop the conversation, ask for a few minutes, and verify the request through a known number or another trusted channel. &lt;/li&gt;



&lt;li&gt;A safe phrase, callback rule, or written approval workflow is more reliable than trying to judge whether someone sounds “off.” No legitimate urgent request should fail because of a short delay used for verification.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;after&quot; class=&quot;wp-block-heading&quot;&gt;What to do after a suspected vishing call&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A suspected phone phishing scam should be reported quickly, even when no money was sent and no password was shared. Near misses are useful because they show which employees, suppliers, or processes attackers may be targeting.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The first step is to record the details:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Time of the call&lt;/li&gt;



&lt;li&gt;Number displayed&lt;/li&gt;



&lt;li&gt;Caller claim&lt;/li&gt;



&lt;li&gt;Requested action&lt;/li&gt;



&lt;li&gt;Names mentioned&lt;/li&gt;



&lt;li&gt;Systems involved&lt;/li&gt;



&lt;li&gt;Whether any information was shared. &lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Make sure that the number provided by the caller is not contacted again.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If credentials, one-time codes, payment details, or remote access were shared, treat it as urgent:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Reset affected passwords&lt;/li&gt;



&lt;li&gt;Revoke sessions where possible&lt;/li&gt;



&lt;li&gt;Review account activity&lt;/li&gt;



&lt;li&gt;Enforce 2FA&lt;/li&gt;



&lt;li&gt;Check whether the same password was used anywhere else.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;proton-pass&quot; class=&quot;wp-block-heading&quot;&gt;How Proton Pass for Business helps reduce credential risk&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vishing is a human attack, but the damage often depends on credential controls such as passwords, shared access, and account protection. A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business helps teams reduce the risk that one successful call turns into broader access.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employees can generate strong, unique passwords for every service through Proton Pass’s built-in&lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt; password generator&lt;/a&gt;⁠, store them in encrypted vaults, use autofill, share credentials securely, manage passkeys, and use built-in two-factor authentication.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is valuable for vishing protection, because even if an attacker gets your password during a call, they still can’t get into the account without the second factor. Proton Pass also includes &lt;a href=&quot;https://proton.me/pass/pass-monitor&quot;&gt;Pass Monitor&lt;/a&gt; with dark web monitoring, which alerts you if your email appears in a known data breach, so you know when credentials may already be compromised.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass also gives businesses a safer default for day-to-day access. When employees have an approved way to store and share credentials, a caller asking them to read out a password or send access through chat should immediately feel unusual.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Make voice requests verifiable by default&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vishing works because the voice feels immediate and personal. A caller can sound confident, familiar, helpful, or authoritative. AI voice cloning makes that trust even less reliable. Businesses need a verification habit that does not depend on how convincing the caller sounds.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The most important rules are simple: do not share credentials on a call, do not approve unusual payments from a phone request alone, and do not trust caller ID as proof of identity. Hang up, verify through a known channel, and document anything suspicious.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For SMBs, the process can stay simple. Sensitive requests should have a callback rule, payments and access changes should require confirmation through another channel, and employees should know the authority and urgency tactics that make vishing convincing. Credentials also need to stay inside a business password manager, where passwords are unique, shared securely, and easier to rotate if a call leads to exposure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Voice phishing will keep evolving, especially as AI makes impersonation cheaper and more convincing. The defense is to make every sensitive request verifiable before anyone acts.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Protect your business credentials from voice phishing with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;⁠.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>What is the ‘kill switch’ that has European businesses so concerned?</title><link>https://proton.me/business/blog/tech-kill-switch-europe</link><guid isPermaLink="true">https://proton.me/business/blog/tech-kill-switch-europe</guid><description>A US-triggered technological “kill switch” could shut down operations of a European business overnight. Here’s what you can do.</description><pubDate>Thu, 06 Aug 2026 14:18:48 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Europe is growing more and more uncomfortable with its technological dependence on the US.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A new Proton study found that as many as &lt;a href=&quot;https://proton.me/business/blog/business-continuity-survey&quot;&gt;74% of European business leaders&lt;/a&gt; are afraid of a US kill switch cutting off their technology access. EU lawmakers are voicing the same concern.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&amp;#8220;The US holds &lt;a href=&quot;https://www.reneweuropegroup.eu/news/2026-06-15/the-suspension-of-access-to-anthropics-frontier-ai-models-is-yet-another-a-wake-up-call-for-europe&quot;&gt;a real &amp;#8216;kill-switch&amp;#8217;&lt;/a&gt; over essential technologies and they are more than willing to use it,&amp;#8221; said Christophe Grudler, a French member of European Parliament.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;His Finnish colleague Aura Salla put it more bluntly: &amp;#8220;Europe cannot keep building its tech stack on access that can be &lt;a href=&quot;https://www.usnews.com/news/top-news/articles/2026-07-22/exclusive-marco-rubio-tells-diplomats-to-play-down-talk-of-american-tech-kill-switch&quot;&gt;switched off overnight&lt;/a&gt; by a foreign government. We must take action to reserve our data and our market primarily for European tech to scale it and build our own frontier AI.&amp;#8221;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;And Henna Virkkunen, the European Commission&amp;#8217;s vice president for tech sovereignty, said the EU wants sensitive services and data controlled in Europe — with no foreign government or company holding a kill switch.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But what is a technological kill switch, and what are EU lawmakers so concerned about?&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is a technological kill switch?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A kill switch in a political context refers to the power of the US administration to restrict or cut off a foreign business&amp;#8217;s access to a tech service.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The government can enact a kill switch through an executive branch decision without any court order or additional sign-off. It just needs the relevant agency exercising authority Congress has already delegated to it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What are EU lawmakers afraid of?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Considering the deep dependence of European businesses on US tech platforms, a kill switch represents an existential risk. Proton research from last year found that &lt;a href=&quot;https://proton.me/business/europe-tech-watch&quot;&gt;74% of public European companies&lt;/a&gt; use American email providers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The fears are not theoretical. Three recent cases show what that looks like in practice:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Export controls on chips to China.&lt;/strong&gt; The US restricts which Nvidia chips can be sold into China, using export control law rather than a sanctions list. Nvidia had to design a cut-down chip, the H20, specifically to stay under the threshold, and even that has been caught up in further restrictions since. The effect lands on every business on the other end of the chip supply chain: Chinese AI companies lose access to leading-edge compute, and Nvidia itself has said the restrictions cost it billions in lost sales. The restriction targets an entire product category — chips, above a certain capability, going to a certain destination — and everyone in that category is affected at once.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The Anthropic Mythos and Fable cutoff.&lt;/strong&gt; In June 2026, the US Department of Commerce &lt;a href=&quot;https://www.anthropic.com/news/fable-mythos-access&quot;&gt;ordered Anthropic to cut off foreign national access&lt;/a&gt; to its two most capable AI models, citing export control rules. This one didn&amp;#8217;t name a country or an individual either. It reached every foreign national at once, including at allied institutions in Europe. Businesses that had built workflows on those models lost access with no warning and no way to appeal individually. The US eventually reversed the order, but the Trump administration continues to &lt;a href=&quot;https://www.techpolicy.press/five-questions-the-us-government-should-answer-about-its-secretive-frontier-ai-framework/&quot;&gt;hold a leash on frontier AI models&lt;/a&gt;.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Sanctions cutting off Microsoft access.&lt;/strong&gt; In February 2025, the &lt;a href=&quot;https://www.bbc.com/news/articles/cqjxddx12qqo&quot;&gt;US placed sanctions on the chief prosecutor of the International Criminal Court&lt;/a&gt; over the tribunal&amp;#8217;s investigation into Israeli Prime Minister Benjamin Netanyahu. Within days, the chief prosecutor, Karim Kahn, lost access to his Microsoft email account. Unlike the chip and Anthropic cases, this one worked through a named designation rather than a category-wide restriction — but the effect was the same: a US company had no legal choice but to comply, and an international institution&amp;#8217;s operations were disrupted as a result.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These cases show how commercial export of US technology sits entirely with a US agency, and the businesses affected have no legal standing to challenge it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How is a technological kill switch even possible?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It can be triggered fast, through either of two US laws.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;The International Emergency Economic Powers Act (IEEPA)&lt;/strong&gt; lets the president declare a national emergency and, on that basis, gives the Treasury Department authority to designate a specific person or entity. Once designated, it becomes illegal for any US company to keep doing business with them — which is what happened when Microsoft cut off the ICC chief prosecutor&amp;#8217;s email access.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The Export Control Reform Act (ECRA&lt;/strong&gt; gives the Commerce Department authority to bar US technology from reaching a listed destination, end use, or category of user — including by nationality — without naming any individual. This is the authority behind both the China chip restrictions and the Anthropic cutoff.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;IEEPA needs a named target, but the ECRA can restrict an entire category of user in one move, which is why the Anthropic order hit every foreign national simultaneously rather than one company or country.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What can Europe do?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;At the macro level, European leaders are focused on reducing the dependence itself. The &lt;a href=&quot;https://proton.me/business/blog/eu-tech-sovereignty-package&quot;&gt;European Commission&amp;#8217;s Cloud and AI Development Act&lt;/a&gt;, announced in June 2026, aims to bring sensitive cloud and AI workloads under EU-based control rather than relying on US providers for them.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Alongside it, the &lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/policies/chips-act-2&quot;&gt;Chips Act 2.0&lt;/a&gt; is meant to build up Europe&amp;#8217;s own semiconductor capacity, so the region isn&amp;#8217;t reliant on Nvidia or other US chipmakers for the hardware underneath its AI ambitions. Both are still years from changing the underlying dependence — sovereignty legislation moves slowly, and Europe&amp;#8217;s tech base is starting from a long way behind.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In the meantime, European businesses don&amp;#8217;t have to wait on Brussels. Choosing providers more carefully — understanding which services sit entirely within one company&amp;#8217;s legal reach, and what happens if that access disappears overnight — is something a business can do today. So is investing in European solutions that keep data and operations under EU jurisdiction, where a US executive order simply doesn&amp;#8217;t reach.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Want to learn more about whether Europe is prepared for an outage, a cyberattack, or a provider cutting off access outright? Read our multi-country survey asking founders, CEOs, and IT directors about &lt;a href=&quot;https://proton.me/business/blog/business-continuity-survey&quot;&gt;the effects of tech disruption on European businesses&lt;/a&gt;.&lt;br&gt;&lt;br&gt;&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>3 in 4 European businesses fear their US tech provider could cut them off</title><link>https://proton.me/business/blog/business-continuity-survey</link><guid isPermaLink="true">https://proton.me/business/blog/business-continuity-survey</guid><description>What happens if a US tech provider pulls support for your business? Most European companies have less than a day’s runway to find out.</description><pubDate>Thu, 06 Aug 2026 11:44:24 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;European business leaders don&amp;#8217;t believe they&amp;#8217;re in control of their digital tools. We discovered that 74% of them worry a US kill switch will disrupt their operations — about the same number as those who feared ransomware or cyberattacks.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That finding, revealed in a Proton survey of 1,500 European business leaders, signals that leadership teams and boardrooms are now weighing a high-level geopolitical risk on the same scale as the everyday threat of hackers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It&amp;#8217;s relatively rare for a foreign government to order a tech company to cut off access to services, what EU policymakers have referred to as a “&lt;a href=&quot;https://proton.me/business/blog/tech-kill-switch-europe&quot; data-type=&quot;link&quot; data-id=&quot;https://proton.me/business/blog/tech-kill-switch-europe&quot;&gt;kill switch&lt;/a&gt;.”But prominent examples from the US have stoked fears in recent months.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Washington signaled &lt;a href=&quot;https://www.bbc.com/news/articles/c33ln4mp1p2o&quot;&gt;threats over Greenland&lt;/a&gt; that put Danish businesses and policy makers on edge, blocked &lt;a href=&quot;https://apnews.com/article/icc-trump-sanctions-karim-khan-court-a4b4c02751ab84c09718b1b95cbd5db3&quot;&gt;Microsoft usage by the International Criminal Court&lt;/a&gt;, and &lt;a href=&quot;https://proton.me/business/blog/us-tech-risk-report-for-europe&quot;&gt;restricted global access&lt;/a&gt; to powerful &lt;a href=&quot;https://proton.me/blog/llm&quot;&gt;large language models&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Add these tensions to the risk of normal technical outages, and organizations are now turning to &lt;a href=&quot;https://proton.me/business/blog/business-continuity-strategies&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://proton.me/business/blog/business-continuity-strategies&quot;&gt;business continuity&lt;/a&gt; strategies to hedge their exposure, putting fallback communications and operations tools in place so they can keep working through any downtime.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To understand whether Europe is prepared for an outage, a cyberattack, or a provider cutting off access outright, we conducted a multi-country survey asking founders, CEOs, and IT directors about the effects of tech disruption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s what we found.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;56% say geopolitical risk is a factor in their tech purchasing decisions&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Worried the US administration could order providers to cut off IT services to foreign businesses overnight, European businesses are weighing these risks as heavily as ransomware or cyberattacks.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The concerns are valid. The US administration has already demonstrated a willingness to wield executive power, including sanctions, export controls, or tariff threats, to accomplish foreign policy goals.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Kill switch anxiety now at par with fear of cyberattacks&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If &lt;a href=&quot;https://proton.me/business/blog/ransomware-small-business&quot;&gt;ransomware&lt;/a&gt; and cyberattacks are worth mitigating with a security plan, then kill switch and outage risk is equally deserving of a proactive response. In reality the response is uneven, with organizations adopting business continuity solutions for one system at a time. Only 34% of businesses have a fallback for their most important platform: email.&lt;/p&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;How concerned are you that your company could lose access to a critical technology service due to a cyberattack or ransomware attack? vs How concerned are you that one of your US technology providers could disable your access through a kill switch?&lt;/em&gt;&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1024&quot; height=&quot;512&quot; src=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/08/20260804-chart_1-1024x512.jpg&quot; alt=&quot;Bar chart comparing concern over &amp;quot;Ransomware/Cyberattack&amp;quot; versus &amp;quot;US Kill Switch&amp;quot; across four groups. Approximate values: Total ~75% vs ~73%; Germany ~68% vs ~68%; France ~70% vs ~71%; UK ~84% vs ~71%.&quot; class=&quot;wp-post-252341 wp-image-252602&quot; srcset=&quot;https://pme.protonblog.tech/wp-content/uploads/2026/08/20260804-chart_1-1024x512.jpg 1024w, https://pme.protonblog.tech/wp-content/uploads/2026/08/20260804-chart_1-300x150.jpg 300w, https://pme.protonblog.tech/wp-content/uploads/2026/08/20260804-chart_1-768x384.jpg 768w, https://pme.protonblog.tech/wp-content/uploads/2026/08/20260804-chart_1-1536x768.jpg 1536w, https://pme.protonblog.tech/wp-content/uploads/2026/08/20260804-chart_1-2048x1024.jpg 2048w, https://pme.protonblog.tech/wp-content/uploads/2026/08/20260804-chart_1-1568x784.jpg 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Business continuity coverage is a patchwork&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A kill switch could impact the entire stack. If all your services are based in the US, a secondary provider that&amp;#8217;s also a US company may not be helpful. Only diversifying outside US jurisdiction provides a solution.&lt;/p&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;Does your company have continuity solutions for any of the following systems in the event of a disruption like an outage, a cyberattack, or losing access to a service you rely on?&lt;/em&gt;&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;512&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1785919299/wp-pme/20260804-chart-2/20260804-chart-2.jpg?_i=AA&quot; alt=&quot;Horizontal bar chart showing percentage of businesses ranking each tool category, from highest to lowest: Email ~33%, Cloud/File Storage ~28%, 2FA/Login Security ~27%, Password Manager ~26%, AI Tools ~24%, Documents/Spreadsheets ~23%, VPN ~22%, Video Conferencing ~19%, Calendar ~16%&quot; class=&quot;wp-post-252341 wp-image-252650&quot; data-format=&quot;jpg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;485 KB&quot; data-optsize=&quot;46 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;90.6&quot; data-version=&quot;1785919299&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1785919299/wp-pme/20260804-chart-2/20260804-chart-2.jpg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1785919299/wp-pme/20260804-chart-2/20260804-chart-2.jpg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1785919299/wp-pme/20260804-chart-2/20260804-chart-2.jpg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1785919299/wp-pme/20260804-chart-2/20260804-chart-2.jpg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1785919299/wp-pme/20260804-chart-2/20260804-chart-2.jpg?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1785919299/wp-pme/20260804-chart-2/20260804-chart-2.jpg?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;h4 class=&quot;wp-block-heading&quot;&gt;Two-thirds of businesses would switch providers after a government-triggered blackout&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A clear majority of businesses is willing to act. Businesses are planning for every kind of disruption — outages, cyberattacks, loss of access. They know that whatever the cause, the cost of going dark is too expensive to ignore.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;If a foreign government intentionally disabled or blocked access to a critical technology service your company relies on, how likely would you be to switch to an alternative provider?&lt;/em&gt;&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;512&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786012683/wp-pme/20260804_-_chart_3/20260804_-_chart_3.jpg?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-252341 wp-image-254395&quot; data-format=&quot;jpg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;185 KB&quot; data-optsize=&quot;10 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;94.8&quot; data-version=&quot;1786012683&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786012683/wp-pme/20260804_-_chart_3/20260804_-_chart_3.jpg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1786012683/wp-pme/20260804_-_chart_3/20260804_-_chart_3.jpg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1786012683/wp-pme/20260804_-_chart_3/20260804_-_chart_3.jpg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1786012683/wp-pme/20260804_-_chart_3/20260804_-_chart_3.jpg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1786012683/wp-pme/20260804_-_chart_3/20260804_-_chart_3.jpg?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1786012683/wp-pme/20260804_-_chart_3/20260804_-_chart_3.jpg?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;54% of businesses would stop work after just a day without access&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;No matter their size, 86% of businesses we surveyed said they experienced at least one disruption in the past 12 months from an outage, cyberattack, or loss of access to a service. And they say real money is at stake.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A huge share of businesses are living on a 24-hour buffer where a kill switch or technical outage would be an immediate operational crisis.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Most businesses are one bad day away from a shutdown&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;More than half (54%) of businesses say they couldn&amp;#8217;t survive more than a single business day before having to shut down services and operations until digital tools were back online. And each day of downtime comes with a real cost, with effects that touch a company&amp;#8217;s finances and its ability to operate.&lt;/p&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;If your company suddenly lost access to cloud and digital services or suffered a cyberattack, how long could it operate before having to shut down?&lt;/em&gt;&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1200&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1200,c_scale/f_auto,q_auto/v1785919845/wp-pme/20260804-chart-4/20260804-chart-4.jpg?_i=AA&quot; alt=&quot;Bar chart with unlabeled y-axis (0-25) showing values across time periods: &amp;quot;&amp;lt; 1 hour&amp;quot; ~10, &amp;quot;Half a day&amp;quot; ~20, &amp;quot;1 day&amp;quot; ~24, &amp;quot;3 days&amp;quot; ~19, &amp;quot;1 week&amp;quot; ~9, &amp;quot;1 week +&amp;quot; ~5.5.&quot; class=&quot;wp-post-252341 wp-image-252722&quot; data-format=&quot;jpg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;260 KB&quot; data-optsize=&quot;20 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;92.5&quot; data-version=&quot;1785919845&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1785919845/wp-pme/20260804-chart-4/20260804-chart-4.jpg?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1785919845/wp-pme/20260804-chart-4/20260804-chart-4.jpg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1785919845/wp-pme/20260804-chart-4/20260804-chart-4.jpg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1785919845/wp-pme/20260804-chart-4/20260804-chart-4.jpg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1785919845/wp-pme/20260804-chart-4/20260804-chart-4.jpg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1785919845/wp-pme/20260804-chart-4/20260804-chart-4.jpg?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1785919845/wp-pme/20260804-chart-4/20260804-chart-4.jpg?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;READ MORE: &lt;a href=&quot;https://proton.me/business/blog/us-tech-risk-report-for-europe&quot;&gt;How deep does Europe’s dependence go?&lt;/a&gt;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;Nearly 1 in 3 large businesses expect a six-figure loss from a single day offline&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Loss scales with size, as you&amp;#8217;d expect — though the number is stark: 29% of large businesses expect to lose more than €100,000 from a single day of downtime.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;If your tech systems went down for a day, how much do you estimate your company would lose?&lt;/em&gt;&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;512&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786022042/wp-pme/20260804-chart-5-1-1/20260804-chart-5-1-1.jpg?_i=AA&quot; alt=&quot;heatmap showing percentages by employee count&quot; class=&quot;wp-post-252341 wp-image-254556&quot; data-format=&quot;jpg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;383 KB&quot; data-optsize=&quot;31 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;92&quot; data-version=&quot;1786022042&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1786022042/wp-pme/20260804-chart-5-1-1/20260804-chart-5-1-1.jpg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1786022042/wp-pme/20260804-chart-5-1-1/20260804-chart-5-1-1.jpg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1786022042/wp-pme/20260804-chart-5-1-1/20260804-chart-5-1-1.jpg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1786022042/wp-pme/20260804-chart-5-1-1/20260804-chart-5-1-1.jpg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1786022042/wp-pme/20260804-chart-5-1-1/20260804-chart-5-1-1.jpg?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1786022042/wp-pme/20260804-chart-5-1-1/20260804-chart-5-1-1.jpg?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;A tech outage hits every part of the business&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A day offline doesn&amp;#8217;t just show up on a balance sheet. It stalls the work itself, strains relationships with customers, and, for some businesses, chips away at their reputation long after access is restored.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;has-text-align-center wp-block-paragraph&quot;&gt;&lt;em&gt;If your company lost access to these critical digital tools, how would it be affected?&lt;/em&gt;&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1200&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1200,c_scale/f_auto,q_auto/v1785920131/wp-pme/20260804-chart-6/20260804-chart-6.jpg?_i=AA&quot; alt=&quot;Lollipop chart showing % of respondents by business impact, color-coded by impact area (Customer-facing, Partners, Financial, Internal, None stated): &amp;quot;Unable to serve or support customers&amp;quot; ~37%, &amp;quot;Employees unable to stay productive&amp;quot; ~36%, &amp;quot;Unable to communicate&amp;quot; ~33.5%, &amp;quot;Unable to invoice or take payments&amp;quot; ~32%, &amp;quot;Unable to deliver goods and services&amp;quot; ~28%, &amp;quot;Supplier disruptions&amp;quot; ~27%, &amp;quot;None of the above&amp;quot; ~4.5%, &amp;quot;I don&amp;#039;t know&amp;quot; ~4%.&quot; class=&quot;wp-post-252341 wp-image-252770&quot; data-format=&quot;jpg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;457 KB&quot; data-optsize=&quot;41 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;91.1&quot; data-version=&quot;1785920131&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1785920131/wp-pme/20260804-chart-6/20260804-chart-6.jpg?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1785920131/wp-pme/20260804-chart-6/20260804-chart-6.jpg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1785920131/wp-pme/20260804-chart-6/20260804-chart-6.jpg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1785920131/wp-pme/20260804-chart-6/20260804-chart-6.jpg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1785920131/wp-pme/20260804-chart-6/20260804-chart-6.jpg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1785920131/wp-pme/20260804-chart-6/20260804-chart-6.jpg?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1785920131/wp-pme/20260804-chart-6/20260804-chart-6.jpg?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;But where that damage lands varies depending on what a business actually does.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;The tech and software segment&lt;/strong&gt; is disproportionately affected across every category, with &amp;#8220;unable to stay productive&amp;#8221; as its top impact. Because its entire business is its digital infrastructure, a kill switch threatens revenue, ops, customers, and reputation all at once.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Healthcare providers&lt;/strong&gt; feel it most acutely in email with 35% reporting disruptions there, the highest of any industry. The sector rates reputational damage as a bigger threat (31%) than any other segment, reflecting how much trust and public perception matter when patient-facing systems go down.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Business services&lt;/strong&gt; firms feel it most in their ability to serve customers with 40% saying a disruption would leave them unable to support clients.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;94% of businesses already have a business continuity plan in place&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Only 6% of businesses said they have no plan at all, or don&amp;#8217;t know if they do. But &amp;#8220;having a plan&amp;#8221; covers a wide range of readiness: 44% test theirs regularly, 36% have one but don&amp;#8217;t test it, and 13% describe theirs as informal.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As you consider your &lt;a href=&quot;https://proton.me/business/blog/technology-risk-management-plan&quot;&gt;business continuity plan&lt;/a&gt;, the findings of our survey point to important takeaways:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Identify which providers are US-owned — a US company can be compelled to cut your service, even if it&amp;#8217;s hosted on EU servers.&lt;/li&gt;



&lt;li&gt;Think in connected systems. Email, calendar, storage, and communications don&amp;#8217;t always fail in isolation during an outage or kill switch.&lt;/li&gt;



&lt;li&gt;Choose &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;&lt;u&gt;a business continuity solution&lt;/u&gt;&lt;/a&gt; before a crisis hits, not during. An outage becomes an operational crisis within a few hours.&lt;/li&gt;



&lt;li&gt;Test how your business continuity plan performs against a full kill switch scenario, not just a single system going down.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton&amp;#8217;s business continuity solution runs on European infrastructure, independent of Google, Microsoft, and Amazon. So when Big Tech goes down, you don&amp;#8217;t go down with them. Set up dormant accounts now, and your team can switch over the moment your primary tools fail, with no interruption to email, calendar, or video conferencing.&amp;nbsp;&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/business-continuity&quot;&gt;See how Proton&amp;#8217;s business continuity plan works&lt;/a&gt;
&lt;/div&gt;



&lt;hr class=&quot;wp-block-separator has-alpha-channel-opacity&quot;/&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Methodology&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This survey was conducted by Proton among 1,500 business leaders across the UK, Germany, and France (500 respondents per country), fielded July 15–24, 2026. Respondents were screened for involvement in their company&amp;#8217;s technology, backup, security, or continuity decisions — 32% identified as the main decision-maker, 38% share decision-making, and 30% influence recommendations. Respondents spanned a range of roles, including IT leaders (16%), founders/owners (7%), marketing and sales leads (12%), HR/People Ops leads (11%), and finance/procurement (10%), among others. Industries represented included technology/software (22%), healthcare (26%), business services (15%), and education/research (15%).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;em&gt;Correction: An earlier version of this article accidentally repeated the wrong survey question above a chart about continuing operations after an incident. It should have read, &amp;#8220;If your company suddenly lost access to cloud and digital services or suffered a cyberattack, how long could it operate before having to shut down?&amp;#8221; &lt;/em&gt;&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>Why human error is your biggest cybersecurity risk — and how to reduce it</title><link>https://proton.me/business/blog/human-error-cybersecurity-business-risk</link><guid isPermaLink="true">https://proton.me/business/blog/human-error-cybersecurity-business-risk</guid><description>Learn why human error is a major cybersecurity risk for businesses and how better systems and safer defaults can reduce employee mistakes.</description><pubDate>Wed, 05 Aug 2026 19:45:54 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Human error in cybersecurity is created by the tensions between how people work and how systems work. &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;Work passwords&lt;/a&gt; get reused when people are expected to remember too much. Credentials move through chat when there is no approved way to share them quickly. Risky access stays open when &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt; depends on someone remembering every account a person used.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The insecure choice is rarely intentional. It usually happens because the safer path is slower, confusing, or not available when people need it. Everyday pressures, like meeting a deadline, logging in from a new device, or getting quick access to a tool, can push people toward riskier shortcuts.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security shouldn’t only rely on employees remembering the rules or making the right choice every time. Training has an important role, but it needs to be reinforced by tools, defaults, and routines that make secure behavior easier in everyday work.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#employee-problem&quot;&gt;Human error in cybersecurity isn’t just an employee problem&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#common-human-errors&quot;&gt;Common human errors in cybersecurity&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#training&quot;&gt;Training alone can’t solve human error&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#default&quot;&gt;Make secure behavior the default&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#credential-mistakes&quot;&gt;Why credential mistakes spread so quickly&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#access&quot;&gt;Access should not depend on memory&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#review&quot;&gt;Review the systems around the mistake&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#tips&quot;&gt;Practical ways to reduce human error in cybersecurity&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#secure-behavior&quot;&gt;Make secure behavior easier than the shortcut&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;employee-problem&quot; class=&quot;wp-block-heading&quot;&gt;Human error in cybersecurity isn’t just an employee problem&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Human error is one of the most persistent risks in business cybersecurity because it’s built into everyday work and can’t be easily patched like a software bug. It can appear in a password reused across platforms, a link opened in a convincing email, a permission granted too broadly, or a credential shared informally.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;IBM’s &lt;a href=&quot;https://www.ibm.com/reports/data-breach&quot;&gt;Cost of a Data Breach Report&lt;/a&gt; reinforces the business impact of security failures. Its 2025 report puts&lt;strong&gt; the global average cost of a data breach at USD 4.4 million&lt;/strong&gt; and highlights identity security as a key area for action. For businesses, the takeaway is: Technical controls can reduce risk, but they can’t eliminate the human decisions attackers exploit when people interact with systems, accounts, and access points.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Human error is more serious when the business has no reliable way to contain it. A reused password, a mistaken click, or an account with excessive permissions can happen in any company. The damage grows when there is no monitoring, &lt;a href=&quot;https://proton.me/blog/what-is-two-factor-authentication-2fa&quot;&gt;two-factor authentication (2FA)&lt;/a&gt; requirement, access review, or clear reporting process. In those cases, the first mistake may be made by a person, but the real exposure comes from the gaps around it.&lt;/p&gt;



&lt;h2 id=&quot;common-human-errors&quot; class=&quot;wp-block-heading&quot;&gt;Common human errors in cybersecurity&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employee cybersecurity mistakes usually look ordinary from the inside because they’re just small decisions made during busy workdays.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Common examples include:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Password reuse:&lt;/strong&gt; Employees reuse a familiar password because creating and remembering a new one can be inconvenient.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Clicking &lt;/strong&gt;&lt;a href=&quot;https://proton.me/business/blog/phishing-attacks&quot;&gt;&lt;strong&gt;phishing links&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;:&lt;/strong&gt; A message looks legitimate enough, arrives at the right time, or appears to come from a trusted contact.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Sharing credentials informally:&lt;/strong&gt; A colleague needs access, so someone sends a password through chat, email, or a shared document through an unapproved, insecure channel.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Granting too much access:&lt;/strong&gt; A user receives broad permissions because it is faster than setting up access limited to their specific role or responsibilities (&lt;a href=&quot;https://proton.me/business/blog/principle-of-least-privilege&quot;&gt;principle of least privilege&lt;/a&gt;)..&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Ignoring update prompts:&lt;/strong&gt; A device or browser asks for an update, but the employee postpones it to avoid interrupting work.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Using &lt;/strong&gt;&lt;a href=&quot;https://proton.me/business/blog/shadow-it&quot;&gt;&lt;strong&gt;shadow IT&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; tools:&lt;/strong&gt; A team adopts a tool without IT approval because the approved alternative is slower, missing a feature, or simply unknown.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When the secure option adds friction or interrupts a task, people are likely to take shortcuts to keep work moving. Cybersecurity needs to account for how people actually behave, not only how they should.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Policies that depend on unlimited attention, perfect memory, and constant vigilance for security threats are unlikely to work.. People can make poor decisions while juggling other tasks, often without all the information needed to recognize a cybersecurity risk. If your business wants safer behavior, you have to create a &lt;a href=&quot;https://proton.me/business/blog/cybersecurity-policy-small-business&quot;&gt;cybersecurity policy&lt;/a&gt; around how your employees actually work.&lt;/p&gt;



&lt;h2 id=&quot;training&quot; class=&quot;wp-block-heading&quot;&gt;Training alone can’t solve human error&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Training helps. Employees need to know &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;how phishing works&lt;/a&gt;, how password reuse can expose your &lt;a href=&quot;https://proton.me/business/blog/credential-stuffing-business&quot;&gt;business to credential stuffing attacks&lt;/a&gt;, how to report suspicious activity, and what the company expects from them. A business with no &lt;a href=&quot;https://proton.me/business/blog/security-awareness-training&quot;&gt;security awareness&lt;/a&gt; at all leaves people without context.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But training alone isn’t sufficient, because it can’t address the security-convenience trade-off. If the secure path is harder than the insecure one, employees may prefer shortcuts. Not because they ignored the training, but because the working environment rewards speed, responsiveness, and getting things done.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Someone may know they should not reuse a password, but still do it if they have no password manager. People may know not to share credentials in chat, but do it anyway if there is no simple way to share access quickly. They may understand two-factor authentication is safer, but skip it if enrollment is optional and nobody follows up.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A training session can explain the risk, but it can’t remove the convenience. That is why security needs to be built into the workflow. Good security design reduces the number of moments where employees have to make a high-stakes decision on their own. It gives them safer defaults, clearer prompts, and fewer reasons to improvise.&lt;/p&gt;



&lt;h2 id=&quot;default&quot; class=&quot;wp-block-heading&quot;&gt;Make secure behavior the default&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The most effective way to reduce human error is to remove unnecessary opportunities for mistakes. A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; is an excellent tool for both employees and businesses, as it can make day-to-day work both easier and more secure. Without one, employees have to create, remember, and type passwords themselves.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That creates space for weak passwords, reuse, forgotten logins, and insecure storage. With Proton Pass for Business, strong passwords can be generated, stored securely, and filled automatically when needed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Autofill also reduces risk because it prevents phishing attacks. When credentials are tied to the correct website, the tool supports safer behavior without asking the employee to inspect every link from memory.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;Secure password sharing&lt;/a&gt; works the same way. If the approved option is quick and easy, there is less reason to paste credentials into chat. If access can be shared through encrypted vaults, the business can reduce informal sharing while still helping teams move quickly.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/support/two-factor-authentication-organization&quot;&gt;2FA enforcement&lt;/a&gt; removes another decision point. When 2FA is optional, employees may delay setup or disable it if it feels inconvenient. When it is enforced, however, your business stays protected&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is the design principle behind reducing human error &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breach&lt;/a&gt; risk: Never rely on people to choose perfectly in imperfect conditions. Instead, build systems where the safer choice is already the path of least resistance.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business⁠ helps businesses turn secure behavior into a default by making strong passwords, secure sharing, autofill, and credential control easier to use in daily work.&lt;/p&gt;



&lt;h2 id=&quot;credential-mistakes&quot; class=&quot;wp-block-heading&quot;&gt;Why credential mistakes spread so quickly&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credential mistakes rarely stay limited when they happen. If someone reuses a password, the risk is not confined to the account they created that day. If, for example, that same password protects a finance platform, a cloud service, or an admin console, &lt;strong&gt;one bad habit can expose connected systems&lt;/strong&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The same applies to shared access. In a small team, sending a login to a colleague may feel harmless, especially when work is moving quickly. But once that credential leaves an approved system, the business loses context: who has it, where it was copied, whether it was saved somewhere else, and whether access should still exist weeks later.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credential management is a practical and effective way to reduce cybersecurity human risk. It gives your business more control over what happens after a mistake:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Strong, unique passwords reduce reuse.&lt;/li&gt;



&lt;li&gt;Encrypted vaults keep access out of unapproved, insecure channels like chats and spreadsheets.&lt;/li&gt;



&lt;li&gt;2FA reduces the risk that a stolen password can be used to access an account.&lt;/li&gt;



&lt;li&gt;Access reviews help identify and revoke credentials that are no longer needed.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our guide to &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection for businesses&lt;/a&gt; explains how layered controls reduce exposure before a breach occurs. For credentials, those layers matter because passwords often sit between ordinary work and sensitive systems.This is especially relevant for startups and smaller teams, where speed often shapes how access is shared.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/tech-startup-security-expert&quot;&gt;Tech startups seeking security tips&lt;/a&gt; can also learn from the common cybersecurity mistakes businesses make early on and the steps they can take to avoid them.&lt;/p&gt;



&lt;h2 id=&quot;access&quot; class=&quot;wp-block-heading&quot;&gt;Access should not depend on memory&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Human error becomes more likely when cybersecurity depends on employees remembering too many details. Modern work can involve dozens of accounts, passwords, access rules, and security prompts spread across different tools. A better approach is to reduce that burden wherever possible by building secure processes into the tools and workflows employees already use. s. A better model is to reduce memory work wherever possible.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With a secure &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;, teams can generate strong passwords, store credentials in encrypted vaults, use autofill, share access securely, manage &lt;a href=&quot;https://proton.me/pass/passkeys&quot;&gt;passkeys&lt;/a&gt;, and use built-in two-factor authentication. Admin features such as &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;password policies&lt;/a&gt;, reporting, logs, role-based access control, SCIM provisioning, and SSO integrations help businesses manage credentials with less dependence on informal habits.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The right tool changes the shape of the work. When people have an approved way to create, store, and share credentials, the business no longer has to rely on everyone inventing their own workaround.&lt;/p&gt;



&lt;h2 id=&quot;review&quot; class=&quot;wp-block-heading&quot;&gt;Review the systems around the mistake&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When an employee makes a cybersecurity mistake (such as &lt;a href=&quot;https://proton.me/blog/how-passwords-become-compromised&quot;&gt;compromising a password&lt;/a&gt;), your business needs to consider the system that allowed that error and then fix those conditions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here are some questions you need to ask:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Was the employee using a weak password because the business had no password manager?&lt;/li&gt;



&lt;li&gt;Was a credential shared in chat because there was no approved sharing process?&lt;/li&gt;



&lt;li&gt;Did someone keep access after changing roles because offboarding was unclear?&lt;/li&gt;



&lt;li&gt;Was an update delayed because people were not given time to restart devices safely?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The employee may need support or guidance, and serious negligence may warrant consequences, but the business also needs to fix the workflow, policy, or feature gap that allowed the risk to appear.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our&lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt; SMB cybersecurity report&lt;/a&gt; can help businesses understand how small and mid-sized companies think about cybersecurity risks and controls. For many, the challenge is turning awareness into processes that fit real work.&lt;/p&gt;



&lt;h2 id=&quot;tips&quot; class=&quot;wp-block-heading&quot;&gt;Practical ways to reduce human error in cybersecurity&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Reducing human error in cybersecurity requires a better environment for everyday decisions. Start with the areas where mistakes are most common and most damaging:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Use a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;⁠ so employees don’t have to create, remember, or store passwords manually.&lt;/li&gt;



&lt;li&gt;Enforce strong &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;password policies&lt;/a&gt; and encourage generated passwords for business accounts.&lt;/li&gt;



&lt;li&gt;Turn on 2FA for sensitive systems and make it mandatory where the risk is highest.&lt;/li&gt;



&lt;li&gt;Replace informal credential sharing with encrypted vault sharing.&lt;/li&gt;



&lt;li&gt;Review access when people join, leave, change roles, or finish a project.&lt;/li&gt;



&lt;li&gt;Keep software, browsers, and devices updated with clear expectations around update prompts.&lt;/li&gt;



&lt;li&gt;Create a simple reporting process for suspicious emails, mistaken clicks, and near misses.&lt;/li&gt;



&lt;li&gt;Talk about errors without assigning blame so employees report issues before they escalate.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The strongest results come when the business stops treating human error as a training issue alone. Employees need guidance, but they also need processes that are easy to follow, security features that reduce risky shortcuts, and a culture where reporting a mistake is treated as part of protecting the company, not as a failure to hide.&lt;/p&gt;



&lt;h2 id=&quot;secure-behavior&quot; class=&quot;wp-block-heading&quot;&gt;Make secure behavior easier than the shortcut&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Human error will always be part of cybersecurity because people will always be part of business. They’ll always need to open messages, approve access, create accounts, share files, install updates, and make decisions. Your business’s cybersecurity simply can’t rely on people taking the right action consistently unless it’s also the easiest action.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For SMBs, the most useful shift is to look at where shortcuts are becoming part of the workflow. Those patterns show where the business can redesign the path around the employee: make strong credentials easier to create, keep access inside controlled vaults, require stronger protection where the risk is higher, and make reporting feel like a normal security step.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;, teams can make secure credential habits easier to follow in daily work.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>7 privacy gadgets a Proton employee actually uses</title><link>https://proton.me/blog/privacy-gadgets</link><guid isPermaLink="true">https://proton.me/blog/privacy-gadgets</guid><description>From kill cords to Faraday pouches, here are the physical privacy tools you can use when a password alone isn&apos;t enough.</description><pubDate>Wed, 05 Aug 2026 19:38:20 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;We asked Harley, a Proton privacy expert on our team, to walk through the physical gadgets she and her colleagues use to protect themselves when a password alone isn&amp;#8217;t enough.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of these replace good digital hygiene, but they cover the gap where the digital world meets the physical one: a stolen laptop, a fake cell tower, a shoulder surfer on the train.&lt;/p&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;Seven Gadgets a Security Expert Actually Uses&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/WfVPjNAbkNY?feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;BusKill: a kill switch for laptop theft&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Picture working in a café. You look away for a second and someone grabs your laptop and runs. &lt;a href=&quot;https://www.buskill.in/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;BusKill&lt;/a&gt; is a magnetic cable built for exactly that moment. If it disconnects unexpectedly, it can lock your screen, suspend the machine, shut it down entirely, or even wipe the drive, depending on how you configure it. It&amp;#8217;s a simple mechanism for a very physical threat, and one you&amp;#8217;ll hope to never need.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;IMSI catcher detectors: watching for fake cell towers&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Phones constantly search for nearby cell towers, which is normally fine. The problem is IMSI catchers: fake towers that trick phones into connecting, sometimes exposing identifying information in the process. Law enforcement has used them to log who attended a protest. An IMSI catcher detector like the open-source &lt;a href=&quot;https://www.eff.org/deeplinks/2025/03/meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying&quot;&gt;Rayhunter&lt;/a&gt; monitors the cellular environment for signs something is off. It can&amp;#8217;t prove a fake tower is present, but it can flag suspicious behavior.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Faraday pouches: going wireless-dark on demand&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://slnt.com/collections/all&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Faraday pouch&lt;/a&gt; looks like a lunch bag but blocks electromagnetic signals entirely, cutting off cellular, Wi-Fi, and Bluetooth. A phone inside one can&amp;#8217;t be tracked, reached, or connected to anything. Some Proton employees use one while traveling or whenever they want certainty that a device is genuinely offline, not just in airplane mode.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Security keys: a physical second factor&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A password alone protects nothing once it&amp;#8217;s phished. A hardware security key like a &lt;a href=&quot;https://www.yubico.com/get-yubikey-5-series/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;YubiKey&lt;/a&gt; or &lt;a href=&quot;https://www.nitrokey.com/products/nitrokeys&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Nitrokey&lt;/a&gt; adds a physical requirement on top of it, so a stolen password isn&amp;#8217;t enough to get in. Many keys also store encryption keys and perform cryptographic operations on-device, keeping sensitive material off a laptop that might already be compromised. Buy two: one to use, one to store safely as a backup, since losing your only key is its own kind of lockout.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Privacy screen protectors: blocking the oldest attack there is&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://www.3m.com/3M/en_US/privacy-screen-protectors-us/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;privacy screen protector&lt;/a&gt; uses thousands of microscopic vertical filters, small enough to be invisible, that let light through straight on and block it from the side. The screen reads clearly to you and as a blank surface to the person next to you. It&amp;#8217;s built to stop the simplest attack on the list: someone reading over your shoulder on a train, in an airport, or in an open office.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;USB data blockers: charging without the data risk&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Public USB ports carry both power and data, which is exactly the problem when your battery is at 2% in an airport. A &lt;a href=&quot;https://portablepowersupplies.co.uk/product/usb-data-blocker&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;USB data blocker&lt;/a&gt;, sometimes called a USB condom, physically blocks the data pins while letting power through. Your phone charges. Nothing else happens.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Cash: the original privacy tool&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Every card payment leaves a record of where you were, when, and how much you spent. Cash doesn&amp;#8217;t. It&amp;#8217;s a reminder that privacy isn&amp;#8217;t only a digital concern. The same instinct that leads us to encrypt an inbox should extend to the physical trail we leave behind.&lt;/p&gt;
</content:encoded><author>Proton Team</author></item><item><title>Apple’s iCloud Private Relay is leaking the IP addresses it’s supposed to hide</title><link>https://proton.me/blog/icloud-private-relay-ip-leak</link><guid isPermaLink="true">https://proton.me/blog/icloud-private-relay-ip-leak</guid><description>Researchers found a flaw in Apple&apos;s iCloud Private Relay that exposes real IP addresses, the second iCloud privacy failure this summer.</description><pubDate>Wed, 05 Aug 2026 19:01:38 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Apple markets &lt;a href=&quot;https://support.apple.com/en-us/102602&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;iCloud Private Relay&lt;/a&gt; as a way to browse the web without exposing your IP address. A &lt;a href=&quot;https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/&quot; data-type=&quot;link&quot; data-id=&quot;https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;new report from 404 Media&lt;/a&gt;, however, shows that promise is broken.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security researchers &lt;a href=&quot;https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Tommy Mysk and Talal Haj Bakry&lt;/a&gt; found the underlying flaws in WebKit, the browser engine behind every iOS browser, and built a &lt;a href=&quot;https://leaks.psylo.app/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;checker site&lt;/a&gt; that lets anyone test whether their device is exposed. 404 Media ran that check and confirmed the exploit works.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How the leak works&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One of the flaws centers on &lt;a href=&quot;https://proton.me/blog/what-is-a-passkey&quot;&gt;passkeys&lt;/a&gt;, the login standard meant to replace passwords. When a site supports (or just claims to) passkeys, your device makes a credential request through the operating system rather than Safari. That request &lt;a href=&quot;https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/&quot;&gt;skips Private Relay&amp;#8217;s proxy entirely&lt;/a&gt;, so the site sees your real IP address while everything on screen looks normal and protected.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Because every iOS browser runs on WebKit, the issue also hits &lt;a href=&quot;https://onionbrowser.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;OnionBrowser&lt;/a&gt;, an app built to route traffic through Tor (the official &lt;a href=&quot;https://www.torproject.org/download/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Tor Browser&lt;/a&gt; is unaffected). &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Apple says it&amp;#8217;s investigating; OnionBrowser&amp;#8217;s developer told 404 Media that &lt;a href=&quot;https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Apple called the issue &amp;#8220;dire&amp;#8221; with no fix timeline&lt;/a&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The second Apple privacy tool to fail in two months&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In July, 404 Media reported that Hide My Email, Apple&amp;#8217;s disposable-alias feature, had been &lt;a href=&quot;https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;exposing users&amp;#8217; real addresses for over a year&lt;/a&gt;. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Apple claimed to have fixed the bug twice before actually patching it. The flaw: if a message to a hidden alias bounced as spam, even a legitimate one, the real address could leak into the sender&amp;#8217;s mail logs, with no way for the user to know.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It&amp;#8217;s the second time in two months a paid iCloud privacy feature has failed, both times caught by outside researchers. It tracks with what we&amp;#8217;ve written about &lt;a href=&quot;https://proton.me/blog/iphone-privacy&quot;&gt;Apple&amp;#8217;s iPhone privacy claims&lt;/a&gt; not holding up to scrutiny.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Private Relay isn&amp;#8217;t a VPN substitute&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Private Relay only protects Safari, not your whole device. A dedicated VPN encrypts all device traffic, so &lt;a href=&quot;https://proton.me/business/vpn/vpn-security&quot;&gt;your real IP never reaches the sites you visit&lt;/a&gt;, which is why a &lt;a href=&quot;https://proton.me/blog/best-vpn-service&quot;&gt;VPN you trust&lt;/a&gt; still matters even with Private Relay on. Proton VPN&amp;#8217;s apps, for example, are open source and independently audited.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The same logic applies to email. If you want to sign up for something without giving out your real address, Proton Mail&amp;#8217;s &lt;a href=&quot;https://proton.me/blog/hide-my-email-aliases&quot; data-type=&quot;link&quot; data-id=&quot;https://proton.me/blog/hide-my-email-aliases&quot;&gt;hide-my-email aliases&lt;/a&gt; let you do just that. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A privacy feature is only as good as the company willing to catch and fix its own mistakes. Apple has spent years promising &lt;a href=&quot;https://www.macworld.com/article/232305/apple-privacy-billboard.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;&amp;#8220;What happens on your iPhone, stays on your iPhone.&amp;#8221;&lt;/a&gt; &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Twice in two months, however, that&amp;#8217;s proven untrue.&lt;/p&gt;
</content:encoded><category>News</category><author>Edward Komenda</author></item><item><title>Lumo can now turn your data into visuals</title><link>https://proton.me/business/blog/lumo-data-visualizations</link><guid isPermaLink="true">https://proton.me/business/blog/lumo-data-visualizations</guid><description>Lumo can now turn your spreadsheets, reports, or internal documents into data visualizations for free — while keeping your information private. Start a chat to try it.</description><pubDate>Mon, 03 Aug 2026 11:55:18 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lumo can now create charts, graphs, and other custom visuals directly in chats, making it easier to understand complex information in a completely private environment. Ask Lumo to analyze a dataset, and it will generate visuals that highlight trends or key findings, so you digest and act on insights faster. Lumo can also decide when an answer is easier to understand with a visual and generate one automatically.&lt;/p&gt;



&lt;div class=&quot;text-center&quot;&gt;&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small bg-purple-500 text-white hover:text-white focus:text-white&quot; href=&quot;https://account.proton.me/lumo/signup&quot;&gt;Try it now&lt;/a&gt;&lt;/div&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;From raw data to insights&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lumo doesn&amp;#8217;t just generate charts. It analyzes the information you provide and presents the results in the format that&amp;#8217;s most useful for the question. Depending on the task, that can include charts, key metrics, summaries, comparisons, and callouts that surface the most important findings.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can then ask follow-up questions, refine the visual, compare different perspectives, or explore another trend without starting over.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;637&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_637,c_scale/f_auto,q_auto/v1785725940/wp-pme/lumo_charts_inline-image01-3/lumo_charts_inline-image01-3.png?_i=AA&quot; alt=&quot;A Lumo conversation with a bar chart generated.&quot; class=&quot;wp-post-243832 wp-image-251709&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;228 KB&quot; data-optsize=&quot;66 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;71.2&quot; data-version=&quot;1785725940&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_637,c_scale/f_auto,q_auto/v1785725940/wp-pme/lumo_charts_inline-image01-3/lumo_charts_inline-image01-3.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_187,c_scale/f_auto,q_auto/v1785725940/wp-pme/lumo_charts_inline-image01-3/lumo_charts_inline-image01-3.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_478,c_scale/f_auto,q_auto/v1785725940/wp-pme/lumo_charts_inline-image01-3/lumo_charts_inline-image01-3.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_956,c_scale/f_auto,q_auto/v1785725940/wp-pme/lumo_charts_inline-image01-3/lumo_charts_inline-image01-3.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1275,c_scale/f_auto,q_auto/v1785725940/wp-pme/lumo_charts_inline-image01-3/lumo_charts_inline-image01-3.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_976,c_scale/f_auto,q_auto/v1785725940/wp-pme/lumo_charts_inline-image01-3/lumo_charts_inline-image01-3.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lumo also generates visuals from information beyond user-provided datasets. When answering questions that involve structured information, trends, or comparisons, it can determine when a visual would help explain the answer more effectively. Rather than asking you to interpret the information yourself, Lumo presents it in the format that&amp;#8217;s most useful for the question.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Built for real business data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The new &lt;a href=&quot;https://proton.me/support/lumo-custom-data-visualizations&quot;&gt;data visualization&lt;/a&gt; feature is especially valuable for the organizations using Lumo for work. Financial reports, sales pipelines, customer data, board presentations, and internal research often contain sensitive information that teams are reluctant to upload to third-party AI services.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Because of &lt;a href=&quot;https://proton.me/blog/lumo-security-model&quot;&gt;Lumo&amp;#8217;s unique encryption&lt;/a&gt;, you can now generate custom visuals while keeping that information private.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Whether you&amp;#8217;re working with confidential business data or internal documents, Lumo can help you:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Review financial performance&lt;/strong&gt; by turning revenue, budgets, and forecasts into charts that highlight trends and key changes.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Analyze sales pipelines&lt;/strong&gt; to compare your internal data without exposing customer information.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Summarize operational metrics&lt;/strong&gt; with visual dashboards that make KPIs and performance easier to understand.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Explore internal reports&lt;/strong&gt; by turning lengthy documents into visual summaries that surface important findings.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Research business questions&lt;/strong&gt; with data visualizations that help explain market trends, industry data, or public information when a visual provides a clearer answer.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Lumo generates visuals directly in the conversation, so you can continue asking questions, refine the analysis, and explore different perspectives without moving your information into separate charting or presentation tools.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;637&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_637,c_scale/f_auto,q_auto/v1785725930/wp-pme/lumo_charts_inline-image02-2/lumo_charts_inline-image02-2.png?_i=AA&quot; alt=&quot;A screenshot of a Lumo conversation generating a chart.&quot; class=&quot;wp-post-243832 wp-image-251733&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;248 KB&quot; data-optsize=&quot;74 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;70.3&quot; data-version=&quot;1785725930&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_637,c_scale/f_auto,q_auto/v1785725930/wp-pme/lumo_charts_inline-image02-2/lumo_charts_inline-image02-2.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_187,c_scale/f_auto,q_auto/v1785725930/wp-pme/lumo_charts_inline-image02-2/lumo_charts_inline-image02-2.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_478,c_scale/f_auto,q_auto/v1785725930/wp-pme/lumo_charts_inline-image02-2/lumo_charts_inline-image02-2.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_956,c_scale/f_auto,q_auto/v1785725930/wp-pme/lumo_charts_inline-image02-2/lumo_charts_inline-image02-2.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1275,c_scale/f_auto,q_auto/v1785725930/wp-pme/lumo_charts_inline-image02-2/lumo_charts_inline-image02-2.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_976,c_scale/f_auto,q_auto/v1785725930/wp-pme/lumo_charts_inline-image02-2/lumo_charts_inline-image02-2.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Private by design&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data visuals are often created from sensitive information, like your personal finances or internal business documents. Lumo for Business is a private &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt; that gives you the power of AI while protecting your information.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unlike many AI services that log your chats, train on your data, and share it with third parties or governments, Lumo is built so your information remains private by default.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;No record of your chats.&lt;/strong&gt; Lumo runs on no-logs infrastructure, and &lt;a href=&quot;https://proton.me/blog/lumo-security-model&quot;&gt;zero-access encryption&lt;/a&gt; ensures only you can access your conversations, uploaded files, or the visuals Lumo generates.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;No AI training on your data.&lt;/strong&gt; Lumo never trains AI models on your conversations. Your business data stays yours.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Protected under European law.&lt;/strong&gt; &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;Built and operated in Switzerland&lt;/a&gt;, Lumo is protected by some of the world&amp;#8217;s strongest privacy laws, helping shield your data from government surveillance and third-party data requests.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Open source and independently verified.&lt;/strong&gt; Like all Proton services, &lt;a href=&quot;https://proton.me/community/open-source&quot;&gt;Lumo&amp;#8217;s codebase is fully open source&lt;/a&gt;, allowing anyone to verify that our apps work exactly as we say they do.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Built for regulated organizations.&lt;/strong&gt; Lumo is designed to &lt;a href=&quot;https://proton.me/business/trust&quot;&gt;support GDPR and HIPAA compliance&lt;/a&gt;, backed by Proton&amp;#8217;s ISO 27001 and SOC 2 certifications, giving security and compliance teams greater confidence when adopting AI.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Get started&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Custom visuals are available for everyone. Upload a spreadsheet or document, paste structured data into a conversation, or simply ask a question. When a visual helps explain the answer, Lumo can generate one automatically as part of its response.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://account.proton.me/lumo/signup&quot;&gt;Start a chat with Lumo for free&lt;/a&gt;
&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-outlined-purple&quot; href=&quot;https://account.proton.me/lumo/signup/business&quot;&gt;Try Lumo Professional&lt;/a&gt;
&lt;/div&gt;
</content:encoded><category>For business</category><category>Lumo AI</category><category>Proton updates</category><author>Eamonn Maguire</author></item><item><title>What is business resilience? Definition and key strategies</title><link>https://proton.me/business/blog/business-resilience</link><guid isPermaLink="true">https://proton.me/business/blog/business-resilience</guid><description>Your board wants a business resilience strategy. Here&apos;s what that means, with a four-pillar framework, and a plan to build resilience fast. </description><pubDate>Fri, 31 Jul 2026 16:51:21 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Cyberattacks, &lt;a href=&quot;https://proton.me/business/blog/supply-chain-attack&quot;&gt;supply chain failures&lt;/a&gt;, and geopolitical shocks shake otherwise stable businesses every year. How your business responds to the unexpected is what will make it last.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A comprehensive business resilience strategy can see you through disruption, help you recover faster, and adapt to whatever comes next.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This article offers:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;A clear definition of business resilience and what threatens it&lt;/li&gt;



&lt;li&gt;A business resilience framework you can take to your board&lt;/li&gt;



&lt;li&gt;A business resilience strategy you can use to maximize your resilience starting today&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is business resilience?&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Business resilience is your organization’s ability to anticipate, withstand, recover from, and adapt to disruption. It protects not just your operations, but your finances, your people, and your reputation.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Businesses today face a range of potential disruptions, including:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Cyberattacks:&lt;/strong&gt; Proton’s SMB Cybersecurity Report 2026 found that &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;&lt;u&gt;nearly 1 in 4 SMBs&lt;/u&gt;&lt;/a&gt; were hit by cyberattacks in the previous 12 months&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Infrastructure outages: &lt;/strong&gt;Many businesses now rely on major cloud infrastructure providers to support their critical business tools. When those infrastructures go down (as in the &lt;a href=&quot;https://proton.me/business/blog/aws-outage&quot;&gt;2025 AWS outage&lt;/a&gt;), thousands of businesses feel the impact, particularly those without resilience&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Supply-chain disruptions:&lt;/strong&gt; We saw the consequences of this risk at its height during COVID, and the lifting of lockdowns hasn’t eliminated it: A 2024 report found that &lt;a href=&quot;https://www.thebci.org/resource/bci-supply-chain-resilience-report-2024.html&quot;&gt;&lt;u&gt;nearly 80% of organizations’ supply chains had been disrupted&lt;/u&gt;&lt;/a&gt; in the last 12 months&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Market and geopolitical shocks: &lt;/strong&gt;In Q4 2024, only 8.3% of CFOs named trade and tariffs as a top concern. By Q1 2025, &lt;a href=&quot;https://www.richmondfed.org/publications/research/economic_brief/2025/eb_25-12&quot;&gt;&lt;u&gt;that share had more than tripled to 30.5%&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The evolution of technology and work:&lt;/strong&gt; The World Economic Forum predicts AI will &lt;a href=&quot;https://www.weforum.org/publications/the-future-of-jobs-report-2025/digest/&quot;&gt;&lt;u&gt;displace 92 million jobs by 2030&lt;/u&gt;&lt;/a&gt;, and create 170 million new ones&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why is business resilience important?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The most resilient businesses are able to:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Anticipate disruption.&lt;/strong&gt; Rather than waiting for a crisis to expose their &lt;a href=&quot;https://proton.me/business/blog/vulnerability&quot;&gt;vulnerabilities&lt;/a&gt;, they identify risks in advance.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Withstand disruption.&lt;/strong&gt; They can take the shock of it, while it&amp;#8217;s happening, without catastrophic failure.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Recover from disruption.&lt;/strong&gt; Resilient businesses minimize costs by rapidly getting back to operational normality.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Adapt to disruption.&lt;/strong&gt; Returning to the status quo means carrying the same vulnerabilities. Resilient businesses update their operations, strategy, and business model in response to what happens.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Business resilience vs. disaster recovery vs. business continuity&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disaster recovery and business continuity are components of business resilience, covering what happens &lt;strong&gt;during&lt;/strong&gt; and &lt;strong&gt;immediately&lt;/strong&gt; &lt;strong&gt;after&lt;/strong&gt; disruption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Disaster recovery&lt;/strong&gt; is about restoring IT infrastructure and operations in the immediate aftermath of a disruption. If a ransomware attack takes your file servers offline, for example, disaster recovery is your IT team rebuilding the servers and restoring data from &lt;a href=&quot;https://proton.me/business/drive/cloud-backup-small-business&quot;&gt;cloud backup&lt;/a&gt; until the system works again.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Business continuity&lt;/strong&gt; is about keeping your business functionally operational while disaster recovery is in progress. That includes your leadership team deciding how to respond, this decision reaching staff, customers, and possibly regulators, and the practical workarounds that keep things running while your systems are down: phone and paper processes, deadlines still being hit, invoices still going out.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disaster recovery is about how you recover from disruption; business continuity is about how you withstand it while recovery is underway. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Business resilience &lt;/strong&gt;is the wider capacity that covers both — plus what happens either side of this: your ability to anticipate a disruption and recover quicker as a result, and your ability to adapt afterwards so the same attack doesn&amp;#8217;t catch you out a second time.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A four pillar business resilience framework&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before you build a business resilience strategy, you need to know what it should cover. This four-pillar framework reflects where disruption actually hits a business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Measure your business against these four pillars to understand how resilient you are, then use the strategy below to close the gaps you find.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;br&gt;&lt;strong&gt;Example scenarios&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Real-world cases&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Operational resilience&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Can you keep critical business functions running?&lt;/td&gt;&lt;td&gt;A supplier fails to deliver.&lt;br&gt;A cyberattack locks your team out of critical systems.&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://www.bloomberg.com/news/articles/2025-05-21/marks-spencer-says-cyber-attack-to-cost-business-300-million&quot;&gt;&lt;u&gt;M&amp;amp;S&amp;#8217;s 2025 ransomware attack&lt;/u&gt;&lt;/a&gt; knocked out the British retailer&amp;#8217;s online ordering for 46 days, wiping an estimated £300 million off annual profit.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Financial resilience&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Can you absorb a disruption’s economic impact without threatening your long-term viability?&lt;/td&gt;&lt;td&gt;A major client defaults during a market downturn.&lt;br&gt;A shock to supply drives material costs up sharply.&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://www.autonews.com/general-motors/an-gm-guidance-0501/&quot;&gt;&lt;u&gt;General Motors cut its 2025 profit guidance&lt;/u&gt;&lt;/a&gt; after estimating tariffs would add $4–5 billion in costs it hadn&amp;#8217;t priced into its original forecast.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;People resilience&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Can you keep the right people available, safe, and able to work through a disruption?&amp;nbsp;&lt;/td&gt;&lt;td&gt;Your CFO resigns mid-crisis.&lt;br&gt;A function is automated faster than your workforce was prepared for.&lt;/td&gt;&lt;td&gt;In 2022, staffing and scheduling failures forced Southwest Airlines to cancel 16,700 flights. &lt;a href=&quot;https://www.transportation.gov/briefing-room/dot-penalizes-southwest-airlines-140-million-2022-holiday-meltdown&quot;&gt;The Department of Transportation fined them&lt;u&gt; a record $140 million&lt;/u&gt;.&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Reputational resilience&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Can you protect and recover stakeholder trust during and after a disruption?&lt;/td&gt;&lt;td&gt;A &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breach&lt;/a&gt; exposes client records.&lt;br&gt;A supplier&amp;#8217;s practices attract negative coverage that reflects on your brand.&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;TikTok had assured regulators that EU user data wasn&amp;#8217;t stored in China, then admitted in 2025 that some had been. This drew a &lt;a href=&quot;https://www.dataprotection.ie/en/news-media/latest-news/irish-data-protection-commission-fines-tiktok-eu530-million-and-orders-corrective-measures-following&quot;&gt;&lt;u&gt;€530 million GDPR fine&lt;/u&gt;&lt;/a&gt; (one of the largest on record) and compounded TikTok’s global trust problem.&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to build a business resilience strategy&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Now you know what your strategy needs to cover. This is where business resilience planning starts.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. Conduct a risk and dependency audit / assessment&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before you do anything else, you need to audit your exposure across all four pillars.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Operational: &lt;/strong&gt;Surface infrastructure and vendor dependencies. Where are you single-sourced, and what comms channels depend on cloud infrastructure that could go down?&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Financial: &lt;/strong&gt;Review insurance coverage against your actual risk exposure. Stress-test financials against plausible disruptions before they happen.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;People: &lt;/strong&gt;Identify single-point-of-failure roles and thin coverage. Where does the business depend on one person, or one team with no backup?&amp;nbsp;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Reputational: &lt;/strong&gt;Assess your current crisis-response readiness. If a breach or scandal broke tomorrow, do you have a communications plan and a spokesperson ready?&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. Define and test your business resilience plan&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Using your findings, you now need to put together a &lt;strong&gt;business resilience plan &lt;/strong&gt;(sometimes called a &lt;strong&gt;business resilience policy&lt;/strong&gt;).&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Document decision-makers: &lt;/strong&gt;Establish who has the authority to declare a crisis, reallocate a budget, or approve a public statement.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Identify priority processes: &lt;/strong&gt;Which functions can’t go down, and which can wait if your resources are stretched?&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Map out provisional measures to maintain operations:&lt;/strong&gt; offsite backups with automated failover, pre-arranged credit facilities so liquidity isn&amp;#8217;t a scramble, clear employee safety protocols, and pre-approved messaging with escalation protocols ready before a crisis breaks.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Make sure the right tech is in place to execute the plan: &lt;/strong&gt;backup communication channels, private and confidential remote access and &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt;, and a flexible working infrastructure.&amp;nbsp;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Test the plan before you need to execute it: &lt;/strong&gt;&amp;#8220;War-game&amp;#8221; scenarios regularly to expose weaknesses and let the team learn in a safe environment.&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. Assign an owner to each resilience pillar&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Resilience fails when it&amp;#8217;s treated as one function&amp;#8217;s job (usually IT’s) alone. Each resilience pillar needs an owner: accountable for its exposure, responsible for keeping the audit current and the plan&amp;#8217;s provisions in place, and ready to act if disruption strikes.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Map named owners to named pillars: your COO for operational, your CFO for financial, your CHRO for people, and legal/comms for reputational.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How Proton supports business resilience&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Workspace is a privacy-first business suite. It increases your operational and reputational resilience by:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Protecting your data:&lt;/strong&gt; Proton Workspace is built on an &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;&lt;u&gt;end-to-end encrypted&lt;/u&gt;&lt;/a&gt;, &lt;a href=&quot;https://proton.me/blog/zero-knowledge-cloud-storage&quot;&gt;&lt;u&gt;zero-knowledge&lt;/u&gt;&lt;/a&gt; infrastructure, which means not even Proton can access your data. It’s additionally protected by some of the world’s &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;most stringent privacy laws&lt;/u&gt;&lt;/a&gt;. Plus, Proton Workspace includes a business p&lt;a href=&quot;https://proton.me/business/pass&quot;&gt;&lt;u&gt;assword manager&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/vpn&quot;&gt;&lt;u&gt;VPN&lt;/u&gt;&lt;/a&gt; to further strengthen data protection.&lt;/li&gt;
&lt;/ul&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Helping you recover: &lt;/strong&gt;In the event of a major cloud infrastructure outage, &lt;a href=&quot;https://proton.me/blog/sustaining-mission-over-time&quot;&gt;&lt;u&gt;Proton’s independent infrastructure&lt;/u&gt;&lt;/a&gt; stays up and your teams can continue to email, use cloud storage, collaborate on documents, and meet via video. You can set up a &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;&lt;u&gt;business continuity plan&lt;/u&gt;&lt;/a&gt; with Proton so you’re ready to quickly switch over when disruption hits&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even the best business resilience strategy depends on a solid technology foundation to succeed. Proton Workspace is built to strengthen that foundation.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Learn more about &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;business continuity&lt;/a&gt; with Proton.&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>Document management systems explained: features, types, and platforms</title><link>https://proton.me/business/blog/document-management-system</link><guid isPermaLink="true">https://proton.me/business/blog/document-management-system</guid><description>Document management systems store your most sensitive data. Here&apos;s what to look for — and why most platforms fall short on security.</description><pubDate>Fri, 31 Jul 2026 16:36:16 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Document management system (DMS) are the software equivalent of an office&amp;#8217;s filing cabinet. It&amp;#8217;s where your business stores, categorizes, organizes, or secures classified documentation. You probably already have one in place.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It could be &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt;, SharePoint, or an internal &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt; system you created yourself. You could be using it to collect contracts, invoices, bank statements, employee records, or product brochure. But how you manage these documents could also be the reason you face astronomical financial losses, industry penalties, and regulatory action.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Why? Because DMS systems were built to keep your documents in order, not protect the data from the threats that have emerged in recent years.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s what secure document management actually looks like, and why the system you&amp;#8217;re using right now may not be providing it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is a document management system?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A document management system is any software used as a central repository to store, track, and distribute digital documents. With the right storage practices, a DMS can remove the need for physical paperwork and keeps hard-to-track archived files within reach.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A DMS can help you:&lt;strong&gt;:&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Store and organize files: In a single location where every document that was once scattered in folders, email attachments and physical files is accessible and searchable in one search, regardless of who created it or when.&lt;/li&gt;



&lt;li&gt;Track who&amp;#8217;s seen or contributed to a file&lt;strong&gt;: &lt;/strong&gt;You can see a structured view of your entire sign-off process to double-check modifications to the document. With permissions and &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt; settings you can also limit internal exposure and keep sensitive records contained.&lt;/li&gt;



&lt;li&gt;Maintain a defensible audit trail: Pre-defined rules can help you archive or delete documents after defined periods, to help meet compliance standards. You can also track every view, edit, or download to stay accountable to regulators.&lt;/li&gt;



&lt;li&gt;Automate approval workflows&lt;strong&gt;: &lt;/strong&gt;Notifications and alerts can route documents through stages of approval requests, sign-off stages and review cycles, so you don&amp;#8217;t have to chase people down in person.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The three most common document management systems — and why they don&amp;#8217;t protect your data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The three platforms below were built for collaboration and scale, and they deliver both. But businesses should want more from their DMS.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data breaches&lt;/a&gt; happen every day and SMBs are particularly at risk. As many as &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;&lt;u&gt;25% of SMBs&lt;/u&gt;&lt;/a&gt; suffered a breach or cyberattack last year. And even if your business isn’t breached, you could fall out of compliance with regulations such as GDPR, HIPAA, or fail audits against standards like ISO 27001 because they mandate proactive data protection. The vulnerability itself is grounds for penalization.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With security in mind, we&amp;#8217;re analyzing the platforms many IT managers and CEOs choose by default.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Microsoft SharePoint&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Why it&amp;#8217;s the office default:&lt;/strong&gt; SharePoint is deeply embedded in the Microsoft 365 ecosystem, which makes it the path of least resistance for businesses already running Outlook, Teams, or Excel. It handles large volumes of documents, supports granular permission settings, and integrates with the rest of the Microsoft stack without additional configuration. For teams that live in Microsoft 365, it works.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;How it introduces security risks:&lt;/strong&gt; SharePoint&amp;#8217;s vulnerabilities are largely structural. It operates under Microsoft&amp;#8217;s broad data access model — meaning Microsoft retains the ability to access your stored content for purposes including service delivery, compliance, and law enforcement requests. Encryption is applied, but Microsoft holds the keys. Your documents are protected from outside attackers, but not from the platform itself. SharePoint also has a history of misconfiguration issues: overly permissive sharing settings are easy to set and easy to forget, and internal data sprawl — documents shared across teams with no clear ownership or expiry — is a common compliance failure mode.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What to look for instead:&lt;/strong&gt; A system where the vendor cannot access your content by design — not by policy. Look for end-to-end encryption with keys you control, clear data residency commitments, and sharing settings that default to least privilege rather than open access.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Google Drive&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Why it&amp;#8217;s the office default:&lt;/strong&gt;&amp;nbsp;&lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt; is the default choice for businesses already in the Google ecosystem — &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail&lt;/a&gt;, &lt;a href=&quot;https://proton.me/drive/google-docs-alternative&quot;&gt;Docs&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive/google-sheets-alternative&quot;&gt;Sheets&lt;/a&gt;, Meet. It&amp;#8217;s fast to set up, requires no IT overhead, and its real-time collaboration features are genuinely best-in-class. For small teams that need to move quickly, it gets the job done.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;How it introduces security risks:&lt;/strong&gt;&amp;nbsp;Google&amp;#8217;s business model is built on data. Even under a &lt;a href=&quot;https://proton.me/business/google-workspace-alternative&quot;&gt;Google Workspace&lt;/a&gt; agreement, Google retains broad rights to process your content — for service improvement, ad infrastructure, and compliance with legal requests. Like SharePoint, encryption is standard, but Google holds the keys. There&amp;#8217;s also the question of sprawl: Drive makes it frictionless to share documents externally, which means sensitive files can quietly end up accessible to anyone with a link, often without the original owner realizing it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What to look for instead:&lt;/strong&gt;&amp;nbsp;A platform that treats your documents as yours — not as data to be processed. &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;Zero-access encryption&lt;/a&gt;, where the vendor cannot read your files under any circumstances, and external sharing controls that require deliberate action rather than a single click.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Dropbox&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Why it&amp;#8217;s the office default:&lt;/strong&gt;&amp;nbsp;&lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;Dropbox&lt;/a&gt; built its reputation on simplicity. It syncs files instantly across devices, plays well with third-party tools, and has a low learning curve that makes it popular with smaller teams and freelancers. For straightforward file storage and sharing, it&amp;#8217;s hard to fault on usability.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;How it introduces security risks:&lt;/strong&gt;&amp;nbsp;Dropbox encrypts files in transit and at rest — but, again, holds the encryption keys itself. That means Dropbox employees, and by extension government requests, can access your content. It also has a notable breach history: a 2012 incident exposed 68 million user credentials, and the platform has faced criticism for how long it took to disclose the scale of that breach. For businesses handling regulated data, Dropbox&amp;#8217;s compliance coverage is also thinner than enterprise alternatives, which can create gaps against GDPR or HIPAA requirements.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;What to look for instead:&lt;/strong&gt;&amp;nbsp;Storage built for &lt;a href=&quot;https://proton.me/business/blog/blog-cybersecurity-compliance&quot;&gt;cybersecurity compliance&lt;/a&gt; from the ground up — with end-to-end encryption, documented data residency, and a vendor whose architecture makes access to your files technically impossible, not just contractually prohibited.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What secure document management actually looks like&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The three platforms above aren&amp;#8217;t insecure by accident. They were built for collaboration and scale, and they deliver both. Security wasn&amp;#8217;t the problem those providers were solving for.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If data security is a priority for your business, these are the features that separate a genuinely secure DMS from one that just looks the part.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Zero-knowledge encryption:&lt;/strong&gt; Your DMS should encrypt your documents before they leave your device. That means the vendor never has access to your content — not for service delivery, not in response to legal requests. If the vendor holds the encryption keys, you&amp;#8217;re trusting their policy. If they can&amp;#8217;t hold them by design, you don&amp;#8217;t have to.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Open-source architecture and independent audits:&lt;/strong&gt; Security claims are easy to make. Look for vendors whose architecture is open source — meaning anyone can inspect it — and whose security posture is verified by independent third-party audits, not just internal assertions.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Recognized compliance certifications:&lt;/strong&gt; ISO 27001, SOC 2 Type II, and HIPAA certification aren&amp;#8217;t just checkboxes. They&amp;#8217;re evidence that a vendor&amp;#8217;s security controls have been tested against an external standard. If you operate in a regulated industry, these aren&amp;#8217;t optional.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Jurisdiction and data residency:&lt;/strong&gt; Where your vendor is headquartered determines which governments can compel access to your data. US-based platforms fall under the CLOUD Act. Make sure you know whose laws govern your documents — and whether that&amp;#8217;s acceptable for your business.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Privacy-safe AI:&lt;/strong&gt; If your DMS includes AI features, confirm that the AI operates without visibility into your document contents — and that your data isn&amp;#8217;t used to train the underlying model.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Choosing a DMS that actually protects your data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The document management system you pick determines who can see your business&amp;#8217;s most sensitive files for as long as you retain them. Proton Workspace pairs secure document storage with team collaboration tools, so your business gets the collaboration features you need without handing a vendor the keys to your data.&lt;/p&gt;
</content:encoded><category>For business</category><author>Greg Ng</author></item></channel></rss>