Skip to content

Security & risk, read from an operations desk

Everything we have published under Security & risk, read from an operations desk: what it changes for a B2B company of 10-200 people.

  1. Latest

    OpenAI Adds No-Retention Option for API Calls to Its Top Models

    OpenAI has extended Zero Data Retention (ZDR) to frontier models accessed via its API, so eligible customers can process prompts and completions without OpenAI storing that data afterward. This matters because it removes a standing objection — data persistence — that has blocked regulated or privacy-sensitive B2B companies from using top-tier models in production sales and support workflows.

    What changes for operators — If your company handles customer PII, contract terms, or support tickets with regulated content, ZDR access changes the calculus on which OpenAI model you can legally route that data through. Previously, many 10-200 person B2B firms either avoided frontier models for sensitive workflows or built custom redaction layers before calls. With ZDR available for eligible accounts, ops and legal teams can revisit those workarounds — potentially simplifying pipelines for support ticket triage, sales call summarization, or CRM enrichment that touch customer data. The catch: ZDR eligibility isn't automatic. It typically requires an enterprise agreement or specific API tier, and it may still exclude certain features (like persistent memory or fine-tuning on your data). Before assuming this unblocks anything, check whether your current OpenAI contract tier qualifies, and confirm which specific models and endpoints the zero-retention policy covers — the announcement does not guarantee blanket coverage across every product surface.

  1. OpenAI Says AI Defenders Have a Closing Head Start Over Attackers

    For a 10-200 person B2B company, this is a prompt to move faster on defensive AI rather than wait for a mature vendor category to settle. Support inboxes and helpdesk queues are already common entry points for AI-generated phishing and social-engineering attempts; wiring AI-based anomaly detection into ticket triage, vendor invoice review, and access request workflows now costs little and closes an obvious gap. Waiting until attackers routinely use AI to craft convincing account-takeover attempts or fraudulent payment requests means playing catch-up instead of using the current asymmetry to harden processes cheaply.

  1. OpenAI and Hugging Face Respond to Security Incident Found During Model Evaluation

    If your team uses Hugging Face-hosted models, evaluation harnesses, or benchmarking tools anywhere in your sales, support or ops stack — even in a dev or staging capacity — this is a prompt to check what data (customer transcripts, CRM exports, ticket samples) may have touched those environments during testing. Most 10-200 person B2B companies don't treat model evaluation as production infrastructure, which is exactly the gap incidents like this exploit; the fix isn't panic, it's adding evaluation/testing environments to your existing vendor risk review instead of scoping that review only to live production integrations.

  2. OpenAI Says It Shut Down AI-Powered Scam Network Targeting Businesses

    If you run sales, support or ops at a 10-200 person B2B company, this isn't abstract — your inbox, support queue and vendor onboarding flow are exactly where AI-generated scam content shows up first, because it's cheap to produce and hard to distinguish from legitimate outreach at a glance. The practical takeaway is to tighten verification steps in anything customer-facing or finance-adjacent that runs partly on autopilot: invoice approval, new vendor setup, password reset requests, and inbound "urgent" messages from executives or partners. If your automation stack handles any of these without a human checkpoint, this is a good moment to add one, not remove it. It's also a reminder that the same AI tooling making your team faster is available to the people trying to defraud you, so detection and process design matter as much as raw automation speed.

  1. OpenAI Scales Up Daybreak, Its AI-Powered Cyber Defense Initiative

    Most 10-200 person B2B companies are not OpenAI's direct customers for Daybreak — this is aimed at critical infrastructure operators, security researchers and large enterprises first. But the underlying warning applies regardless of company size: AI is making attack tooling cheaper and more automated, which means phishing, credential-stuffing and social-engineering attempts aimed at smaller companies will likely get more convincing and more frequent, not less. If your ops stack touches customer data, payment systems or shared credentials across sales and support tools, this is a prompt to audit access controls and multi-factor authentication now rather than wait for AI-native defense tools to trickle down to your budget tier.

Next step

Free AI Diagnostic

Fifteen minutes, no email required. It maps where your work actually goes and ranks what is worth automating first.

Start the free diagnostic

Starts immediately in the browser.

Fee
Free
Length
15 minutes

You keep the ranked list of candidates either way.