Skip to main content

Before You Switch On AI: Five Foundations to Get Right First

AI doesn't create risk. It accelerates whatever is already there.

In almost every business we speak to right now, someone on the team is asking to use AI. Copilot, Claude, ChatGPT, a local model, an agent that automates a process. The interest is genuine, and often it comes from your best people.

That enthusiasm is a good thing. The question is no longer whether your business will use AI. It's whether your environment is ready for it when you do.

AI amplifies your current posture


AI tools don't bypass your security. They work inside it, at speed. Copilot will happily summarise any document a user already has permission to open, including the folders nobody remembers sharing.

If access is broader than intended, AI makes that visible on day one. If sensitive data has no owner, AI will surface it to whoever asks. Nothing was "hacked". The permissions simply allowed it, and AI removed the effort of looking.

That's why the right first move isn't picking a tool. It's understanding what the tool will inherit.

The five foundations


Before rolling out AI to your team, these are the areas we check first:

  • Identity and access. MFA enforced for every user and administrator, admin roles reviewed, and emergency access documented. Accounts are the front door, and AI raises the value of what's behind it.
  • Data location and ownership. You know where sensitive information lives, and a named person owns each location. If nobody owns it, nobody notices when AI starts reading it.
  • Sharing and permissions. External sharing reviewed, broad "everyone" access reduced, and permissions aligned to real roles rather than history.
  • Recovery confidence. Backup coverage confirmed and a restore actually tested. As AI becomes part of daily work, the cost of losing that data grows with it.
  • Usage guidance and ownership. Staff know what can and can't go into AI tools, and someone in the business owns AI decisions, so adoption doesn't happen by default.

"No" is the wrong answer. So is "sure"


When a team member asks to bring in AI, blocking it usually just moves the activity somewhere you can't see it. Waving it through without guardrails hands your data governance to a tool that doesn't know your business.

The response that works is a structured trial: agree what the tool is for, decide where it can pull information from, put the guardrails in place, then expand from evidence rather than enthusiasm.

That conversation is far easier when you know where the foundations actually stand, rather than where everyone assumes they stand.

How to find out where you stand


This is exactly what our Cyber Snapshot was built for. It's a plain-English review of identity, email, data, recovery, monitoring and AI readiness, delivered as a traffic-light report with a 30/60/90 day plan.

  • No jargon, written for business owners and directors
  • Clear view of what's solid, what needs attention, and what can wait
  • An AI readiness baseline, so adoption starts from facts

From there, the path forward is deliberate: fix the highest-impact items first, then bring AI in on ground that holds.

Final thought


Every business will adopt AI over the next few years. The ones that get value from it safely won't be the ones that moved first. They'll be the ones that got the foundations right, then moved fast.

Thinking about AI for your business?

Find out where your foundations stand before you switch anything on.

Get a Cyber Snapshot