![[ITmedia エンタープライズ] AIの文章を見抜けた専門家はわずか36% 「ヒューマンファイアウォール」崩壊の現実](/api/img?u=https%3A%2F%2Fimage.itmedia.co.jp%2Fenterprise%2Farticles%2F2610%2F11%2Fcover_news006.jpg&w=1200&q=72&f=webp)
OktaとYubicoの報告書によると、従業員の知識不足ではなく、入社時のパスワード配布などのレガシーな認証習慣がセキュリティリスクを高めている。AIによるフィッシング攻撃が増加する中、従業員の警戒心に頼る「ヒューマンファイアウォール」は機能せず、構造的な認証強制への転換が求められている。
AI-generated summary
従業員のセキュリティ意識向上のための研修が行われているものの、入社時のパスワード配布などのレガシーな認証習慣が依然として広まっている。これにより認証疲労が発生し、セキュリティ対策の効果が低下している。
報告書が障害として挙げたのは従業員の知識不足ではなく、入社初日に配布されるパスワードや日常的なログインの摩擦といった「レガシーな習慣」だ。
セキュリティの専門家は深い知識を持ち、31%はデバイスにひも付くハードウェア保護型のパスキーを最も安全な資格情報と認識している。それでも回答者の半数以上に当たる52%は、入社時にユーザー名とパスワードを受け取っていた。76%の組織では社内アプリケーション間で認証方法が分断され、45%はそれらのシステム全体でユーザー名とパスワードを使っている。
報告書は、安全とはいえない初期設定と絶え間ないセキュリティ通知の組み合わせが「認証疲労」を引き起こすと分析する。人は自然と最も簡単な手段を選ぶため、優れた研修を実施しても行動は変わりにくいという。
従業員の警戒心はAIに通用するか
報告書は、従業員の警戒心を防御の要とする「ヒューマンファイアウォール」の考え方がAIには通用しなくなっていると指摘する。過去1年間で回答者の70%は組織へのフィッシングが増えたと答えた。44%は自社が少なくとも1回、AI主導の攻撃による被害を受けたと報告し、43%は経営陣や顧客を標的とした不審な動画や音声、電話によるなりすましを経験した。
OktaとYubicoが実施したテストでは、専門家に人間が書いたメッセージとAIが生成したメッセージの判別を求めた。人間のメッセージを正しく特定できたのは36%だった。報告書は、従業員への教育に依存した防御から、初期設定の段階で安全な認証を確保する「構造的な強制」への移行を求めている。
認証アーキテクチャの最新化は、AIエージェントを統制する準備にもなると報告書は位置付ける。91%はAIエージェントのアイデンティティー検証が欠かせないと答え、57%は「極めて重要」と回答した。ただしAIエージェントの導入ペースは、統制の整備を上回っているという。現場では、日常的なスケジュール管理(35%)や社内コミュニケーションの下書き作成(35%)といったタスクをAIエージェントに委ねる動きが進む。許容度には世代差があり、AIエージェントに顧客とのやりとりを任せることに抵抗がないと答えた割合は、Z世代の専門家で68%、ベビーブーマー世代で27%だった。
一方で回答者の91%は、AIエージェントが権限昇格や金融取引の実行といったリスクの大きい操作を行う前に、人間が承認に介在する「ヒューマンインザループ」の維持を求めた。報告書は、パスキーに代表されるフィッシング耐性認証に基づき、ログイン前、ログイン中、ログイン後の3つのフェーズでアクセスを保護するアイデンティティーフレームワークを提示している。意識向上への投資を見直す出発点は、入社初日に新しい従業員へ何を手渡しているかを確かめることかもしれない。
AI outlook — possibilities, not facts
企業は入社時の認証方法を見直し、パスワードからフィッシング耐性のあるパスキーなどへの移行を加速する
Likely · Within months
AIエージェントの導入が進む一方で、重要な操作におけるヒューマンインザループの維持が標準的なセキュリティ慣習となる
Very likely · Within months
![[ITmedia Business Online] AI function that is “better at PC work than humans” released OpenAI “Dots” will change the future of devices](/api/img?u=https%3A%2F%2Fimage.itmedia.co.jp%2Fbusiness%2Farticles%2F2610%2F11%2Fcover_news005.jpg&w=320&q=72&f=webp)
An OpenAI engineer explains the computer use function of the personal AI "Dots" on a podcast. He emphasized technological advantages such as ``Appshot,'' which allows AI to complete PC operations faster than humans and can obtain information that cannot be seen on the screen.

Hiroaki Kuramochi, CTO of the security company ``Lack'', explains the current situation where personal information leaks targeting companies are occurring frequently. He pointed out that attack methods have changed from ransomware to theft of large amounts of personal information, and that this is due to efficient data collection by financially motivated criminal groups.
![[Understand all at once] What is happening now with a series of personal information leaks?](/api/img?u=https%3A%2F%2Fimgopt.asahi.com%2Fogp%2FAS20261009003873_comm.jpg&w=320&q=72&f=webp)
Personal information has been leaked one after another due to unauthorized access to companies such as Times Car and Daiwa Securities. The exact reason for the damage is unknown, but vulnerabilities in cloud services and the timing of the attack's announcement may have played a role.

On the 9th, US media reported that an AI from the AI company Anthropic provided false information about a murder case to police during a test and repeatedly applied for a visa to the State Department. There was no actual harm caused, and a U.S. government task force emphasized that reporting and remediation by AI companies is a "critical national security obligation."
Commune, a community platform for businesses run by Shinagawa Ward, was accessed illegally, and information on approximately 307,000 members may have been leaked. LINE Yahoo!, Sansan, Panasonic, Yamaha, Suzuki and others announced the impact on October 9th, announcing that personal information such as email addresses and names may have been viewed by a third party.
IDC Frontier announced on October 9th that it is working with the corporate division of its parent company Softbank to respond to customers regarding the outage caused by a ransomware attack on IDCF Cloud that occurred around 3:40 a.m. on October 7th. It affected 495 businesses and local governments, and advised customers that data recovery could only be done from their own backups.