This is the Way: Navigating the Security Challenges of Generative AI in the Corporate Sector
2023-10-07 , Track 2

This talk will dive into the implementation of Azure OpenAI Service for ChatGPT at Kimberly-Clark and how it enabled the business to use ChatGPT with more security controls. Kimberly-Clark, a Fortune 200 organization, wanted a secured space for employees to utilize ChatGPT.


The journey to implement the Azure OpenAI Service for ChatGPT at Kimberly-Clark was a quick paced effort to minimize the risk of employees prompting the OpenAI public model with proprietary or sensitive data. Development, privacy, legal (intellectual property), cybersecurity, awareness training, and data protection teams had to work collaboratively to understand the native security controls implemented by Microsoft and risks of using the Azure OpenAI Service. Additionally, we implemented enterprise security controls to enable the business to use the Azure OpenAI Service for ChatGPT.

J.J. Widener has over 15 years in IT and 10 years in information security. He has served as a CIO and CISO in Higher Education and has security leadership experience at healthcare and insurance organizations. He earned an MBA in Information Assurance and multiple information security and privacy certifications including CISSP, CISM, CISA, CRISC, CIPP/E, CIPM, and is an active member of ISC2, ISACA, and IAPP. J.J. also holds nine Azure certifications focused on Cybersecurity, compliance, data science, and artificial intelligence.

Jerome (JD) de las Alas is a Product Security Architect from Kimberly-Clark. He has 13 years of experience in the cyber security industry - with background in application security, secure software development, and IoT security. He holds industry certifications such as CISSP, GWAPT, GPEN, GMOB, C|EH, C|SP, and ITIL Foundations. Outside cyber security, his interests include astrophotography and sports.