hybridresourcing Sign up for the waitlist

Kennisbank

Privacy and security: what a level up really requires from you

Privacy and security is one of the seven dimensions in hybridresourcing's maturity assessment. It is also the dimension that generates the most questions, usually in the form of: what does it cost to move up a level here. The answer is never an amount. It depends on what is already in place, on who already has a say in it, and on how far along the rest of the organization is.

What this dimension measures

Privacy and security is about whether the organization knows which data an AI application touches, who is allowed to decide about that, and whether that decision is fixed or just happens to go well by chance. That is something different from a privacy statement or an ISO certificate. An organization can be fully compliant on paper and still have no idea what happens the moment an AI tool processes customer data that no one had designated as input. This dimension does not measure documentation. It measures whether the organization can answer the question before anyone asks it.

That makes privacy and security one of the foundational dimensions, together with the maturity of your organizational structure and the state of your IT infrastructure. Foundational dimensions come first, not because they are more important, but because the rest of the framework rests on them. An organization that is already far advanced on people and skills but not on privacy and security is building on a foundation that can shift at any moment.

How you can tell where you stand

At the baseline level, there is no shared picture. Some people in the organization know exactly which data is sensitive, others have never given it a thought, and no one has ever exposed that difference. That is exactly what the baseline level in practice means: not that nothing is in place, but that what is in place happens to be sound, or happens not to be.

At the foundation level, there is a first shared agreement: which categories of data are sensitive, who decides about that, what may and may not be processed by an AI tool. That agreement exists, but it is not yet followed equally strictly everywhere, and not everyone is aware of it. The foundation level in practice describes what that first step looks like in other dimensions, and the pattern here is comparable: the agreement exists, the consistency does not yet.

At activation, the agreement is embedded in the process itself: new AI applications are only used once it has been established which data they touch and who has approved that. At insight, that process is monitored and adjusted based on what goes wrong in practice or is noticed just in time. At intelligence, the question of data and consent is no longer a separate process, but built into how every new application is assessed, by whomever is assessing it.

The spread between these levels becomes visible in the plotting round: different people in the organization score this dimension separately, without seeing each other's answers. For privacy and security, that spread is often larger than for other dimensions. A CISO sees the process he himself set up and scores it high. A team lead who uses AI tools without ever having heard of that process scores it low. Both answers are true. The spread itself is the measurement.

What a level up requires

There is no fixed amount or fixed timeline to name, because that depends on where the organization already stands and how complex its data landscape is. What is certain is the nature of the step. Moving from baseline to foundation does not require a technical project, but a conversation: which data is sensitive, who decides about that, and is that answer the same for everyone who is asked. Moving from foundation to activation requires that the agreement no longer stands apart from the process, but is woven into it, so that a new AI application does not go into use before the question about data has been answered.

That step rarely affects privacy and security alone. An organization that wants to move forward here often discovers that the question of who is allowed to decide can only be answered if it is also clear who in the organization has which skills to make and oversee that decision. And without some form of structural assessment of how AI applications perform, the question of whether the process works remains unanswered until something goes wrong. The seven dimensions do not stand apart from one another; they hold each other back or carry each other forward.

What this does not answer

This measurement says something about whether the organization can support an AI application without privacy and security becoming the weak point. It says nothing about which work, which task, or which part of a role AI can take over. That is a different question, with a different instrument. FTE TO AI's work scan calculates, per task, which part of the work can be taken over, based on what that task requires and what AI can actually do. That outcome is only reliable once the supporting side, including privacy and security, is in order. hybridresourcing's maturity assessment precedes that.

The tool with which you can carry out this assessment yourself, including the plotting round with multiple assessors, is under construction. Anyone who would like to be notified once it becomes available can sign up for the waiting list.

Robbyde assistent van de volwassenheidsmeting

Vraag maar wat er moet staan voordat AI in uw organisatie kan landen.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.