Page 16 of 55

Tech sector navigating layoffs while riding GenAI wave, says GlobalData

The technology industry, says GlobaData, has already witnessed substantial changes in 2024, including layoffs by big companies such as Google, Amazon and Meta, a trend, it adds, that began last year, affecting over 191,000 employees, driven by factors like post-COVID-19 pandemic adjustments and a focus on emerging tech like artificial intelligence (AI).

Despite these and other challenges, the data and analytics firm says there is a “positive outlook for AI roles, especially those in customized generative AI solutions and machine learning operations (MLOps). This underscores the dynamic nature of the employment landscape within the technology sector.”

Kiran Raj, practice head of Disruptive Tech at GlobalData, said, “in the context of AI jobs, this trend represents a dual narrative. While layoffs create challenges within the tech industry, there is also a growing demand for specialized AI and machine learning talent as these technologies become increasingly integrated into business operations.”

This demand, added Raj, is “particularly for generative AI-powered custom applications, catering to specific market needs while enhancing privacy and security.”

According to Saurabh Daga, associate project manager of Disruptive Tech, “the shift towards tailored generative AI tools is increasingly evident, catering to the specific market niches and user needs. This approach is particularly advantageous in sectors like healthcare, finance, and legal, enhancing efficiency and privacy.”

A release issued this week points out that recent analysis of Global Data’s Job Analytics database “underscores these trends where the job postings related to generative AI (GenAI) have grown by 42 per cent from Q3 2023 to Q4 2023. Moreover, the data points towards a much lower five per cent increase in overall AI-related jobs in the same period. This emphasizes the importance that enterprises are placing on transformative outcomes through generative AI.”

In 2024, said Daga, the tech industry stands at a crossroads of transformation and adaptation: “The employment landscape is being shaped by a combination of macroeconomic and technological changes. This dynamic landscape underscores the need for workforce development, hiring, and reskilling to meet the industry’s evolving demands.”

The post Tech sector navigating layoffs while riding GenAI wave, says GlobalData first appeared on IT World Canada.

Cyber Security Today, Week in Review for week ending Friday, Feb. 9, 2024

Welcome to Cyber Security Today. This is the Week in Review for the week ending Friday, Feb. 9th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



In few minutes Terry Cutler of Montreal’s Cyology Labs will be here to discuss recent news. That includes how a deepfake video conference call fooled an employee of a Hong Kong company into wiring US$25 million to crooks, why the U.S. Federal Trade Commission called the cybersecurity of a company “shoddy,” details about a hack at Cloudflare and promises by some countries to get tougher on the abuse of commercial spyware.

Before we get to to discussion I want to do a quick review of other headlines this week:

Remember that deepfake video conference call that I said Terry and I will talk about? One of the ways fake content can be spotted is if it doesn’t have a label or watermark attesting to its legitimacy. There’s a group of tech companies called the Coalition for Content Provenance and Authentication that’s trying to do that. In the latest news Google joined the coalition this week. The goal is to create tamper-resistant metadata that can be attached to any digital content — a photo, a video or an audio file — that shows how and when the content was created or modified.

Remember I said in the discussion Terry and I will also talk about countries promising to take action against the abuse of commercial spyware? The spyware comes from developers who find holes in applications and exploit them. How big a problem is it? Google issued a report this week saying commercial spyware is behind half of the known zero-day exploits targeting Google products and Android devices.

Separately, Google said it is about to start a pilot project in Singapore that blocks the loading of financial fraud apps on Android devices. If it’s successful the effort could spread to other jurisdictions.

A New York City medical centre will pay US$4.75 million to settle allegations by the U.S. Department of Health and Human Services that potential data security failures led to an employee stealing and selling health information on 12,000 patients. The hospital didn’t know about the theft until alerted by police. Problems included failing to monitor and safeguard the hospital’s health information system.

Two big data breach notifications in the U.S. took place this week: Verizon Communications said a staff member stole the personal information of over 63,000 employees last September. And Bayer Heritage Federal Credit Union of West Virginia said personal information on just over 61,000 customers was taken in a cyber attack last fall.

Finally, JetBrains, Cisco Systems, Fortinet and VMware this week released security fixes. JetBrains says there is a critical vulnerability in TeamCity server that needs to be patched. The Cisco patches fix critical holes in Cisco’s secure remote access Expressway Series. Fortinet released updates for its FortSIEM system event manager to plug holes. And VMware released patches for Aria Operations for Networks to close five vulnerabilities.

(The following is a transcript of the first of four topics discussed. To hear the full conversation play the podcast)

Howard: Topic One: An employee was recently suckered into transferring millions to crooks based on a sophisticated deepfake video call.

Hong Kong police say the employee, who worked in the finance department of an unnamed multinational company, was tricked into sending $25 million to crooks by what appeared to be the company’s chief financial officer on a video conference call. The employee got an email message asking them to get on the call, which was about a secret transaction. And there on the video call was the CFO and other people the staffer recognized. So he followed instructions.

This is an example of the sophistication of fake video calls, perhaps helped with artificial intelligence. But the big question is did this company have no business process rules? Like “transfers over $1 million must have double authorization?”

Terry Cutler: This is going to require a multifaceted approach. If you’re dealing with a CFO used to transferring this large amount of money it’s going to be a bit more tricky than just saying, ‘Oh, they didn’t have the proper processes.’ But they’re going to start bringing in more AI-based detection and prevention solutions. What’s going to be happening now is because these deepfakes are so difficult to find it’s going to be having like a detection system on steroids. It’s going to come down to ‘My AI bot just beat your AI bot.’ That’s going to get really tricky. You think humans are eventually going to lose control because they can’t keep up with what’s going on behind the scenes with AI. But have to start looking at something more — maybe more advanced authentication and verification methods. For example, signing their payments with digital signature algorithms either from RSA or ECDSA, which is the elliptic curve digital signature algorithm. These are all tactics that can help.

As for awareness training, we’re seeing a big problem because users are so used to templated training which is very, very, very boring. Employees are not engaging with it. They don’t see a need for cyber security because it doesn’t concern them, but they need to understand that this is everyone’s responsibility. So we need to have other types of training that’s more edutainment. That will help educate them on why it’s so important to stay up-to-date with cyber security, and not just that because they’re a victim of a scam. We [also] need proper incident response plans for what happens when this type of thing goes wrong, especially around deepfakes. It’s getting so difficult to spot them And, of course, they should be sharing information of how this [scam] occurred so other companies don’t fall victim.

Howard: One tip for the employee was the email that that invited him onto this video conference call was, ‘This is a secret transaction.’ In awareness training one of the things you’re warned is to look for little signs like, ‘Please treat this as confidential’ or ‘This is a matter of urgency and you’ve got to transfer this money quickly.’ To be fair to the employee, according to the police, initially was suspicious. But all of the people on this video call looked real and looked like they were people he knew.

Terry: That’s what’s going to be tricky. Imagine you wake up one morning and your bank account is drained and you call up your bank and it says this was an authorized transaction. Your your colleagues were on the call. It was voice-verified. It was email signature verified. Everything was verified — and you’re left with an empty bank account. It’s very very scary what’s coming up.

Howard: I appreciate that this was a big company and presumably was used to transferring large amounts of money — and I assume that the employee was someone who had authorization to transfer large amounts of money. But $25 million is big cash. You need verification controls.

Terry: I agree, and I think this is something they’re going to put in place now. We’re going to have multiple members [of the company] that have to sign off on this [large transfers]. More than just dual authentication. Maybe it’s going to be better to have other people that are responsible for the transaction to be actually on the call. as well as a separate call to make sure it was really them — implement a hierarchical approval workflow. Maybe have some independent channels that can verify via a phone call. Maybe also set up transaction limits.

I’ll give you an example. One of my friends was defrauded of $445,000 from his company. Originally he was never wiring more than $50,000. But when he got hacked the scammers took control of his bank account and started wiring large amounts to Mexico. The banks never stepped in because his accounts were preauthorized for half a million dollars. Because the the threshold was set to to that the [crooks’] transaction went through. So I think they [banks] are going to start looking at transaction limits before giving approvals.

Howard: And as you said, this incident speaks to the sophistication of fake voice and video these days.

Terry: This is really scary stuff, because it’s very difficult to know if it’s fake. We’re going to need help from third-party vendors, maybe some telecoms that can trace the signature see where if it came from.

Howard: In related news, this week Meta announced that it will soon label all AI-generated images that are posted on Facebook and Instagram to help people be aware of fake pictures. It won’t matter whether the images were created with Meta’s AI tool or another company’s tool. There will be some sort of label or watermark. Right now Meta marks photos on Facebook and Instagram that use its tool. It says beside the picture ‘Imagined with AI.’ Hopefully there will soon be a capability to tag not only AI-generated still photos but also videos and audio files. Meta says that if it determines that a digitally created or altered image video or audio has a high risk of deceiving the public on a matter of importance the label may be more prominent than the label that it gives to other images. This watermarking wouldn’t have helped in the deepfake video call case that we just discussed, because that was a private call. But it shows that industry players are thinking about this and trying to find solutions.

Terry: It’s going to be interesting to see, because AI is heavily used for marketing as well. And since since the rise of ChatGPT we see all these so-called marketers that are coming in with new methods to sell their products. There’s a heavy reliance on AI. It’ll be interesting to see social media platforms saying, ‘This was created with ChatGPT and is not original.’

The post Cyber Security Today, Week in Review for week ending Friday, Feb. 9, 2024 first appeared on IT World Canada.

Canada falling behind G7 peers in cybersecurity oversight, warns BlackBerry

Opposing viewpoints on the Liberal government’s proposed cybersecurity law for critical infrastructure providers highlighted a Parliamentary committee hearing on Thursday.

A BlackBerry official urged MPs on the House of Commons national security committee to pass Bill-26, because other countries have laws putting legal cybersecurity responsibilities on the private sector.

“Canada is out of step with its closest allies, and this legislation will help close the gap,” said John de Boer, the company’s senior director of government affairs and public policy for Canada.

Jennifer Quaid, executive director of the Canadian Cyber Threat Exchange, a threat information co-operative, said that with “a few small modifications” the bill will help strengthen cybersecurity among critical infrastructure providers.

And Chris Loewen, executive vice-president for regulatory affairs at the Canadian Energy Regulator (CER), which regulates interprovincial pipeline and electricity operators, said the bill’s mechanisms for regulators would be similar to the way CER currently works.

But Francis Bradley, CEO of Electricity Canada, an association of power providers, warned that the proposed legislation could put Canadian energy producers offside with the cybersecurity requirements of the North American Electric Reliability Corp. (NERC), which oversees U.S. and Canadian companies.

Leila Wright, executive director for telecommunications at the Canadian Radio-Television and Telecommunications Commission (CRTC), said that C-26 would give her agency a new mandate to promote cybersecurity among telecom providers and ensure carriers comply with government cybernetics-related orders. But she wouldn’t comment on omissions or ways the bill could be improved, because it’s a proposed law. The commission’s job, she explained, is to implement legislation that has been passed.

To emphasize the importance of action, de Boer noted that in the last four months of 2023, BlackBerry stopped 5.2 million cyber attacks on behalf of customers; 62 per cent of them targeted critical infrastructure (CI) providers like banks and government departments.

A Five Eyes report this week on the China-backed Volt Typhoon threat group said it had compromised several critical infrastructure providers in the U.S., he noted, including some in the communications, energy, transportation and water sectors. A U.S. official, he added, fears the report is just “the tip of the iceberg.”

Aside from data privacy protection requirements in the Personal Information Protection and Electronic Data Act (PIPEDA), Canada has no legislation to make critical infrastructure providers report, prepare for, or prevent cyber attacks, he said.

By contrast, in 2022 the U.S. passed the Cyber Incident Reporting for Critical Infrastructure Act, requiring CI providers to report cybersecurity incidents to the government within 72 hours. Also in 2022, the European Union passed legislation forcing providers to implement baseline cyber security and to notify national cybersecurity authorities of serious incidents within 72 hours.

“Canada is falling behind our G7 peers in cybersecurity,” de Boer said.

Bill C-26 has two parts: One would amend the Telecommunications Act to give the federal cabinet and the Minister of Industry the power to order designated telecom providers to do “anything” to secure their systems against a range of threats. The CRTC would have a role in ensuring telecom providers comply with the act.

The other part of C-26, creating the CCSPA, would apply to other critical infrastructure providers. Initially, these would be limited to banking, financial clearing firms, interprovincial transport and energy companies, and nuclear power operators. Similar to the Telecommunications Act changes, it would create a cyber security compliance regime for designated firms. Included would be a requirement to report cyber incidents “immediately” to the Canadian Security Establishment (CSE), the branch of the Defence Department responsible for government cybersecurity.

The CCSPA will help governments and the private sector quickly share cyber attack information, de Boer said, warn and protect other potential victims, and rapidly deploy assistance to contain damage from attacks.

The proposed CCSPA isn’t perfect, he said. He recommended three changes:

— the obligation for CI providers to report cyber events immediately should be changed to within 72 hours;

— there should be guarantees that companies can’t be sued or prosecuted for cyber-related information reported to the government;

— and the bill should make it clear firms won’t be punished if they put good faith efforts into cybersecurity, but their firm suffered a breach of security controls or is believed to be offside the law.

Quaid said CCSPA’s preamble should encourage all Canadian public and private organizations to share their cyber threat information; should allow CI providers to share threat information through cyber exchanges as well as with government; and should allow CI providers to join any cyber security threat information sharing association.

Bradley complained the bill doesn’t recognize established security standards and expertise within the Canadian power sector. Among other problems, he said, the bill leaves the definition of a cybersecurity incident that has to be reported to yet-to-be-announced regulations. Our definition must be the same as NERC’s, he said.

Click here to see Electricity Canada’s written submission

NERC’s cybersecurity requirements — which Electricity Canada members have to follow — are higher than the CCSPA, he added, which is why he believes the bill won’t improve cybersecurity among his members on this side of the border.

But Bradley did say that while the cybersecurity of the energy providers here is higher than in other sectors, the CCSPA would help fill the gap.

He doesn’t want to see the passage of the bill delayed, but thinks it should be amended in some areas.

Hearings resume Monday, with testimony from federal Privacy Commissioner Philippe Dufresne, the Office of the Superintendent of Financial Institutions, the Canadian Bankers Association and the Canadian Telecommunications Association.

The post Canada falling behind G7 peers in cybersecurity oversight, warns BlackBerry first appeared on IT World Canada.

Cyber Security Today, Feb. 9, 2024 – A record US$1 billion paid to ransomware gangs last year, and more

A record US$1 billion paid to ransomware gangs last year, and more.

Welcome to Cyber Security Today. It’s Friday, February 9th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Organizations paid out more than $1 billion to ransomware gangs last year. That’s according to numbers compiled by Chainalysis. And that’s just the cash. It doesn’t include the clean-up costs victims paid — and, the report notes, victims who didn’t pay had to cover those business and recovery costs as well. The willingness of organizations to pay is the main reason why ransomware gangs survive and expand, despite arrests, convictions and the takedowns of some gangs’ IT infrastructure. One strategy of many gangs: Fewer attacks but targeting big organizations that can afford to pay big money to get access back to stolen or scrambled data.

One ransomware gang pulled in an estimated US$100 million by not executing ransomware: That was the Cl0p group, which exploited a vulnerability in the MOVEit file transfer application to steal data from over 1,000 organizations. At that scale data theft was more efficient than running ransomware.

According to a separate report this week issued by the NCC Group, three new ransomware groups were detected in December alone. The number of successful ransomware attacks in 2023 rose to a record 4.667 cases.

Meanwhile on Thursday the U.S. State Department announced a US$10 million reward for information leading to the identification of key members of the Hive ransomware gang. It’s also offering US$5 million for information leading to the arrest or conviction of anyone linked to the Hive gang. The FBI took down the gang’s IT infrastructure 12 months ago.

Ivanti has found another vulnerability in its Connect Secure and Policy Secure gateways, as well as its ZTA gateway. The patch was quietly released for customers on January 31st and is only publicly being announced now. IT administrators that haven’t plugged this hole by now had better get cracking.

Want to download the LastPass password manager for your iPhone? Beware of an app impersonating the real one on the Apple App Store. Despite Apple’s attempts to keep malware out of the store, this one snuck in. The fake can be identified by its name: LassPass, instead of LastPass.

The U.S, has created an Artificial Intelligence Safety Institute Consortium. Its goal is to unite AI creators and users, academics, industry researchers and others to help develop and deploy trustworthy AI applications. This follows President Joe Biden’s Executive Order of last October requiring developers of the most powerful AI systems to share their safety test results with the federal government.

Later today the Week in Review podcast will be out. Terry Cutler of Cyology Labs and I will discuss some news headlines from the past seven days.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 9, 2024 – A record US$1 billion paid to ransomware gangs last year, and more first appeared on IT World Canada.

Superbowl ad from Microsoft tries to make peace between artists and AI: Hashtag Trending for Friday, February 9th, 2024

Microsoft’s Superbowl ad tries to make peace with artists. Google giveth – bringing Gemini to Canada and Meta threatens to taketh away with a veiled threat against their Montreal workforce if the government regulates AI in a way they don’t like.

All this and more on the “nice economy you got there, shame if something should happen to it” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

I was about to do a story asking if Google was punishing Canada for our government’s insistence that they actually pay Canadian publishers for the news they use and make money from, but then the folks at Google made me eat my (almost) words.

Google has announced the launch of its generative artificial intelligence (GenAI) chatbot, Bard, now available in Canada and rebranded as Gemini.

So not only are we getting the latest in Google’s AI, but we get in in Canada – no more VPN to pretend we’re American.

And Google is offering this to both English and French-speaking Canadians.

The rebranding to Gemini seems to indicate that Google is trying to turn a new page and give OpenAI a run for our money.

There are various versions to cater to different devices and use cases, including Gemini Nano for smartphone processing and Gemini Ultra for more complex tasks like coding and logical reasoning.

And Gemini Advanced is part of the new Google One AI Premium Plan, priced at $26.99 per month CANADIAN.

It offers subscribers an integrated AI experience across Google Workspace applications, including Gmail, Docs, Slides, and Sheets. This integration, formerly known as Duet AI, embeds AI into everyday digital experiences, making sophisticated AI tools more accessible to a wider audience.

Mobile apps are coming soon, but initially only in English, we hope that French will be coming soon.

Sources include: IT World Canada,

Meta, the parent company of Facebook, has expressed concerns over Canada’s proposed Artificial Intelligence and Data Act (AIDA). During a parliamentary hearing, Rachel Curran, head of public policy for Meta Platforms in Canada, voiced that Meta might reconsider launching some of its products in Canada if the proposed AI law remains unchanged.

More than that, she said, “Our global AI research is based in Montreal. The wrong regulatory framework, over-reach, or over-regulation by the government would drive that kind of activity out of the country. And I would hate to see that because we are leaders in AI research.”

AIDA, part of Bill-C-26, seeks to regulate AI systems by categorizing them into three classes based on their potential impact.

The legislation aims to mitigate risks of harm or biased outputs from AI systems, a move that has been met with both support and criticism from the tech industry.

While some provisions of AIDA are applauded for their intent to maintain public trust in AI applications, tech leaders, including those from Amazon, Google, and Microsoft, have called for more clarity and flexibility in the law.

They argue that overly stringent regulations could stifle innovation and place an undue burden on the Canadian AI industry.

As Canada strives to align its AI legislation with international standards, the outcome of these discussions will be crucial in shaping its position as a leader in AI research and development.

But as a Canadian, I must say that this “nice economy you got there, be a shame if something should happen to it” sounds a little thuggish from Meta.

Sources include: IT World Canada

Two quick stories for this week that we want to make sure you catch. First, in response to the AI Deep Fake calls that have happened which have faked Joe Biden’s voice and are spreading what Biden would call  “malarkey” – the Federal Communications Commission in the US is outlawing robocalls that have AI generated voices.

Telemarketers in the US cannot use automated dialers or artificial or pre-recorded voice messages to call cellphones, and they cannot make such calls to landlines without prior written consent from the call recipient. And if they use Deep Fakes, there will be penalties.

Sources include: AP News

And I know Howard Solomon has covered this on our sister podcast, CyberSecurity Today, but this week it was discovered that a Chinese Hacker Volt Typhoon had infiltrated US infrastructure and had been there for more than 5 years. I wouldn’t bet against them having a similar foothold in Canada.

Check out Howard’s podcast or stories for me news. But ITWC also will be doing a look at civic infrastructure in Canada in our Technicity event series – watch for it.

And yes, even we have a mandatory SuperBowl story.

Microsoft has recently unveiled a significant update to its Copilot AI search and chatbot experience, introducing a new AI image creation and editing functionality alongside a fresh AI model named Deucalion.

This move not only enhances the capabilities of Copilot and not also signals Microsoft’s deepening commitment to integrating generative AI technologies into everyday digital tools, but it says – hey, we’re not ceding the digital image space to anyone.

But they are also doing some brilliant PR on this one.  Microsoft’s has a new Super Bowl ad, which positions Copilot and AI as empowering tools for innovation and creativity, challenging the narrative around AI as a threat to creative professions.

This is one time when an audio podcast is a bit of a disadvantage, because the ad is really well done and describing it won’t do it justice.

But we’ll put a link in the show notes for those of your who may not catch the Swift Bowl, I mean the SuperBowl.

Link to the YouTube version of the ad.

Sources include: VentureBeat

Hashtag Trending goes to air five days a week with daily news and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Fabulous Friday and a Swifty Superbowl weekend.

The post Superbowl ad from Microsoft tries to make peace between artists and AI: Hashtag Trending for Friday, February 9th, 2024 first appeared on IT World Canada.

Google launches Bard GenAI in Canada, rebrands it to Gemini

Google today announced that its generative artificial intelligence (GenAI) chatbot, Bard, is now available to Canadians, in both English and French. At the same time, it announced that Bard has been renamed Gemini.

Sissie Hsiao, vice president and general manager, Gemini experiences and Google Assistant, explained the name change: “Our mission with Bard has always been to give you direct access to our AI models, and Gemini represents our most capable family of models. To reflect this, Bard will now simply be known as Gemini.”

Google’s group product manager, Gemini experiences Jules Walter said Gemini is, a “much more powerful model,” which the company launched in December in three flavours of various sizes to accommodate different devices and use cases.

Gemini Nano was released to handle on-device smartphone processing, Gemini Pro for Bard, and Gemini Ultra, an even more powerful model capable of coding and logical reasoning, is available in Gemini Advanced, a premium subscription service.

Gemini Advanced is part of the new Google One AI Premium Plan, launched today at C$26.99 per month, with a two month free trial.

According to Jack Krawczyk, product lead, Gemini experiences, the plan includes all of the features of the Google One Premium Plan, plus what he called “the best of Google AI”, and, in addition, subscribers will soon be able to use Gemini in Gmail, Docs, Slides, and Sheets. This functionality was formerly known as Duet AI, but is now called Gemini for Google Workspace.

Also coming soon are mobile apps, but only in English to begin with. Android will receive a new Gemini app, while iOS users will access Gemini through the Google app.

For now, Gemini access is via its website.

The post Google launches Bard GenAI in Canada, rebrands it to Gemini first appeared on IT World Canada.

Meta may not bring some products to Canada unless proposed AI law changed, Parliament told

Officials from four of the biggest tech companies in the world — Amazon, Google, Microsoft and Meta — largely offered polite criticism of the country’s proposed artificial intelligence law to Canadian parliamentarians for over an hour at a hearing Wednesday.

Several agreed the Artificial Intelligence and Data Act (AIDA) legislation should be passed quickly, but with certain provisions more clearly defined, and allowing more rules to be set in regulations than in the law so it will be flexible.

And then it was like a mask dropped.

It came after Microsoft Canada’s Amanda Craig, the company’s senior director of public policy in the office of responsible AI, gave a lengthy explanation of things that could be improved.

Then Rachel Curran, head of public policy for Meta Platforms in Canada, was asked to comment.

“I think Amanda is being very diplomatic,” she told the House of Commons industry committee.

“AIDA in a number of respects goes well beyond the most stringent proposal out there internationally, which is the EU Act — which is already the subject of a lot of debate amongst [European Union] member states. It doesn’t have the support of countries like France, for instance, who want to make sure their own domestic industry is given a chance to flourish. So AIDA has created a standard that doesn’t exist anywhere else in the world.”

If AIDA passes as is, Meta could meet its requirements for regulating AI systems, she said. But, Curran added “the compliance costs are incredibly high. Would that mean certain [Meta] products would not be launched in Canada? Maybe. But all of us work for companies that are able to meet very high [regulatory] thresholds because we have the resources and money to do that.” On the other hand, “it’s going to have a significant impact on the Canadian AI industry and on innovation in Canada.

“Canada should make sure it aligns itself [in AI legislation] with other jurisdictions. We’re a relatively small market. The EU is setting a benchmark that is world-leading. We should at the very least not exceed that.”

Passing AI legislation fast is important, Curran said, if only to maintain public trust in artificial intelligence applications. But, she added, it’s also important to get the legislation right. AIDA is “a pretty good bill,” she said at one point. “It’s just a question of whether we can get the good details right.”

But, at another point, she said this: “Our global AI research is based in Montreal. The wrong regulatory framework, over-reach, or over-regulation by the government would drive that kind of activity out of the country. And I would hate to see that because we are leaders in AI research.”

Nicole Foster, director of Amazon Web Services’ global artificial intelligence and Canada public policy, agreed with Curran on the need to not get ahead of other countries. At the very least, she added, MPs should hear the opinions on the impact of AIDA from Canadian firms who are, or will be, using AI applications.

AIDA is part of Bill-C-26, which includes a proposed Consumer Privacy Protection Act (CPPA).

AIDA would oversee three classes of AI systems — high-impact, general impact, and machine learning systems — used in areas such as employment, providing services to an individual, processing biometric information for identification, moderating content on a search engine or social media platform, and more. It would be illegal to deploy an AI system likely to cause serious physical, psychological, or economic harm to an individual. Persons responsible for high-impact systems would have to establish measures to identify, assess, and mitigate the risks of harm or biased output that could result from the use of the AI system.

In its initial version, AIDA left a lot of grey areas — such as defining a “high impact” AI system — to be filled in by regulations proclaimed by the government. Those regulations would be set after consultations with experts, including the tech industry. The approach would allow flexibility to meet the challenges of fast-moving AI technology. But some worried about passing vague legislation. So Innovation Minister Champagne sent the committee a letter outlining amendments and clarifications the government is willing to make to the legislation.

However, Curran believes the original version — leaving a lot to regulations — was better. “The minister’s proposed amendments, if accepted by this committee, are going to box Canada into a regulatory framework that may look very different than the one that emerges from international discussions,” she said.

In addition, Curran objected to AIDA covering the moderation of content on social media platforms like Meta. Controls over social media would be better put in the government’s long-promised online harms bill, she said.

Several of the witnesses Wednesday also objected to AIDA’s proposal to give a new AI and Data Commissioner power to enter a firm’s premises, access systems, copy data, and conduct testing of AI systems if the commissioner has reasonable grounds to believe that an organization has contravened or is likely to contravene their obligations under AIDA.

There were also objections over the proposal that employees could be convicted of a criminal offence for mishandling personal data from an AI system. And there were suggestions that some enforcement of AIDA should be put in the hands of regulators that already look after specific industries.

“I’m a bit confused,” Bloc Quebecois MP Jean-Denis Garon admitted late in the session. “You say Parliament needs to regulate AI,” he said to the four witnesses, “then you say C-27 is trying to cover too much, and one suggests it may be better to regulate AI by amending existing legislation covering regulated sectors.” That, he said would require “un-ending legislative work …and bottom line, we’d end up with no regulation … Is this your way of telling us you don’t want regulation?”

“We support good regulatory frameworks,” replied AWS’s Foster. “All of us do.” But if acting fast is the issue, potentially the government can move faster by amending existing legislation.

The U.K. has decided for the time being to let regulators such as the Information Commissioner and the Competition and Market Authority to issue regulations for AI oversight.

The post Meta may not bring some products to Canada unless proposed AI law changed, Parliament told first appeared on IT World Canada.

CIO Association of Canada turns 20: Hashtag Trending for Thursday, Feb 8, 2024

Tesla’s stock is the biggest loser on the S&P 500. YouTube is hailed as one of the most engaging social media sites, LinkedIn introduces AI tools to save time managing your network, Vision Pro headsets may be a hazard and the CIO Association of Canada turns 20.

All this and more on the “my how the years have flown” edition of Hashtag Trending. I’m your host Jim Love, CIO of IT World Canada and TechNewsDay in the US.

This month marks the 20th Anniversary of the CIO Association of Canada (CIOCAN).

Founded in 2004, with its roots tracing back to Vancouver in 1998, CIOCAN emerged from a collective aspiration to forge a unified platform for Chief Information Officers (CIOs) and technology leaders. This platform was envisioned as a space for sharing ideas, insights, and best practices among the brightest minds in what was at the time still a C level job that was all too often struggling for recognition.

As CIOCAN celebrates this landmark anniversary, few would question how important technology is today, but it wasn’t too long ago that technology was thought of as something like plumbing or heating – we needed it, but we weren’t looking to use it strategically. In many companies, the CIO reported into Finance where they were treated like an expense to be kept under tight management.

Today, as the cloud and AI accelerate the digital transformation of every aspect of business and our lives, the role of the CIO is often respected and in most successful companies, the head of technology, is thought of as a true C level strategic business leader.

Over the years, we CIOs have had to change and the support of our association and our peers has been essential.

Full disclosure – I am a member of the CIOCAN, and it is still the place where technology leadership can gather and discuss our mutual concerns, issues and opportunities with our peers. There are chapters all across the country where they have regular meetings and every year there is an annual Peer Forum, this year it’s in Calgary.

If you’ve been around for a few years, and what to think about how we got here, my friend and colleague Philippe Johnston shares his reflections and the journey of the CIO Association of Canada on the association’s website.

If you want to learn more about the role of the CIO, look for our annual CIO Census coming out in the next month or so or join us in one of the local or even the national events.

And if you work for a great CIO or an up-and-coming tech leader, why not nominate them for the Canadian CIO of the Year award – sponsored by CIOCAN and IT World Canada.

As always there are links in the show notes or just check ITWorld Canada.com

Sources include: CIO Association of Canada, https://www.ciocan.ca/20th-anniversary

A recent story from DigitalSilk.com analyzed data from SimilarWeb and came up with a rating of social media sites in terms of user engagement – taking metrics like the average number of pages visited per user and duration of visits.

Topping the charts is YouTube, hailed as the most engaging social media site.

YouTube’s dominance is attributed to its impressive average visit duration of 19 minutes and 35 seconds coupled with users navigating through 11.08 pages per visit.

Following closely are Reddit and Snapchat, securing the second and third spots, respectively, with Reddit users spending about 15 minutes and 55 seconds and Snapchat users 14 minutes and 10 seconds per visit.

X.com, the platform formerly known as Twitter, and Instagram round out the top five.

There’s a table on the show notes with a link to DigitalSilk.com

Interestingly, despite the buzz around TikTok, it didn’t crack the top ten, suggesting that engagement metrics may not be catching mobile usage or some other measurement issue. I’ve put a message out to DigitalSilk, but haven’t heard back as of the time of recording of today’s episode.

Sources include: DigitalSilk.com

 

Rank
Social media site
Pages per visit average
Average visit duration (mins)

1
YouTube
11.08
19:35

2
Reddit
10.49
15:55

3
Snapchat
8.34
14:10

4
X.com
10.19
10:53

5
Instagram
11.53
08:19

6
Facebook
9.15
10:36

7
BlueSky
6.30
09:37

8
LinkedIn
7.98
07:42

9
Tumblr
6.84
08:44

10
Pinterest
7.74
07:05

 

In a recent LinkedIn article, Naman Goel, Senior Director of Product at LinkedIn, talked about the evolving landscape of professional networking in 2024. With an astonishing 85% of professionals contemplating a job change this year, the significance of networking has never been more pronounced.

However, the challenge of nurturing a professional network is time consuming, taking over 300 hours annually for nearly a quarter of individuals who dedicate 6-10 hours weekly to this endeavor.

LinkedIn’s response to this is a revamp of the Network Tab, now featuring two distinct sections: “Grow” and “Catch Up.”

The “Grow” tab aims to simplify the expansion and management of your network by offering personalized recommendations through LinkedIn’s sophisticated AI algorithms.

On the other hand, the “Catch Up” tab provides users with timely prompts to reconnect with your network, celebrating milestones like new jobs, work anniversaries, or birthdays, thereby fostering meaningful engagements.

LinkedIn is also tackling the “blank page problem” head-on with a new Premium feature that employs AI to assist users in crafting initial messages to potential connections. This tool suggests drafts based on the profiles of both the sender and the recipient, encouraging personalized and relevant communication.

As I said in my comments on LinkedIn, the tools to help manage our networks and help us be more efficient at keeping track of people are welcome. But if you need an AI program to help you send me a message, I’d say don’t bother.

By all means use AI to help you with all kinds of writing tasks, brainstorming, outlining and yes, please – proofreading. But when it comes to personal messages?  If you don’t know what you want to say, you probably don’t really want to talk to me.

I can talk to ChatGPT directly and cut out the middleman.

Sources include: Naman Goel’s LinkedIn article (search for it on Linked In)

Tesla’s stock performance makes it as the worst-performing stock in the S&P 500 this year, with a 24% decline.

This downturn is attributed to a number of factors.

Key among these challenges are the numerous recalls that have plagued Tesla, raising concerns about the reliability and safety of its vehicles.

Additionally, CEO Elon Musk’s erratic behavior has been well documented in terms of its impact on Twitter, but now at Tesla, his behaviour has again come under scrutiny, with reports of alleged drug use so concerning that it’s rumored his board has suggested rehab.

But Musk alone isn’t the total cause of Tesla’s stock woes. There is also increased competition from both domestic and international automakers, which are rapidly expanding their electric vehicle offerings. This competitive pressure is intensifying at a time when Tesla needs to solidify its market leadership and innovate to maintain its edge.

In that light, investor sentiment has been further dampened by Musk’s outsized influence on the company. While Musk’s visionary leadership has been a key driver of Tesla’s past success, his recent actions and the controversies surrounding him have led to significant shareholder value erosion.

The company’s annual report acknowledges its heavy dependence on Musk, highlighting the risk that his less favorable antics pose to investor confidence and the company’s market valuation.

Sources include: Quartz

A recent trend has emerged that even in an age of social media stunts, seems particularly inane – people wearing Apple Vision Pro headsets in inappropriate and unsafe places.

The Vision Pro headsets, released by Apple on February 2, 2024, promise an immersive experience that blends digital applications with the user’s physical environment. However, the allure of this new gadgetry has led to a spate of social media stunts, including videos of individuals navigating the roads in Teslas, their vision obscured by the headsets.

These videos, while not widespread, have been alarming enough to prompt a public response from figures like Transportation Secretary Pete Buttigieg and the National Highway Traffic Safety Administration (NHTSA). Their message is clear: the act of driving demands undivided attention, a principle seemingly forgotten by those chasing viral fame.

If we have reached a point where officials must explicitly warn against driving while watching virtual reality, what does it say about our collective judgment in the digital age?

Content creators like Dante Lentini, whose video of driving while wearing the Vision Pro went viral, claim their actions are purely for entertainment.

Yet, the implications of such stunts ripple far beyond their intended comedic value, highlighting a disturbing trend of prioritizing online engagement over real-world consequences.

Lentini’s admission that the video was staged and that police presence was coincidental does little to mitigate the potential risks such content glorifies.

As we navigate the complexities of a world increasingly augmented by digital innovations, we may be in danger of losing the distinction between the virtual and the real, which sadly can have tragic consequences in situations as critical as driving.

We worry about artificial intelligence dooming the human race, when lack of intelligence may be a bigger concern.

Sources include: New York Times article by Jesus Jiménez, February 6, 2024

Hashtag Trending goes to air five days a week with daily news and a weekend interview show that we creatively called – the weekend edition.

We love to hear from you. Send us a note at jlove@itwc.ca or drop us a comment under the show notes at itworldcanada.com/podcasts – look for Hashtag Trending.

Thanks for listening and have a Thrilling Thursday.

The post CIO Association of Canada turns 20: Hashtag Trending for Thursday, Feb 8, 2024 first appeared on IT World Canada.

Info-Tech report outlines 5 GenAI initiatives CIOs must key in on

As generative artificial intelligence (GenAI) continues to reshape the digital landscape, CIOs and IT leaders are at a pivotal point, tasked with navigating the profound opportunities and challenges this disruptive technology presents, a new report from Info-Tech Research Group concludes.

To help guide CIOs who wish to take advantage of what the technology can offer, the CIO Priorities 2024 report outlines what the research firm describes as “five key initiatives poised to drive significant value across diverse organizational contexts in 2024.”

The five revolve around:

Augmenting the business with GenAI: Survey findings indicate a “cautious approach toward adopting new GenAI features among organizations, particularly those with lower IT maturity possibly due to vendor risk or intellectual property concerns. In contrast, high IT maturity firms are more proactive, with more than half reporting either planning to apply for beta access to new features or planning to move ahead upon their general availability.” CIOs and IT leaders, a release states, need to strategically integrate GenAI capabilities into business processes, deciding whether to develop in-house solutions or procure them.

Right-sizing AI governance: According to the report, organizations are facing a “balancing act with risk management and fostering innovation. When asked about who is responsible for AI governance, 30 per cent of respondents from both high and low IT maturity organizations reported that it is the role of the CIO. This year, CIOs and IT leaders must design and establish AI governance frameworks that provide necessary oversight and specific policies that align with existing risk management practices without imposing bureaucracy and auditing that stifles innovation.”

Updating vendor risk assessments: The research, Info-Tech maintains, “underscores the increasing threat of supply chain attacks, where cybercriminals exploit vulnerabilities in the software tools and services used by organizations. This threat makes companies susceptible to the risks of their vendors. To mitigate these threats, especially those related to AI, Info-Tech advises that CIOs and IT leaders establish or update their vendor risk assessment programs to include AI-specific considerations.”

Exponentially increasing innovation: According to the report, CIOs identified innovation as a key driver for maintaining competitiveness and enhancing customer and employee experiences. It notes that “despite AI being earmarked as a primary area for new investment in 2024, many organizations report not having conducted proofs of concept or pilots with AI to validate business cases. To harness AI’s full potential, CIOs and IT leaders must prioritize expanding their exploration of AI use cases, moving from ideation to pilot testing more rapidly.”

Exponentially improving customer experience: Analysis of the survey data reveals that IT leaders are “moderately concerned about potential disruptions to their organizations due to changing customer behaviors, second only to cybersecurity incidents. By embedding AI into customer journey interactions, CIOs and IT leaders can automate, augment, and reduce friction at every point of the customer journey, accelerating service delivery and enhancing overall satisfaction.”

Brian Jackson, principal research director with Info-Tech and lead analyst for the report, said, “in our assessment of the 2024 IT landscape, GenAI emerged as the clear trend, a focal point of our Tech Trends 2024 report.

“This technology introduces significant opportunities and challenges. The critical question for CIOs and IT leaders is which capabilities need enhancement to leverage these opportunities and which initiatives should be prioritized to navigate the accompanying enterprise risks effectively.”

This year, he added, GenAI is “like an elephant in the C-suite office, trumpeting its demands to be addressed. Whether through internal build efforts or through new vendor features, generative AI must be addressed by CIOs and IT leaders. This technology is the next wave lifting the expectations of customers and business stakeholders.”

The post Info-Tech report outlines 5 GenAI initiatives CIOs must key in on first appeared on IT World Canada.

China group may have been hiding in IT networks for five years, says Five Eyes warning

Following recent American warnings of China’s efforts to secretly plant itself on critical infrastructure for future cyber attacks, Canada and other members of Five Eyes intelligence co-operative today issued a joint advisory so firms in all countries in the group will be on alert — and other nations watching their actions will hear as well.

“People’s Republic of China (PRC) state-sponsored cyber actors are seeking to pre-position themselves on IT networks for disruptive or destructive cyberattacks against critical infrastructure in the event of a major crisis or conflict,” the warning says.

In fact, it notes, the U.S. has evidence Volt Typhoon has been maintaining access and footholds within some victim IT environments for at least five years.

The partners — including Canada, the U.S., Australia, the U.K., and New Zealand — released the advisory to warn critical infrastructure organizations about the assessment by American cyber authorities, based on incident response activities at critical infrastructure organizations.

In particular, the warning urges infosec pros to watch for activity from the PRC state-sponsored cyber group known to researchers as Volt Typhoon (also called Vanguard Panda, Bronze Silhoutte, Dev-0391, UNC3236, Voltzite, and Insidious Taurus by different researchers).

“The U.S. authoring agencies have confirmed that Volt Typhoon has compromised the IT environments of multiple critical infrastructure organizations—primarily in communications, energy, transportation systems, and water and wastewater systems sectors—in the continental and non-continental United States and its territories, including Guam.” the warning says.

“Volt Typhoon’s choice of targets and pattern of behavior is not consistent with traditional cyber espionage or intelligence gathering operations, and the U.S. authoring agencies assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable lateral movement to OT assets to disrupt functions. The U.S. authoring agencies are concerned about the potential for these actors to use their network access for disruptive effects in the event of potential geopolitical tensions and/or military conflicts.”

The Canadian Centre for Cyber Security believes that the direct threat to Canada’s critical infrastructure from PRC state-sponsored actors is likely lower than that to U.S. infrastructure, the warning says. But, it adds, should U.S. infrastructure be disrupted, Canada would likely be affected as well, due to cross-border integration of critical infrastructure providers.

Public warnings of Volt Typhoon emerged last May in a report from Microsoft. It said the group has targeted critical infrastructure organizations in Guam and elsewhere in the United States since 2021, probably for espionage. Its tools include the KV botnet for distributing malware.

Then, in December, researchers at Lumen Technologies reported details about the KV botnet. Researchers at SecurityScorecard followed up with a report that Volt Typhoon had compromised two models of vulnerable end-of-life routers from Cisco Systems in December.

Fighting back, last month the U.S. disabled Volt Typhoon’s botnet of hundreds of U.S.-based small office/home office (SOHO) routers that were distributing malware.

Volt Typhoon will compromise a network in various ways, including password cracking, leveraging stolen credentials, and exploiting hardware or software vulnerabilities. In one confirmed compromise, the report says, Volt Typhoon actors likely obtained initial access by exploiting CVE-2022-42475 in a network perimeter FortiGate 300D firewall that was not patched.

After establishing a foothold, a favoured tactic is to use common tools already on a victim’s IT or OT network (also called living-off-the-land) to hide and maintain persistence on the network. “Evidence of their meticulous approach is seen in instances where they repeatedly exfiltrate domain credentials, ensuring access to current and valid accounts,” says the warning.

The warning also links to mitigations that critical infrastructure providers — including utilities, financial institutions, transportation firms, hospitals and others — should act on.

The post China group may have been hiding in IT networks for five years, says Five Eyes warning first appeared on IT World Canada.