Cybersecurity Newsletter #6: Think Before You Prompt
August 2026 Cybersecurity Update | ODVI DTT – DTT IT Department
Hello Team!
Artificial Intelligence tools such as ChatGPT, Gemini, Copilot, and other AI assistants can help us draft messages, summarize information, organize ideas, create templates, and complete repetitive tasks more quickly.
AI can be a valuable work assistant—but we must still use it carefully.
AI is a helpful assistant, but it is not automatically a private place for company information.
Not every AI tool handles information in the same way. Before typing, pasting, or uploading anything related to work, make sure that the tool and its intended use are appropriate.
The goal is not to stop people from using AI. The goal is to use AI in a way that protects company information while still allowing employees to exercise their own judgment.
📤 What Counts as Sharing Information with AI?
Sharing information with an AI tool is not limited to typing a question.
You are also sharing information when you:
- Copy and paste an email or message
- Upload a spreadsheet, PDF, contract, or report
- Attach a screenshot from a company system
- Paste meeting notes or customer concerns
- Ask AI to review source code or system settings
- Allow an AI browser extension to read a webpage
- Upload a photo containing documents, computer screens, or employee information
Uploading a file means giving the AI tool access to the information inside that file.
Changing the filename, removing the document title, or converting a file into another format does not remove the confidential information inside it.
Before sharing anything, ask yourself:
Would I be comfortable giving this information to someone outside ODVI?
If the answer is no, do not enter it into a public or unapproved AI tool.
🧠 Ask Generally. Think Specifically.
A safer way to use AI is to ask for a general guide, template, checklist, or structure instead of sharing the complete details of a real company situation.
This approach has two benefits:
- It reduces the amount of company information shared with the AI tool.
- It leaves room for the employee to analyze the situation and make the final decision.
Instead of asking AI to decide:
“Review this employee’s complete evaluation, salary, attendance record, and performance history. Should this employee be promoted?”
Ask AI for a general framework:
“Create a checklist that a manager can use when evaluating an employee’s readiness for promotion.”
The AI can suggest factors to consider, but the manager should still review the real information privately and make the final decision.
Use AI to help you think—not to do all the thinking for you.
🚦 Use the AI Traffic-Light Guide
Before entering work information into an AI tool, identify whether it is Green, Yellow, or Red.
🟢 GREEN — Generally Safe
These activities are generally safe when they do not contain confidential, personal, or internal company information:
- Creating a blank meeting-agenda template
- Asking for general grammar or writing assistance
- Brainstorming general ideas
- Creating a generic checklist
- Asking general industry questions
- Reformatting nonconfidential text
- Summarizing information already available to the public
- Asking for sample questions, formats, or presentation structures
Example:
“Create a general checklist for preparing a monthly department report.”
The prompt does not include employee names, company figures, customer records, or confidential documents.
🟡 YELLOW — Stop and Check First
These may contain internal company information. Confirm with your manager or DTT IT before using them with an AI tool:
- Internal meeting notes
- Draft company announcements
- Internal procedures or workflow documents
- Unpublished reports and presentations
- Screenshots from company systems
- Project plans and status reports
- Internal financial information
- Company source code or technical configurations
- Documents containing employee, customer, or supplier names
Whenever possible:
- Remove real names
- Remove account numbers
- Remove confidential figures
- Avoid uploading the complete document
- Ask for a general template instead
- Use sample or fictional information
Yellow means: Do not upload immediately. Check first and use only the minimum information necessary.
🔴 RED — Never Share with a Public or Unapproved AI Tool
Never enter the following into a public or unapproved AI service:
- Passwords
- MFA verification codes
- Recovery codes
- API keys or access tokens
- Bank account and payment information
- Payroll and salary records
- Government identification numbers
- Customer or employee personal information
- Confidential contracts
- Legal or investigation records
- Security findings and vulnerability reports
- Unreleased financial statements
- Private account credentials
AI does not need your password, MFA code, recovery code, or access key to help you.
DTT IT will never ask you to enter these credentials into an AI chatbot.
❌ Unsafe Prompt vs. ✅ Safer Prompt
Example 1: Employee Evaluation
❌ Unsafe
“Summarize this employee evaluation and recommend whether the employee should be promoted. The employee’s name, salary, attendance record, and performance comments are attached.”
This prompt exposes identifiable and confidential employee information and asks AI to make a decision that requires human judgment.
✅ Safer
“Create a general checklist that managers can use when evaluating an employee’s readiness for promotion. Include performance, attendance, skills, conduct, and development needs.”
The safer prompt asks AI for a framework. The manager can then apply that framework privately to the actual employee information.
Example 2: Customer Complaint
❌ Unsafe
“Review this customer complaint,” followed by the customer’s name, phone number, account number, and transaction history.
This shares personal and account information that should remain protected.
✅ Safer
“Create a general template for summarizing a customer complaint. Include the issue, actions already taken, unresolved items, and recommended next steps.”
The safer prompt provides useful assistance without exposing a real customer’s information.
Example 3: Internal Project Concern
❌ Unsafe
“Here is our complete internal project report, budget, delays, and employee concerns. Tell me who is responsible and what management should do.”
This shares unnecessary company details and asks AI to make a decision without fully understanding the people, history, and business context.
✅ Safer
“Create a general framework for reviewing project delays. Include possible causes, responsibilities, business impact, and recommended next actions.”
The employee can use the framework to review the real situation and prepare a responsible recommendation.
👤 AI Should Support Human Judgment—not Replace It
AI can help organize information, suggest questions, improve wording, and present possible approaches.
However, AI may not fully understand:
- The history of a project
- The relationships between employees and departments
- The company’s priorities
- The reason behind a management decision
- Unwritten business considerations
- The complete context of a customer or employee concern
That context still comes from people.
For important work, AI should provide a starting point, not the final answer.
Employees should still:
- Review the information
- Consider the actual business context
- Check important facts and figures
- Adjust the output to match company requirements
- Consult the appropriate manager or department
- Take responsibility for the final decision
The person using AI remains responsible for the final output.
Before sending AI-assisted work to a customer, manager, executive, or colleague, make sure you have reviewed it and can explain it yourself.
✋ PAUSE Before You Prompt
Use the word PAUSE as your quick AI safety check:
P — Public?
Is the information already publicly available?
A — Approved?
Is the AI tool appropriate or approved for this type of company work?
U — Use Less
Can you ask the question without uploading the entire document, using real names, or sharing confidential details?
S — Sensitive?
Does the information contain personal, financial, legal, operational, or security-related details?
E — Exercise Your Judgment
Are you using the AI response as a guide while still reviewing, thinking, and making the final decision yourself?
When in doubt, pause and ask your manager or DTT IT first.
🧠 Quick Knowledge Check
You are preparing a recommendation about an employee’s promotion. The supporting file contains the employee’s name, salary, attendance, performance ratings, and manager comments.
What is the safest way to use AI?
A. Upload the complete file and ask AI to decide whether the employee should be promoted.
B. Rename the file before uploading it.
C. Ask AI to create a general promotion-evaluation checklist, then privately apply that checklist to the actual employee information.
D. Remove only the employee’s name and upload everything else.
✅ Correct Answer: C
Asking for a general framework protects the employee’s information and keeps the final assessment with the responsible manager.
Renaming the file does not protect its contents. Removing only the name may also be insufficient because salary, attendance, job details, and performance records may still identify the employee.
🛡️ Remember the Three AI Safety Rules
1. Share Less
Use general prompts whenever possible. Do not upload confidential documents or include unnecessary names, records, or company details.
2. Think More
Ask AI for ideas, templates, structures, or questions—but keep analysis, judgment, and final decisions with the responsible employee or manager.
3. Check First
Use appropriate tools, review the output, and consult your manager or DTT IT whenever you are uncertain.
AI can help us work faster, but speed should not come at the cost of confidentiality, accountability, or human judgment.
🔗 Quick Access
- DTT Policy Portal — Review current company policies
- Newsletter Archive — Browse previous cybersecurity updates
- Raise an IT Concern — Submit IT and cybersecurity concerns
For questions about whether an AI tool, prompt, or document is appropriate for work, please contact:
John Lester Rosima
Assistant Manager, IT & Cybersecurity · ODVI Group
lprosima@oakdriveventures.com
🤖 USE AI SMARTLY. SHARE LESS. THINK MORE.
Cybersecurity is everyone’s responsibility. Before entering company information into an AI tool, remember:
Think before you prompt.