It started with a simple request. A local organization asked our team to help them better understand how AI was being used across their team. Not because something had gone wrong or they’d experienced a breach. Moreso because they’re worried about AI usage within their company.
“We know people are using AI. We’re just not sure how.”
As a leading IT company in Ottawa that specializes in cybersecurity solutions, we took a look.
The Reality Wasn’t Shocking. But It Was Important.
What we found is something we’re seeing more and more. Employees were using AI tools every day to move faster. Writing emails. Summarizing documents. Cleaning up reports. Analyzing spreadsheets.
It all made sense. It was helpful and efficient. We get that… But underneath that, something else was happening quietly in the background.
Sensitive Data Was Leaving the Organization
Not through a breach, but rather, through everyday work. People were pasting information into public AI tools. No one was trying to do anything wrong. There just weren’t clear guardrails in place. Most businesses have always focused on things like network security or cloud security, but AI is newer to the list of risks we have to worry about.
This Is the New IT Blind Spot
Most security tools weren’t designed for this. You can have strong protection in place. Firewalls, endpoint security, and email filtering. All of it likely working exactly as it should. And still have no visibility into how AI is being used. If you haven’t read our Cybersecurity Risk Report: 2026 Edition (we highly recommend taking a look!), here’s an important consideration…
The average cost of a data breach hit 6.98 million CAD in 2025 - and to make matters worse, unsanctioned AI tools used within the workplace add approximately $308,000 CAD to the total breach costs.
So How Did We Know Sensitive Data Was Leaving the Organization?
The first step wasn’t to lock anything down. It was to understand what was actually happening. Our team put monitoring and governance in place to get a clear picture of how AI was being used across the organization. Which tools were being used, how often, and where potential risks were showing up.
This wasn’t about watching employees. It was about giving leadership clarity.
Once that clarity existed, the path forward became obvious.
The Shift Ottawa Businesses Need to Make
At that point, the conversation changed. Instead of asking how to stop AI use, the question became: How do we make this safe and structured? That’s where most organizations get stuck. Because enabling AI properly requires both the right tools and the right setup behind them. And here’s where it gets even more important: PIPEDA is expected to evolve due to the usage of AI tools.
This means businesses will be directly held accountable for minimizing the risk of confidential, personal information being disclosed via AI tools.
How We Helped: Transitioning to Secure AI Without Slowing Anyone Down
Once there was visibility, the next step was straightforward. Replace risky behavior with something better. If people are already using AI, taking it away isn’t realistic. The better approach is to give them a version that works the way the business needs it to.
Moving Away From Public AI Tools
Public tools don’t give organizations much control. You can’t see how they’re being used. You can’t control what data goes in. And you can’t tie usage back to your internal security structure. So even when the intent is harmless, the risk is still there. Instead of trying to track dozens of external tools, we helped bring everything into a controlled environment.
Implementing Microsoft Copilot Properly
Microsoft Copilot became the foundation. But the important detail here is that it has to be set up correctly. Copilot works within your Microsoft 365 environment. It reflects your existing permissions and data structure. If those aren’t clean, AI will surface that very quickly.
So before rollout, we worked through the fundamentals:
- Cleaning up permissions
- Making sure people only had access to what they should
- Organizing data across SharePoint, Teams, and OneDrive
- Putting proper identity controls in place through Microsoft Entra
- Applying sensitivity labels where needed.
This is the part most organizations skip. And it’s the part that matters most. Cypher already supports Microsoft environments as part of its core services, so this fits naturally into how they manage security and infrastructure overall .
Keeping Data Where It Belongs
One of the biggest advantages of this approach is simple: The data stays inside the organization. It doesn’t leave the Microsoft environment. It isn’t used to train external models. Access is controlled the same way it already is across the business. That removes the need for employees to copy and paste sensitive information into external tools in the first place.
Adding Oversight Without Getting in the Way
Even with a secure setup, visibility still matters.
So AI governance was layered on top. Not to control every action, but to keep a clear understanding of how AI is being used over time. This allows leadership to spot patterns, catch potential risks early, and adjust as needed. All without interrupting how people work.
Get Started with Proper AI Governance and Security for Your Ottawa Business
AI isn’t going anywhere. But most organizations are still either ignoring it or trying to block it. Neither approach works. The ones getting ahead are doing something different. They’re putting structure around it early, before it turns into a problem. Cypher Systems has always focused on solving issues before they become real problems.
This is just the next version of that.
Because IT today isn’t only about systems and infrastructure. It’s about how people actually work. The tools they use. The way information moves. And right now, AI is a big part of that. Get in touch with us to get started with proper AI governance and security. Contact us to book a complimentary assessment.

Gabriel Rapacz
He believes IT is ultimately about supporting people, not just technology. Gabriel focuses on making systems approachable and effective for each client and their team, adapting to different levels of comfort and experience.
With a strong interest in cybersecurity, Gabriel stays current on emerging threats and attacker tactics, helping clients stay protected in an evolving landscape.



