ChatGPT - 資安與金融業

OpenAI於2022年11月推出的ChatGPT(Chat Generative Pre-trained Transformer)是一款近期非常流行的聊天機械人,廣泛應用於資料搜集、文章撰寫、語言翻譯、程式碼編寫和調整、計算等領域。那麼,ChatGPT在金融方面能夠提供什麼樣的助力呢?然而,ChatGPT可能會出現資安問題?    

1966年,麻省理工學院推出了世界上公認的第一個聊天機械人Eliza,其應用範圍主要是模擬與心理治療師的對話。隨著聊天機械人的功能不斷演進,其應用範圍已經不僅限於單一用途。現代的聊天機械人配備學習功能,能夠自動學習和理解人類語言的語法和語意,並具備與人類進行自然對話的能力。    

金融業可以利用ChatGPT獲得多種效益。其中最常見的應用之一是在客戶服務方面,為客戶提供24小時不間斷的對話、回覆或推廣,提高客戶的滿意度和體驗。此外,ChatGPT還可以分析大量關於金融方面的數據,從而預測市場的走勢,有助於投資者做出更明智的投資決策。同時還可以應用在機構上的風險評估和風險控制,通過自然語言處理技術來監測客戶的交易行為和交易風險,提高風險管理的效率和準確性。    

ChatGPT雖然可以為金融企業帶來好處,但在資訊安全方面仍然是企業需要考慮的重點。因此,有些企業已經禁用員工使用ChatGPT。這是因為ChatGPT本身需要龐大的資料庫支持運作,其中包括了不少敏感資訊,如個人身分資訊和銀行資訊等。如果這些敏感資訊被非法獲取或洩露,會對用戶和企業造成嚴重的損失。知名消費電子產品及電子元件製造商三星就曾因員工將半導體設備、程式碼相關的資訊上傳給ChatGPT以方便工作,導致公司機密資料外洩。這也表明,企業在使用ChatGPT時需要特別注意資訊安全問題。   

因此,如何對資料進行加密及保護,配合國家如何監管,制定法規會成為ChatGPT的一大課題。只有在資訊安全問題得到充分解決和保障的情況下,ChatGPT才能夠被廣泛使用。   
    

尹展軒   
Senior IT Consultant

More Updates

Further reading

𝗪𝗵𝘆 𝗣𝗵𝘆𝘀𝗶𝗰𝗮𝗹 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗥𝗲𝗺𝗮𝗶𝗻𝘀 𝗘𝘀𝘀𝗲𝗻𝘁𝗶𝗮𝗹 𝘁𝗼 𝗜𝗻𝗳𝗼𝗿𝗺𝗮𝘁𝗶𝗼𝗻 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗶𝗻 𝗜𝗦𝗢 𝟮𝟳𝟬𝟬𝟭

𝗪𝗵𝘆 𝗣𝗵𝘆𝘀𝗶𝗰𝗮𝗹 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗥𝗲𝗺𝗮𝗶𝗻𝘀 𝗘𝘀𝘀𝗲𝗻𝘁𝗶𝗮𝗹 𝘁𝗼 𝗜𝗻𝗳𝗼𝗿𝗺𝗮𝘁𝗶𝗼𝗻 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗶𝗻 𝗜𝗦𝗢 𝟮𝟳𝟬𝟬𝟭We spend so much time talking about firewalls, encryption, and phishing simulations — but what happens when someone simply walks into your server room, steals a laptop, and causes damage to company’s assets?Why does physical security matter so much? Because many real incidents start physically:💫 A tailgater slipping into a restricted area and accessing sensitive systems.💫Unlocked desks leaving confidential documents visible to visitors or cleaners.💫Natural disasters such as typhoons and flooding disrupting servers, leading to downtime or hardware damage if environmental protections aren't in place.Physical security directly supports the core principles of information security—the CIA Triad (confidentiality, integrity, and availability) of data and systems. Threats such as theft, tampering, or natural disasters can bypass digital protection entirely.In ISO 27001:2022, physical security is addressed through a dedicated theme under Annex A. Issues like expired fire extinguishers, missing CCTV footage, sticky notes with account passwords, or unlocked server room racks are common findings in an ISO 27001 audit. These are often fixed in a short time but can lead to non-conformities if ignored. Usual physical security practices are as follows:💫 Clear desks and screens (e.g. keep sensitive information in restricted areas)💫Physical entry and access control (e.g. door access restriction)💫Physical Monitoring (e.g. CCTV)💫etc.

𝗛𝗼𝘄 𝗚𝗼𝗼𝗱 𝗔𝗿𝗰𝗵𝗶𝘁𝗲𝗰𝘁𝘂𝗿𝗲 𝗥𝗲𝗱𝘂𝗰𝗲𝘀 𝗧𝗲𝗰𝗵𝗻𝗶𝗰𝗮𝗹 𝗗𝗲𝗯𝘁 𝗶𝗻 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗣𝗿𝗼𝗷𝗲𝗰𝘁𝘀

𝗛𝗼𝘄 𝗚𝗼𝗼𝗱 𝗔𝗿𝗰𝗵𝗶𝘁𝗲𝗰𝘁𝘂𝗿𝗲 𝗥𝗲𝗱𝘂𝗰𝗲𝘀 𝗧𝗲𝗰𝗵𝗻𝗶𝗰𝗮𝗹 𝗗𝗲𝗯𝘁 𝗶𝗻 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗣𝗿𝗼𝗷𝗲𝗰𝘁𝘀Technical debt is often an unavoidable byproduct of rapid development—but good architecture ensures it doesn’t become toxic.1️⃣ Defines Standards and Enforces ComplianceArchitecture sets clear standards for platforms, data, and security, reducing inconsistencies and redundancies. Guidelines and regular architecture reviews ensure new code complies with best practices, preventing unmaintainable implementations from entering the system.2️⃣ Manages Complexity through ModularityModular architecture, such as microservices or well-structured layers, reduces tight coupling and isolates components. This simplifies maintenance, allows teams to work independently, and makes it easier to identify and fix areas of high technical debt before they snowball.3️⃣ Enables Scalability and FlexibilityProactive architectural design anticipates future growth and changing requirements. Systems can scale, adapt to new technologies, and incorporate new functionality without extensive rewrites, minimizing long-term debt and maximizing agility.4️⃣ Improves Maintainability and Reduces RiskClear structure and documentation provide visibility into system dependencies, helping developers understand the impact of changes. Combined with CI/CD pipelines and automated testing, architecture acts as a safety net, allowing incremental improvements while controlling debt accumulation.5️⃣ Aligns Technology with Business GoalsGood architecture ensures systems support business objectives efficiently, balancing speed with quality. It enables sustainable technical choices that maximize ROI while reducing the cost of misaligned or obsolete solutions.In essence: architecture is a strategic investment that turns technical debt from a hidden risk into a manageable, predictable factor—supporting sustainable growth, maintainable code, and long-term innovation.