Human Firewall

Setting up employee notifications within MetomicScreenshot of Metomic platform, showing how to set up employee notifications

Metomic built its human firewall to put the choice in front of your people the moment data was at risk in SaaS. The same idea now runs where the risk is today: the AI tools your people use and the agents they set to work.

Integrate with the tools you already use:

How Oyster used Metomic automations to educate their team

Download the case study

Keep your people moving with AI, while your sensitive data stays safe

Your people see the risk in the moment, before sensitive data reaches an AI tool. Your agents get what they need, and stop short of what they shouldn't touch.

Warning icon

Notifications

Metomic tells the agent's owner in Slack or Teams the moment a policy trips.

Bell icon

Approvals

A risky request waits for a person. Approve or deny it, and the agent carries on from there.

Clock icon

Real-time

Security guidance arrives at the moment of the request, while the work is still in front of them.

Our Customers Love us

We're trusted by security teams worldwide

Testimonials

What our customers are saying about Metomic

Use keyboard

to navigate through testimonials

Metomic provides an excellent, easy-to-navigate interface with the necessary features to help keep our workspace secure.

Stephen Droner
IT Help Desk Analyst

We use Metomic to uncover sensitive company data and prevent it from being shared or residing in places it shouldn't. It's a really great supplement where technical controls that could be our frontline of defense don't exist.

Colin O'Shea
IT Manager

Easy integration. It is as simple as a few clicks (and the Metomic onboarding process is excellent, too, as the team guides us through the process).

Philippe Cartier
Cloud Infrastructure Engineering Manager
Financial Services

We can confidently respond, ‘Yes, we have a DLP solution in place,’ and support that claim with verifiable results. That has been crucial for establishing trust with our customers.

Oyster
Director of Trust and Technology
Financial Services

Having real-time data-driven insights to share with stakeholders has been invaluable. Metomic ensures that we’re compliant, secure, and proactive, providing the operational resilience necessary to grow in a competitive digital commerce market.

Juni

Metomic addresses risks efficiently—blocking unsafe data sharing or sending alerts to users. This allows our team to remain productive while keeping our data secure. The visibility and control Metomic provides has been game-changing in helping us implement a solid, proactive approach to data security.

Jeff May
Director of Trust and Technology, Oyster

The machine learning aspect of AI means that, when paired with security solutions such as identity verification and biometric authentication (voice or fingerprint), it improves in its detection over time, increasing accuracy but also reducing the number of false positives.

Nick France
CTO

I appreciate how configurable and easy it is to setup alerting workflows. The tool is lightweight and easy to integrate into the platforms that our company uses. The customer support team has been excellent at addressing all of our company's concerns.

Caitlin M.
Director of IT Risk & Compliance

The big thing for me was how interactive it was in Slack. That was one of our biggest problem points and there was a solution for that immediately.

Cary Vidal
Director, Security & IT

Immediately, especially for the Google Workspace document sharing, Metomic has paid for itself seven fold.

Hatitye Chindove
Head of Information Security and Data Compliance

We were able to find some legacy AWS keys from years ago...that gave us the confidence that in the event of new secrets appearing insecurely across our tech stack, we could rely on Metomic to help us swiftly detect and respond in a click of a button.

James Moos
Head of Security

Metomic is a SaaS enabler. They help us protect sensitive data in applications like Google Drive, so we can grow our business knowing our data is safe.

Simon Burns
Co-founder and CEO

Having real-time data-driven insights to share with stakeholders has been invaluable. Metomic ensures that we’re compliant, secure, and proactive, providing the operational resilience necessary to grow in a competitive digital commerce market.

IT Team
IT Team
Financial Services

We are a Slack and Google shop, and Metomic had out-of-the-box integrations that made implementation a breeze.

Tim Collins
FAQ

Questions before the rollout.

What is the human firewall?

The human firewall is a term that refers to your employees who act as a barrier to cyber security risks like phishing and social engineering attacks.

They follow best practices in cybersecurity to ensure the business is protected and keep the security team updated with any suspicious activity they’ve noticed.

What is an example of the Human Firewall?

A financial services firm wants its customer service team to get the benefit of AI without customer records ending up inside it. Metomic scans what heads toward an AI tool, and when card numbers or account details show up in a prompt, the person hears about it right there and gets the chance to fix it. On the agent side, a request that reaches for something sensitive waits for a person to approve or deny it, and the security team keeps a record of every request that was made.

That moment of feedback is what builds a security-conscious team, and it does more than a policy document nobody opens. It costs your people a few seconds, and it saves you the incident you would otherwise be writing up later.

What could a human firewall defend against?

#1. Phishing

Phishing attacks have grown more sophisticated, with attackers posing as well-known companies to persuade people to hand over sensitive data.

According to IT support company AAG-IT, 323,972 internet users worldwide were victims of phishing attacks in 2021.

Reddit disclosed a breach caused by a phishing attack that used plausible-sounding prompts to push staff toward a site imitating its own intranet portal.

Helping your team spot a phishing attempt is still the first line of defense, and AI has made the writing in these messages harder to fault.

#2. Baiting

Baiting works on curiosity. It promises free goods, or leaves something like a USB stick lying around for someone to pick up.

Once the victim hands over their details or plugs the device in, the attacker installs malware on the machine.

Keeping your team current on the techniques in circulation goes a long way, and it costs far less than the cleanup.

#3. Scareware

Scareware looks helpful. It claims a virus has been found on someone's computer and pushes them to download software to clean it up. The software is the attack, and it hands the attacker access to whatever sits on that machine.

Anti-virus coverage across company machines helps, and so does teaching your team which alerts deserve attention.

#4. Pretexting

Pretexting runs on manipulation. Someone poses as a manager or a senior colleague and applies pressure until information comes out. It often lays the groundwork for phishing.

The same instinct now matters for AI. A person who pauses before pasting customer data into a chat prompt is the same person who pauses before letting an unknown delivery driver through the door.

Why do you need a human firewall for AI tools?

Most sensitive data reaches an AI tool because someone was moving fast, with no bad intent anywhere in the story.

Your people are also using AI you have not approved, on accounts you do not manage, in browsers you cannot reach through an API. Enterprise-only controls miss all of it.

In our webinar on the human firewall, Christopher Russell, CISO at tZERO, described the thinking as, "I'll just share this in Slack, then delete it and it'll be fine."

AI has made that instinct faster and quieter. A document goes into a prompt, an agent gets handed a connector, and the data is out of your hands before anyone files a ticket. Meanwhile your people are being told from the top to move at speed.

"You have to be an enabler for the business to meet their deadlines and not have this process that makes sharing these things arduous," Chris continues. "If you make it painful, not feasible, or inefficient, they will work around that."

Metomic sits in the path. It scans what goes toward an AI tool and what an agent asks for, prompts the person when something sensitive is in play, holds a risky request for approval, and keeps the record your auditor asks for. All of it runs in the background, and your people carry on at the same speed. Start with what AI your team is already using.

How to create & strengthen your human firewall?

There are a few ways to start building your human firewall:

#1. Make yourself known

If people don't know who you are or what your role is, they won't think to include you in the decisions that matter. They also won't know who to raise a security concern with. Being visible across the business fixes both.

#2. Be available in the moment

Making yourself available when someone is worried about a security issue is worth the interruption. Once your team knows you can help, they come to you when something looks wrong instead of hoping it resolves itself.

#3. Tailor sessions to each team

Generic security training has stopped landing. Content that speaks to a particular team's work earns more attention than a company-wide deck.

Help each team see where they sit in the bigger picture. If your customer service team shares customer records in Slack every day, show them what that data would mean in the wrong hands.

#4. Use automation to put the power in their hands

You cannot fix every problem yourself, and handing the decision back to the person who created the risk is what keeps a security-aware culture alive. Jonathan Jaffe, CISO at Lemonade, suggests trying "to automate as much of the responsibility and notification of the issue to the person who raised the issue. If you can automate a response that notifies them in nearly real-time of the issue, there's proximity which increases learning and retention."

This is the part Metomic does for you. Your people get the prompt while the work is still open, and agents wait for a human when a request reaches for something sensitive.

#5. Don't overwhelm your team

Spread awareness training across a few weeks rather than delivering it in one sitting. A mix of short videos and in-person sessions covers the ground without swallowing your calendar, and it gives the message time to settle.

#6. Get buy-in from your leadership team

Buy-in from leadership decides how far this goes. The time, cost, and resources that security education takes are a hard sell to people who have not seen an incident yet.

Speak to them in the terms they use. "Speak in terms of risk, and metrics they understand like ARR or MRR," says Chris. "For example, it cost us this much, or this many work days, or this person's entire week." With AI, the same argument has a sharper edge, because the exposure now moves at machine speed and lands in a regulator's inbox.

Book a demo

Our team of security experts are on hand to walk you through the platform and show you the impact it can have on your business.

Simply fill in the form and we'll get back to you as soon as we can.

Loading the form…