So the interim director of the Cybersecurity and Infrastructure Security Agency had to upload sensitive files into ChatGPT

People don’t come to work to fail or do bad things (exceptions apply).

Most of the time, they’re just trying to do their job in the best possible way and sometimes they pick paths that lead to bad outcomes.

A shallow incident post-mortem will call out "human factor," prescribing more rigorous controls, training, and awareness.

But if we ask "why?" five times (huge thanks Remi POUJEAUX), the real reason would most likely be poor UX, lacking functionality in the approved tools, or the lack of approved tools at all.

The environment determines the decisions made. Fix it.

Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT

CISA acting director uploaded sensitive files to public ChatGPT due to poor internal tooling