Title of the thesis: Security risk assessment and analysis of AI-powered CRM.
Author: Iloghalu Kelechukwu Agnes.
Supervisor: Jesús Alberto Cázares Montes.
Scope of work: 78 pages, 22 tables, 7 figures, 31 bibliographic references.
Keywords: AI-POWERED CRM, CHATBOT SECURITY, ISSRM, STRIDE, RISK MITI-
GATION, GQM.
Artificial intelligence (AI) added into customer relationship management (CRM) sys-
tems has significantly transformed how organisations manage and interact with customers.
AI-powered chatbots enable automated support, personalised communication,improve effi-
ciency and customer experience. However,the reliance on conversational AI also introduces
critical cybersecurity risks, particularly when sensitive customer data is processed through
automated dialogue systems.
This paper presents a structured security risk assessment of AI-powered CRM chatbot
environments, focusing on identifying and analysing potential threats that may compromise
customer data and system operations by adopting a conceptual analytical approach. The
Information System Security Risk Management (ISSRM) model identifies key assets, vulner-
abilities, and threats in CRM chatbot process. Through this approach, critical components
such as customer databases, chatbot interfaces, and backend CRM infrastructure are examined
to understand how security risks may arise in the system. STRIDE threat modelling frame-
work categorise potential attacks affecting chatbot-based CRM systems. STRIDE allows for
the systematic identification of threats such as spoofing, tampering, information disclosure,
denial of service, and privilege escalation. The analysis highlights key risks including prompt
injection, unauthorised access to customer data, and disruption of chatbot services through
malicious inputs. The Goal–Question–Metric (GQM) approach assess how proposed mitiga-
tion strategies reduce identified risk. These allows the assessment of how security controls
contribute to reducing identified risks while maintaining the confidentiality, integrity, and
availability of customer information. This study proposes several risk mitigation strategies,
including improved authentication mechanisms,and stronger protection of CRM data. These
measures aim to reduce vulnerabilities and strengthen the overall security posture of CRM
systems.
Abstract (latvian):
Disertācijas nosaukums: Uz mākslīgo intelektu balstītas klientu attiecību pārvaldības
sistēmas drošības riksu analīze un novērtējums.
Autors: Iloghalu Kelechukwu Agnes.
Darba vadītājs: Jesús Alberto Cázares Montes.
Darba apjoms: 78 lappuse, 22 tabulas, 7 attēli, 31 bibliogrāfiskās atsauces.
Atslēgvārdi: AR MĀKSLĪGO DARBINĀMA CRM, ČATBOTU DROŠĪBA, ISSRM,
STRIDE, RISKA MAZINĀŠANA, GQM.
Klientu attiecību pārvaldības (CRM) sistēmas ieviestais mākslīgais intelekts (MI) ir
būtiski mainījis to, kā organizācijas pārvalda un mijiedarbojas ar klientiem. MI darbināmi
tērzēšanas roboti nodrošina automatizētu atbalstu, personalizētu komunikāciju, uzlabo efektivitāti un
klientu pieredzi. Tomēr pilnīga paļaušanās uz sarunu MI rada arī kritiskus kiber-
drošības riskus, ̄īpaši, ja sensitīvi klientu dati tiek apstrādāti, izmantojot automatizētas dialoga
sistēmas.
Šajā darbā tiek uzrādīts strukturēts MI darbināmu CRM tērzēšanas robotu vides
drošības risku novērtējums,identificēšana un analīze, izmantojot konceptuālu analītisku
pieeju. Informācijas sistēmas drošības riska pārvaldības (ISSRM) modelis identificē galvenos aktīvus, ievainojamības un draudus CRM terzēšanas robota lietošanā un, izmantojot šo pieeju, tiek pārbaudīti kritiski komponenti, piemēram, klientu datubāzes, tērzēšanas robota saskarnes un CRM aizmugures infrastruktūra, lai izprastu, kā sistēmā var rasties
drošības riski. STRIDE draudu modelēšanas ietvars kategorizē potenciālos uzbrukumus,
kas ietekmē tērzēšanas robotu CRM sistēmas. STRIDE ļauj sistemātiski identificēt tādus
draudus kā krāpšanās, manipulācijas, informācijas izpaušana, pakalpojuma atteikšana un
privilēģiju eskalācija. Analīzē ir izcelti galvenie riski, tostarp uzvedņu injekcijas, neatļauta
piekļuve klientu datiem un tērzēšanas robotu pakalpojumu darbības traucējumi, izmanto-
jot ļaunprātīgu informācijas ievadi. Mērķa-Jautājuma-Metrikas (GQM) metode novērtē,
kā ierosinātās mazināšanas stratēģijas ietekme un samazina identificētos riskus, vienlaicīgi
saglabājot klientu informācijas konfidencialitāti, integritāti un pieejamību. Šajā pētījumā
ir ierosinātas vairākas risku mazināšanas stratēģijas, tostarp kā uzlaboti autentifikācijas
mehānismi un spēcīgāka CRM datu aizsardzība. Šo pasākumu mērķis ir samazināt ievaino-
jamību un stiprināt CRM sistēmu vispārējo drošības stāvokli.
This work is protected by copyright and/or neighboring rights. It can be freely used for personal use, scientific research, or self-education. Other uses require permission from the right holder(s).
APLIS statement of rights:
Protected by copyrights - not in commercial circulation
APLIS access notice:
Accessible online (without the ability to download)