PetSafe Brands cuts potential data leakage risk with an NROC Security Assessment
GenAI adoption was encouraged at PetSafe Brands but visibility was lacking and governance was all-or-nothing. Employees mixed company-paid business subscriptions with free and personal accounts which were chosen individually rather than by policy. PetSafe Brands’ security team used an NROC Security Assessment to replace guesswork with real usage data — then moved seamlessly from observation to enforcement — resulting in full visibility across every location, executive alignmenton governance, and a significant reduction in potential data leakage risk.
KEY TAKEAWAYS
[[TAKEAWAYS]]
TAKEAWAY: [70%] less data leakage risk with guardrails for free and personal chatbots.
TAKEAWAY: [1,100+] users deployed in a single day – no plugins, no agents.
TAKEAWAY: Significant increase in sanctioned GenAI use within [2 months] of the Assessment.
[[/TAKEAWAYS]]
COMPANY OVERVIEW
PetSafe Brands
PetSafe Brands is the leading manufacturer of pet products, with a purpose of unleashing freedom for pet parents by keeping their pets happy, healthy, and safe. Its family of brands includes PetSafe®, Invisible Fence® Brand, SportDOG™, Kurgo®, and Premier Pet™. Founded in 1991, PetSafe Brands has grown into an international corporation of over 1,100 employees, selling in over 52 countries, with a portfolio spanning electronic training and containment systems, waste management products, fountains, pet doors, innovative treats, and more.
THE CHALLENGE
Visibility was challenging and governance meant block-or-allow
PetSafe Brands had no single, sanctioned GenAI application. A policy existed but the controls to enforce it didn't — visibility required a difficult manual process, and governance meant only blocking an app or allowing it. This resulted in a patchwork of business and personal-plan accounts, each selected independently.
The PetSafe Brands security team had clear goals — control which apps and plans people could use, reduce the risk of sensitive data going to the wrong place, and monitor how company-paid licenses were actually being used. Visibility was the prerequisite for all of it and for justifying the governance the team wanted: how much GenAI usage was there, which apps and plans, and what was the risk level based on the data going into prompts and attachments?
"You can't scope a problem you can't see. Getting visibility first told us the real scale of what we were solving, and that made the budget conversations far easier — we were working from hard facts, not hunches. And the speed can't be overstated. In a sea of tools that take days or weeks to deploy, this gave us the picture almost immediately."
Mike Stolarik
CISO, PetSafe Brands
THE SOLUTION
A six-week NROC Security Assessment made GenAI usage visible, then enforceable
PetSafe Brands’ engagement had three phases:
- An authenticated pilot tied every prompt to a real user
A small pilot group tested the NROC Security Assessment's configuration options, including authenticated vs. anonymous monitoring. Authenticating against the company IdP via SSO ties every prompt and response to a company user ID, giving visibility by department and location and surfacing the most active and highest-risk users. This validated the approach ahead of full governance. - An agentless rollout reached all employees in a day
The second phase extended monitoring to all 1,100+ employees in observation-only mode — deliberately unauthenticated to capture a true baseline without changing behavior. The NROC AI Security Proxy is a cloud-based service that inspects GenAI prompts, responses, and attachments with no browser plugins or endpoint agents; IT distributed a PAC file and certificate via Intune, and the rollout had no side effects on end-user machines.
"We were live across the whole company in a day — no agents, no plugins, nothing for employees to install. Almost immediately we could see which GenAI tools were actually in use and where the risk sat. Getting that picture that fast changed the whole conversation."
Arjun Bery
Security Program Manager, PetSafe Brands
"Working with the NROC Security team through our iterations has been great. We wanted a phased rollout, and they met us there — with both their time and their tools. As our business needs shifted, the product and the people flexed to fit how we work rather than the other way around."
Mike Stolarik
CISO, PetSafe Brands
THE RESULTS
Full visibility, aligned leadership, and less risk
The NROC Security Assessment gave PetSafe Brands’ security team a real-time dashboard across every location it operates in. Of the 1,100+ deployed users, about a third were active with GenAI during the observation window, and nearly 20% used it at least weekly — 4,500 prompts a week across 18 GenAI app families. A significant share of those prompts went to free or consumer-plan chatbots rather than sanctioned business accounts. The Assessment also gave leaders a baseline read on prompting skills, and flagged one employee group whose usage patterns warranted a separate risk and business review.
Authenticated deployment pinpointed PetSafe Brands’ highest-risk individuals, including its heaviest users (“superprompters”) — giving the security team a concrete starting list for policy calibration, now built into an ongoing governance process. With stakeholders aligned, PetSafe Brands moved directly from assessment into production, with policy enforcement live through the NROC Management Console.
"The risk reduction was immediate, and now every prompt is traceable to a user. That traceability is exactly what lets my team move faster — people can lean into GenAI more confidently because we've brought the risk down, not because we've told them to slow down."
Mike Stolarik
CISO, PetSafe Brands
WHAT’S NEXT
From a one-time Assessment to continuous, fact-based governance
PetSafe Brands now monitors GenAI usage continuously and enforces an acceptable use policy calibrated to the risks the NROC Security Assessment surfaced. In the two months since, validated use of sanctioned GenAI apps has grown, while prompts to free and personal chatbots have dropped 70%. The security team continues refining the policies, like applying different data-protection controls to personal vs. business subscriptions, and is working with NROC Security on visibility and guardrails for agentic use.




.png)


