Tackling Cyber Threats: Is AI Cybersecurity Our Only Hope?
Jane Frankland
Cybersecurity Influencer | Advisor | Author | Speaker | LinkedIn Top Voice | Award-Winning Security Leader | Awards Judge | UN Women UK Delegate to the UN CSW | Recognised by Wiki & UNESCO
Could artificial intelligence (AI) be the key to outsmarting cyber threats in an increasingly connected world? Is it our only hope for survival? These are questions I've been asking myself recently as AI and cybercrime have become hot topics in the tech industry, and for world leaders.
On one hand, AI has been hailed as a game-changing technology with the potential to transform industries and improve our daily lives. On the other hand, it's been portrayed as a potential threat to our privacy, security, creativity and even mankind’s existence. So where does AI stand in the realm of cybersecurity, and how can we leverage it for protection rather than harm?
This is what I'll be delving into in this blog, where I'll be exploring how these two fields are intersecting and what that means for our digital landscape. From the potential benefits of using AI to detect and prevent cyberattacks, to the ethical concerns surrounding its use in cybersecurity, I'll be covering a wide range of topics.
I'm partnering with Palo Alto Networks again, and will be shining a spotlight on Precision AI?, which they recently unveiled. As a global leader in cybersecurity, known for their innovative approach to cybersecurity, and offering a range of products and services designed to safeguard businesses and organisations against cyber threats, their vision for a world where each day is safer and more secure than the day before aligns perfectly with mine.
Constantly Evolving Threats
Just as the night follows the day, the world of cybersecurity is no stranger to constant change and adaptation. As technology advances, cybercriminals are finding new ways to exploit vulnerabilities and infiltrate systems. With the emergence of new attack methods such as (but not limited to) ransomware, supply chain, fileless attacks, and IoT botnets, traditional cybersecurity measures are struggling to keep up. This is where AI comes in as a potential game-changer.
The Power of AI in Cybersecurity
AI has been around for a while, driving productivity and efficiencies. However, over the past 18-months, it’s accelerated thanks mostly to the launch of GenAI. Affecting every enterprise, it's shaken up the business world. Considering developers, they're able to code 133% faster with AI assistance. GitHub notes an exponential increase in coding projects featuring AI.
When it comes to the workplace, ChatGPT set a record for the fastest growing user base ever when it launched at the end of 2022, reaching 100 million users in 3-months, outperforming TikTok. Then, there’s been a huge increase in vendors offering or including AI in their products. In fact, according to G2, there's been a growth rate of 39% - double the next closest software category.
Regarding cybersecurity, AI is transforming cyber defence by quickly analysing terabytes of data, detecting anomalies and patterns which may indicate cyberattacks, and blocking them in real-time. With machine learning algorithms, it can now continuously learn and adapt to new threats, making it a powerful tool in cybersecurity.
AI can also automate mundane and time-consuming tasks such as patching vulnerabilities and managing security alerts. This not only frees up valuable time for security professionals to focus on more complex tasks but also reduces the risk of human error. Given the current levels of burnout, where alert fatigue is causing a compounding cyber risk, with a majority (83%) of IT security professionals admitting that they or someone in their department have made errors due to burnout that resulted in a security breach, this is useful.
The Limitations of AI in Cybersecurity
However, as with any technology, AI is not infallible. One of its major limitations is its reliance on data. If the data it is trained on is biased or incomplete, it can lead to inaccurate threat detection and response which can have severe consequences. AI can also be vulnerable to adversarial attacks, where hackers purposely manipulate the data to trick the system into making incorrect decisions and misclassifying threats. Then, as AI becomes more integrated into our lives, there are growing ethical concerns about privacy and security. For example, who has access to the data being collected, and how is it being used?
The Human Factor
Humans play a crucial role in the realm of AI and cybersecurity despite its advanced capabilities. While AI excels in processing data and predicting patterns, human intervention is essential for complex problem-solving, creative thinking, interpreting nuances and ambiguity, contextual understanding, and detecting subtle patterns, biases, errors and misuse. Humans also do better at communication, collaboration across teams and departments, training, and oversight of AI systems, ensuring they operate ethically and efficiently.
The Future of AI in Cybersecurity and its Growth Potential
As technology continues to accelerate the transformation of our digital world, the role of AI in cybersecurity will grow. According to research, the market is expected to reach $102,78 billion by 2032, seeing a CAGR of 19.43% between 2023 and 2032.
Unfortunately, threat actors recognise the same potential for growth – from speed (hours - from compromise to exfiltrate data), scale (ransomware - volume to surge), and scope (prompt injection - GEN AI's biggest flaw). In response, there’s a widespread surge in innovation involving adversarial AI, effectively reducing entry barriers for adversaries with low technical skills. And this trend is simplifying the exploitation of system vulnerabilities, enabling easier access for them to compromise data, manipulate code, and disrupt business operations.
The Responsible Way Forward
?Although the outlook for securing businesses appears bleak, with a probable fast rise in software supply chain, ransomware, and social engineering attacks, like phishing and deepfakes, which have experienced a staggering 3000% increase in recent years, there is a secure way forward.
领英推荐
As CISOs, and ITDMs who are responsible for cybersecurity we can do three things:
1. ? Countering AI with AI – by using cutting-edge machine learning capabilities coupled with deep learning and GenAI to review networks, endpoints, and cloud environments we can identify and block AI generated attacks in real-time.
2.? Using AI secure by design principles – by protecting enterprise applications that leverage AI models at the design stage, we can bolster code security, fortify the integrity of the AI software supply chain, and reduce the risks associated with data exposure and compliance breaches.
3.? Using Precision AI to simplify cybersecurity and reduce complexity – by using tools that speak human to summarise large volumes of data and threat intelligence with a simple user-friendly interface we can tackle data silos, long response times, and the numbers of ever-changing products which increase the overhead for our teams.
Precision AI, powered by Palo Alto Networks, brings exciting and timely capabilities to secure key enterprise security use cases. Built on the world’s largest data set among pure-play cybersecurity companies, it combines machine learning’s predictive accuracy and automated remediation with the accessibility of GenAI for instant, accurate and trustworthy security outcomes. Palo Alto’s innovative approach to AI and the cyber threat, delivered with platformization reduces cyber risk while simplifying operations, freeing up CISOs and other ITDMs from the perpetual onslaught of cyberattacks, compliance failures and stress that accompanies cyber resilience.
I wholeheartedly recommend exploring the transformative benefits of Precision AI to fortify your organisation's cybersecurity posture effectively.
To End
AI is indisputably revolutionising business, enhancing productivity, and redefining the cybersecurity landscape. As this technology evolves, and our reliance on it intensifies, so too must our approach to cybersecurity. As we harness the immense potential of AI, we must also remain vigilant to the attendant risks, adopting proactive measures to secure our digital future against the looming shadow of AI-powered threats. In doing so, we will not only safeguard our assets and reputation but also steer our organisations towards sustainable growth and resilience in this new frontier. It’s up to us as CISOs and ITDMs to ensure that AI is used as a powerful tool for defence.
Now I want to hear from you…
Tell me, how do you envision the future role of AI in enhancing your organisation's cybersecurity posture, and what steps are you taking to prepare for the inevitable evolution of cyber threats in the AI era?
Then, head over to Palo Alto Networks to learn more about Precision AI.
Finally, in the spirit of full disclosure, please be aware that I’ve received compensation for promoting this thought leadership blog for Palo Alto Networks. Because your success is important to me, I only align myself with brands I believe in, and Palo Alto Networks is one of them.
About Jane Frankland
Jane Frankland is an award-winning cybersecurity leader, author, and women’s change agent. Her authority is referenced by Wiki, LinkedIn (Top Voice), Thinkers360, and UNESCO. She built her own global penetration testing firm in the late 90s, has worked as a Managing Director at Accenture, and contributed to numerous industry initiatives, including CREST, Cyber Essentials, and Women4Cyber. Through her IN Security Movement, 419 women have received scholarships, a value of almost USD $800,000. She regularly shares her thought leadership and leader-developer skills with forward-thinking companies and governments, and has been featured in the Sunday Times, The Financial Times, The Guardian, Forbes and the BBC.
To find out more, visit https://jane-frankland.com
First, I respect everyone’s beliefs and thoughts on all situations. But — and maybe it’s because I was hacked back in November so badly that I live in a world of paranoia because of my work. Speaking of my work, I’m a court stenographer who has been told forever that AI will take over my job. Do you know how many cases I’ve done already with people suing for wrongful termination because they couldn’t come close to a usable AI product. Now I follow this as I am waiting to see where it blows up first. Will it be in the legal arena(let’s for the confidentiality and HiPAA). Will it be in the medical space for charting? My mom uses it. She loves it but It’s like j need my secret decoder ring to figure out what she said — oh and the radio was on so there’s someone else in there. No punctuation. Missing words. Here’s my final example. I take very high end corporate litigation. Confidential. Lots and lots of firms. Think about Dopesick. I had 40 plus attorneys in that room. And while I’m taking down a scientist with a heavy accent using unfamiliar, non everyday words I’ve got 10 out of 40 objecting. I stop them. Remind them one at a time. I have sort of a photographic memory like rain man so — tbc
Security, Privacy and AI
6 个月In my experience, there are 3 fundamental reasons why security incidents happen: (1) No clean separation between code and data. Code comes into your application masquerading as data and therefore, compromises the integrity of your application: e.g. buffer overflow, SQL injection, XSS... This is a fundamental architectural issue. (2) Misconfigurations (much more common in cloud settings as most enterprises don't have a handle on how to harden their cloud deployments relative to how they harden their on-prem deployments. (3) Your end user behavior - something that all kinds of co-pilots are attempting to address. I don't see how pure AI can solve the first of these issues. AI is definitely useful but there is not a whole lot of data enterprises are willing to share (as you've rightly observed above). Furthermore, enterprises want determinism and explainability - something that still needs maturing for AI.
Ph.D. in Information Security | Keynote Speaker | Executive Partner, Director at Gartner
6 个月Great article!
Interesting perspective, Jane! The rise of Precision AI? tools like Palo Alto's offering is definitely a positive step. Industry reports suggest a staggering 2.3 million new cyber threats emerge daily, highlighting the need for AI-powered defense mechanisms. By focusing on adversarial AI defense, data protection, and secure deployment, these tools can foster trust and accelerate safe AI adoption across various sectors.?
CISO & Cyber Strategist | CEO - Chaleit | Former co-founder of Cyber firms NotSoSecure & 7Safe (both acquired) | Designer of Cyber MSc(s) | Commercial Helicopter & Aeroplane Pilot | JetPack Pilot | Sat-Radio Nerd
6 个月Jane Frankland you raise fundamental points in your article here. The interesting parallel is that of humans too. Poor data in = poor decision making ?? . AI does not socialise in groups and thinking for its learning in the same way we do so its judgement is not binary, but not as plastic as a human. Therefore bad data in at the very minimum at this stage is bad data out... and to your point on the bad actors; I agree its now another, and much more advanced tool in helping them in their endeavours...