ComputerWeekly

GCC organisations must ‘fight AI with AI’ to stay ahead of cyber threats


Artificial intelligence (AI) is fundamentally changing the cyber threat landscape, enabling attackers to launch more sophisticated attacks faster while reducing the technical expertise traditionally required to carry them out, according to Huawei.

Sultan Mahmood Malik, chief security officer at Huawei Gulf North, said AI is reshaping cyber security in three significant ways: by lowering the skills barrier for threat actors, accelerating attacks and increasing their complexity.

“Previously, hackers were supposed to have much higher capability to launch complicated attacks,” said Mahmood. “That is no longer true. They can leverage AI to launch complicated attacks with ease.”

The shift is particularly relevant for organisations across the Gulf, where governments and enterprises are accelerating investments in AI, cloud computing and digital transformation. While these technologies create new opportunities for innovation and economic growth, they also expand the attack surface available to cyber criminals.

According to Mahmood, the pace of attacks is also increasing dramatically, leaving defenders with less time to react. “The speed of attack is very, very fast now,” he said. “Defenders now need to act within minutes, and sometimes even seconds, to detect and respond to threats.”

At the same time, threat actors are increasingly using AI to orchestrate more sophisticated attacks spanning multiple systems and environments.

“Hackers can launch multi-dimensional, multi-vector attacks with ease using some of the offensive large language models,” he added.

Cyber security fundamentals

Despite these developments, Mahmood argued that organisations should not lose sight of cyber security fundamentals. “While machine speed has enabled hackers to launch complicated attacks, the fundamentals remain the same,” he said. “We still need strong cyber security hygiene.”

To address the challenge, Huawei is embedding AI capabilities and integrating security requirements across its technology portfolio as part of a strategy the company describes as “embedded intelligence, built-in resilience”.

“We are trying to fight AI with AI,” said Mahmood. “The security capabilities of devices and networks are enhanced using AI.”

Huawei has operated in the Middle East for more than 27 years, and has worked with governments, telecommunications operators and enterprises across the region during multiple waves of digital transformation. Mahmood said the company continues to invest in cyber security, allocating approximately 5% of its R&D investment to cyber security and privacy protection, with a focus on helping organisations strengthen cyber resilience while supporting national digital ambitions.

“What Huawei is doing is embedding artificial intelligence into our own solutions,” he said. “The security perspective and security capabilities of the devices are enhanced using AI.”

The company is also incorporating AI into its research and development processes to strengthen its long-standing secure-by-design and privacy-by-design approach.

“Our R&D process was already comprehensive, but we have enhanced it with AI capabilities,” said Mahmood. “A lot of cyber security-related testing can now be done much faster through AI.”

Identifying potential weaknesses

According to Mahmood, AI is helping Huawei identify potential weaknesses earlier in the development cycle while improving the overall security posture of products before they are deployed in customer environments.

“Huawei believes human-in-the-loop is fundamental and necessary,” he added. “But AI helps us minimise vulnerabilities in our products and enhance their capabilities from day one.”

Beyond product development, the company is also applying AI to vulnerability management processes. “We are doing AI-enabled vulnerability management,” he said. “We believe we can detect vulnerabilities faster and more comprehensively.”

The objective, said Mahmood, is to identify and remediate vulnerabilities before threat actors have an opportunity to exploit them.

“That means we will detect vulnerabilities, fix those vulnerabilities and proactively communicate with customers even before threat actors discover those things,” he added.

While discussions around AI often focus on technology, Mahmood believes operational readiness remains one of the most important factors determining whether organisations can withstand modern cyber threats.

He identified security operations as the first major area requiring attention. “Organisations who rely on human-level speed of doing operations, analysis and taking actions are at great risk,” said Mahmood.

Many security teams continue to depend heavily on manual workflows and analyst-driven decision-making. However, Mahmood believes those approaches are becoming increasingly difficult to sustain in an environment where attacks can unfold within minutes. “They need to enhance their operations with AI,” he said.

Data protection represents the second major priority, according to Mahmood, and ransomware continues to be one of the most significant threats facing organisations today, regardless of industry or geography. “Ransomware is the number one threat any organisation is facing now,” he said.

As attacks become more disruptive and financially damaging, organisations must strengthen their ability to recover quickly from incidents and maintain business continuity.

“They need to upscale their data protection solutions,” said Mahmood. “At least when they get attacked, threat actors will not be able to hold them hostage.”

Rather than focusing solely on prevention, organisations should ensure they can continue operating even after a successful attack.

“They should be able to overcome this kind of scenario without paying any ransom and with minimum downtime,” he added.

The third priority identified by Mahmood is workforce capability and skills development. As AI becomes increasingly embedded across business processes, security teams need a deeper understanding of how to manage and secure these technologies.

“More than 60% of cyber security professionals believe they need AI security capabilities in solutions as well as in their own teams’ skill sets,” he said.

Shadow AI

Mahmood also warned against the growing phenomenon of shadow AI, where employees use AI tools without appropriate governance or oversight. “Shadow AI should not be allowed in the organisation,” he added.

Beyond technology investments, Mahmood argued that resilience ultimately depends on how organisations operate and make decisions.

“Having a very secure product and a very good vendor as your partner is one thing,” he said. “But resilience comes from how you use that product in your production environment.”

According to Mahmood, many successful attacks continue to exploit basic weaknesses rather than sophisticated technical vulnerabilities. “We need very good security hygiene, very good security governance and the right operational capabilities,” he said. “You can build a very strong door, but if you leave it open, the threat actor does not need to break it.”

The final component of resilience, added Mahmood, is organisational culture. Cyber security can no longer be viewed solely as the responsibility of security teams, particularly as AI-driven threats continue to evolve.

“If the board members, the CEO or the CXOs do not care about cyber security and leave it only to the cyber security officers, that is not enough,” he said.

Instead, organisations should ensure cyber security considerations are embedded across leadership teams and business functions. “When cyber security professionals identify something that needs to be done, the board should listen and support them,” said Mahmood. “The threat actors will not wait for you.”

Quantum computing

Looking ahead, Mahmood believes AI governance will remain a key focus area for organisations over the next few years, but he also pointed to quantum computing as a technology security leaders cannot afford to ignore.

“The second most important threat in the coming two to three years is quantum computing,” he said. “We need to understand it, and we need to know that quantum computing is coming. There is no debate about it.”

While practical quantum threats have yet to materialise at scale, organisations should begin assessing their preparedness for a future in which current cryptographic approaches may no longer provide adequate protection.

Yet despite the emergence of new technologies, Mahmood maintained that cyber security fundamentals will continue to underpin effective defence strategies. “Identity and access management, password rotation, routine audits, governance frameworks and people capability enhancement are all well-established principles,” he said. “They do not change.”

For Mahmood, the challenge facing organisations is not abandoning those foundations in favour of new technologies, but combining them with AI-driven capabilities that can keep pace with an increasingly automated threat landscape.

“We need to be able to adapt and evolve along with the changing landscape,” he concluded. “Or, quite possibly, stay ahead of it.”



Source link