ITSecurityGuru

Why AI won’t fix your cybersecurity problem


James Gillies, Head of Cyber Security at Logicalis UKI

There is no escaping the fact that AI is creating significant opportunities for cybersecurity teams, from analysing security data and identifying suspicious activity to accelerating detection, response and remediation. However, the same capabilities are also changing the threat landscape.

This comes at a time when security teams are already under considerable pressure, with recent research showing that 77% of organisations experienced a cybersecurity incident in the past 12 months.

With AI models becoming increasingly capable, they could increase the speed at which vulnerabilities are discovered and exploited. For organisations already struggling with gaps across their security environments, the window between identifying a vulnerability and needing to remediate it could become considerably smaller.

Preparing for AI-driven threats therefore isn’t simply about investing in more technology. It starts with addressing the weaknesses organisations already have. Five areas in particular should be a priority, spanning visibility and identity through to how quickly organisations can detect, respond to and remediate threats.

Do you know what you’re trying to protect?

If you can’t see an asset, you can’t protect it, so visibility is fundamental to cybersecurity.

Maintaining that visibility is becoming increasingly difficult as cloud services, applications, endpoints, infrastructure and third-party systems continually change. Without a complete view across the environment, vulnerabilities can emerge that security teams may not know are there.

AI could make those blind spots more significant. Recent research found that 34% of CIOs say AI has already created new security blind spots. Attackers understand the importance of visibility too. Reconnaissance is typically one of the first stages of an attack, as threat actors build an understanding of the environment they are targeting.

Organisations need that same understanding of their own estate, including where critical services and data reside and which vulnerabilities present the greatest business risk.

Can you trust the identities accessing your systems?

Cybersecurity has traditionally focused heavily on protecting the network perimeter. But cloud services, hybrid working and distributed infrastructure have changed where that perimeter sits. Increasingly, identity is the control point.

Attackers are targeting users through phishing and social engineering, as well as obtaining legitimate credentials exposed through previous compromises. In those circumstances, they don’t necessarily need to hack into an organisation. They can simply log in.

This makes strong identity and access controls essential. Zero Trust principles such as verifying explicitly, applying least-privilege access and assuming breach can help limit what compromised identities are able to reach.

Organisations also need visibility into how identities behave after authentication. Identifying unusual activity and quickly revoking access can prevent one compromised account from becoming a much wider incident.

Are your security tools actually making you more secure?

The response to growing cyber risk has often been to invest in more security technology. That has left some organisations managing dozens of different tools across their estates.

The problem isn’t necessarily the capability of those products. It’s whether they work together.

When security technologies operate independently, telemetry becomes fragmented, alerts are spread across multiple platforms and teams can struggle to establish a consistent view of what is happening.

The priority should be getting more from existing investments. Better integration and correlation of security telemetry, including through technologies such as XDR, can provide broader visibility and help teams move from detection to response more quickly.

More tools do not automatically create better security. Making existing tools work together effectively can often deliver greater value.

What happens when attackers can move faster than you can respond?

Here is where AI could fundamentally change the equation; for example, Frontier AI models are demonstrating the potential to discover exploitable vulnerabilities significantly faster than traditional human-led research. If that capability continues to develop, the time organisations have to patch vulnerabilities before attackers can exploit them is likely to shrink.

That puts greater emphasis on time to detect and time to respond, areas where organisations are already feeling pressure. New research shows that 41% of CIOs say incident response times have worsened.

Organisations should understand how quickly they can identify an incident, prioritise a vulnerability and contain an attacker that has gained access. Automation will form part of that response, however, so will effective processes, appropriate logging and access to the right expertise.

Is technical debt becoming security debt?

Legacy infrastructure and long-standing vulnerabilities have always created challenges for IT teams. As remediation windows shrink, they increasingly create cybersecurity risk too.

Older systems can be difficult to patch, particularly where applications have reached end of life or operational dependencies make remediation difficult. That doesn’t remove the risk; it makes understanding and managing the exposure more important.

Where patching isn’t immediately possible, organisations need to consider compensating controls, exposure management and approaches such as virtual patching to reduce the opportunity for exploitation.

No longer just an IT modernisation challenge, technical debt is a cybersecurity risk. Organisations need to identify where ageing and legacy technology leaves them most exposed, understand the potential impact on the business and prioritise remediation where the risk is greatest.

Strengthen the foundations first

AI will undoubtedly play a growing role in cybersecurity, but it cannot compensate for weaknesses that already exist. Poor asset visibility, weak identity controls, disconnected security tools and exposed legacy systems will remain vulnerabilities – and AI could enable attackers to identify and exploit them faster.

Preparing for that shift means getting the fundamentals right: understanding the environment, controlling access, making existing security investments work together and improving the ability to detect and contain threats quickly.

As AI accelerates the pace of attack, those foundations will matter more, not less. The organisations best placed to respond will be those that address the gaps before attackers find them.



Source link