Andy Norton, European Cyber Risk Officer at Armis: “One of the most valuable skills that IT professionals need to harness is AI literacy”

Thanks to AI, the speed of innovation has never been quicker. But without proper safeguards, progress can quickly become vulnerability. This is a reality that Andy Norton knows well. With over two decades in cybersecurity and now European Cyber Risk Officer at Armis, he knows not just how to defend against threats, but prevent them before they appear.

While AI innovations have served to boost outputs and profits, itโ€™s also opened new vulnerabilities. Or as Andy puts it: โ€œAs transformation continues, an organisationโ€™s attack surface will grow exponentially.โ€ For him, the only defence is found in taking a more proactive stance, both โ€œadopting processes and technology that focus on protecting the entire attack surfaceโ€ while also โ€œmanaging cyber risk exposure in real-timeโ€.

While todayโ€™s defences hold against current threats, Andy believes that weโ€™ve โ€œbarely scratched the surfaceโ€ of AIโ€™s capabilities. And that goes both ways. As the speed of innovation accelerates, so does the risk of AI being weaponised by bad actors. AI toolkits are already being sold on the dark web, allowing criminals to both โ€œautomate and optimise their tacticsโ€ while serving to โ€œlower the bar of entryโ€ for attacks.

Andy warns that โ€œnation-states and rogue factions are increasingly targeting critical infrastructure,โ€ with attacks on energy grids, healthcare and financial services becoming more prevalent. Compounding this threat is the growing potential of quantum computing. While still in its infancy, quantum computing may soon โ€œchallenge the security of traditional encryption methods,โ€ a threat that has triggered an arms race to โ€œdevelop quantum-resistant encryption standardsโ€ within the decade.

Still, Andy is confident that IT teams will rise to the challenges, but only if theyโ€™re willing to evolve. โ€œIT professionals who will succeed in the coming years,โ€ he says, โ€œare those who can navigate the convergence of AI, cybersecurity and communication, while continuously adapting to the technological changes ahead.โ€

With so much on the line, keeping up with the next innovations has never been more important. Thatโ€™s why we started this interview by asking Andy what he sees coming for the IT industry in the near future.

General outlook  

What do you think will be the most significant changes in the IT industry over the next 5-10 years? 

Digital transformation will continue to have a broad scope, encompassing all business objectives and operations. As transformation continues, an organisationโ€™s attack surface will grow exponentially. Whilst the adoption of new technologies has helped unlock higher outputs and profits, in some instances, it has been at the detriment of cyber resilience and safety.

To safely keep pace with the challenges introduced by the proliferation of connected assets, it’s essential that organisations shift from reactive to proactive cybersecurity operations. This means adopting processes and technology that focus on protecting the entire attack surface and managing cyber risk exposure in real time. This starts with an understanding of the environment and what an organisation has. From there, security teams can layer on to gain the benefits of a comprehensive security program – proactive threat hunting, vulnerability prioritisation and remediation and beyond.

AI will also be a key enabler of this, and weโ€™ll continue to experience minor and major improvements to all aspects of our daily lives as a result. For example, as the attack surface grows exponentially, the volume of data IT teams must manage becomes more difficult to manage. As such, AI solutions that automate tasks will become indispensable to empowering teams to not only interpret information sets quickly and easily but also to act on these insights automatically without human intervention. In the context of cybersecurity, this is game-changing for effective vulnerability management.

Emerging technologies  

Which emerging technologies do you think will have the biggest impact on IT in the coming decade?ย 

AI will continue to have a significant impact on IT over the next decade. It’s a technology that we’ve barely scratched the surface of. However, the benefits of the technology are a double-edged sword. When used by bad actors, the technology can be weaponised. On the other hand, AI is a strategic enabler, serving as a powerful defensive tool for security teams.

One way criminals are using AI to automate and optimise their tactics is through the use of toolkits. These kits are available to purchase on the dark web and significantly lower the bar of entry for bad actors, allowing those with less technical expertise to inflict damage with the same sophistication as their more experienced counterparts. This has significantly increased the volume of cyberattacks. For example, zero-day exploits, once taking weeks to develop, can now be weaponised in days ,and AI-driven tools can scan emails, Slack channels and social media rapidly for details that can be used in extortion.

When used for good, the technology enables teams to identify vulnerabilities early, detect patterns of malicious activity and neutralise threats rapidly. Security teams already have a โ€˜home court advantageโ€™ through their in-depth knowledge of their environment and experience with the existing security tools, so AI only works to further assist this. By providing IT teams with a holistic overview of their environment, it enables them to derive impactful insights and subsequently act with the speed and efficiency needed to defend against bad actors, also using AI.

The technologyโ€™s abilities will only continue to advance, to the benefit of both cyber actors and organisations’ defence. Looking to the future, the next generation of machine learning-powered weapons will autonomously learn, adapt and evolve.

Another potential significant threat of emerging technology is quantum computing. Whilst still in its early stages, future breakthroughs may challenge the security of traditional encryption methods. This has triggered a race to develop quantum-resistant encryption standards before the end of the decade. In response, over the next few years, organisations will need to look at adopting quantum-resistant security, replacing legacy systems and strengthening visibility into vulnerabilities.

Business and industry impact  

In what ways do you think IT will transform industries like healthcare, education, or finance? 

Within the cybersecurity landscape, nation-states and rogue factions are increasingly targeting critical infrastructure as part of their strategy. Successful attacks targeting these industries – such as energy grids, healthcare, manufacturing facilities and financial services – can create mass chaos. This threat will only continue in state-sponsored cyberattacks aimed at creating widespread disruption.

As mentioned, technological innovation has enabled widespread digital transformation, but also further expanded the attack surface. Digital transformation will undoubtedly continue at its pace, if not faster, and defences will need to keep up.

Looking at healthcare in particular, this industry has evolved at an unprecedented rate. Smart hospitals embrace advanced technologies and automation, including AI-based diagnostics, robotic surgeries and connected medical devices. However, whilst these innovations enhance patient care, they also require a proactive security-first approach so that every layer of hospital infrastructure can be, and remain, secured to enable improved quality of care for patients.

IT has not only impacted critical industries’ ability to perform well but has also ensured that security can fight modern-day threats and vulnerabilities introduced by continuous digital transformation. Unified cyber exposure management platforms that integrate early warning intelligence, risk and vulnerability prioritisation and asset management across an enterpriseโ€™s entire infrastructure, for example, provide a clear, comprehensive view of security vulnerabilities, risks and threats. This battle between IT innovation, which extends the attack surface and IT innovation, which helps to defend it, will continue, remaining extremely prominent in the most critical sectors.

Skills and workforce  

What skills do you think will be most valuable for IT professionals in the future? 

As AI continues to revolutionise the technology industry, one of the most valuable skills that IT professionals need to harness is AI literacy. The integration of AI into almost every aspect of business operations means that professionals must be able to understand, implement and manage AI technologies.

The implications that AI will have on cybersecurity cannot be overstated either, and, as such, IT professionals will need to shift both their minds and skillsets accordingly. Jobs will be transformed and new ones will be created. In this environment, there will be a need for professionals to develop, train and maintain AI-powered cybersecurity solutions, ensuring that they are not only effective but also resilient against ever-evolving threats.

Beyond technical skills, the โ€˜soft skillsโ€™ IT professionals need will also change. In particular, the need for effective communication about the benefits and risks introduced by this technology and how it relates to the overall business will become increasingly important. As AI tools become more advanced, they are helping IT teams bridge the gap between themselves and non-technical team members by simplifying complex data and translating it into insights that can be more easily digested.  This support enhances the ability of IT professionals to communicate their security issues and the business impact in a way that is not only understandable but also actionable.

IT professionals who will succeed in the coming years will be those who can navigate the convergence of AI, cybersecurity and communication, while continuously adapting to the technological changes ahead.

Challenges and opportunities  

What are the biggest challenges IT professionals will face in the next decade? 

Going into the next decade, IT professionals will undoubtedly face a number of challenges, especially in the realm of cybersecurity. One of the biggest hurdles will be keeping pace with the rapidly evolving tactics used by cybercriminals and state-sponsored threat actors. For a long time, IT teams and their cybercriminal counterparts have been caught in a game of cat and mouse and while this wonโ€™t change anytime soon, the introduction of AI has thrown out the rule book. Over the coming years, cybersecurity teams will need to contend with a lowered bar of entry for criminals and increased severity, frequency and scale of attacks. As mentioned, however, security teams are also enabled by this technology, empowering them to finally shift to a proactive stance that puts the power back in their hands.

This problem is only compounded by the increasingly difficult task of gaining a real-time understanding of the environment. The proliferation of connected physical and virtual assets – from IoT devices to cloud-based services – has made it much harder for businesses to gain a complete understanding of their infrastructure, as itโ€™s constantly changing. Without this insight, IT teams are unable to effectively manage vulnerabilities, detect threats or respond to incidents in a timely manner. With the right cybersecurity solutions in place, this tough challenge can be effectively solved.

In addition to the technical challenges that IT teams face, the evolving regulatory landscape will continue to present challenges. While itโ€™s impossible to predict what new regulations will emerge by the end of the decade, itโ€™s certain that IT teams will be required to continue adapting their security practices to meet stricter standards. Industry leaders continue to work to simplify the regulatory landscape for organisations, so they know what they need to consider, where time and attention are needed, and to ensure with full confidence that organisations are in compliance.

In short, the challenges facing cybersecurity teams in the coming years will by no means be an easy feat. But, for those who adapt to stay a step ahead, use AI to the benefit of their team, prioritise managing the entire attack surface and maintain strong compliance and security practices, it will be a challenge they can rise to, overcome and excel well beyond in the future.

Global and societal impacts  

How will IT contribute to addressing global challenges like climate change or social inequality? 

IT has already played a significant role in addressing some of our most pressing challenges. For example, technology has become a powerful equaliser by democratising our access to information. Robotics solutions have increased efficiencies in manufacturing facilities, telemedicine has made healthcare more accessible, and smart grid technology is making energy use more efficient.

Additionally, emerging technologies such as quantum computing are enabling the development of sustainable solutions by improving energy efficiency and facilitating the discovery of new, environmentally friendly materials. Another vital role technology plays is in protecting our critical national infrastructure (CNI). As technology continues to impact every part of our lives, itโ€™s more important than ever that we safeguard the systems that are responsible for the stability of our nations and societies.

As such, in the coming years, we will need to prioritise robust cybersecurity practices alongside innovation. Striking the right balance between progress and ensuring security will become absolutely critical. By securing the infrastructure that we rely so heavily on, we can make sure that progress towards addressing global challenges goes unhindered.

More interviews

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.