Kennet Harpsøe, Lead Researcher at Logpoint: “Data protection is the main challenge for IT professionals”

One of our favourite things about interviewing IT leaders is that they often see the world differently. That’s certainly true for Kennet Harpsøe, Lead Researcher at Logpoint, who makes two excellent points about GenAI that we hadn’t considered before. Or, more particularly, about Large Language Models (LLMs).

“LLMs understand programming languages and one of the benefits of that is that they can de-obfuscate malicious code,” he explained. “It might not be able to say why it’s malicious, but it can make it readable.” And that means that cybersecurity professionals have a new weapon in their armoury.

Naturally, however, Kennet also sees downsides to the technology, one of which is the explosion in content created by generative AI. “Authentic content is becoming rarer, which means that there is a risk that the LLMs will collapse,” he points out. “It is kind of like a snake eating its own tail.”

But the biggest challenge Kennet identifies is around data protection. Despite the fact that “feeding sensitive information into generative AI is a risk” he sees “many examples” of people doing exactly that with everything from financial info to personal identifiable information, or PII. “IT professionals need to find ways of preventing that from happening, so that information that can harm business, citizens or society doesn’t fall into the wrong hands.”

This is the kind of challenge that keeps Kennet busy at Logpoint, where he conducts cybersecurity analysis and develops machine learning models to finetune SIEM (Security Information and Event Management) system alerts.

Before Logpoint, he worked in both the private and public sector including the Danish Centre for Cybersecurity. One of his responsibilities: machine learning for detecting security incidents and investigating cybersecurity events. And if you need any more convincing that Kennet is worth listening to, he holds a PhD in Physics from the Niels Bohr Institute in Copenhagen…

There is a lot of hype around AI in cybersecurity. The reality is that the generation of Large Language Models (LLMs) used in cybersecurity today don’t do much to address the big challenges in cybersecurity like alert fatigue, the growing number of false positives and lack of cybersecurity professionals.

LLMs are great at transforming text. For example, LLMs understand programming languages and one of the benefits of that is that they can de-obfuscate malicious code. It might not be able to say why it’s malicious, but it can make it readable.

Still, the problem with LLMs is that they can hallucinate and out of the blue give answers that are outright wrong or don’t make any sense, which means we can’t always trust the output. And we don’t have any way of determining whether an output is a hallucination or not. In cybersecurity accuracy is important, and wrong answers can have impactful consequences for businesses and their environments.

One of the problems is that the output can’t be better than the input, which means that high-quality data is necessary. But the reality is that ChatGPT etc are built on data from the entire internet, which includes biased and wrong information.

In the future, we’ll see a move towards agentic models in cybersecurity. The idea here is that you train smaller language models to solve specific tasks. For example, you have one model that can help you generate queries, one to dive into threat intelligence and so on, but they can’t answer questions outside their specific domains. That would increase trust and enable AI to solve deeper issues.

What ethical considerations do you believe will become more critical as IT continues to advance?

AI is a major ethical concern. LLMs are trained on data from the entire internet. Already now 57% of the content on the internet is generated by AI or translated using AI and that number is increasing all the time. What happens is that LLMs start training on data they generated themselves, which must have an impact on the output. Authentic content is becoming rarer, which means that there is a risk that the LLMs will collapse. It is kind of like a snake eating its own tail.

Another ethical concern regarding AI is the filters that are put on them. LLMs like ChatGPT and DeepSeek both have censor filters on them that prevent you from getting access to specific information. But if they end up being a main source of information it is problematic.

In what ways do you think IT will transform industries like healthcare, education or finance?

I’m from Denmark, which is one of the most digitalised countries in the world. What we’re seeing here is that digital transformation has made a lot of things easier. Organisations in industries like healthcare, education or finance can collaborate more easily and support the people who use their services better. It’s also changing the Danish economy with increased productivity and growth.

However, it has become clear that the monopolisation of big tech is problematic. For example, when Microsoft increases its prices, the result is that Municipalities, who rely heavily on Microsoft 365, will have to allocate a significant part of their budget to that, which results in deteriorated services for citizens or increased taxes.

Another pitfall to be mindful about is that digitalisation brings increased risk from threat actors. When critical national infrastructure is digital, cybercriminals and nation state actors can exploit that to destabilise society. We’ve already seen hospitals having to postpone procedures due to cyberattacks in the UK and attacks against power grid in Ukraine causing electricity outage to name a few examples.

Cybersecurity is important to keep in mind to make sure we can keep people safe, can complete financial transactions, and access educational material. Societal stability depends on our ability to secure our systems and detect attempts to breach them.  

What are the biggest challenges IT professionals will face in the next decade?

Data protection is the main challenge for IT professionals, as generative AI and cloud make it difficult to know with certainty where data flows to or how it’s used. We don’t know what happens to the data that we put into LLMs like ChatGPT or DeepSeek. We don’t know with certainty where cloud services store our data.

What we do know is that feeding sensitive information into generative AI is a risk. Even so, there are many examples of people sharing sensitive data like financial information, personal identifiable information (PII), proprietary information and confidential information. IT professionals need to find ways of preventing that from happening, so that information that can harm business, citizens or society doesn’t fall into the wrong hands.

We also know that data plays a significant role in the geopolitical game of chess. American big tech companies dominate the European market, but the alliance with the US is unstable with Donald Trump’s presidency. The Foreign Intelligence Surveillance Act (FISA), section 702, also known as the spy program, gives American intelligence agencies the power to collect, use and disseminate data stored by US organisations without a warrant. That means that many European organisations run the risk that the NSA, FBI or CIA can access critical data.

How will IT contribute to addressing global challenges like climate change or social inequality?

As society gets more digitalised, cybersecurity is a central component to keep it stable. Cybersecurity is increasingly becoming a question of national security, and as such it plays an important role in protecting democracies. In many ways, cybersecurity is preconditioning to the efforts that arise from the United Nation’s sustainable development goals number nine, which is about supporting a resilient infrastructure, and number 16, which is about supporting effective, accountable and transparent institutions and public access to information.

If power supplies fail due to a cyberattack, it can paralyse private organisations and NGOs, stop production lines and disrupt daily lives and humanitarian efforts. Without electricity, vital machines in the hospitals don’t work, and neither do traffic lights or refrigerators and freezers. Threat actors can also target water supplies, shutting down the supply completely, or changing the settings, so the water becomes harmful to health. Cyberattacks can also disrupt access to information or halt interaction between critical entities.

Cybersecurity needs to be prioritised, if we want it to have a positive impact on global challenges like societal inequality, because without it, the risks are just too high and any initiatives to address global challenges can be disrupted, manipulated or thwarted. Especially as society gets more digitalised.

Can you share a project or innovation you’re currently working on that you believe has the potential to influence the future of IT?

At Logpoint, I’m working with my team to find a way to help security analysts make better sense of the detections and alerts they get from cybersecurity tools like Security Information and Event Management (SIEM), Network Detection and Response (NDR), and Endpoint Detection and Response (EDR). The aim is to help critical national infrastructure providers and Managed Security Service Providers (MSSPs) get access to the technology they need to efficiently detect cyberattacks.

We use hypergraphs to connect the dots across tools and vendors automatically and correlate it with threat intelligence and security content to give the security analysts a manageable way to detect threats. It means that analysts won’t have to react on every alert, and that the number of false positives decreases dramatically. This will help security teams overcome the core problems that they have today.

I’m also working with agentic language models to simplify security operations further, by making it easier to understand how to go about detections in the best possible way, getting a better understanding of what detections mean and advice on what next steps should be used to handle them in the best possible way. The hypergraph in combination with agentic language models would be a game changer for organisations that struggle with sufficient resources to run a mature cybersecurity program, which is often the case for mid-market critical national infrastructure providers.

More interviews in the series

Avatar photo
Tim Danton

Tim has worked in IT publishing since the days when all PCs were beige, and is editor-in-chief of the UK's PC Pro magazine. He has been writing about hardware for TechFinitive since 2023.