This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
Within cyber security, AIโs dual role as a powerful defensive tool and a potentially devastating vulnerability requires security leaders to take a nuanced approach. As bad actors increasingly use AI in cyber attacks and create new unknowns in cyber security, itโs time to meet this threat head-on โ with the very same technology.
AI for Security
AI has cemented itself within cyber security with threat actors quick to adopt it. So much so that institutions like the UKโs NCSC have shared explicit warnings of the danger it poses. But with 50% of enterprises already using AI/ML in their cyber security, the industry is starting to catch up.
Thereโs still a way to go to make AI-enhanced defences the standard. AI supercharges the amount of real-time data processing, spotting patterns and anomalies that a human might miss or require intensive training to see. Itโs also faster at detecting both known and unknown threats and can even automate response actions. This makes the step from detection to mitigation instantaneous, which will only become more crucial as the volume and sophistication of attacks continue to increase.
Traditional methods of traffic analysis remain in place, but organisations are adapting. Using AI, systems can scan through not only network and system data but also data from third-party sources like social media that could indicate planned attacks. This way, known threats like common attack types can be monitored while unknown threats such as zero-day vulnerabilities or ransomware can be identified by anomalous behavioural patterns across data sets.
Automated defences also free up teams, by taking the more easily automated tasks off their plates, leaving more time to coordinate strategy and become even more effective with these tools at their disposal.
Securing AI
However, AI canโt just be lifted and shifted into existing systems. It needs to be carefully thought through, starting with the existing cyber defences. They must be up to scratch to ensure AI is a resource, not a vulnerability. Before any work is done, organisations need to carry out thorough risk assessments to identify where AI could aid their defences. The vulnerabilities that it brings when being used in day-to-day operations, whether in generative AI (genAI) models or automation, are also a key consideration. Itโs essential to ensure its integrity and security, down to the data itโs trained on to maintain effectiveness and prevent manipulation.
In the case of genAI, organisations also need to consider the threat posed by prompt injection attacks that specifically target Large Language models (LLMs). Attackers can disguise malicious inputs as legitimate prompts to manipulate models. At the very least, this will result in misinformation. At worst, organisations could face sensitive data leaks that could lead to serious reputational and financial damage.
As a baseline, organisations implementing AI need to carry out regular application security hygiene and code maintenance. Developers should bake security into the code as itโs written to avoid bad actors manipulating it. If organisations can control the code, they can control what comes out of it.
As cyber threats grow more sophisticated, organizations need more than just software-based security. Dell Trusted Workspace delivers comprehensive endpoint protection, integrating hardware, firmware, and software defenses to safeguard devices from modern attacks.
Download this whitepaper to learn more about Dell Technologies solutions powered by Intel vProยฎย platform, Built for Business.
Best practices and actionable insights
While thereโs much to cover in using AI for security and in securing AI, there are a few steps all organisations integrating AI need to consider. Before they move to integrate AI, they need to thoroughly review existing security frameworks. Instead of shoehorning AI into every process, organisations should only be using it to augment existing methods โ rather than replacing them. The use of AI should also be benchmarked against the rest of the existing security model to evaluate its performance benefit.
In instances where models are operating using sensitive data, organisations should take every possible precaution including data encryption, enforcing strict access controls, and carrying out regular security audits. As for the nature of the data itself, a set of guidelines should be developed, including specifications for its source and quality.
But once organisations successfully implement AI, they face a new challenge. The nature of AI means that it is evolving constantly, and considerably faster than other technologies. By the time itโs integrated, thereโs a fair chance it would have become outdated โ so how can it be kept current and secure?
To implement and use AI securely, organisations must be prepared to invest budget and time to keep pace with the evolving technology. With cyber threats adapting and new attack patterns emerging daily, AI must evolve and deal with them effectively. Itโs a similar story with genAI. It requires new data sets regularly to stay updated, but such data needs to be high-quality and diverse. To get a useful output, you need to provide a useful input and accuracy is key with cyber defences.
Whatโs ahead for AI in cyber security
As AI continues to evolve, so too will its role in cyber security. Organisations must keep themselves up to speed with the latest developments and be nimble in adapting their strategies accordingly. By leveraging AIโs strengths while addressing its potential vulnerabilities, enterprises can successfully navigate the complexities of an AI-driven security landscape. And, most importantly, stay one step ahead of ever-evolving cyber threats.
You might also be interested