AI for security and securing AI: the two sides of AI


This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.


Within cyber security, AIโ€™s dual role as a powerful defensive tool and a potentially devastating vulnerability requires security leaders to take a nuanced approach. As bad actors increasingly use AI in cyber attacks and create new unknowns in cyber security, itโ€™s time to meet this threat head-on โ€“ with the very same technology. 

AI for Security 

AI has cemented itself within cyber security with threat actors quick to adopt it. So much so that institutions like the UKโ€™s NCSC have shared explicit warnings of the danger it poses. But with 50% of enterprises already using AI/ML in their cyber security, the industry is starting to catch up.

Thereโ€™s still a way to go to make AI-enhanced defences the standard. AI supercharges the amount of real-time data processing, spotting patterns and anomalies that a human might miss or require intensive training to see. Itโ€™s also faster at detecting both known and unknown threats and can even automate response actions. This makes the step from detection to mitigation instantaneous, which will only become more crucial as the volume and sophistication of attacks continue to increase. 

Traditional methods of traffic analysis remain in place, but organisations are adapting. Using AI, systems can scan through not only network and system data but also data from third-party sources like social media that could indicate planned attacks. This way, known threats like common attack types can be monitored while unknown threats such as zero-day vulnerabilities or ransomware can be identified by anomalous behavioural patterns across data sets.

Automated defences also free up teams, by taking the more easily automated tasks off their plates, leaving more time to coordinate strategy and become even more effective with these tools at their disposal. 

Securing AI 

However, AI canโ€™t just be lifted and shifted into existing systems. It needs to be carefully thought through, starting with the existing cyber defences. They must be up to scratch to ensure AI is a resource, not a vulnerability. Before any work is done, organisations need to carry out thorough risk assessments to identify where AI could aid their defences. The vulnerabilities that it brings when being used in day-to-day operations, whether in generative AI (genAI) models or automation, are also a key consideration. Itโ€™s essential to ensure its integrity and security, down to the data itโ€™s trained on to maintain effectiveness and prevent manipulation. 

In the case of genAI, organisations also need to consider the threat posed by prompt injection attacks that specifically target Large Language models (LLMs). Attackers can disguise malicious inputs as legitimate prompts to manipulate models. At the very least, this will result in misinformation. At worst, organisations could face sensitive data leaks that could lead to serious reputational and financial damage. 

As a baseline, organisations implementing AI need to carry out regular application security hygiene and code maintenance. Developers should bake security into the code as itโ€™s written to avoid bad actors manipulating it. If organisations can control the code, they can control what comes out of it. 

Download “Dell Trusted Workspace” Now

As cyber threats grow more sophisticated, organizations need more than just software-based security. Dell Trusted Workspace delivers comprehensive endpoint protection, integrating hardware, firmware, and software defenses to safeguard devices from modern attacks.

Download this whitepaper to learn more about Dell Technologies solutions powered by Intel vProยฎย platform, Built for Business.

Best practices and actionable insights

While thereโ€™s much to cover in using AI for security and in securing AI, there are a few steps all organisations integrating AI need to consider. Before they move to integrate AI, they need to thoroughly review existing security frameworks. Instead of shoehorning AI into every process, organisations should only be using it to augment existing methods โ€“ rather than replacing them. The use of AI should also be benchmarked against the rest of the existing security model to evaluate its performance benefit. 

In instances where models are operating using sensitive data, organisations should take every possible precaution including data encryption, enforcing strict access controls, and carrying out regular security audits. As for the nature of the data itself, a set of guidelines should be developed, including specifications for its source and quality.

But once organisations successfully implement AI, they face a new challenge. The nature of AI means that it is evolving constantly, and considerably faster than other technologies. By the time itโ€™s integrated, thereโ€™s a fair chance it would have become outdated โ€“ so how can it be kept current and secure?

To implement and use AI securely, organisations must be prepared to invest budget and time to keep pace with the evolving technology. With cyber threats adapting and new attack patterns emerging daily, AI must evolve and deal with them effectively. Itโ€™s a similar story with genAI. It requires new data sets regularly to stay updated, but such data needs to be high-quality and diverse. To get a useful output, you need to provide a useful input and accuracy is key with cyber defences. 

Whatโ€™s ahead for AI in cyber security

As AI continues to evolve, so too will its role in cyber security. Organisations must keep themselves up to speed with the latest developments and be nimble in adapting their strategies accordingly. By leveraging AIโ€™s strengths while addressing its potential vulnerabilities, enterprises can successfully navigate the complexities of an AI-driven security landscape. And, most importantly, stay one step ahead of ever-evolving cyber threats.

You might also be interested

Headshot_Rob_Robinson
Rob Robinson

With decades of experience holding leadership positions in sales, service management and consulting, Rob Robinson is a passionate security and network professional. He has contributed to TechFinitive under its Opinions section.