Trending Topics

How are CISOs and organisations navigating rising AI cyberattacks?
This article is part of our Opinions section.
Enterprise cyberattacks are nothing new, with their frequency and sophistication steadily increasing year after year. But a new threat of AI-enabled cyberattacks is emerging. These attacks weaponise the power of AI, making them more sophisticated, targeted and potentially more devastating.
But whilst many recognise the potential severity of this emerging threat, it remains to be seen how CISOs will develop specific strategies to defend against them.
Same old storyโฆ or is it?
It’s not news to anyone that cyberattacks are on the rise. Research from Check Point, a threat intelligence research group, found that organisations across the world experienced an average of 1,158 cyberattacks per week during 2023. While these numbers are immense, theyโre also not surprising given how rapidly the security threat surface has grown.
This expanded threat landscape has continued to pile on pressure over the past few years, with Check Point research also showing that one in every ten organisations worldwide were targeted by attempted ransomware attacks last year, with ransomware payments exceeding $1 billion – the highest number ever recorded.
As AI proliferates across organisations, it continues to be harnessed by bad actors. These institutionalised hacking groups can and are using AI to increase the scale, frequency and overall effectiveness of attacks. The development of AI recently prompted 62% of CISOs surveyed by ClubCISO – the largest member organisation for in-role chief security officers – to label the looming threat as critical or high.
Considering the above, youโd be forgiven for assuming that the industry is taking up arms, developing all sorts of strategies to target this specific threat. However, the same survey by ClubCISO also suggested that CISOs were taking a measured and considered approach to the evolving threat. AI is not yet altering priorities for a significant chunk of respondents (40%), and for more than three-quarters of respondents (77%), AI hasnโt triggered an increase or decrease in cybersecurity spending.ย
So, what are we doing?
Although cybersecurity budgets are not increasing, this doesnโt mean CISOs are not taking action against AI cyberattacks. A sizable chunk (40%) of respondents to the ClubCISO survey suggested that CISOs are training employees to recognise and defend against AI cyberattacks. Rather than hiring new employees with specialised skills, CISOs are focusing on upskilling their existing workforce, with only 6% of survey respondents opting to recruit employees with pre-existing expertise in this area.
To support these upskilling efforts, CISOs are also leveraging AI technology itself. In fact, a staggering 80% of ClubCISO respondents revealed that they are currently using AI technology in detection. Increasingly, CISOs are also starting to implement AI as part of response and prevention strategies.
But CISOs canโt focus all their attention on AI cyberattacks. Ransomware, third-party risk and software vulnerabilities continue to be front of mind for security practitioners as key risks, particularly as AI can accelerate and augment these threats. CISOs have been responding with multi-faceted business and technology-driven approaches to improve overall resilience, and it seems that the industry is quietly confident that maintaining a course on holistic resilience strategies is the best way forward for the time being.
What next?
The emergence of AI and the implications it has for cyber threats is clearly being balanced with a range of technology, skills, risk and macroeconomic factors to align with existing business goals. Whilst the investment context will be different for every organisation, driving a positive security culture across the entirety of an organisation continues to be one of the most important levers practitioners can pull to improve resilience.
Culture is key, and one that is best described as โcollaborativeโ should be the guiding light for CISOs. The National Cyber Security Centre recognises that a positive and shared security culture is essential as itโs the people that make an organisation secure, beyond technology and processes. With a collaborative security culture employees understand why security rules exist, meaning theyโre more likely to spot existing problems and suggest potential improvements. While itโs not a physical defence, the cultural approach can significantly enhance resilience and even reduce the stress burdens associated with roles in cyber security.
Although awareness and education are also key, CISOs are now moving towards designing โinfluenceโ programmes to elicit specific behavioural responses, which continues to be the best way to embed lasting change. For example, even just highlighting how practising good security hygiene is becoming increasingly important in other areas of life beyond just work to make these types of behaviours more valuable and rewarding.
CISOs canโt and arenโt ignoring the threat posed by AI cyberattacks, with many recognising the threat and opting for a measured approach that aligns with current cybersecurity priorities. The key focus for CISOs remains to be improving overall resilience by addressing persistent risks such as ransomware and software vulnerabilities, with the goal to also mitigate AI cyberattack risks as they stand today.
At the same time, CISOs are training staff to recognise and defend against AI threats, whilst starting to leverage AI in detection and planning to implement AI in response and prevention strategies. The key will be striking the right balance between addressing the AI threat and maintaining a comprehensive cybersecurity strategy aligned with business goals. This balance must be fostered by cultivating a collaborative, security-conscious and resilient culture throughout the organisation.
