spot_img

Date:

Share:

When cyber attackers are using AI, your defence needs to do the same

Cyber threats have become increasingly sophisticated thanks to the use of Artificial Intelligence (AI), and attacks can now be executed rapidly and scaled beyond anything a human is capable of. Add in Machine Learning (ML), and attacks can now adapt and evolve in real time, becoming more sophisticated and stealthier than ever. Traditional security measures are simply no longer effective; we need to counter the offensive AI with the use of defensive AI. More than that, however, we need to understand that humans remain the weakest link in any security chain, and awareness of threats and security measures is a critical component in any robust and resilient cyber defence strategy.

The human element

When it comes to social engineering, AI has changed the game for bad actors.

Attackers leverage AI and ML tools to analyse social media profiles, online activity, and other publicly available information to create increasingly tailored and convincing phishing messages. This vastly increases the likelihood of success.

While AI can be used in several ways to counter this, from fully automated firewalls and policy management to segmentation, firmware updates, and more, this is not a foolproof solution. Humans are still essential links in the security chain.

Education and awareness are critical. We need to be mindful of how we share personal information and what information we place online in the public domain to safeguard our own privacy. Regular training and awareness can help educate people on cyberattack techniques and best practices for adopting a security-driven culture.

In addition, the human element remains essential in verifying what AI tools are doing; while AI can speed processes and automate manual tasks, people provide the contextual understanding of nuance that AI struggles with.

People are also critical in ensuring that ethical considerations are taken into account when building AI models and when using and processing data. To counter today’s threats, it has become vital to create ‘human in the loop’

defence models, where AI works in tandem with human analysts to respond to threats.

Collaboration is critical

Managed Security Service Providers (MSSPs) can be an invaluable asset for businesses in providing guidance on best practices and industry standards related to AI. This can help organisations understand the ethical implications of AI and security and develop appropriate strategies to address ethical risk. This includes assessing fairness and transparency in the design of both algorithms and processes. MSSPs can also assist with providing education and training, documenting and communicating processes, and implementing and managing solutions. This includes how algorithms are selected, trained, and deployed, as well as how data is collected, processed, and used for analysis.

Working with MSSPs in collaboration with regulatory bodies can help organisations align security objectives, ensure compliance, and assist in implementing ethical practices effectively. Working together is the key to successfully implementing AI, especially when it comes to AI as part of a cyber defence strategy. It is essential to build trust between humans and AI, invest in robust defence systems, and monitor for emerging threats, and this requires human oversight as the ultimate decision-maker. Organisations, MSSPs, and regulatory bodies, by working together, can create collaborative ecosystems that foster the development of solutions built on trust that can enhance security posture and mitigate cyber risk effectively.

spot_img
spot_img

━ More like this

Kaspersky discovers a new version of MacSync malware stealing credentials and crypto from macOS users

Kaspersky researchers have discovered a sophisticated, updated version of the macOS infostealer known as MacSync. First emerging in 2024–2025 as a variant of the...

Cloud security in the age of complexity: why the risk hasn’t disappeared

For years, cloud adoption was seen as a destination. Organisations moved workloads, updated applications, and welcomed the flexibility and scalability promised by cloud environments....

Antivirus alone won’t save you: why endpoint protection is only as strong as what happens after you buy it

Angela Pringle, Cyber Security Lead at CyberLogic, argues that the real gap in endpoint security isn't the software on the laptop, it's configuration, monitoring...

More than code: protecting Intellectual property in Mobile Application Development

In today's digital economy, mobile applications have become essential tools for businesses to deliver services, drive innovation and engage with customers. Whether developed for...

Family IT support becomes essential for older generations in South Africa, Kaspersky survey highlights

Kaspersky’s recent survey undertaken in the Middle East, Turkiye and Africa (META) region reveals that younger family members and friends are playing a critical role...
spot_img
spot_img