Artificial intelligence is intensifying the cat-and-mouse game in cybersecurity, enabling cybercriminals to enhance their attack strategies while simultaneously offering organizations improved defense mechanisms, according to industry experts.
On the one hand, AI equips companies with advanced tools for rapid and effective defense. On the other, the same technologies empower attackers to expedite processes, putting considerable pressure on organizations to sharpen their cybersecurity responses. “Speed is the defining factor,” notes Rob Malone, U.S. head of cyber at Axa XL. His perspective reflects a growing consensus that the adversarial advantages afforded by AI are significant.
Both defensive and offensive capabilities have evolved thanks to AI technology. Danielle Roth, head of cyber claims for Axa XL, asserts that organizations now have access to sophisticated AI-driven resources, enhancing traditional security methods. “The capacity for defense is not solely in the hands of the attackers,” Maria Long, chief underwriting officer at cyber insurer Resilience, emphasizes, highlighting the dual-edged impact of AI in this arena.
However, the adaptability of cybercriminals often outpaces that of organizations. Mike Colford, senior vice president and cyber product leader at Westfield Specialty, points out that while AI bolsters defenses significantly—such as through improved vulnerability scanning—it also allows criminals to automate attacks. This lowers the barrier for entry into cybercrime, with Ian Walsh from QBE North America noting an observable expansion of the attack surface.
Unlike companies that must navigate regulatory frameworks and operational limitations, cybercriminals are free to adopt new technologies quickly. This disparity raises essential questions about how companies can keep pace. Tiago Henriques of Coalition highlights a historical trend: defensive strategies tend to take longer to implement than offensive ones.
To address this imbalance, experts suggest companies consider investing in AI patching technologies. These systems can automate routine tasks such as deploying patches and addressing vulnerabilities—areas where human effort fails to keep up at scale. “Organizations must respond at machine speed,” says Marcello Antonucci of Beazley, focusing on the critical need for rapid adaptation in the face of emerging threats.
Interestingly, many of these AI-driven tools are financially accessible to smaller and mid-sized enterprises, allowing them to achieve comparable protective capabilities to larger organizations through managed detection and response systems. Craig Linton, head of U.S. underwriting management for Beazley, confirms that smaller firms can now compete in terms of cybersecurity readiness.
As the playing field becomes more sophisticated due to AI, John Farley from Arthur J. Gallagher & Co. underscores the need for organizations to leverage AI-enabled defense mechanisms fully. Strengthening governance alongside AI solutions will yield the best outcomes, experts argue.
AI’s integration into cybersecurity shapes a new era of risk management. “A mature AI-driven defense system can perform near real-time assessments for vulnerabilities,” Colford states, indicating that organizations employing these tools may find themselves in a more favorable position compared to threat actors.
Security vendors and businesses are now contemplating how to enhance responses to AI-enabled threats. Kara Higginbotham from Zurich North America highlights the importance of implementing proactive controls tailored to the capabilities of AI-driven threats. “Organizations need to rethink their strategies with a focus on AI-enhanced capabilities,” she advises.
Importance of Network Segmentation and Patch Management
An effective IT network structure is vital in defending against AI-driven breaches. Industry experts assert that meticulous network segmentation is foundational for successful defenses against these new threats.
Creating a network design that limits unnecessary connections can effectively contain a breach, preventing it from compromising critical systems. Mike Colford emphasizes that such segmentation is a recurring topic during the underwriting process for cyber insurance. Vulnerable components should be isolated from core operational technologies to minimize risks.
Danielle Roth reiterates the relevance of basic cybersecurity measures in the current climate. She points to patch management, endpoint detection, data classification, and network segmentation as especially crucial in defending against sophisticated AI-based attacks.
The principle of least privilege is a key tenet in this approach. “You want to restrict access to only what’s necessary, minimizing potential pathways for attackers,” Roth explains. This strategy aims to limit the damage from a successful breach, allowing organizations to control threats effectively.
However, implementing internal segmentation can be challenging, as highlighted by Tiago Henriques. Even though it serves as a powerful control method, the complexities involved in execution can hamper efforts. “This isn’t easy from an IT perspective,” he concedes.
Ultimately, the pursuit of a fortified defense that incorporates AI while adhering to fundamental cybersecurity principles will define the strategies of organizations facing the persisting pressures from evolving cyber threats.