news.mlab.sh
Back to the feed
threat-intel

AI is set to help cyber attackers much more than defenders, says UK official

High
Summary

A UK cybersecurity official warns that AI is significantly accelerating the pace of cyberattacks, giving attackers a major advantage over defenders. The imbalance stems from the ability for attackers to clearly measure success – an exploit works, malware ‘calls home’ – while defensive AI actions often lack a definitive ‘success state,’ making them riskier to automate. While the NCSC is developing AI-powered defenses, experts caution that fully autonomous defensive AI is not yet ready for deployment and organizations should continue traditional security practices in the interim.

A senior official at Britain’s National Cyber Security Centre (NCSC) has warned that artificial intelligence is rapidly shifting the balance of power in cybersecurity, with attackers leveraging AI far more effectively than defenders. The warning comes amid growing concerns about the transformative impact of AI on both offensive and defensive cyber operations.

Dave Chismon, the NCSC’s chief technology officer for architecture, argues that the core difference lies in the ability to measure success. Attackers can clearly determine if an exploit works – for example, if malware ‘calls home’ – providing a definitive signal of success that automated systems can readily interpret. Conversely, defensive AI actions often lack a clear ‘success state,’ meaning a patch might inadvertently disrupt a business function, or a firewall rule could break a critical service. Because of the potential for significant disruption, a human must carefully weigh each defensive action, a process that’s difficult to replicate with automated systems.

The Five Eyes intelligence alliance, including GCHQ, has also raised similar concerns, with the Chinese Communist Party’s top intelligence official expressing similar views. While software makers have issued patches at a record rate since the initial Five Eyes warning, a comparable surge in cyberattacks has not yet been observed.

The NCSC is currently developing a cyber defense capability called Cyber Shield, which intends to deploy agentic AI systems to discover and fix cybersecurity weaknesses across government networks and critical national infrastructure. However, Chismon emphasizes that building truly autonomous defensive AI is a complex challenge and will require significant time, effort, and research.

He recommends that organizations begin with low-risk uses of AI, such as having AI summarize threat intelligence for human analysts. The NCSC provides a framework to assess the risk of automation by considering factors like reach, impact, criticality, predictability, and reversibility. Despite these efforts, Chismon cautions that organizations “cannot risk just waiting for agentic defense to roll in and protect them” and should continue to improve their security using traditional methods.

Read the full article at The Record