The Double-Edged Sword Of AI In Cyber Security

The Double-Edged Sword Of AI In Cyber Security

AI is quickly becoming a huge part of our lives, both inside and outside of Cyber Security, and I'm here to tell you that it's not always for the better. While vendors will sell you on their new AI driven Cyber Solutions, not all of AI's products are as glamorous. Sure, you can use AI tools to find vulnerabilities, troubleshoot issues, and detect emerging threats, but it can just as effectively be used to exploit those vulnerabilities by bad actors. Not only that, but as software developers use AI to write code, and as AI tools become more and more integrated into the software we use every day, you'll find that we introduce many risks that didn't exist previously. Let's summarize a few of the pros and cons of AI with a Cyber Security focus.

The Good

Let's go over the pros first. Naturally we can automate tasks with AI, such as automated threat detection, or trend analysis. We can use it for reading event logs, integrating AI tools within our SIEM solutions. We can do predictive analytics, or automate incident response. Truly the possibilities are endless. I personally use it to streamline a lot of my documentation and policy documents as well, saving me a ton of time. AI is an effective tool in the hands of a Cyber Security Professional.

In practice, I see it often used for problem solving and troubleshooting in the IT workspace. It's amazingly effective for the sysadmin, enabling them to do much more much quickly, although some restraint should be used ensuring they're following the correct change management procedures. It's also effective at scraping policy documents, enabling you to query your entire document library for relevant information, or update your documents when required. After using it in this regard, it's become an essential tool in my personal toolkit.

The Bad

However, AI isn't without significant drawbacks and risk. You can't just blindly trust it when using it. AI tools can hallucinate, make mistakes, and given enough privileges, can wreak havoc on your production environment if you leave it unchecked. While it's an amazing tool, it still has to be used with caution. This is all before even considering how a malicious actor could use these tools for nefarious purposes.

Cyber Security professionals need to understand the significant threat AI poses in the hands of bad actors. While Cyber Security pros have access to powerful tools, these tools are just as effective for our adversaries. AI can power sophisticated phishing and social engineering based attacks. The emergence of AI deepfakes is another enabler for Social Engineering. Voice and video are getting easier every day to replicate with AI.

AI can automate vulnerability discovery, sure- but critically, also for the adversary. They can build tools (with the help of AI) to exploit vulnerabilities found with AI tools. AI accelerates the black-hats as much as the white-hats defending our networks.

The threat AI assisted malicious actors pose is significant. Malware built with AI assistance will reach new levels of sophistication that Cyber Security Professionals will have to quickly adapt to combat. AI is on both sides of the conflict, and it's shaping Cyber Security in big ways going into the future. It's going to be up to us to ensure that stakeholders understand these risks, or we leave ourselves vulnerable for what's coming.

Know Thy Enemy

With all that said, what do we do now? I personally recommend you familiarize yourself with these new and emerging AI technologies. It's important that we understand what the attackers are working with. I use many AI tools, from ChatGPT, Claude, Grok, Gemini, etc. I also play with locally run LLMs, where I can experiment with open-source open-weight models. I've started some software development where I write code with AI assistance. I also have integrated AI into several of my daily workflows, using it to accelerate my normal operations. It's a tool I wouldn't want to live without. While you may be hesitant to heavily adopt AI tools, I recommend you at least understand it, so that you know what you're up against.

Conclusion

To wrap it up, AI is a double-edged sword. It's a powerful tool- one that I don't want to live without, but it's also one of the biggest threats to my networks. Every open vulnerability becomes even more of a ticking time-bomb, and we need to be vigilant. AI in Cyber Security can be overshadowed by the capabilities that AI provides to bad actors. It's up to us to understand the threats and to be prepared to react to them.