Shopping

'C-suite executives need to upskill themselves to really understand the threats': AI is becoming a tool for attackers and defenders, but true resilience requires a constantly changing strategy, says former GCHQ intelligence expert

'C-suite executives need to upskill themselves to really understand the threats': AI is becoming a tool for attackers and defenders, but true resilience requires a constantly changing strategy, says former GCHQ intelligence expert
Image: techradar.com

Artificial intelligence is fast becoming a game-changer for cybersecurity, with new frontier models such as Claude Mythos and OpenAI's GPT-5.5 demonstrating their capabilities in hunting software vulnerabilities and evaluating how they can be chained to harm an organization.

But these models have proven to be a double-edged sword, with both companies disclosing incidents where their models have escaped sandbox testing and compromised other organizations.

Couple this with how threat actors are turning to AI to increase their own skill in breaching organizations at an industrial scale, and you are presented with a bleak picture for the future of cybersecurity. But the best resilience is to adapt, and make sure those at the top can make the right decisions at the right time.

AI as a tool for defense and resilience

The latest challenge threat actors are presenting for businesses is their ability to match the skill of state-sponsored groups. The tactics, techniques, and procedures (TTPs) of these groups are being bolstered by the adoption of AI tools. Jailbreaking allows groups to use legitimate AI models to perform reconnaissance and research at scale, as well as the ability to modify and improve existing malware and attack vectors.

A recent IBM report found that since 2025 there has been a 44% increase in cyber-attacks exploiting public-facing applications, a 40% increase in vulnerability exploitation, and a 50% growth in the number of active ransomware operators. Much of this is the result of attackers adopting AI tools into their workflows.

Professor Julian Richards is a leading expert in intelligence and security who held senior roles in intelligence analysis, training program design, and strategic liaison at the UK's Government Communications Headquarters (GCHQ).

I spoke with Professor Richards on the effects AI is having on the threat landscape, how defense strategies can adapt, and where training can be best applied to keep businesses one step ahead.

  • What does cyber resilience really mean in a world where AI is being leveraged by threat actors to compromise businesses at a level that matches the craft of state-sponsored groups?

It is indeed the case that highly advanced techniques, the likes of which were previously the preserve of advanced states, are now readily available to a range of threat actors. This is partly because of thefts of highly advanced exploits such as ETERNALBLUE and their resale on the dark web.

Cyber resilience is about a range of approaches, however, which go beyond the technical into human layer factors. Keeping the response dynamic, diversified and creative will offer opportunities for resilience.

  • Has the age of saving and storing vulnerabilities for later use passed, and how are defense strategies changing in regard to the rapid exploitation of vulnerabilities?

Almost certainly not, and experience from potentially parallel worlds such as that of cryptography tell us that exploits can remain productive for multiple years after their exposure.

Many threat actors are investing heavily in HNDL (harvest now, decrypt later); and a widened notion of "harvest now, exploit later" is also on the menu. Again, a reverse view offers opportunities for defenders.

AI can be used, for example, to more comprehensively and dynamically map and analyse attacks, even where they are mutating and evolving rapidly. This allows for more immediate and dynamic response.

  • How are active defense strategies shaping the protection of businesses and their infrastructure, and what challenges are businesses experiencing with implementing these strategies on aging and legacy infrastructure?

As above, dynamic and active defense strategies are sensible and increasingly necessary. As with all areas of cybersecurity however, there are good and bad products on the market, and good and bad investment decisions being made.

One of the most important considerations for all businesses is making sure the defense strategy is appropriately tailored in scale and shape to the business itself; and making sure we deal with honest and adept brokers.

  • AI is rapidly reducing the timescale between vulnerability discovery and exploitation for both businesses and intelligence agencies. Where do legislated threat disclosure windows play into these shrinking timeframes, and how do you perceive they will evolve?

One of the problems with compliance legislation (or indeed any legislation) is that it moves and updates much more slowly than technology. This will increasingly mean that the challenge described becomes a real problem.

In intelligence, selective disclosure has always been an understood protocol under the rubric of protecting national security, but this may not wash for commercial organisations. Two things will need to happen.

First, compliance legislation in such areas as threat disclosure will have to be written in a way that businesses are protected in fast-moving situations, allowing, perhaps, for post facto disclosure in many cases. Creative regulation and legislation is possible to allow for this.

Second, court cases may have to be brought to challenge overly stringent threat disclosure penalties, and subsequent case precedents will hopefully balance and protect organisations in this fast-moving situation. All of this will require the leveraging of advanced cyber expertise in the areas of law and legislation.

  • What are the major blind spots business leaders have when it comes to the latest threats, and what is the role of AI in addressing these problems?

Probably two things, both of which have applied for a long time and are proving remarkably intractable! The first is complacency: "sure this happened to them, but it won't happen to us". Well it probably will.

The second is not understanding the importance of the human factor risk, which continues to be the biggest threat factor. Training, awareness, exercising for crises and internal compliance protocols might be irksome, but they remain crucially important for all businesses.

  • What steps can business leaders take to ensure their AI tools are providing accurate intelligence and data while reducing false positives and hallucinations?

Work with reputable cyber threat intelligence suppliers and analysts. Develop expertise such that triangulation (checking across multiple sources and feeds rather than just accepting one source of information) is understood and readily implemented.

Expect the unexpected - in short, all the things that intelligence organisations have had to do since the dawn of time. For larger organisations, this is will mean a continual upskilling of key staff to be at the top of the game of understanding the dynamic threat picture.

  • Where can C-suite executives seek support in making key decisions on incident response when defending against threat actors increasingly leveraging AI?

C-suite executives need to upskill themselves to really understand the threats and their dynamism in such a way that they can support everyone in the organisation battling with these issues.

It is still the case that many at the top have either a sketchy understanding of the risk, or see it as something that others in the organisation will sort out. This is increasingly untenable today.

Ultimately, those at the top will have to take the hit when it all goers horribly wrong! What this means is that training, workshopping and exercising through crisis scenarios is as important for the C-suite executives as it is for any other members of the organisation.

This is a preview from the original publisher. Continue reading at the source:

Read Full Article on techradar.com →

More News