AI fuels cyberattacks as defenses evolve

| 5 min read

Artificial intelligence is accelerating the cyber arms race, enabling attackers to move faster while giving organizations new tools to defend themselves, industry sources say.

While AI offers companies more defensive options, criminals may be quicker to put the technology to work, increasing pressure on businesses to speed up their cyber responses, they said.

“This is not the first time an emerging frontier technology has transformed the offensive and defensive landscape,” said Rob Malone, New York-based U.S. head of cyber for Axa XL, a division of Axa SA.

Both sides have access to AI tools and organizations can use the technology to strengthen and speed up their defenses, said New York-based Danielle Roth, head of cyber claims, North America, for Axa XL.

“The one word that comes up to my mind is speed,” Mr. Malone said. There is evidence that bad actors are using AI and open-source models to accelerate each step of the breach process, while defenders are using AI to improve the effectiveness of more traditional controls, he said.

“We have to remember that the capability is not solely in the hands of threat actors,” said Maria Long, New York-based chief underwriting officer at cyber insurer Resilience.

AI technology is being used extensively by cybercriminals, said Mike Colford, Berkeley Heights, New Jersey-based senior vice president, cyber product leader at Westfield Specialty.

“AI also is greatly improving the defensive side as a way to help fight against these threat actors. We’ve seen tremendous improvements in vulnerability scanning,” for example, Mr. Colford said.

AI-powered tools have also enabled greater numbers of cybercriminals by automating attacks.

“That barrier to entry is continuing to fall,” said New York-based Ian Walsh, U.S. cyber product leader, QBE North America. “With AI, you can definitely see that attack surface begin to widen.”

Criminals can often be more nimble in their use of technology because they do not face the same constraints as organizations that abide by laws, regulations and corporate guidelines.

“Historically, we’ve seen that defense usually takes a little bit longer to adopt new ways of doing things, and I think that’s the situation we’re in right now.” said Tiago Henriques, Lagos, Portugal-based chief underwriting officer for cyber insurer Coalition.

Companies should consider investing in AI patching technologies, in which AI agents perform the jobs humans used to do, such as deploying patches and fixing software vulnerabilities, because humans can’t keep up at scale, Mr. Henriques said.

“Those tools are enabling organizations to do what’s called responding in at-machine speed,” said Marcello Antonucci, New York-based claims team leader, cyber and tech risks, for Beazley.

Many of these tools are within the financial and operational reach of smaller and mid-sized enterprises, said Craig Linton, New York-based head of U.S. underwriting management for Beazley.

Smaller organizations should be able to achieve nearly the same level of protection as large organizations using managed detection and response systems, Mr. Linton said.

“Organizations on the defense need to adapt more quickly than they ever have,” said John Farley, New York-based managing director of Arthur J. Gallagher & Co.’s cyber practice, adding they should make full use of AI-based defense tools.

AI has made the field of cybercrime and cybersecurity more sophisticated, said John Butler, Franklin, Tennessee-based cyber product development leader at E-Risk, a subsidiary of Nationwide.

“The organizations that pair AI-enabled security with strong governance will be best positioned to manage risk,” he said.

“A mature AI-driven defense can operate near real-time for vulnerability assessment and remediation, which in the long term puts them in a very positive position relative to the threat actors,” Mr. Colford said.

Security vendors and companies are considering AI and how they can make tools respond quicker or more intelligently to AI-enabled threats and attacks, said Kara Higginbotham, New York-based head of professional liability and cyber at Zurich North America.

“Organizations need to think about implementing controls and processes with an eye toward what AI-capable threats, AI-enabled threats or AI-capable threat actors are able to do,” she said.


Businesses renew focus on network segmentation, patch management

A prudent information technology network structure, including appropriate network segmentation, can help form the backbone of successful defenses against artificial intelligence-powered breaches, industry experts say.

Properly designing an information network with only necessary connections can help prevent a breach from spreading through an organization’s critical systems.

“We talk a lot about that segmentation and the architecture of the network in the underwriting process,” said Mike Colford, Berkeley Heights, New Jersey-based senior vice president, cyber product leader with Westfield Specialty.

Anything that is potentially vulnerable should not be connected to the main operational technology or network technology used for daily operations, Mr. Colford said.

Organizations should create a segmented structure to prevent lateral movement in the case of a breach.

Artificial intelligence has “really reminded us about the importance of the basics,” said New York-based Danielle Roth, head of cyber claims, North America for Axa XL, a division of Axa. “Patch management, endpoint detection, data classification, and network segmentation are going to be particularly important.”

These actions can help prevent a threat actor that has penetrated a system from accessing the entire system.

“It’s still the principle of least privileged access. You don’t want people having access to things that they don’t need access to, and you don’t want systems touching each other and being connected if they don’t need to,” Ms. Roth said.

Limiting connectivity of data can reduce the impact of a breach, said Marcello Antonucci, New York-based claims team leader, cyber and tech risks, for Beazley. He added that the insurer has been emphasizing segmentation for years.

Internal segmentation is a great control but it’s also one of the hardest to implement, said Tiago Henriques, Lagos, Portugal-based chief underwriting officer for cyber insurer Coalition. “It’s not something that’s easy to implement from an IT perspective.”

Source: Matthew Lerner · www.businessinsurance.com