Old School Is Your Best Defense Against Hacking; and It’s Surprising
"*" indicates required fields
Security teams are on high alert following reports that AI agents have hacked into business systems without clear human instructions. As AI models become more powerful (and difficult to regulate), companies are growing more worried about how to guard against attackers employing the same technology.
Cybercriminals are also utilizing AI to operate faster and more effectively, just as legitimate enterprises are. But every AI tool a corporation puts in might also offer new security dangers.
That leaves organizations balancing the pressure to use AI with the dangers of moving too fast. “They think everyone’s going to pass them by,” says Leslie Nielsen, executive vice president and chief information security officer at Mimecast. “But then the other side is if you adopt too fast, it’s adopt and die, right?”
AI-driven threats are increasing. So are AI defenses. But experts believe many of the strongest defenses are well-known, basic security procedures.
The strategies for AI-assisted attacks tend to be the same as traditional attacks, says Nielsen – they just tend to be faster and more effective. This makes fundamental security precautions all the more crucial.
Make sure that access to sensitive information is limited, security fixes are applied in a timely manner, and backups of essential data exist and can be restored. Strong passwords, multifactor authentication and good phishing protection are still vital.
AI solutions can also help security teams respond faster, Nielsen argues, especially at small and midsize organizations where security resources may be constrained.
Advanced models can combine small vulnerabilities in innovative ways to break into systems, making the threat harder to foresee, says Simon Jelley, vise president of product management at Dell Technologies. But the fundamental risks are not new, he says, AI is only amplifying them.
The artificial intelligence systems a firm uses can constitute insider threats itself. An agent may not be malicious, but it may pursue its designated goal with ruthless determination, even when that means obtaining credentials or data it has no business touching.
“AI is the eager intern that’s going to do what you tell it to do,” Nielsen says. “But it’s going to keep working 24-seven to get it done and it’s going to do everything it needs to do.”
Companies should establish well-defined boundaries on what AI agents may perform and what information they can access. And they need to watch how those systems act. Sometimes organizations grant agents wide permissions “in the name of productivity,” warns Ed Jennings, president and CEO of Darktrace.
“Those agents have unfettered access,” Jennings adds. “You have to learn to watch what they are doing.”
Written rules are important too. Companies need to create acceptable-use policies for AI, like they do for other workplace technology. Unapproved personal use can generate security risks and costs, especially if employees are using substantial quantities of paid AI usage.
Perimeter protections can help keep attackers out, but businesses also need to be able to detect and contain threats that sneak in. Given the scope and sophistication of assaults, experts say organizations should plan for a breach rather than assume it will never happen.
“Darktrace has always been about anomaly detection in systems,” Jennings explains. The similar technique can be used to spot questionable activities by AI agents. These tools may be operating on email, networks and other systems so monitoring just one layer may not be sufficient.
Companies should also determine the most vital activities and data, and how to recover them after an incident. They don’t need to strive to safeguard everything equally, they need resilient infrastructure and a pragmatic recovery strategy.
“But the question is whether the organization has a mitigation plan and the resilience to recover if an attack is successful,” says Jelley.
Contact us today for better cybersecurity protections for your organization: percentotech.com/contact-us