Intelligent CISO Issue 81 | Page 42

expert

OPINION
The future of cybersecurity is projected to be an interplay between offensive and defensive AI . Our challenge is to stay ahead of adversaries who are increasingly leveraging AI to enhance their capabilities .
Compliance costs an added burden
This wave of external threats is coupled with the increasing regulatory requirements across the globe , adding increased complexity to security challenges . C-suite are struggling to keep up with the speed of change in requirements under directives such as GDPR , NIS2 , and DORA . In fact , NIS2 Directive mandates swift reporting of cybersecurity incidents including a 24-hour early warning alert for affected organisations . This is to be followed by a more detailed incident report to be submitted within 72 hours of becoming aware of the incident , including information about the nature , scope and potential impact of the breach .
Similarly , GDPR guidelines across the EU demand organisations to notify the supervisory authority within 72 hours of becoming aware of the breach in cases where personal data breach can likely result in a high risk to the rights and freedoms of individuals . This is why now is a crucial time to prioritise cyber resilience , especially when regulatory and recovery costs can often be so costly that a business has to shut down .
Counter AI attacks with AI defence
While AI has become one of the most powerful tools at an attacker ’ s disposal , it also remains a great asset for cybersecurity experts to leverage and stay one step ahead . While it empowers adversaries to launch more targeted , evasive , and high-impact attacks , it also offers unparalleled capabilities for threat detection , incident response and automation .
Organisations should look to incorporate AI as a first line of defence , as its threat detection and
analysis can help block the most sophisticated of cyberattacks . Proactively implementing lines of defence in case AI has detected a potential attack should be the first course of action , without the need for conducting manual triage to check if it ’ s a credible attack or a false positive .
Unit 42 at Palo Alto Networks recently found that the average days from compromise to exfiltration was 44 days in 2021 , 30 days in 2022 and just five days in 2023 . However , with the rise of AI in 2024 , this has now been slashed to a mere handful of hours . Such instances are extremely time sensitive and organisations cannot achieve real-time monitoring without leveraging AI .
Historically , cybersecurity defences relied heavily on manual oversight by cyber sleuths and security analysts . However , the sheer volume and complexity of modern data have rendered these traditional methods insufficient . With its ability to analyse diverse security data sources in real-time to identify emerging threats and anticipate potential attack vectors , AI has made predictive analytics an essential component of a cybersecurity strategy . This includes leveraging adversarial AI techniques to
42 WWW . INTELLIGENTCISO . COM