Security decision-makers at organizations are more concerned about AI than about ransomware. These same people have enormous confidence in their own security teams to handle everything properly, yet at the same time, there is little trust in AI when it comes to using it autonomously for defensive purposes. This is despite the huge number of incidents they report. What is happening here?
The above conclusions come from the AI & Cybersecurity Trends Report released today by Arctic Wolf. This is the fifth time the company has published this report, which is based on research conducted by a research firm. According to Christopher Fielder, Field CTO at Arctic Wolf, this is a unique report for the company. While many other studies and reports from Arctic Wolf are based on what the company observes in its own SOC, the findings in this report are based on responses from 1,350 security and IT decision-makers. Fielder identifies CISOs, VPs of Security, and SOC Managers as the respondents.
Many incidents, but also a lot of confidence
In and of itself, it’s very interesting to see market input compiled in this way. However, studies like this also yield findings and figures that sometimes contradict each other, because people participating in the survey don’t necessarily always provide answers that are entirely accurate.
The best example of this is that 63 percent of respondents reported experiencing a significant incident in the past year. Here, “significant” means that the organizations actually noticed it in some way. However, 96 percent of those same respondents also casually state that they are confident their teams can handle current threats.
More realism is needed
When we presented this to Fielder, he said he burst out laughing when he saw that 96 percent figure. After all, that can’t be true if you’re experiencing incidents so frequently. Still, he believes this percentage is reasonably explainable because “CISOs have to project confidence,” he says. “A large part of that 96 percent is hope, hype, and bravado,” he continues. “It may be that they’re genuinely convinced their teams can stop one aspect of an incident, but not the entire breach.”
A bit more realism among CISOs and other security decision-makers would certainly be welcome, even though we also understand that factors such as the way questions are phrased in a survey and its somewhat formal nature can strongly influence these kinds of responses. It’s quite possible that the respondents themselves know how things really stand.
Fielder is therefore not overly concerned about the discrepancy between incidents and trust. In his view, that distinction goes to the 7 percent who indicated they didn’t know whether any incidents had occurred in the past year. “You can add them to the 63 percent,” he says.
Trust in AI, up to a point
As mentioned earlier, AI is a top priority for organizations. This applies to the number of LLMs employees are allowed to use, but certainly also to purchasing decisions in the field of cybersecurity. Virtually every organization included in this study has invested in security tools that use AI, or is currently evaluating them.
Of course, these AI investments in cybersecurity aren’t made on a whim. Many of the respondents are convinced that AI outperforms humans in certain areas. More than 80 percent of respondents believe that AI makes their organization more secure, can correlate and analyze data, and can provide a consolidated overview of key components.
There is, therefore, a great deal of confidence in what AI can contribute to security teams. However, that confidence evaporates completely when questions arise about making AI central to SecOps. That is, allowing AI to act autonomously in certain areas. Only a meager 14 percent remain in favor. Even something relatively straightforward, such as autonomously blocking malicious IP addresses or domains in the firewall, can count on support from only a small majority.
In itself, this mistrust is not surprising. After all, AI does make quite a few mistakes, especially when it is not optimally configured and when it operates on a much larger scale than humans can. In addition, there are concerns regarding data privacy, manipulation, a lack of transparency, and the absence of human intuition.
AI must move from hype to tool
Part of the explanation for the slow adoption of the AI SOC, where AI is actually in charge, has to do with how AI is still perceived. Fielder returns to this point regularly during our conversation. According to him, AI is still very much caught up in the hype cycle. “Many people and vendors want to hype it up and claim it’s a panacea, but it’s a tool,” he says. “It’s about who uses it and how they use it, and organizations need to have a legitimate business case before they start using AI,” he notes.
To move AI out of the hype cycle, vendors themselves will therefore have to take responsibility. However, that does not relieve companies of their responsibility to view AI differently as well. According to Fielder, this starts with defining what your organization considers acceptable when it comes to AI. He calls this an AI acceptable use policy. It outlines how organizations can and may use AI, with which models and which processes. “You lay everything out in a legal document,” he summarizes.
More education is needed
The second thing organizations need to do, according to Fielder, is to actually train employees in the use of AI. “I’m not talking about the kind of security awareness training that used to be done in the past, but about real education on AI, in sessions that everyone must attend,” he explains, making this a bit more concrete.
Specifically for cybersecurity, education means teaching people what AI is good at and what it isn’t good at. “People have been sold a product that isn’t perfected. In cybersecurity, best guesses aren’t acceptable,” Fielder points out. Once security professionals start to recognize these kinds of issues, hopefully they will see the light. He’s already seen in practice that AI can lead to a significant reduction in false positives, one of the things that takes up a lot of security teams’ time. That’s something the teams can definitely build on.
Finding a balance between AI and trust
Looking at the theme of the report Arctic Wolf is releasing today, AI & Cybersecurity Trends, the results primarily indicate that there is still a great deal of uncertainty surrounding AI. This is challenging for security decision-makers, but they must remain realistic about what they can do themselves and what is better left to AI to handle autonomously. This balance will likely vary slightly for each organization. That’s why it’s so important to establish very clear internal guidelines about what is and isn’t possible or permissible.
Furthermore, in our view, there really needs to be a bit more realism. If properly implemented, AI can contribute significantly to cybersecurity. In addition, there must inevitably be more autonomy for AI in cybersecurity. Perhaps not right away, since we’re still in the hype phase. However, we must work toward that goal, because attacks are becoming faster and more complex. It will be a matter of finding the right balance between humans and AI, and between AI and trust.
We’ll conclude with one final statement from Fielder regarding the prevailing sentiment of doom and gloom when it comes to AI and cybersecurity: “AI is a tool that can be used both offensively and defensively. Both sides more or less negate each other. Do what you can and provide your people with the necessary training.”
Read also: Arctic Wolf introduces Decipio for rapid detection of credential theft