How should companies use AI to protect against hacker attacks? [Photo: ChatGPT]

Fears are growing that AI is completely reshaping cybersecurity threats, but an analysis says it is closer to amplifying existing risks faster and more broadly.

TechRadar, an IT media outlet, reported on Aug. 12 that the core vulnerabilities companies face are not much different from 5 or 10 years ago. Unpatched systems, weak identity and access controls, excessive privileges, insecure third-party connections and incomplete asset management remain major pathways for attacks.

AI is changing the speed and scale at which these long-standing weaknesses are found and exploited. Attack steps such as reconnaissance, malware modification, writing phishing messages and lateral movement, which previously required time, skill and persistence, are being automated. Even less skilled hackers can use AI to carry out more sophisticated attacks at scale. Deepfakes and voice cloning make social engineering attacks more convincing, and malware can morph faster to evade detection.

The problem is "strategic distraction" that arises when AI is viewed only as a completely new threat. It is positive that executives and boards focus on AI risks, but if discussion leans toward adopting AI-only solutions, basic security tasks can be pushed back. Old challenges such as patch management, asset inventories, supply chain exposure and privilege management remain unresolved, and have become even more important in the AI era.

Companies should therefore focus their response on strengthening basic principles rather than buying new tools. No organisation can be 100 percent secure, and AI may find unknown vulnerabilities. Still, the response remains prioritisation, fixing vulnerabilities and reducing exposure. Red-team exercises and simulated response drills should evolve to include AI-based attack scenarios, and incident response teams should be ready to handle evidence generated or manipulated by AI.

Deploying AI inside companies also broadens the attack surface. Hackers can target AI workflows, development environments and prompt injection. They can also hide malicious instructions inside legitimate content to make AI systems take unintended actions. This, too, is closer to a new application of familiar security principles such as input validation, supply chain security and data integrity.

Security in the AI era hinges not on exaggerated fear but on accurate distinctions. Organisations need to understand what has changed and what has not. AI speeds up both attack and defence, but the starting point for protecting an organisation remains basic security systems, clear accountability, risk tolerance standards and consistent execution.

Keyword

#AI #TechRadar #deepfakes #voice cloning #prompt injection
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.