The Abundance Paradox for Cybersecurity: AI Edition

My Cup Runneth Over

Our previous post was about the Abundance Paradox in its many forms namely having lots of something turns out to have downsides in addition to upsides. My cup runneth over (and now the table is wet).

That post was about cybersecurity (C/S) in general being vulnerable to this problem. This post is about how apply AI to C/S in particular has risks associated with it.

Using AI to do your C/S survey work is very handy and allows you to keep up with lots of rote tasks but there are two downsides: the AI makes mistakes (fewer all the time, but still the occasional whopper) and relying on the AI means that your abilities atrophy or never develop in the first place. Is that a problem? After all, horse-handling is no longer a very common requirement of modern life. However, for years after the introduction of the automobile horse-handling remained quite a useful skill.

The fact is that the set of skills you need over your life changes, faster than it ever has in human history, and our value judgments about what is important has to change with it. When I learned to drive I learned to shift gears manually. For many years automatic transmissions were inferior to a skilled human. Recently automatic transmissions have surpassed even skilled humans. Now shifting your own gears is something you do for fun. Where are we on that curve with AI, the curve from "not as good" to "better"? I don't know, exactly, but I am unconvinced that we are at "as good," let alone "better."

Using AI to do your security analyses has a very similar cost-benefit ratio: you get more done with a risk of massive error and your ability to do these analyses yourself degrades over time. How does this cost-benefit ratio look in your environment? Have you checked?

Using AI to do the basic tasks of your SOC, such as monitoring activity logs, has a bit of a twist: in this case there is often an excellent case to be made for sophisticated pattern-matching because there is such a volume to be checked and such a good definition of "abnormal." I don't know that you need a full-blown AI to do this. I don't know how you avoid getting complacent about updating the patterns to be checked. But I have seen automation applied to this aspect of C/S in a way that seemed to me to be low in cost and high in benefit.

AI is still shiny and new but it is getting more mature by the month. I am very uneasy that the questions of cost and business model and infrastructure seem to be still in flux. I am very uneasy that there seems to be so little emphasis on making sure that AI agents are trustworthy and not prone to corruption. But I don't think that a reasonable person can, at this point, simply dismiss AI out of hand any more than I think that a reasonable person can embrace AI with open arms in every aspect of C/S.

Finding this balance is hard, especially when senior management is dazzled by the hype. We can help. Ask us how.

Comments