Warnings about AI-powered cyberattacks can sometimes sound like another extension of the hype surrounding artificial intelligence. But Atos believes the threat is real – and many organisations aren’t moving quickly enough to prepare for it.

Cameron Prescott-Young, director of cyber consulting services UK&I at Atos (pictured), said AI is beginning to change both the speed and accessibility of cyberattacks, potentially giving defenders far less time to respond to vulnerabilities.

“The first thing I’d say is don’t ignore it,” he told delegates at Think Digital Identity & Cybersecurity for Government. “I am worried about the levels of awareness, especially across government.”

Prescott-Young believes organisations will increasingly need to use the same technology defensively if they are to keep pace with attackers.

“There is no way to deal with the scale and the pace of these attacks aside from using AI yourself in a defensive way,” he said.

One of the biggest changes, according to Prescott-Young, is the potential compression of the time between finding a vulnerability and exploiting it. Traditional vulnerability management assumes organisations have some time to identify a flaw, develop or obtain a patch and deploy it before widespread exploitation.

But Prescott-Young argued that increasingly capable models can search for previously unknown vulnerabilities and then rapidly work out how to exploit them. That could require a “fundamental rethink” of asset management, vulnerability management and patch management, he said.

Atos has been testing the potential itself. Prescott-Young described an AI-enabled penetration test against a hardened banking image used for a capture-the-flag exercise. Using what he described as a less capable model than some of the latest cyber-focused systems, the test gained access in 11 minutes.

“The behaviour of it is also interesting because it effectively comes up with the ideal, optimal path of attack and then relentlessly goes at it,” he said.

That relentlessness can make an attack easier to detect, he acknowledged. But 11 minutes also leaves defenders with very little time to react.

The second concern is accessibility. Capabilities that previously required significant technical expertise could increasingly be available through natural-language prompts, Prescott-Young warned, potentially putting more sophisticated offensive capabilities into the hands of less skilled attackers.

That doesn’t mean every AI-assisted attacker suddenly possesses the capabilities of a nation state. But Prescott-Young believes that organisations should be changing their preparations now.

“This is the most concerning thing I’ve seen” in 15 years working in cybersecurity, he said.

The problem is compounded by weaknesses that already exist inside many organisations. Asset inventories may be incomplete, vulnerability management varies significantly across large estates, and patching can be inconsistent across servers, network devices, databases and other infrastructure.

AI therefore risks accelerating attacks against environments that already struggle to keep on top of conventional vulnerabilities.

Atos has responded by establishing a UK task force across technical, operational, procurement and other functions, with senior executive oversight.

The company is reviewing areas including patching, supplier arrangements, contracts and incident response processes to determine whether they can cope with what Prescott-Young described as “machine-speed attacks”.

It is also building a platform intended to bring together security information and use AI to model how an attacker could exploit an environment. The aim is to improve prioritisation, model attack paths and help orchestrate remediation.

But Prescott-Young said the answer isn’t handing defence over to AI. Atos currently intends to retain a human decision point before recommended controls are applied, reducing the risk that automated defensive action itself causes an outage.

Asked whether cybersecurity is now entering an AI arms race, Prescott-Young was unequivocal.

“There’s definitely an arms race,” he said.

Yet he remains optimistic about AI’s potential on the defensive side, describing it as a possible “force multiplier” for security operations.

The immediate challenge for government is therefore not to avoid AI, but to reconsider whether cyber processes designed around human timescales remain sufficient.

For Prescott-Young, waiting to find out is the greater risk: “There is no way to deal with the scale and the pace of these attacks aside from using AI yourself in a defensive way.”

Event Logo