I spent more time digging into the new NIST Cybersecurity Profile for AI... The document frames AI cybersecurity around three distinct focus areas. Not just securing AI systems. But understanding how AI changes cybersecurity as a whole. The first focus area is securing AI systems themselves. This includes protecting and understanding training data implications, safeguarding model artifacts, securing inference APIs, and preventing things like model theft, prompt injection, or adversarial manipulation. The second focus area is using AI to strengthen cybersecurity operations. Security teams are already experimenting with AI for threat detection, GRC, anomaly analysis, and automating investigation workflows. The third focus area is defending against attackers who are using AI. That last point is where things start to change the security landscape. AI can accelerate vulnerability discovery, generate convincing phishing campaigns, and automate reconnaissance in ways that were previously very manual. In other words, AI is now influencing both sides of the cybersecurity equation. Organizations have to secure the AI systems they deploy while also preparing for attackers who are increasingly augmented by AI themselves. That dual pressure is why AI security is quickly becoming part of mainstream cybersecurity strategy. It is not a niche governance topic anymore. It is becoming part of how modern security programs operate. #AI #GRCEngineering
Effects of AI on Cybersecurity
Explore top LinkedIn content from expert professionals.
Summary
Artificial intelligence (AI) is rapidly transforming cybersecurity, introducing both powerful defenses and new risks. AI refers to computer systems that perform tasks typically requiring human intelligence, such as learning, reasoning, and decision-making. As AI becomes more integrated into security tools and systems, it speeds up threat detection and response but also enables attackers to discover vulnerabilities and launch sophisticated cyberattacks more quickly than ever before.
- Adapt security strategies: Shift from relying on vendor promises to using evidence-based practices that monitor what's exposed and can be realistically exploited right now.
- Continuously verify trust: Establish and regularly validate who controls system behavior and automated decisions, ensuring transparency and accountability as AI is embedded in critical systems.
- Monitor AI-driven risks: Stay vigilant for threats such as adversarial attacks, data poisoning, and AI-aided phishing, by implementing robust protocols and regular checks of AI operations.
-
-
The Unseen Threat: Is AI Making Our Cybersecurity Weaknesses Easier to Exploit? AI in cybersecurity is a double-edged sword. On one hand, it strengthens defenses. On the other, it could unintentionally expose vulnerabilities. Let’s break it down. The Good: - Real-time Threat Detection: AI identifies anomalies faster than human analysts. - Automated Response: Reduces time between detection and mitigation. - Behavioral Analytics: AI monitors network traffic and user behavior to spot unusual activities. The Bad: But, AI isn't just a tool for defenders. Cybercriminals are exploiting it, too: - Optimizing Attacks: Automated penetration testing makes it easier for attackers to find weaknesses. - Automated Malware Creation: AI can generate new malware variants that evade traditional defenses. - Impersonation & Phishing: AI mimics human communication, making scams more convincing. Specific Vulnerabilities AI Creates: 👉 Adversarial Attacks: Attackers manipulate data to deceive AI models. 👉 Data Poisoning: Malicious data injected into training sets compromises AI's reliability. 👉 Inference Attacks: Generative AI tools can unintentionally leak sensitive info. The Takeaway: AI is revolutionizing cybersecurity but also creating new entry points for attackers. It's vital to stay ahead with: 👉 Governance: Control over AI training data. 👉 Monitoring: Regular checks for adversarial manipulation. 👉 Security Protocols: Advanced detection for AI-driven threats. In this evolving landscape, vigilance is key. Are we doing enough to safeguard our systems?
-
Criminals, Spies, and AI: A New Front in Cyber Warfare The use of AI in cybersecurity is rapidly changing the landscape, creating a new "arms race" between hackers and cybersecurity professionals. Here's a look at how different groups are leveraging this technology. AI and Malicious Actors Bad actors are increasingly incorporating AI into their cyberattacks. For example, Russian hackers have been caught using large language models (LLMs) to create malicious code for phishing campaigns, enabling them to automate the search for sensitive files on a victim's computer. Similarly, cybersecurity firm CrowdStrike has noted a growing trend of advanced adversaries, including Chinese, Russian, and Iranian state-sponsored groups, using AI to their advantage. The technology is making skilled hackers more efficient and effective, particularly in areas like social engineering and creating convincing phishing emails. AI in Cyber Defense The cybersecurity industry is also using AI to combat these threats. Google's security team, for instance, has used its Gemini LLM to hunt for software vulnerabilities. This process has already led to the discovery of at least 20 overlooked bugs in commonly used software, allowing companies to fix them before they can be exploited by criminals. While AI isn't yet finding entirely new types of vulnerabilities, it is significantly speeding up the process of discovering and patching known types of flaws. As Google's VP of Security Engineering, Heather Adkins, said, "It’s the beginning of the beginning." The use of AI in both offensive and defensive cybersecurity is still in its early stages, but it is clear that the technology is making a tangible impact, creating a faster, more complex, and more dynamic environment for everyone involved.
-
The most consequential impact AI is having on cybersecurity isn’t better phishing emails or faster malware generation, it’s forcing the entire industry to move from promise-based security to evidence-based security. That’s a radical shift. For decades, security largely relied on promises. A company would buy a firewall, EDR, SIEM, or another security product and, implicitly, buy the promise that the vendor would stop the breach when it happened. And to be fair, many vendors have done an excellent job preventing the most common attacks. Now AI is turning this approach upside down because it is dramatically shortening the time between exposure and exploitation. Attackers can move faster, discover weaknesses faster, and scale reconnaissance faster than ever before. In the new world, promises are no longer enough. Security leaders need evidence. They need to know: - what is exposed, - how infrastructure is configured, - where controls are weak, - what is actually monitored, - what can realistically be exploited right now. That’s why so many of the fastest-growing categories in cyber are converging around the same core idea: - Vulnerability Management with AI - Exposure Management - CTEM - Autonomous Pentesting - Attack Surface Management - Continuous Validation They’re all fundamentally solving the same problem: helping organizations understand what is actually exposed, and fix it before attackers get there first. That’s the real paradigm shift AI is driving in cybersecurity that we see at The Core Strength Network.
-
AI is increasingly moving into the control plane of our digital platforms, and that shift has profound implications for cybersecurity. Much of today’s AI discussion focuses on productivity and automation. Important topics, but not the most consequential from a security perspective. What matters more is where AI is being embedded. Increasingly, it is becoming part of the control layers we depend on, including identity, access, analytics, decision support, and security tooling itself. Cybersecurity has traditionally focused on protecting data: where it resides, who can access it, and how it is encrypted. These concerns remain essential, but they are no longer sufficient. AI systems do more than process information. They infer, prioritise, adapt, and influence behaviour. As AI becomes embedded in security-relevant platforms, the core question shifts from where data is stored to who controls system behaviour. From a security perspective, control equals trust. As AI capabilities advance, some long-standing assumptions about static trust need to be re-examined. Systems are updated frequently, operate across platforms and jurisdictions, and increasingly act autonomously. In this environment, trust cannot be implicit. It must be continuously established, verified, and monitored. Protecting customer data therefore means protecting the whole system. Data flows through identities, platforms, APIs, and AI-driven components. When AI influences these flows, security requires transparency, accountability for automated decisions, the ability to intervene, and resilience when dependencies change or fail. At SEB, we approach AI with both ambition and discipline. Our focus is on strong control, continuous verification, and resilience by design. AI does not reduce our responsibility for cybersecurity. It increases it. The real question is not whether AI will change cybersecurity. It already has. The question is whether we are prepared for what that change truly means.
-
"Artificial intelligence (AI) is rapidly reshaping the cyber security landscape. As highly capable AI becomes more widely available, malicious actors are using it to deliver cyber threats at greater scale and speed. Organisations that don’t re-evaluate and improve their defences will remain vulnerable to these AI-enabled cyber threats. Cyber security has traditionally relied on specialised teams and reactive workflows to manage risk. These approaches remain important, but the scale and complexity of the modern cyber security landscape increasingly strain them. Heavy dependence on manual processes can make it difficult to prioritise risks, investigate potential threats and maintain consistent defensive coverage. AI presents a significant opportunity for cyber defenders. When used safely, securely and responsibly AI can: • strengthen prioritisation of cyber risks • improve detection of threats and vulnerabilities • support faster response and recovery • reduce reliance on repetitive manual tasks. This guidance outlines how organisations can use AI to strengthen organisational cyber security while managing the risks of using AI. It outlines how the cyber security landscape is evolving and describes how organisations can use AI aligned with the Information security manual (ISM) cyber security functions of Govern, Identify, Protect, Detect, Respond and Recover. It also sets out principles for securely adopting AI, along with key questions for cyber defenders to ask AI vendors to support secure use. Human oversight, governance and Secure by Design practices remain essential. AI can significantly enhance cyber security, but it is not a replacement for strong cyber security fundamentals. Poorly designed or poorly governed AI systems can introduce new attack paths. This can occur through excessive system access, reliance on untrusted inputs, or automated actions without adequate safeguards." Australian Signals Directorate
-
AI is removing entire cybersecurity roles. Like how the flight engineer was removed from planes. Not because there was no need for engineers but because the nature of the work changed. Cybersecurity is going through a similar shift. Roles built around repetitive review, predictable workflows, and manual triage are becoming easier to automate. Not that the work is going away. It means the bar for human value is moving. The real question is no longer, “Will AI affect cyber jobs?” It is, “Which cyber professionals will become more valuable as AI takes over routine work?” Here are 4 shifts I think leaders should pay attention to. 1. Routine work is the first to be transformed. Tasks that are the easiest to automate. • Initial alert review. • Basic enrichment. • Simple reporting. • Low-level analysis. • Repeatable policy checks. If a role is heavily built on structured, repetitive work, AI will change it. Maybe not all at once. But enough to reshape the role. 2. Judgment becomes more valuable, not less. When the routine work is reduced, the remaining work becomes harder. • Weigh tradeoffs. • Own the outcome. • Challenge assumptions. • Someone still needs to interpret context. • Make decisions with incomplete information. That is where human value rises. Especially in cybersecurity, where the stakes are rarely just technical. The strongest cyber professionals will be the ones who can connect technology to business impact. 3. Knowing the tools still matters. But that alone will not be enough. The people who stand out will be able to investigate clearly, communicate calmly, brief leadership, and help the organization make sound decisions under pressure. In other words, execution will matter even more so. Are you delivering value? Daily? 4. Training needs to evolve with the role. Many teams are still developing people for yesterday’s version of cyber work. That is a mistake. We should be training for: • decision-making under pressure • business impact assessment • cross-functional coordination • higher-quality analysis • crisis communication AI is not removing the need for cybersecurity. It is removing some of the work that is most mechanical. That is a big difference. Just as aviation evolved, cybersecurity will evolve too. The teams that adapt early will not just protect jobs better. They will build stronger cyber capability overall. P.S What are you actively doing to evolve?
-
Anthropic’s Mythos AI Is Triggering a Massive Cybersecurity Response Across U.S. Banking Anthropic’s advanced cybersecurity AI model, Mythos, is reportedly forcing major U.S. banks into accelerated remediation efforts after uncovering large numbers of previously unidentified software vulnerabilities across financial infrastructure systems. According to reports, several of the nation’s largest banks with direct access to Mythos are now racing to patch hundreds or even thousands of newly identified weaknesses. Many of the vulnerabilities are considered low to moderate in severity, but the sheer scale and speed of discovery are dramatically increasing operational pressure on cybersecurity and infrastructure teams. The findings are reportedly cascading through the broader banking ecosystem. Large institutions are sharing remediation intelligence with regional and community banks that do not have direct access to Mythos, allowing smaller financial organizations to proactively strengthen defenses before potential exploitation occurs. One of the most significant developments is the acceleration of remediation timelines. Security flaws that previously might have remained unresolved for weeks are now being patched within days as institutions respond to the unprecedented discovery velocity enabled by AI-driven vulnerability analysis. This intensified pace raises concerns about operational strain, change-management risk, and the possibility of temporary service interruptions during emergency system updates. The situation highlights the transformative — and disruptive — impact advanced AI systems may have on cybersecurity operations. AI models like Mythos can analyze software environments at speeds and depths far beyond traditional human-led auditing processes, fundamentally changing how organizations identify and respond to cyber risk. At the same time, the technology presents a double-edged challenge. While AI dramatically improves defensive capability, the same vulnerability discovery techniques could potentially be weaponized by sophisticated attackers if similar tools become widely available outside tightly controlled environments. Key Takeaways for the material include the growing operational impact of AI-powered cybersecurity systems, the accelerating pace of vulnerability remediation inside critical financial infrastructure, and the emerging reality that AI is reshaping cyber defense at national scale. The broader implication is that AI may fundamentally compress the timeline between vulnerability discovery and exploitation. Organizations capable of deploying advanced defensive AI rapidly may gain major security advantages, while institutions slow to modernize cybersecurity operations could face increasing exposure in an AI-accelerated threat environment. I share daily insights with tens of thousands followers across defense, tech, and policy. Keith King https://lnkd.in/gHPvUttw
-
Dear AI and Cybersecurity Auditors, AI changes how risk enters your environment and expands your attack surface. Traditional cybersecurity controls no longer cover model behavior, training data, prompts, agents, and AI-driven decisions. This draft extends NIST CSF 2.0 into AI systems. It treats models, data, prompts, agents, and AI decisions as real cyber assets. It also addresses how attackers already use AI to scale speed, deception, and impact. Here is why this framework matters for security, risk, and audit leaders. 📌 AI expands the attack surface beyond infrastructure into training data, models, prompts, agents, and third-party AI services 📌 Governance shifts from IT ownership to enterprise accountability with clear risk ownership, oversight, and decision authority 📌 Traditional controls still apply, but AI requires added focus on model integrity, data provenance, output reliability, and human oversight 📌 The framework maps AI risk directly to CSF functions so teams avoid parallel AI security programs 📌 Defensive teams use AI to reduce alert fatigue, improve detection accuracy, and support faster incident response 📌 Adversaries already use AI for phishing, malware generation, social engineering, and automated attack orchestration 📌 Continuous monitoring extends beyond systems into model drift, hallucinations, and unexpected behavior 📌 Risk tolerance must account for AI failure modes, not only system outages or data loss 📌 Audit and assurance teams gain a structured way to test AI controls across Secure, Defend, and Thwart focus areas 📌 The profile supports assessment, control design, and executive reporting without adding unnecessary complexity AI security fails when teams treat AI as software. NIST IR 8596 reframes AI as a risk domain inside cybersecurity. If your organization builds, buys, or relies on AI, this profile gives you a practical path to govern, secure, and defend it with intent. #NIST #Cybersecurity #AIGovernance #AIRisk #AIControls #ITAudit #CyberRisk #AISecurity #GRC #CSF #CyberVerge ♻️ Share this with your team or repost so more professionals. 👉Follow Nathaniel Alagbe for more.
-
The release of advanced AI systems like Anthropic Mythos marks a pivotal moment for the cybersecurity community — one that brings both meaningful opportunity and material risk. On the benefit side, capabilities are accelerating in ways we’ve been chasing for years: • Signal over noise – AI-driven correlation can drastically reduce alert fatigue by identifying true positives faster and with greater context • Speed of response – Autonomous or semi-autonomous response has the potential to compress incident containment from hours to minutes • Threat intelligence at scale – Real-time synthesis of global threat data improves detection of emerging attack patterns • Augmented analysts – Security teams can operate at a higher level, focusing on strategy and complex investigations instead of repetitive triage But we should be equally clear-eyed about the risks: • Adversarial use of AI – Threat actors now have access to the same (or similar) capabilities, lowering the barrier to sophisticated attacks • Model exploitation – Prompt injection, data poisoning, and model manipulation introduce a new attack surface • False confidence – Over-reliance on AI outputs without validation could amplify risk rather than reduce it • Data exposure – Sensitive security telemetry and proprietary data flowing into AI systems must be governed with precision The reality is this: AI like Mythos doesn’t replace cybersecurity professionals — it raises the stakes for how we operate. The organizations that win will be the ones that treat AI as both a force multiplier and a risk domain, embedding it into their security strategy with the same rigor applied to any critical system. Curious how others are thinking about integrating AI into their security stack — where are you leaning in vs. holding back? #Cybersecurity #ArtificialIntelligence #AI #Infosec #CISO #RiskManagement #ThreatIntelligence #SecurityOperations #ZeroTrust #AIinSecurity #EmergingTech #DigitalRisk #SecurityLeadership