BCX Connects
From trends to industry insights, BCX news, client success stories and thought leadership from our experts, BCX Connects is your go-to for the industry intelligence you need to know.
BCX Connects
AI in Cybersecurity
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of BCX Connects, hosts Garith Peck and Chris Bester explore the double-edged nature of AI in cybersecurity. As AI empowers organisations, it also introduces new risks through “Shadow AI.” They unpack how this hidden layer impacts security, blurs the line between innovation and risk, and challenges control of technology.
For more information visit: https://www.bcx.co.za/
Welcome back to BCX Connects. I'm Garith Peck. I'm the managing executive for cybersecurity at BCX. Today we're going to be focusing on AI, artificial intelligence in cybersecurity. AI has moved from science fiction to boardroom reality. It's reshaping industries, redefining productivity, and now it's transforming cyber. But as AI becomes more capable, it also becomes more unpredictable. It's both a shield and it's a weapon. So depending on who's holding it. In this episode, we'll trace AI's journey in cybersecurity and unpack the rise of what we commonly refer to as shadow AI and discuss the dual nature of this technology. So with me today, I have uh Chris Bester. Welcome again, Chris. Thank you for having me. Good morning, Garith.
SpeakerThank you.
Speaker 1So, what we're going to be discussing is around how this artificial intelligence empowers defenders that uh, but it also amplifies attackers. You know, we we've mentioned things like you know, artificial intelligence is what we refer to as a force multiplier, it amplifies and multiplies any kind of activity and actions that uh is being focused on.
Digital Defence and AI Governance
Speaker 1So, Chris, as we're gonna be exploring, I think we're gonna touch on the the digital defense and the governance around around AI. But before we begin, I want to just take the um the listeners through a little bit of the evolution of AI. You know, this it's actually been 75 years of learning. That's right. Yeah, um, AI story is is one of persistence and uh reinvention. So from Arthur Samuel's self-learning uh checkers program in 1949 uh to IBM's uh Deep Blue defeating uh Garrickus Parov in 1997. I still remember having those Garrichus Parov chessboards uh in the 90s and again showing my age. Each milestone um you know marked uh a shift in the the program logic to adaptive intelligence. But by now, by the early 2010s, deep learning had started to take over and cybersecurity tools began moving away from static signature-based detection towards behavioral and anomaly-based systems. So today, with uh you know the very popular and common large language models like ChatGPT, you have uh the Deep Seek and uh Claude, etc. AI can reason, it can explain, it can adapt in ways uh that was one once I think we and we also know it it also hallucinates, right? And we'll discuss that. So I think Chris, uh when when you look at this evolution, I mean you've been part of this journey, right, on this evolution. So how do you see that line between that uh human judgment and machine reasoning changing in cyber?
SpeakerYeah, Harid, it's it's it's interesting. I mean, it with the coming of Chat GPT and the large language model, it put AI in the hands of the common man in the street. But it it used to be just big corporates like IBM and Google that that played in that playground. But the ultimate goal of the AI gurus, I think, is to get to a point where human judgment is just sidelined and and and where the machine can be the judging entity. But you know, like in the super AI scenario that we've discussed at length as well at the security summit. Now, for me though, there's one thing that AI will always lack, and that's that human intuition, uh, that gut feel or sixth sense, you know, with everything looks perfect, but you feel that it's it's not, you know. Yeah, that feeling that makes you dig deeper. That's for me.
Speaker 1Uh I I don't think AI will get to that point where I think, and that's a very important point for our listeners to understand is that um AI is not replacing analysts, right? It's reshaping the scale, uh it's reshaping um the scale and speed at which they operate. So it's not there just to um uh rip and replace. So I think shadow
Shadow AI
Speaker 1AI is is something that uh um we touched on in our last episode very briefly. And we we've reached a stage where AI isn't just in a lab, right? It's it's in every app, in every workflow, every process. Um, but it's not all sanctioned, and that's the challenge. We're now seeing the rise of what's being called shadow AI. Now, just like um shadow AI before it um you know shadow AI presents uh innovation without oversight. Now uh employees experiment with AI tools, automate tasks, you know, the build models, you know, um without formal governance. Um, and the difference, you know, shadow AI um learns uh uh and it evolves and it can also expose data or create unpredictable outputs. So how serious? I mean, uh so from a compliance and governance perspective, you know, this threat of shadow AI, should organizations ban it or find a way to embrace it responsibly?
SpeakerYou know, experience, life experience actually showed us that um if you ban something, people find it, they find it a challenge to break that ban, you know, to get to to to circumvent the things that you put in place to ban it. So um for me, you know, uh the curious minds, um, you know, you should realize embrace it or or put your guidance up and and and govern uh put your governance um in place. No, don't don't jeopardize your security, but if you can even go as far as as create a fenced off playground for your shadow ITers, you know, your the guys that so things like ethical frameworks, uh exactly, yeah. You you you can create an environment where they can be innovative, but where you have control and we can make sure that it doesn't go out of the boundaries of that um that material because exactly like you're saying, I mean, banning AI won't stop its use.
Speaker 1No, it's not true. I mean it's it's embedded in everything that we do nowadays, right? Um the answer lies in governance, um, creating visibility, setting boundaries, and embedding ethics um in the design. And I think uh what's important is um like we discussed last week when we spoke about the you know technology in the workforce, it also spills out into their home life as well. Yeah, and I'm looking at this specifically from like my children, you know, and how children are interacting with artificial intelligence as well, you know, the way they're studying, the way they're consuming data. So all of these kind of um ethical frameworks and controls need to have an element of a spillover into your your your your private uh uh life.
SpeakerYeah, and and it's inevitable. It's inevitable. You can you just we can't get around that.
Speaker 1Yeah. So I think you know, AI is there's a bit of a promise, right? And uh, you know, and that promise is around uh you know strengthening cyber defense. I mean, we know the big challenge in cyber is like skill shortage
Skill Shortages
Speaker 1is is probably one of the biggest challenges with these uh millions of um vacant roles for worldwide available because you know with the kind roles can't be filled, there's no skills. Now, on the positive side, AI has transformed cyber defense. Uh machine learning can detect patterns across millions of data points. Um very fast as well. Yes, and identifying um uh anomalies uh you know the humans might might miss. Now, predictive analytics allow us to anticipate threats before they strike. Uh automated response is another breakthrough. AI can contain and you know neutralize threats in seconds, uh, reducing the dwell time uh dramatically. And it's scale, uh scalability is unmatched from a human perspective. It's we we we can't we can't scale. So processing the data volumes that overwhelm uh even the largest um security team. So that is really one of the benefits and the promise that AI gives. But how AI is changing the SOC environments? I mean, uh uh you know how do you see that? Um the way analysts operate in the next five years, what's what's your prediction on that?
SpeakerHarid, for me, I mean, you made a statement earlier that um AI is not a replacement, or it's you're not replacing analysts. But uh in a SOC environment, your your level one analyst or your triage specialist, um that environment is almost entirely automated already. So the level, the analyst level, that level one analyst, and my prediction is that level uh where a physical human being is gonna do that, um, is going to sort of fade away. Yeah.
Speaker 1Um, and we're gonna focus on the level two and three analyst week, you know, where yeah, I've I've I've seen examples to customers that said that uh they they see that they're moving in that direction, level zero, level level one triage, uh, you know, um analysts, it's they start to automate those functions, yeah.
SpeakerAnd and and to be honest, I mean AI is gonna do it better on on the automation level, on that on that level. On that level. Just on that level. Moving up, we're getting back into our earlier discussion about human intuition, yeah. Uh, but AI cannot replace.
Speaker 1So, I mean, look, then then the so from the SOC uh perspective, um, the the the SOC of the future won't replace analysts, like you're saying, it will amplify them.
SpeakerExactly.
Speaker 1Um, so AI will handle the scale and humans will handle the context. Yeah. I think that's that's important.
SpeakerI like that. I like the yeah, this the scale is AI managed and the context, the context is quite human interventional.
Speaker 1But then again, we need to talk about the dark side of AI. I mean, um, you know, that's that's now when we're referring to the uh weaponizing of intelligence,
Weaponising of Intelligence
Speaker 1right? Um every every technology that defends can also attack, right? So roughly 40% of uh modern cyber attacks now use AI in some form, um whether it is now adaptive malware, only 40%. I think it's probably more. Yeah, uh, you know, uh deepfake social engineering is getting really big and and automated phishing that that learns from user behavior. I mean, worse is uh AI security models themselves can be poisoned and uh manipulated, you know. Adversarial attacks now we've seen how they they can corrupt data sets or even teach AI systems to misclassify threats. Yeah, um, yeah, it's the digital equivalence of uh blinding your guard dog, essentially. Exactly. Yeah. So and you know, the the the thing is we we've seen like in the past with with regards to how um phishing emails have been written, you're gonna pick it up with pure grammar, poor poor grammar, etc. Now with uh um AI, you know, a non-English speaking uh threat actor can use AI to write a perfect email.
SpeakerThat actually disappeared completely. You don't have that, yeah.
Speaker 1It and and it makes you know that human factor that we spoke about in episode one about the you know um picking up those kind of uh things, you need to be more on your guard, essentially. Yeah, so I think um how do you see like for like
How to prepare for AI as Cybersecurity Leaders
Speaker 1how does how should cybersecurity leaders prepare? And I always think about this, you know, for a world where attackers and defenders use both use AI weapons. That's always the the new challenge that we have.
SpeakerYeah, it it is it's um it's quite a challenge to actually answer that perfectly. But uh for me, the battleground hasn't changed. Uh it that the tools or the weapons has. Um it became very sophisticated. Our battleground is still the same, it's still good versus evil type of thing. So um my my worry is that that that leaders get complacent and think that AI is gonna do it all for them and that they will be protected. Just slap in AI, we're gonna be fine. Um you know I had a conversation with my my son the other day, and you got frustrated because he's been coding for a few years and then he's uh frustrated with this uh what they call it AI kiddies that now or coding kitties uh rather that now use AI to write the code and then he gets tasked to fix that because it this is it's it's full of errors and and it's not working properly. So and he he made the statement Papa AI is a tool, it's not a replacement. And these guys need to realize that it's it's not a replacement. Yeah, so and and that is what how our leaders have to think about uh about you know the the whole element of AI into cybersecurity. It it is a tool, we have to embrace it, and we have to recognize that our enemy is also embracing that.
Speaker 1Yeah, so um AI assurance is is is things that need to be looked at, validation layers, etc. I think and that's where the resilience will shift. Uh from simply defending systems to defending intelligence that defends the systems is is what needs to be looked at. So the dual use dilemma and the the path forward, I think uh the dual use of uh the dual use nature of AI um is perhaps uh its greatest paradox. Uh the the the same algorithms that help identify threats uh threats can also create them. Um the same generative models that build code securely can also generate the exploit kits. Um the challenge now is to ensure that uh our adoption of AI is matched with that ethical governance that the governance that we spoke about earlier. Um, the transparent data use and accountable frameworks, this isn't just uh a technology problem. I think it's a leadership issue. Um, I mean, for you in the governance world, right? Um what what does a responsible AI look like in the security domain?
How does responsible AI look like
SpeakerUh that's a bit of a loaded question.
Speaker 1Yeah, no, I said it on purpose.
SpeakerUh not that easy to answer. But I mean the age old saying that you you you have to think like a criminal to catch one. It's still coming to mind here. Uh, but that doesn't mean that you have to become one. Uh and this is where we have to tread lightly and make sure that our internal governance is on par to make sure this tool does not become an insider threat and that AI is not as used responsibly within our corporate boundaries. And and the only way you're gonna do that is to put your governance frameworks in place and make sure your policies just make sure you're governed.
Speaker 1Yeah, yeah, yeah. And I think that's where uh leaderships need to evolve. I mean, from managing systems to managing intelligence, um, AI governance must now be seen uh as as core to the cyber strategy, um, not a compliance afterthought.
SpeakerAnd that's true. I mean, uh really I like that, yes.
Speaker 1No, though so I think look in closing for me, um AI is changing everything, um, how we detect threats, how we respond, um, how we're consuming information in our daily lives, but also how we govern, right? But it also enforces how um it forces us to confront an uncomfortable truth. You know, innovation's moving faster than regulation. That's uh that's a crazy reality. I mean, shadow AI, adversarial models, you know, you name it, um, you know, the dual use algorithms, these challenge our definitions of control. And the answer isn't fear, it's the the disciplined innovation that we need to look at. The organizations that win this war, I suppose, uh will win with um those that pair both um the power of uh uh uh AI with strong governance, ethical frameworks, and that uh relentless focus on trust. I mean, trust uh is still the core fiber from a cyber perspective. So, Chris, thank you again for for joining me. I really enjoyed this uh this episode. Um, and to our listeners, stay informed, stay curious, and remember the future of cybersecurity isn't about defending systems, it's about defending intelligence itself. Thank you very much. Thank you.