Cyber agencies from multiple countries published a joint guide on using artificial intelligence safely. Plus, CERT’s director says AI is the top skill for CISOs to have in 2024. Plus, the UK’s NCSC forecasts how AI will supercharge cyberattacks. And a global survey shows cyber pros weighing pros and cons of AI. And much more!
Dive into six things that are top of mind for the week ending January 26.
Is your organization – like many others – aggressively adopting artificial intelligence to boost operational efficiency? If so, you might want to check out a new guide published this week about how businesses can use AI securely.
Created by the Australian Cyber Security Centre (ACSC) in collaboration with cyber agencies from 10 other countries, the “Engaging with Artificial Intelligence” guide highlights AI system threats, offers real-world examples and explains ways to mitigate these risks.
AI threats discussed in the document include:
And here are some of the guide’s recommendations:
To get more details, check out:
For more information about using AI securely:
Mastering AI. That’s the number one skill CISOs must acquire in 2024, according to Greg Touhill, Director of the CERT Division of Carnegie Mellon University’s Software Engineering Institute (SEI).
In his article “The Top 10 Skills CISOs need in 2024,” published on the SEI’s blog this week, Touhill unequivocally ranks AI at the top of his list, advising CISOs to “master AI before it masters you.”
“CISOs need to understand the power and potential of AI-enabled technologies well beyond the mechanics of how AI is constructed and operated,” Touhill writes.
CERT Director Greg Touhill (Credit: Carnegie Mellon University)
Specifically, CISOs must:
“The present and near-future for CISOs will be marked by breathtaking technical advances, particularly those associated with the inclusion of artificial intelligence technologies being integrated into business functions,” he writes.
Rounding out the top five skills CISOs need to develop in 2024 are:
“Some forecasts have already characterized 2024 as a pressure cooker environment for CISOs. In such an environment, skills are critical,” writes Touhill, who was the U.S. federal government’s first CISO, appointed by former President Barack Obama.
For more information about CISO priorities and challenges in 2024:
VIDEOS
CISO Predictions for 2024 (CISO Tradecraft)
Achievements and Aspirations: Reflecting on 2023 and Predicting 2024 (CISO Global)
The volume and impact of cyberattacks, including ransomware, will grow over the next two years, as malicious actors of all stripes incorporate AI into their toolboxes. Still, how the bad guys use AI and what benefits they get from it will depend on their level of skill and knowledge.
So says the U.K. National Cyber Security Centre (NCSC) in its new report “The near-term impact of AI on the cyber threat,” published this week.
Here’s a table with a nifty breakdown of how the NCSC projects that AI will supercharge the cyberattack capabilities of cybercriminals with different levels of sophistication.
Extent of Capability Uplift Caused by AI over the Next Two Years
(Source: NCSC’s “The near-term impact of AI on the cyber threat” report, January 2024)
In a companion statement, the NCSC highlighted how AI will likely heighten the already critical threat from ransomware by making it easier in particular for unskilled hackers to launch more effective cyberattacks.
“This enhanced access, combined with the improved targeting of victims afforded by AI, will contribute to the global ransomware threat in the next two years,” the NCSC statement reads.
For more information about how to address AI-powered cyberattacks:
PODCAST
Defending Against AI Threats (FBI)
A global survey of cybersecurity pros once again shows how they view AI technologies as a blessing and a curse, offering powerful capabilities for cyber defenses and for cyberattacks.
Specifically, the 1,000-plus cyber pros surveyed for the “EC-Council Threat Report 2024” identified these top risks in AI-fueled cyberattacks:
Meanwhile, here are the main areas where respondents see AI helping cyber defenders:
“AI has emerged as a double-edged sword in cybersecurity, offering unprecedented defense capabilities and new avenues for attackers,” EC-Council President and CEO Jay Bavisi said in a statement.
Other key findings from the 47-page report include:
What’s business executives’ main concern going into 2024? That’d be the consequences of suffering a cyber event, according to a report from insurer company Allianz Commercial.
For the third straight year, the “Allianz Risk Barometer” ranks cybersecurity incidents first among business risks. They’re specifically worried the most about data breaches and about cyberattacks against critical infrastructure and physical assets.
Which cyber exposures concern your company most over the next year?
(Source: “Allianz Risk Barometer” report, January 2024)
Factors expected to increase cybersecurity risk for businesses this year include the weaponizing of AI by cyberattackers; weak cyber defenses; lax mobile device security; and the skills shortage among cyber pros, according to the report, based on a global survey of 3,000-plus risk management experts.
Rounding out the top 5 business risk rankings were business interruption; natural catastrophes; changes in legislation and regulation; and macroeconomic developments.
The Top 10 Global Business Risks for 2024
(Source: “Allianz Risk Barometer” report, January 2024)
To get more details, check out:
An emergency directive from CISA is requiring all federal agencies in the civilian executive branch to address active vulnerabilities in the Ivanti Connect Secure and Ivanti Policy Secure products.
Specifically, the instructions in the “Emergency Directive (ED) 24-01 Mitigate Ivanti Connect Secure and Ivanti Policy Secure Vulnerabilities” include:
“Even as federal agencies take urgent action in response to this Directive, we know that these risks extend to every organization and sector using these products. We strongly urge all organizations to adopt the actions outlined in this Directive,” CISA Director Jen Easterly said in the statement “CISA Issues Emergency Directive Requiring Federal Agencies to Mitigate Ivanti Connect Secure and Policy Secure Vulnerabilities.”
To get all the details about these Ivanti vulnerabilities, read the Tenable blog “CVE-2023-46805, CVE-2024-21887: Zero-Day Vulnerabilities Exploited in Ivanti Connect Secure and Policy Secure Gateways.”
Juan has been writing about IT since the mid-1990s, first as a reporter and editor, and now as a content marketer. He spent the bulk of his journalism career at International Data Group’s IDG News Service, a tech news wire service where he held various positions over the years, including Senior Editor and News Editor. His content marketing journey began at Qualys, with stops at Moogsoft and JFrog. As a content marketer, he's helped plan, write and edit the whole gamut of content assets, including blog posts, case studies, e-books, product briefs and white papers, while supporting a wide variety of teams, including product marketing, demand generation, corporate communications, and events.