Home Posts tagged Massachusetts Office of Consumer Affairs and Business Regulation
Cybersecurity Features

Getty Images

The Landscape Is Shifting

It’s become cliché — in industries of all kinds — to call some new development both a threat and an opportunity.

But in the case of artificial intelligence (AI) and its impact on cybersecurity, it’s true, in several distinct ways, said Delcie Bean, CEO of Paragus Strategic IT.

“It’s changed cybersecurity more than any single event I can think of, at least in recent history. Unfortunately, as is often the case in these situations, it tends to help the offense faster than the defense, and the defense has to play catch-up and respond. And right now, the offense seems to have the upper hand.

“The level of sophistication and frequency of attacks has increased substantially, and there’s no reason to think that will change soon,” Bean added. “It’s a very busy time for our cybersecurity division to make sure clients are safe and protected because things are changing so quickly and so often.”

This acceleration of AI threats comes at a time when data breaches are already a significant problem. According to a recent report by the Massachusetts Office of Consumer Affairs and Business Regulation (OCABR) and the MassCyberCenter, in 2024 alone, OCABR received 2,292 data breach submissions across a wide swath of industries.

“The level of sophistication and frequency of attacks has increased substantially, and there’s no reason to think that will change soon.”

Among the key findings of this study, most incidents involved malicious or criminal conduct, with system intrusion being the dominant method; financial services, healthcare, and banking represent the top industries affected; organizations struggle with preventing, attributing, and detecting breaches; and people, process, and technology contribute to data breaches through identified weaknesses such as insufficient multi-factor authentication and passwords.

“With cyber threats continuously evolving, there is a growing need for cybersecurity and information security professionals to protect computer networks and systems,” wrote Sean O’Brien, director of Cybersecurity & Computer Science at Bay Path University, in a recent article. “In fact, according to the U.S. Bureau of Labor Statistics, the demand for information security analysts is projected to grow 29% between 2024 and 2034, notably faster than the national average for all occupations.”

And this breach data, and projections about talent demand to fight threats, largely predate what technology experts are seeing now in the rise of AI. In short, it’s a quickly changing world.

On Guard

Delcie Bean

Delcie Bean says AI can cut through the noise and make threat detection more efficient.

Bean laid out a few ways in which AI is making life easier for hackers, one of which is the ability to identify many loopholes in an existing system much faster than a human could.

“Using these AI tools, you can uncover hundreds of vulnerabilities, if not thousands. And when those become exploited, there’s no easy answer,” he explained, noting that these can quickly turn into ‘zero day attacks,’ which are exploitations of a previously unknown security flaw before the developer is aware of it or has time to create a patch.

“A second issue is deepfakes and how much more broadly and more powerfully hackers are able to trick people, whether it’s amazing phishing emails looking exactly like normal emails, or more sophisticated attacks,” such as deepfaked video, Bean said.

He cited one example of a company’s employee finding himself on a Zoom call with what he thought was an FBI agent, and wound up exposing critical information to an individual who didn’t actually exist. “A video with that level of sophistication, being able to trick people into thinking it’s real — that’s really changing the game.”

Another threat is the ability, using AI, to autonomously attack companies, Bean said, which can make cyber threats both more numerous and more random. “We’re seeing powerful AI systems being set up to basically scan the internet for businesses and find a company to review for vulnerabilities and launch an attack completely autonomously.”

AI on AI

When asked how AI is changing cybersecurity,
here are the main points outlined in Google’s AI overview:
AI-powered Threats
• Sophisticated social engineering: Attackers use large
language models to generate highly personalized,
grammatically flawless phishing and spear-phishing emails at scale.
• Deepfakes and impersonation: AI-generated video and audio
clones are actively deployed to trick employees into authorizing
fraudulent transactions or divulging sensitive credentials.
• Machine-speed attacks: Threat actors utilize AI to scan massive
networks for vulnerabilities, rapidly test evasion techniques against
legacy defenses, and program malware that mutates to avoid detection.
• Adversarial machine learning: Hackers actively attempt to manipulate
or ‘poison’ the data pool used to train enterprise machine learning models,
leading to compromised security outputs.
Advanced Cyber Defenses
• Real-time threat detection: AI analyzes petabytes of data to establish
baseline ‘good behavior’ and immediately flag subtle, anomalous user or
network activities that indicate a breach.
• Endpoint detection and response: AI-powered endpoints act continuously
without relying on static file signatures, neutralizing unknown and zero-day
threats based on malicious actions.
• Automated incident response: AI tools can instantly isolate infected systems,
validate alerts, and disseminate threat intelligence, shrinking manual response
times from hours to minutes.
• Vulnerability management: AI models prioritize system patches by
analyzing internet accessibility, active exploits, and business criticality —
far beyond traditional scoring systems.

However, AI also offers opportunities to improve cyber defenses, again, in numerous ways — one of which is better honing those defenses.

“A lot of what we’ve done to combat cybersecurity is getting more tools and systems and technologies in place to keep businesses safe. The downside is it generates more and more noise — alerts, false positives, information that’s hard to understand; it takes a lot of additional work to sort through that, which can be overwhelming,” Bean explained.

“Where AI has been successful is helping cybersecurity companies analyze all this noise and determine whether it’s actually information that needs to be addressed, which cuts down on false positives.”

Then there’s the ability to analyze potential threats on a macro level, where suspicious activity on one computer might not immediately read as a threat, but similar activity across a network would — and AI is more adept at picking those patterns up.

Finally, “like AI setting up autonomous agents to attack, we’re also looking at setting up autonomous agents to defend,” Bean said. “Being able to keep track of more data and intelligence than humans are able to — especially in small businesses — means we can respond more effectively and efficiently, 24 hours a day.”

Sean Hogan, president of Hogan Technology Inc. (see related story on page 24), recently wrote about another under-discussed threat from AI. He cited a recent report that 86% of workers use AI at least weekly for work tasks, and 49% of workers admit using AI tools at work without employer approval.

“Whether workers are using these tools to conduct searches, create documents, or enter organization information, they are doing it in a risky manner because none of the tools are secure,” Hogan noted. “Most organizations have invested in cybersecurity. They have implemented firewalls, endpoint protection, multi-factor authentication, email security, backup systems, and network monitoring. However, most are now unknowingly bypassing all of those protections the moment workers begin interacting with an unsecured public AI tool.”

That’s why his company has begun helping clients establish guardrails around how AI is used, allowing workers to benefit from automation and intelligence while maintaining oversight, compliance, and human review.

“Companies want the productivity benefits of AI, but we step in and lock down these tools, so they are safe and secure.”

“Whether workers are using these tools to conduct searches, create documents, or enter organization information, they are doing it in a risky manner because none of the tools are secure.”

Future Shock

In Bean’s mind, the biggest question right now is what’s coming next on both the offensive and defensive sides.

“The thing we’re really afraid of is waking up someday, and there’s a new AI model out there, and you can point it at a company, and it bores its way in, no matter what, and finds an opening and takes that company down. We all believe AI is headed in that direction, and it’s becoming more a matter of when than if.”

However, he added, “the opportunity, in the interim, is to develop some other technology to help combat that, or at least minimize the damage of it. We haven’t seen this level of sophistication yet, but the industry thinks it’s coming. It’s just a matter of who’s going to get there first, offense or defense, and when it’s going to happen.”