{"id":20460,"date":"2018-07-25T14:01:12","date_gmt":"2018-07-25T13:01:12","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/2018\/07\/25\/from-hype-to-reality-paladion-expert-on-ai-in-cybersecurity\/"},"modified":"2018-07-30T11:48:44","modified_gmt":"2018-07-30T10:48:44","slug":"from-hype-to-reality-paladion-expert-on-ai-in-cybersecurity","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2018\/07\/25\/from-hype-to-reality-paladion-expert-on-ai-in-cybersecurity\/","title":{"rendered":"From hype to reality: Paladion expert on AI in cybersecurity"},"content":{"rendered":"<p><em>Jose Varghese, EVP and HEAD \u2013 MDR Services at Paladion, explores AI and the role it will continue to play in combating modern cyberthreats.<\/em><\/p>\n<p>Artificial Intelligence (AI) in cybersecurity has recently made several headlines. These headlines make seasoned cybersecurity professionals wary. We\u2019ve seen other emerging technologies receive similar attention and we\u2019ve seen many of them fail to live up to their expectations.<\/p>\n<p>In this article, we will build a real-world perspective on AI in cybersecurity. We will explore where skepticism regarding AI in cybersecurity is justified, how the technology can provide tangible value and what to look for in an AI-driven cybersecurity provider.<\/p>\n<p><strong>Why we really do need to bring AI to cybersecurity<\/strong><\/p>\n<p><strong>\u00a0<\/strong>Much of the scepticism regarding AI\u2019s application to cybersecurity comes out of a faulty understanding of why we are bringing this technology to our field in the first place. For sceptics, our industry is only discussing AI in cybersecurity because it is a hot tech topic in general and some vendors are bringing it to cybersecurity to simply cash in on the trend.<\/p>\n<p>It\u2019s undeniable that there are some unscrupulous vendors looking to do just that. But we\u2019ve needed to bring a technology like AI to cybersecurity for a long time now due to fundamental changes in the threat landscape.<\/p>\n<p>Over the last five to 10 years, nearly every organisation has undergone digital transformation by adopting cloud, mobile and IoT. These technologies have opened up amazing new organisational capabilities but they have also created new complexities, interconnections and vulnerability points that cybercriminals have quickly learned to exploit. Their new wave of creative, complex, multi-channel attacks flood organisations with thousands of alerts and hundreds of thousands of potentially malicious files to analyse every day.<\/p>\n<p>Traditional perimeter and rules-based approaches to cybersecurity no longer apply to the new digital organisation and human-only cybersecurity teams cannot process the flood of threat data they now contend with every day. Artificial Intelligence\u2019s speed, accuracy and computational power offers our only chance to protect a perimeter-less organisation and to continuously process the overwhelming volume of threat data every organisation now faces daily.<\/p>\n<p><strong>What value AI does and does not offer to cybersecurity<\/strong><\/p>\n<p><strong>\u00a0<\/strong>Now, even though AI is necessary to protect the new digital organisation against next-generation threats, that does not mean AI is a \u2018magic bullet solution to modern cybersecurity problems. AI offers a necessary \u2013 but limited \u2013 element of modern cybersecurity.<\/p>\n<p>These limitations of AI\u2019s application to cybersecurity are not discussed often enough, contributing to the sense that AI is simply hype. Many discussions of AI technology describe it as a kind of generalised human intelligence that can handle every single aspect of cybersecurity on its own, rendering human cybersecurity expertise obsolete.<\/p>\n<p>This is not true. In the real world, AI primarily focuses on deploying Machine Learning (i.e. the automation of data science activities) to process massive quantities of threat data. AI\u2019s ability to perform these activities at near-unlimited scale, with near real-time speeds, makes it an invaluable ally within a modern, effective cybersecurity program.<\/p>\n<p>And these activities can be performed at every stage of cybersecurity, allowing AI to offer value before, during and after an organisation suffers an attack. But they do not replicate human insight. They do not obviate the need for human cybersecurity experts. And they limit the areas where AI offers the most real-world value to cyberdefence.<\/p>\n<p><strong>Where AI offers the most real-world value to cyberdefence<\/strong><\/p>\n<p><strong>\u00a0<\/strong>At the moment, AI\u2019s data-processing capabilities offer the most value to the following areas of cyberdefence:<\/p>\n<ul>\n<li><strong>Threat anticipation:<\/strong> AI can process over 100 TB of global threat data daily, from hundreds of threat intelligence feeds, to determine which emerging threats are most likely to attack your organisation, allowing you to then proactively adapt your defences against them \u2013 before they strike<\/li>\n<li><strong>Threat hunting:<\/strong> AI can constantly monitor and comb through all of your organisation\u2019s data \u2013 not just your security data \u2013 to detect patterns, anomalies and outliers that indicate a likely compromise (even if that compromise does not conform to known attack patterns)<\/li>\n<li><strong>Alert triaging:<\/strong> AI can deploy Machine Learning methods \u2013 such as historical patterning, clustering, association rules and data visualization \u2013 to quickly filter out false positives, reducing the burden on your security team<\/li>\n<li><strong>Incident analysis and investigation:<\/strong> AI can provide data-based answers to threats, in order to quickly determine the identity of the attacker\u2019s identity, map the attack chain and define the attack\u2019s spread and impact<\/li>\n<li><strong>Incident response:<\/strong> AI can centralise and quickly orchestrate a comprehensive response that automates playbooks and includes containment, recovery, mitigation and defensive improvements to get you back to business ASAP<\/li>\n<\/ul>\n<p>While these activities are impressive \u2013 and now essential \u2013 it\u2019s important to note they can only be brought to your organisation through the correct AI deployment \u2013 which is harder to get right than you might think.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jose Varghese, EVP and HEAD \u2013 MDR Services at Paladion, explores AI and the role it will continue to play in combating modern cyberthreats. Artificial Intelligence (AI) in cybersecurity has recently made several headlines. These headlines make seasoned cybersecurity professionals wary. We\u2019ve seen other emerging technologies receive similar attention and we\u2019ve seen many of them [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":20466,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,275,399,258,262],"tags":[496,386,388,6018,390,6019],"class_list":["post-20460","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-intelligent-technology-newsletter","category-more-news","category-newsletter","category-used","tag-ai","tag-artificial-intelligence","tag-cybersecurity","tag-evp-and-head-mdr-services-at-paladion","tag-iot","tag-jose-varghese"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/20460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=20460"}],"version-history":[{"count":6,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/20460\/revisions"}],"predecessor-version":[{"id":20468,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/20460\/revisions\/20468"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/20466"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=20460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=20460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=20460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}