Three distinct optical regions meet while a cool interior remains clearly bounded.

Cybersecurity

How AI Changes Cybersecurity Threats and Defence

Review how AI affects attacks, detection and the human response.

MT BYTES6 min read
Read the perspective

Separate the different AI security questions

A report about AI-assisted attacks, a vendor’s security assistant and an employee connecting an AI tool to company records raise different questions.

The first concerns changes in attacker capability. The second concerns whether a defensive tool improves the team’s work. The third concerns the information and permissions the business has exposed through its own adoption.

Keep those questions separate when deciding what to fund. Buying an AI-labelled security product does not automatically address an insecure AI integration. Restricting an internal tool does not remove the need to protect ordinary accounts and systems.

In its May 2025 assessment looking ahead to 2027, the UK NCSC judges that AI is likely to make parts of cyber intrusion more effective. It is an intelligence assessment of developing capability, not a measured forecast of attacks against an individual SME.

The practical response is to identify which business weaknesses become more consequential under faster or more effective misuse. That creates a basis for action without turning every new announcement into an urgent procurement decision.

Start with critical access, exposed services, important information and the ability to respond. Then examine where AI changes the assumptions around them.

AI adoption needs the same attention to ownership and change that other consequential systems require.

Verify requests through an authorised process

A convincing request can reach the business through email, messaging, voice or another channel. The safer operating question is whether the requested action follows an authorised process.

For changes to payment details, sensitive access or important records, use a verification route already known to the business. Do not rely only on the request’s writing style, urgency or apparent familiarity.

Make the rule practical for employees. They need to know which actions require verification, how to perform it and what to do if the requester applies pressure. A process that exists only in a policy document may not help during a busy working day.

Review access and update practices at the same time. If an important service has an exposed weakness or an account with excessive permissions, the business should address that exposure rather than assume staff awareness alone can compensate.

Keep the inventory current enough to identify affected systems when a relevant vulnerability or supplier issue appears. A faster response depends on knowing what the business uses and who can act.

Rehearse reporting. An employee who is uncertain about a request should have a straightforward way to pause and ask for help. Reward early reporting with a useful response, not a demand that the employee first prove an attack occurred.

Choose defensive AI for a defined task

AI-assisted security work may help a team organise evidence, summarise alerts or compare patterns. Evaluate a proposed use through the task it supports and the decision a person needs to make.

The August 2026 joint guidance on AI in cyber defence describes opportunities for analysis and defensive decision support while retaining human oversight and security fundamentals. For a small business, that suggests a bounded trial rather than a promise of complete automated protection.

Choose a reviewable output. An incident summary should point to relevant records. A proposed priority should explain the affected asset and the evidence. A recommendation should state the assumptions that would change it.

Test against representative known cases, including false alarms and incomplete information. Measure the analyst’s verification effort as well as the speed of the generated response. A tool that produces more plausible explanations can still create more work.

Check what information leaves the environment and where it is processed. Security data can contain sensitive details about users, systems and weaknesses. The tool’s access and handling arrangements need review.

Set a clear decision after the trial: continue within the tested scope, revise the use case or stop. The evaluation should remain open to all three outcomes.

Review the exposure your AI tools create

An AI system connected to company information becomes part of the technology estate. An agent that can act through tools also becomes part of the business’s permission structure.

Record the purpose, owner, data sources, connected services and permitted actions. Include employee-adopted tools where they are used for business work, not only centrally purchased platforms.

The joint guidance on careful adoption of agentic AI identifies risks across components, integrations and downstream use. Review those connections together instead of assessing the model in isolation.

Treat material retrieved from documents, messages or external pages as evidence for the task, not as authority to change the agent’s operating rules. Test how the system handles conflicting or malicious instructions embedded in that material.

Limit access to what the use case needs. A tool that drafts a response may not need permission to send it. A tool that analyses records may not need permission to alter them. Review permissions again when the use case expands.

Keep a route to suspend consequential actions without losing the records needed to understand what happened. The business should know who can make that decision and how normal work continues afterwards.

AI adoption needs the same attention to ownership and change that other consequential systems require.

Set stronger conditions before automating a response

Automatically collecting information has different consequences from disabling an account, blocking traffic or changing a production configuration.

Before permitting a defensive action, establish its scope, the evidence required and the effect on legitimate work. A false positive can interrupt a customer service or lock out an employee who is needed to respond.

Use enforceable limits and appropriate approvals. The operator should see the proposed action, affected resources and reason for escalation. Approval should not require reconstructing the entire incident from an unexplained recommendation.

Define how success is verified and how a mistaken action is corrected. Some actions can be reversed quickly; others leave operational consequences that require additional work.

Avoid loops in which an automated system repeatedly acts because the original symptom remains. Set stop conditions, limits and a route to a person who can reconsider the diagnosis.

Test the complete chain in a controlled environment or bounded scope. Include an uncertain result and a failed action, not only the expected successful case.

Defensive automation is useful when it improves the response without making its authority or consequences harder to understand.

Keep the security plan aligned with exposure

Review AI-related developments through the business’s actual exposure. A new threat capability matters when it changes the risk of a system or process the company depends on.

Keep a small set of priorities: critical access, supported systems, appropriate data handling, useful monitoring and a rehearsed response. Add AI-specific controls where the adopted tools or new evidence require them.

Assign ownership for reviewing AI services and defensive trials. Record changes to models, integrations, permissions and suppliers that could affect the original assessment.

Use incidents and exercises to improve the plan. If the team cannot identify an affected account, retrieve relevant records or reach the right supplier, resolve that operating gap before assuming another tool will compensate.

The next security decision should follow a change the business can identify in its own exposure. Keep the resulting action assigned, review its effect and preserve the team's ability to respond when the expected protection fails.

MT
MT BYTES

Perspectives on technology and business.

Explore perspectives

Review the security consequences of your AI use

MT BYTES can help assess a defined AI workflow, its access and its surrounding controls, or scope a bounded defensive use case. Bring the task and the systems or information it can reach.

Discuss your project