For a long time, the typical approach to cybersecurity has been reactive: systems watch for certain kinds of problems or threats to pop up, and when they spot one, they react.
A reactive approach does provide a level of protection. But reactive cybersecurity tools can’t catch every threat, and it doesn’t always react swiftly enough to eliminate all risk or damage.
Now, AI is changing the landscape. New AI-powered proactive systems are finding threats before they become real attacks. But on the flipside, AI-enhanced cyberattacks are a looming threat.
Microsoft recently made the news with some positive new developments in proactive cybersecurity. So this week we’ll share what’s new with Microsoft, how AI is changing cybersecurity, and what aspects aren’t really changing at all.
Microsoft MDASH
Microsoft has been using AI internally to look for security vulnerabilities within Windows 11 itself.
The system is made up of over 100 AI agents, all built internally to work together to identify vulnerabilities before the bad guys do. The name MDASH — a clever nod to generative AI’s inexplicable love for the punctuation mark enclosing this phrase — is clever, and the concert is a sound one.
MDASH agents poke around in all corners of Windows, looking for vulnerabilities no human has discovered yet. AI agents can do this work at a scale no sustainable human team can match, and it’s helping make Windows more secure.
Microsoft stated that in initial testing, MDASH identified numerous previously unknown vulnerabilities, including some critical vulnerabilities and some that could be executed remotely.
Fewer False Positives
One weakness of automated and AI-powered proactive systems has been the number of false positives — kind of an “AI that cried wolf” situation.
Essentially, these are complex vulnerabilities that require sometimes significant human effort to investigate. A system that delivers a bunch of false positives — vulnerabilities that aren’t real or aren’t usable — doesn’t help all that much. Human engineers could get so lost in the false positives that they still miss the real threats.
MDASH seems to have gotten a handle on this issue, reliably pointing engineers to real risks.
An AI Cybersecurity Arms Race?
Of course, as with every other aspect of life and tech that AI touches, AI is a double-edged sword. It makes the good guys better, but it makes the bad guys better, too.
So it’s only a matter of time before cyber criminals find success using similar AI agents to find vulnerabilities in major systems. This requires greater diligence and innovation on the cybersecurity side, which leads to further advancements on the cyberattack side, and so on.
All of this is with ever-more-complex scenarios, both defenses and attacks.
So what’s a small business to do?
The honest reality for most small businesses is that they rely on the big tech firms to handle the frontline battles. You don’t have a small army of AI security professionals on your team, but Microsoft, Google, and all the other big firms do.
It’s programs like MDASH that feed into Windows Defender and other security products in the Microsoft ecosystem. Other third-party security tools add additional layers of protection.
If you aren’t sure whether your current setup is reliable or safe, we can help. Reach out anytime to discuss your current approach, and we’ll help identify any significant gaps.
The Good News: The Basics Aren’t Changing
There may not be much you can do if a rogue AI decides to target your small business with all its wrath and fury (or compute power). But the good news is most attacks just aren’t that complex.
Most still succeed based on stolen credentials, out-of-date software, and social engineering (like phishing attacks).
The same advice we’ve shared before still holds true:
- Keep software and operating systems up to date.
- Invest in appropriate security tools (and make sure they are properly configured).
- Have a backup and make sure it works.
- Develop a disaster recovery plan.
- Follow common sense and best practices around email, SMS, and links to avoid phishing and malware schemes.
That’s it for this week. Got questions? We’re here to help. Reach out anytime.