The vast majority (93%) of businesses now worry that AI-driven attacks will be a daily concern by the close of 2024, a new survey by Netacea has revealed.
Despite the potential impact of AI on cybersecurity as a threat-enhancement tool still being hotly debated, cyber leaders are gearing up for an all out cyber war, driven by AI advancements.
About two in three leaders (65%) predict that offensive AI – using AI as part of a threat attack – will soon be standard practice among cyber-criminals.
AI has already lowered the entry barrier for threat actors, allowing less skilled and tactful instigators create malware and more effective and sophisticated social engineering campaigns.
But the attack vector of most concern to business leaders, according to the survey, is ransomware, as noted by around half of CISOS (48%). Phishing (38%), malware (34%), bot attacks (16%), and data exfiltration (13%) followed.
Concerns over AI are parallel to overall security concerns, with the list of attack vectors falling in the same order when CISOs were asked what they saw as the greatest threat in the coming six months.
Defending against AI typically requires AI, but the majority (83%) of businesses surveyed in an Office of National Statistics 2023 poll said they had no plan to adopt AI in 2024.
Small businesses will more limited resources were typically less likely to plan on adopting the emerging tech than larger companies, despite the UK government promising financial aid for AI initiatives.
Large organisations that have adopted AI are implementing it into their defence, Netacea found, showing that 100% of enterprises have incorporated AI within their security stack to some degree.
Despite expecting AI-driven attacks across several fronts, the majority (90%) of respondents are confident in their organisations’ AI capabilities of perimeter defenses such as WAF, DDoS and API security.
Recommended reading
- Strong Cybersecurity Key to AI Superpower Ambitions, Microsoft Says
- NCSC Releases Cyber Incident Response Guidance for CEOs
- AI Brings Cybersecurity Woes to the Fore
However, just 60% felt the same about bot management. This does seem to align with security strategies, as enterprises are typically more often using AI in DDoS, WAF and API security than for bot management.
This could be because CISOs are often seeking a single vendor approach to security, with a third (33%) having or planning to consolidate specialised solutions.
“AI is a means to an end. The attacker has an objective and will use any and all tools available to achieve it as quickly and cheaply as possible,” Cyril Noel-Tagoe, principle security researcher at Netacea said.
“However, we are still in the test and learn phase. And yes, that applies to both the attackers and the defenders. As attackers become more confident, and proven use cases emerge, we can expect an explosion of offensive AI. That will require a reciprocal explosion in defensive AI.”





