AI SECURITY
CONTINUED
APIs and other non-human identities can multiply quickly, often with broad permissions and limited oversight. “Customers should be asking who or what has access to critical systems, which services really need to be exposed and how actions can be monitored and controlled. AI adoption needs guardrails from the outset, with clear governance and identity controls built in.” Rachel Rothwell, senior regional director at Zyxel Networks, says that as well as accelerating the cybersecurity arms race, AI is making the subject even more complex and difficult for businesses to understand and address. “This is especially worrying for SMBs who are almost certainly going to be targeted even more now that AI is being used to develop and broaden attacks,” she says. “Reseller and MSP partners need to make it as simple as possible for SMBs to deal with the threats – that was true before and it’s even more important now. We expect to see continued growth in this area and more partners offering simple managed security services to SMB customers – it’s still a big and growing opportunity.” Mike Barron, UK managing director at SYNAXON, says that for resellers and MSPs providing protection is more of a responsibility as well. “If they don’t have their own in-house expertise or capability, resellers and MSPs will need to form partnerships with vendors and service providers who can provide solutions that will safeguard their customers,” he says. Growing threats and expectations All commentators agreed that AI-driven threats will continue to grow and evolve in the coming months, although so will customer expectations. “Organisations will increasingly expect infrastructure that supports cyber resilience, sovereign control and AI simultaneously rather than treating them as separate technology investments,” says Paul. “AI is also being used defensively in areas such
as anomaly detection and recovery validation. This creates a significant opportunity for partners able to advise on long-term data infrastructure strategies instead of individual point products.” Alex agrees that customer buying behaviour will evolve quickly. “Recovery outcomes, operational resilience and independence from hyperscaler ecosystems will become bigger purchasing criteria alongside traditional cybersecurity capabilities,” he says. “That creates a significant opportunity for MSPs to deliver recovery testing, resilience assessments, governance and continuity services rather than simply selling backup licences. Backup will increasingly be viewed as a core operational dependency rather than an insurance policy.” Geert adds that the bigger shift is that cybersecurity is moving towards machine speed. “Attackers will use AI to move faster, but defenders will use it to detect, triage and contain threats faster too,” he says. “The challenge for customers is making sure they can operate at that speed without losing visibility, control or accountability. Strong governance, clear ownership and robust identity controls will become increasingly important.” Scott says AI is enabling faster and better defensive tools to be created, and patching of security vulnerabilities that have not been identified until now. “It feels like an arms race with AI being used by both sides,” he says. “If we want to stay safe, we need to make sure we keep getting the basics right and maintain good cybersecurity hygiene. “We also need to build AI fluency within our teams and partners, so that we understand where the risks may lie and how best to use security tools. Policy is also important, and we must continue to train people on what to look for and how to spot threats. Security and resilience need to be front and foremost in conversations around AI – at all levels in the business.” n
Contributors
Rachel Rothwell
zyxel.com
Mike Barron
synaxon-services.com
“
Attackers will use AI to move faster, but defenders will use it to detect, triage and contain threats faster too.
”
46
Powered by FlippingBook