Opens in a new tab
vmblog logo 2024 wht (updated)

Ontinue 2024 Predictions: How CISOs Can Harness the Power of AI in 2024

Share: 

David Marshall | Published: January 18, 2024

vmblog-predictions-2024 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

How CISOs Can Harness the Power of AI in 2024

By Gareth Lindahl-Wise, CISO, Ontinue

An organization’s surroundings are in a constant state of change, especially with the rapid increase of artificial intelligence innovation this past year. There has been a lot of hype and promise around how it can streamline and transform business operations. Even with the speculation and uncertainty present, AI is showing itself to be resilient. Amid a wave of “disruptive” startups falling apart at a faster rate this past year, more than 25% of funding went to startups building AI products, and funding of AI startups has more than doubled from 2022 to 2023. Even with attempts to keep the fast-moving technology in check – such as the Biden Administration’s Executive Order on Artificial Intelligence in October – the adoption of AI within every facet of the technology stack will not wait for regulatory approval.

With that being said, I want to focus on the actual impact AI will have on security operations, zeroing in on how CISOs can practically implement it to squeeze as much value from as they can. There are three key areas within the security playbook CISOs can improve by harnessing the power of artificial intelligence.

Proactivity & a Streamlined Workforce

AI in security will evolve to not only identify and address emerging threats, but also strengthen defenders. AI-powered Security Operations (SecOps) can significantly improve an organization’s ability to prioritize efficiently, streamline a team’s efforts, and help respond to threats. It’s the organizations who harness AI, while also leveraging human expertise, that will be able to continuously strengthen their security posture, while allowing their staff to concentrate on their core competencies. In fact, according to a report from IBM, 25% of companies are adopting AI due to a shortage of personnel, to optimize operations and compensate for the lack of human resources. Over the next year, we’ll see more organizations find new ways to leverage AI in cybersecurity – so their teams can better prioritize, communicate and streamline operations. 

Prioritization

Organizations will start to demand transparency about how vendors actually apply AI, including the specific benefits they’ll see. Many Managed Security Service Providers (MSSPs) and Managed Detection and Response (MDR) providers rely on AI and machine learning (ML) to detect behavioral patterns indicative of attacks, inundating security teams with a barrage of alerts, often without guidance on prioritization or actionable insights. The issue is not always the use of AI or ML itself, but with the implementation that fails to filter and prioritize the alerts effectively. This flood of threats becomes counterproductive, especially when teams are already understaffed and overwhelmed. It is crucial to partner with a cybersecurity provider that effectively distinguishes and prioritizes genuine threats, offering actionable insights. 

Understanding Your Environment

Your organization’s environment is quite different from any other organization’s environment, down to the systems, workflows, access controls and people. The biggest potential of AI in cybersecurity lies in its ability to enhance its knowledge and capabilities as it gains a better understanding of an organization’s specific environment. Organizations are turning to MDR providers in record numbers to implement additional security expertise and 24/7 EDR and XDR service. But these providers lack the ability to properly triage, investigate, respond, or even prevent without an in-depth understanding of the environment being protected. Although AI has been used to dissect and understand threat behavior, it hasn’t been widely used to “localize” insights to each specific environment. This application of AI can significantly improve incident investigation, response, and prevention. CISOs need to ensure AI tools transcend mere alerting to provide customized insights, investigations, and responses tailored to your organization’s unique context. AI can continuously learn your organization’s environment so that the models can better determine relevant next steps. 

AI-powered security operations go beyond just these three applications, but these are three key ways CISOs can harness AI. In 2024, I believe the companies that will remain secure and innovative are the ones harnessing AI in these ways, as the hype around the technology settles down to make way for actual, practical and valuable implementation.

##

ABOUT THE AUTHOR

Gareth Lindahl-Wise 

As Chief Security Advisor and CISO, Gareth’s role has two focus areas. As CISO, Gareth is responsible for making sure that Ontinue’s own internal information security – as well as security for the Ontinue ION managed extended detection and response service platform – is appropriate to the threats we face and the trust our customers put in us. As the Chief Security Advisor, Gareth also has an outward-facing role to help raise awareness of new threats and novel ways of dealing with them. With Ontinue’s focus on Microsoft technologies, and the importance of people and processes, he helps potential customers understand where Ontinue’s services might fit.