NCSC Warns: AI Defense Lags Behind Offensive Capabilities
A senior official at the **National Cyber Security Centre (NCSC)** has issued a stark warning: artificial intelligence currently provides a significant advantage to attackers over defenders. This imbalance is projected to fuel a rise in AI-enabled cyberattacks as automated defensive systems struggle to keep pace with evolving threats.
The cybersecurity landscape is on the cusp of a profound transformation, driven by the rapid advancements in artificial intelligence. However, according to **Dave Chismon**, the **NCSC**βs chief technology officer for architecture, this transformation is not symmetrical.
In a recent blog post, Chismon highlighted a critical imbalance: attackers can leverage AI more freely than defenders. This disparity suggests an impending surge in AI-powered cyberattacks, with automated defenses likely to be outmaneuvered.
### The Attacker's Advantage: Technical vs. Political Problems
Chismon's argument hinges on a maxim from security researcher **Halvar Flake**: "All offensive problems are technical problems, and all defensive problems are political problems."
Attackers, operating in a largely technical domain, have clear metrics for success. An exploit either works, or malware successfully "calls home." This unambiguous feedback loop is ideal for automated tools and AI systems.
Defensive operations, conversely, lack such clear-cut success states. It's often difficult for an automated system to definitively determine if a defensive action truly worked, or if an attack was simply averted by other means.
### The High Stakes of Defensive Actions
Beyond the measurement challenge, defensive actions carry significant risks. Unlike an attack that might simply fail, a botched defensive move β such as a patch that takes down a VPN or a firewall rule that disrupts business operations β can cause the very disruption it was meant to prevent.
Given these steep downsides and the difficulty in measuring success, human oversight becomes critical. Chismon noted that some board members might see little difference between a successful attack and a self-inflicted outage, "except that the board canβt shout at an attacker over the phone."
This inherent risk and accountability mean defenders "simply cannot put AI to work in the same way attackers can," an "inconvenient truth" as Chismon describes it.
### Early AI Adoption and Future Plans
Despite these challenges, the **NCSC** is actively exploring AI for defense. The agency is developing **Cyber Shield**, a capability designed to deploy agentic AI systems for discovering and remediating cybersecurity vulnerabilities across government networks and critical national infrastructure.
Chismon advises organizations to begin with low-risk AI applications, such as using AI to summarize threat intelligence for human analysts. The **NCSC** blog provides a framework to assess the risk of automation based on its reach, impact, criticality, predictability, and reversibility.
However, he acknowledges that making autonomous defensive actions safe enough for widespread deployment remains an unsolved problem. To address this, the **NCSC** will soon publish an "AI for Cyber Defence" research agenda as part of the **Cyber Shield** initiative.
### A Call for Continued Traditional Security
For now, Chismon cautions against over-reliance on agentic defense, stating it's not yet ready and will require substantial time, effort, and research. In the interim, organizations "cannot risk just waiting for agentic defence to roll in and protect them" and must continue enhancing their security through "the traditional way."
Concerns about AI's impact on cybersecurity are echoed across the global intelligence community. The **Five Eyes** intelligence alliance, of which **GCHQ** (the **NCSC**'s parent agency) is a part, warned in June that frontier AI could reshape offensive and defensive cyber operations within months. Similar apprehensions have been voiced by the chair of the **G20**βs financial stability board and Chinaβs top intelligence official.