Blog

Artificial intelligence is changing the rules of cybersecurity

For decades, cybersecurity mainly consisted of protecting systems against attacks initiated by humans. The tools evolved and the methods grew more sophisticated, but behind every intrusion there was generally a person or a group able to identify a vulnerability, exploit it, and move through the targeted infrastructure. That reality is changing fast.

The most recent research suggests that some artificial intelligence agents are now capable of autonomously chaining together several stages of a cyberattack. In controlled experimental environments, they succeeded in identifying vulnerabilities, compromising servers, deploying their own execution environment, and continuing their operations on other systems, with no human intervention while the scenario was running.

This work does not mean that companies today face autonomous artificial intelligences spreading freely across the Internet. The researchers conducted their experiments in a controlled laboratory, on deliberately vulnerable applications and without the protective mechanisms usually found in production environments. They acknowledge these limitations themselves. That said, the results demonstrate an important trend: artificial intelligence is gradually becoming capable of executing complete sequences of actions that previously required human intervention at every step.

For organizations, this shift profoundly changes the way cybersecurity must be considered. In the past, companies concentrated their efforts on protecting perimeters: firewalls, antivirus, access control, network segmentation, security patches, and event monitoring. These mechanisms remain indispensable, but on their own they no longer answer one essential question.

Is my organization behaving, right now, the way it should normally behave?

Every company has a digital signature of its own. Employees connect according to certain habits, applications exchange data at relatively predictable rates, backups run at known times, systems communicate with identified partners, and bandwidth consumption generally follows relatively stable profiles.

When a behavior suddenly departs from that reality, it is not necessarily a cyberattack. It may be a new application, an exceptional project, a configuration error, or a legitimate operational change. But it may also be an event that warrants immediate investigation. That is why understanding the organization's normal behavior is becoming an essential complement to traditional cybersecurity tools.

We believe companies will gradually have to move beyond simply monitoring devices and develop genuine behavioral intelligence of their digital flows. It is no longer only a matter of knowing whether a server is active or whether a firewall is blocking a connection, but of understanding how the organization normally operates in order to quickly recognize any behavior that departs from that baseline.

This approach adds a new dimension to cybersecurity. It helps detect unusual activity, whether it stems from human error, malware, an internal compromise, or, tomorrow, artificial intelligence agents capable of acting with growing autonomy.

Artificial intelligence represents a tremendous opportunity to accelerate innovation, improve productivity, and expand organizations' analytical capacity. It is also transforming the nature of the risks companies will have to face in the coming years.

Quantum Beyond believes that digital resilience will still rest on an accumulation of security technologies, but that it will also rest on the ability to understand how the organization actually operates, to learn its normal behaviors, and to recognize, almost instantly, when an event no longer matches what should normally be happening.