While you’re worrying about Hackerbot 3000, don’t forget about Human 1.0

Photo credit: Sebastiaan Stam via Unsplash

Let’s use the term Hackerbot 3000 to refer to all of those AI models which supposedly present a new and unprecedented level of cyber threat. These threats have been framed in a few alarming ways: AI companies have declared that their models are too dangerous to be released; governments have imposed restrictions and regulations; and AI organisations have revealed that they have made successful cyber attacks on other organisations (although that’s not quite how they describe it).

I like the term Hackerbot 3000, partly because it is silly (and, despite the seriousness of these threats and their consequences, there is something silly about the rogue AI agent cyber attack narrative), but also because it captures the impression that we are confronted with faceless, implacable and dangerous machines which, just like the T-800 in the original Terminator film, can't be bargained with, can't be reasoned with, don’t feel pity, or remorse, or fear, and absolutely will not stop . . . ever!

Given the hype, rhetoric, obfuscation and marketing value of these claims, it is hard to determine their truth. It may be that the latest AI models are capable of constructing completely novel cyber attacks, or it may be that they are capable of reorganising and synthesising information which already existed. It may be that AI agents have displayed unexpected levels of autonomy and breached containment, or it may be that the companies which built them are bad at implementing basic controls.

Given the difficulty of assessing the threat, it might seem best to assume the worst, and respond by strengthening cyber security defences. I think that is actually a reasonable thing to do, but not because of the supposed threat from advanced models and AI agents. It is a reasonable thing to do because it of the threat which already exists.

The reality is that the primary threat to most organisations does not come from obscure zero day vulnerabilities detected by advanced AI models, exploited through complex and subtle combinations of commands. It comes from vulnerabilities which were identified days, months or years ago, for which the patches have not yet been applied. It comes from systems running beyond the end of their supported life, for which patches are no longer even issued. It comes from bespoke code implemented in a rush, where the penetration testing was skipped in order to meet a go live date. It comes from people downloading unauthorised software because the approvals process takes too long, and clicking on links in emails because they skipped the phishing training.

The biggest threats come from humans, and will continue to come from humans. Some of these humans are malicious: the people who steal data and compromise systems. But most of them (including me at various times in my career) are simply ignorant, stressed, overworked, prone to mistakes and insufficiently attentive to their accountabilities. Humans create vulnerabilities (even if they do so at great speed using AI coding agents); humans make bad choices about the priority of maintenance and patching; humans fail to invest in the removal or remediation of legacy systems; and humans cut corners, compromise controls and fall for scams.

Panicking about the imminent threat of Hackerbot 3000 is like securing your house by installing cameras and motion detectors, while leaving the windows and doors wide open. The advanced measures serve a purpose, and could form part of your defence in depth strategy, but are useless unless you have addressed the basics.

At the same time, we should not judge those people panicking about Hackerbot 3000 too harshly. After all, they are being bombarded with news which encourages them to panic. This is not a new trend in cyber security, either in popular culture or professional life.

Popular depictions of hacking typically show cool people in sunglasses typing at speed and manipulating 3D objects on a screen, or sneaking through a building and evading laser sensors to access the mainframe. I’m in. In our professional life, we talk in jargon, using codewords for attacks, and adopting military-inflected terms such as killchain and attack vector.

It should not be a surprise, therefore, that people without cyber expertise get the impression that attackers are mysterious, well-equipped, patient and sophisticated. Some attackers fit that profile, but organisations are just as vulnerable to mundane, crude criminals who can execute a basic scan and download a script from the Internet.

Perhaps this mystique is necessary. After all, organisations routinely underinvest in their cyber capabilities, are routinely hacked as a result, and routinely fail to make sustained changes in their behaviour. Perhaps the image of the cool hacker in sunglasses, or their AI counterpart, Hackerbot 3000, is required to get them to take the threat seriously. But I am optimistic by nature, and hope that honesty can win over hype: perhaps if we explain things better, we might get the action we need.

Previous
Previous

AI leadership needs practical wisdom

Next
Next

Let’s avoid the equation ai_fragility * software_fragility = very_bad_things