Distinguishing between hype and reality has always been a challenge in cybersecurity.
For years, industry commentators have repeated the refrain: “Defenders have to be right every time. Attackers only have to be right once.” And for security practitioners, these expressions can be frustrating because they perpetuate the idea that a major security breach is inevitable.
While it’s true that security incidents are inevitable (even failed attacks can cause disruption, after all), plenty of organizations have been able to avert major breaches with solid security practices.
Still, from time to time, major events in security and IT disproportionately benefit attackers. And, at least in the short term, the rapid advancement of LLMs and AI technology in general seems to be one such event.
The reason why AI appears to be such a problem for security teams is that it has radically lowered the bar for bad actors to launch serious attacks against as many targets as possible.
Reconnaissance is a good example. Machine learning and LLMs enable bad actors to automate target selection. For example:
At least for the time being, AI is not providing the same degree of benefit to security teams in addressing these threats. That may well change in the coming months, but that’s of little consolation today.
Naturally, strong encryption is essential to protect against all manner of cyber threats, including those that include AI. Effective implementation of encryption can prevent many attacks from achieving their objectives and thwart attackers’ attempts to access sensitive data.
But, naturally, encryption isn’t an entire security strategy.
Strong encryption protects content, but not metadata. Traffic analysis, timing attacks, and side-channel leakage all work around cryptography rather than through it. The most sophisticated attacks of the past few years have rarely involved breaking encryption. Instead, they have involved compromising endpoints, stealing keys, or abusing trust relationships in public key infrastructure.
PKI has its own substantial attack surface. Rogue certificates, compromised certificate authorities, and man-in-the-middle attacks against TLS handshakes have all featured in major incidents. Static keys and long-lived sessions widen the window for every kind of attack, AI-driven or not. And once an attacker has a foothold, time is on their side.
Effective security is a system of overlapping layers, each compensating for the gaps in the others.
Security practitioners have long organized this around three core functions: protection, detection, and response. But to make it easier to conceptualize, we might add two further dimensions: cyber hygiene, which underpins everything else, and validation, which ensures the other components are working properly. Together, these five layers provide defense-in-depth.
Cyber hygiene is the foundation. Configuration management, network segmentation, asset inventory, User Access Controls (UAC), and Network Access Controls (NAC) might not be exciting, but their absence is a common theme in post-incident reports. The CIS Controls offer a prioritized set of basic hygiene practices designed to prevent the most common threats.
Some experts consider cyber hygiene less as a security function and more like IT quality assurance: keeping the environment clean enough for every other control to do its job.
Protective controls like firewalls, Intrusion Detection and Prevention Systems (IDPS), and content filtering represent the first active attempt to stop attacks at the point of entry. Their job is to prevent most threats outright, preventing low- and mid-sophistication attacks from causing harm. Of course, not all attacks can be prevented altogether, but the more attacks that can be prevented, the fewer resources will be expended in the next layer.
Data protection (including cryptography but also functions like Data Loss Prevention) is a protective control because it aims to both prevent attacks from being successful and protect the organization from the harm associated with data theft.
Detection and Response catch what gets through. Anomaly detection, behavioral analysis, and SIEM and XDR platforms give security teams the visibility to identify threats that have bypassed protective controls. SOC and incident response functions act on detected threats by investigating, containing, and remediating before harm occurs. Naturally, speed matters. The faster an attack is detected, the less opportunity they have to act, and (usually) the less disruption they can cause.
Validation recognizes that security controls don’t always work as intended and may also degrade over time. Configurations drift, new attack paths emerge, and the threat landscape evolves. Security testing methods such as penetration testing, red teaming, and bug bounty programs provide ongoing assurance that controls across every security layer are operating as intended.
Notably, validation has become even more important in the “AI era,” as some previously viable controls may not withstand the latest threats, and “control drift” is likely to be exploited quickly.
Encryption protects data in transit, at rest, and (increasingly) in use. It's also the control that remains relevant even after an attacker has penetrated every other layer. But cryptography only delivers on that promise if it's visible and up to date.
Most organizations have cryptography running across dozens of systems, protocols, and integrations. However, many have no clear picture of which algorithms are in use, where they are used, or whether they are still viable. That visibility gap can be a huge problem, particularly since it often goes unnoticed until it’s too late.
AI-fueled reconnaissance can allow attackers to identify weak or outdated encryption technologies much faster and more easily than ever before. So, just as you should validate your other security controls, it’s also important to validate that your cryptographic estate is in good shape.
Encryption Intelligence gives organizations complete visibility into their use of cryptography. It identifies vulnerabilities, uncovers risks, and provides clear guidance to reduce exposure, helping ensure your encryption provides a sufficient safety net.
To find out how Encryption Intelligence can help you validate your cryptographic estate, make improvements, and support your PQC migration roadmap, visit our website.