GDN DESKTOP 1

Advertisement

The Next Cyberattack May Already Be Inside Your Organisation: Why Britain Must Rethink Cybersecurity in AI Age

Iyanuoluwa David Adeoye

By Iyanuoluwa David Adeoye

Cybersecurity can no longer be treated as an IT problem. Artificial intelligence, digital supply chains and increasingly sophisticated attackers mean cyber resilience must become a boardroom, business and national priority.

For decades, businesses approached cybersecurity much like they approached physical security: build strong walls, control the entrances and keep intruders outside.

That model is becoming dangerously outdated.

Advertisement

Today’s organisation may operate from an office in London while its data is stored in several cloud environments, its employees log in from homes and mobile devices around the world, its payroll is managed by one external provider, its customer platform by another, and its software contains thousands of components developed by people the organisation has never met.

Add artificial intelligence to this ecosystem and the attack surface becomes even more complex. The modern cybersecurity challenge is therefore no longer simply about keeping attackers out. Organisations must also be able to recognise when something has gone wrong, contain the damage, maintain important services and restore trusted operations quickly.

EFN Non Oil Export

The question facing business leaders should no longer be simply, “How do we stop cyberattacks?”

It should also be: “What happens to our organisation when one succeeds?”

Advertisement

Artificial intelligence is changing the threat

Artificial intelligence is often discussed as if it belongs exclusively to the future. In cybersecurity, however, its influence is already being felt. Generative AI can provide enormous benefits. Security teams can use AI-supported tools to analyse large volumes of information, identify anomalies, assist with security investigations, improve vulnerability management and accelerate repetitive tasks.

Software developers can use AI to help write and review code. Businesses can deploy AI assistants to improve productivity, customer service and decision-making. But technologies available to defenders are also available to attackers.

One particularly important example is phishing. For years, security awareness training taught employees to look for spelling errors, strange language and poorly written emails. Generative AI weakens that defence. A malicious actor no longer needs excellent English or specialist writing skills to construct a convincing message.

Highly polished emails can be produced almost instantly. The significance of this becomes clearer when we consider that phishing remains Britain’s most common form of cyberattack. AI can potentially make those attacks more personalised. Imagine an employee receiving an email apparently written by a senior manager. The writing style appears professional. The names are correct. The project referenced is real. The message creates urgency and directs the employee to a convincing login page.

Traditional advice such as “look for bad grammar” becomes increasingly inadequate. The European Union Agency for Cybersecurity has also documented malicious actors exploiting interest in AI itself.

Passwords are no longer enough

One of the most important changes organisations can make is to stop treating a password as sufficient proof of identity. Cybercriminals do not always need to “hack” through a sophisticated technical defence. Sometimes they simply log in.

Credentials can be obtained through phishing, malicious software, password reuse or other forms of account compromise. Once an attacker possesses legitimate credentials, the activity may initially appear similar to that of a normal employee.

This is why identity has become one of the most important cybersecurity battlegrounds. Organisations should increasingly adopt the principle of Zero Trust. Zero Trust does not mean trusting nobody. Nor does it mean requiring employees to prove who they are every thirty seconds.

Advertisement

It means abandoning the assumption that someone or something should automatically be trusted simply because it has already entered the corporate network. Access should be based on factors such as identity, device security, the sensitivity of the information being requested, privilege levels and unusual behaviour. Someone working in finance, for example, may legitimately require access to financial systems. That does not mean the same account should automatically have administrator privileges across unrelated infrastructure.

Similarly, if a legitimate account suddenly attempts to download enormous quantities of sensitive data from an unusual location, the organisation should be able to recognise that the behaviour deserves scrutiny.

The principle is simple: Give people the access they need, when they need it, but minimise the damage that can be caused if their account is compromised.

Cybersecurity begins in the boardroom

There is another misconception that urgently needs correcting: cybersecurity belongs to the IT department. IT teams certainly play an essential role, but cybersecurity is fundamentally a business-risk issue. Consider a ransomware incident affecting a manufacturing company.

The immediate technical problem may involve compromised servers. But the consequences quickly extend beyond IT. Production may stop. Orders may not be processed. Employees may be unable to work. Customers may lose access to services. Personal information may have been stolen. Regulators may need to be informed. The communications team may need to respond publicly. Lawyers, executives, insurers, suppliers and law enforcement could all become involved.

Cybersecurity is therefore not merely concerned with protecting computers. It is concerned with protecting the organisation’s ability to operate. Yet Britain’s latest statistics suggest that many businesses still have significant gaps in preparedness.

Only 25 per cent of UK businesses reported having a formal incident-response plan in the Government’s  survey. That means many organisations discovering cyber incidents may still be forced to make important decisions while the crisis is already unfolding. Who has authority to disconnect a critical system? Who contacts customers? Where are clean backups stored? How will staff communicate if normal systems are unavailable? Which services must be restored first? Which external specialists should be contacted? These questions should not be answered for the first time during an attack.

Cybersecurity plans must also be tested. A document stored somewhere on a corporate drive does not prove that an organisation can recover from an incident. Cyber exercises, including realistic tabletop simulations, can reveal weaknesses that would otherwise remain invisible until a genuine crisis occurs.

The weakest organisation may be your supplier

Another major cybersecurity challenge is the extraordinary dependence businesses now have on third parties. Few organisations build and operate their entire digital infrastructure themselves. They depend on cloud providers, payment processors, software companies, contractors, managed service providers, telecommunications companies and countless software libraries.

This means an organisation’s security increasingly depends on companies outside its direct control. Yet only 15 per cent of businesses formally reviewed cybersecurity risks associated with their immediate suppliers according to the latest UK breaches survey. This deserves much greater attention.

Businesses do not need to assess every supplier as though it represents the same level of risk. The supplier delivering office furniture does not necessarily deserve the same scrutiny as a company that hosts customer information or has administrative access to critical systems. The first step should be identifying which suppliers could seriously affect the business if they were compromised.

Businesses should ask: Who holds our sensitive data? Which companies can access our systems? Which external services would prevent us from operating if they became unavailable? Who is responsible for security when our information crosses organisational boundaries?

These are governance questions as much as technical ones.

Stop measuring cybersecurity by the number of attacks blocked

There is also a problem with the way success in cybersecurity is sometimes measured. A company might proudly announce that its security systems blocked one million malicious emails. That sounds impressive. But the figure tells us surprisingly little about whether the organisation is actually resilient.

More meaningful questions include: How quickly can we detect a compromised account? How many critical systems are protected by strong authentication? How quickly are dangerous vulnerabilities addressed? Do we know which systems are genuinely critical? Could we restore our essential services from trusted backups? How much access would an attacker obtain if one employee account were compromised? How quickly could that access be revoked? How often do we test our incident-response procedures?

These measurements focus on outcomes rather than activity. No organisation can reasonably conclude that cyber risk is disappearing.

Build systems expecting that something will eventually fail

One of the most valuable principles in modern security engineering is surprisingly simple: Assume that something will eventually go wrong. This is not pessimism. It is responsible engineering. Banks do not abandon vaults simply because they also install alarms. Aircraft are not designed around the assumption that no component will ever malfunction.

Fire safety does not consist solely of trying to prevent fires; buildings also have detectors, evacuation procedures, fire-resistant materials and emergency services. Cybersecurity should adopt the same philosophy. We should continue trying to prevent attacks while simultaneously designing organisations that can survive them. If one computer becomes compromised, it should not automatically expose an entire company. If one password is stolen, it should not provide unlimited access. If one supplier experiences an outage, critical operations should have contingency arrangements. If ransomware encrypts important systems, organisations should have tested recovery processes.

If unusual activity occurs, security teams should have sufficient visibility to recognise it. This is the difference between cybersecurity and cyber resilience. Cybersecurity attempts to reduce the likelihood of harmful events. Cyber resilience asks whether the organisation can continue functioning when preventive measures are not enough. We need both.

People remain part of the defence

The cybersecurity industry frequently says that humans are the “weakest link”. I believe that description is incomplete. People can certainly make mistakes. Employees click malicious links, reuse passwords and occasionally send information to the wrong recipient. But employees can also recognise suspicious behaviour, report unusual requests and prevent incidents from escalating.

Instead of treating workers as security problems, organisations should design security around human behaviour. Security training should be relevant and continuous rather than a compliance presentation delivered once a year. Reporting suspicious messages should be simple.

Employees should not fear punishment for promptly reporting genuine mistakes. Security controls should reduce dependence on perfect human judgement. Multi-factor authentication, restricted privileges, automated detection and secure default configurations are particularly important because even well-trained employees will occasionally be deceived. The purpose of cybersecurity should not be to create perfect humans. It should be to create systems capable of tolerating human imperfection.

Britain has an opportunity

The cyber challenge should not be discussed only in negative terms. Britain has an opportunity to position cybersecurity as an enabler of digital growth. Businesses increasingly depend upon customers trusting them with personal information, payments and digital services.

Artificial intelligence, fintech, healthcare technology, smart infrastructure and cloud services will only achieve their potential if people believe the underlying systems can be trusted. Security therefore should not be viewed simply as a cost imposed on innovation.

Done properly, cybersecurity enables innovation. A company with strong identity management can allow employees to work flexibly without abandoning security. An organisation that understands its data can adopt AI more confidently. A business with tested incident-response and recovery capabilities can pursue digital transformation with a clearer understanding of its risks.

Software built securely from the beginning costs less to protect than technology requiring security to be added after problems appear. Cybersecurity can therefore become a competitive advantage.

Author Bio

Iyanuoluwa David Adeoye is an emerging Cybersecurity Specialist with early-career experience and a Master’s degree in Cybersecurity from the University of Chester, United Kingdom. His current areas of professional focus include Penetration Testing, Active Defence, Digital Forensics, Incident Response, and Governance, Risk and Compliance (GRC).

Alongside his academic studies, David has actively pursued opportunities to broaden his practical exposure to the United Kingdom’s cybersecurity landscape. Through volunteering, internships, and hands-on cybersecurity roles, he has gained valuable insight into security operations, organisational security practices, and the practical application of cybersecurity principles within professional environments.

David is continuously developing his technical capabilities through practical projects, hands-on labs, and real-world security scenarios. His commitment to continuous learning, combined with his growing technical experience, positions him to contribute effectively to cybersecurity teams while continuing to develop into a well-rounded security professional.

Join Our Channels

Taboola Recommendation Widget