Nearly half of security professionals agree GenAI is their biggest security risk

HackerOne has revealed data that found 48% of security professionals believe AI is the most significant security risk to their organization.

  • Sunday, 22nd September 2024 Posted 1 year ago in by Phil Alsop

Ahead of the launch of its annual Hacker-Powered Security Report, HackerOne revealed early findings, which include data from a survey of 500 security professionals. When it comes to AI, respondents were most concerned with the leaking of training data (35%), unauthorized usage of AI within their organizations (33%), and the hacking of AI models by outsiders (32%).

When asked about handling the challenges that AI safety and security issues present, 68% said that an external and unbiased review of AI implementations is the most effective way to identify AI safety and security issues. AI red teaming offers this type of external review through the global security researcher community, who help to safeguard AI models from risks, biases, malicious exploits, and harmful outputs.

“While we’re still reaching industry consensus around AI security and safety best practices, there are some clear tactics where organizations have found success,” said Michiel Prins, co-founder at HackerOne. “Anthropic, Adobe, Snap, and other leading organizations all trust the global security researcher community to give expert third-party perspective on their AI deployments.”

Further research from a HackerOne-sponsored SANS Institute report explored the impact of AI on cybersecurity and found that over half (58%) of respondents predict AI may contribute to an “arms race” between the tactics and techniques used by security teams and cybercriminals. The research also found optimism around the use of AI for security team productivity, with 71% reporting satisfaction from implementing AI to automate tedious tasks. However, respondents believed AI productivity gains have benefited adversaries and were most concerned with AI-powered phishing campaigns (79%) and automated vulnerability exploitation (74%).

“Security teams must find the best applications for AI to keep up with adversaries while also considering its existing limitations — or risk creating more work for themselves,” said Matt Bromiley, Analyst at The SANS Institute. “Our research suggests AI should be viewed as an enabler, rather than a threat to jobs. Automating routine tasks empowers security teams to focus on more strategic activities.”

Black Kite and Sayari have partnered to combine cyber risk data with corporate and supply chain intelligence for third-party risk management.
SonicWall has introduced the NSv XS, a subscription-based virtual firewall designed for small and distributed environments, offering enhanced...
By integrating the Alteryx One platform, the Marine Conservation Society has enhanced its data processing, driving meaningful environmental...

State of the channel 2026: navigating the AI era

Posted 2 days ago by Sophie Milburn
The latest GTIA report reveals AI's dominant role in the future of IT service provision across the UK and Ireland.
63% report operational downtime while manual IT/OT coordination continues to slow response.

Integris expands global reach with acquisition

Posted 1 week ago by Sophie Milburn
Integris has acquired First Focus to expand its MSP footprint and broaden services for SMB customers.
Climb Channel Solutions UK introduces a model emphasising personal connections to improve MSP growth, aiming to challenge platform-centric IT...

AI trust fails to keep pace with rate of adoption

Posted 1 week ago by Phil Alsop
Two thirds of organisations (64 per cent) are actively using artificial intelligence across the UK, a 12 per cent increase from last year according...