Discussion about this post

User's avatar
Ollie's avatar

NCSC has provided extensive guidance here to UK organisations

Retaining defensive advantage in the age of frontier AI cyber capabilities

https://www.ncsc.gov.uk/blogs/retaining-defensive-advantage-in-the-age-of-frontier-ai-cyber-capabilities

Preparing for a ‘vulnerability patch wave’

https://www.ncsc.gov.uk/blogs/prepare-for-vulnerability-patch-wave

10 questions to ask when using AI models to find vulnerabilities

https://www.ncsc.gov.uk/blogs/10-questions-ask-using-ai-models-find-vulnerabilities

then more generally on AI adoption for cyber defence and more broadly

Supporting AI adoption for UK cyber defence

https://www.ncsc.gov.uk/blogs/supporting-ai-adoption-for-uk-cyber-defence

Thinking carefully before adopting agentic AI

https://www.ncsc.gov.uk/blogs/thinking-carefully-before-adopting-agentic-ai

Careful adoption of agentic AI services with FIVEEYE peers

https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services

Software Bill of Materials (SBOM) for Artificial Intelligence - Minimum Elements with G7 partners

https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/SBOM-for-AI_minimum-elements.html

Understanding adversarial attacks against Machine Learning and AI

https://www.ncsc.gov.uk/paper/understanding-adversarial-attacks-against-machine-learning-and-ai

Ryan Baker's avatar

Everyone is talking about patching like that's the problem. The problem is deploying patches (and releases containing patches and framework updates containing patches supporting your releases built on the framework..): https://substack.norabble.com/p/deployments-cant-wait

In many ways the best thing many organizations could be doing is drop everything else and improve their deployment pipelines with whatever tools and staff they have available. If you have a great deployment pipeline, you might be okay. If not, it seems likely there will be a window you'll be at risk, and then it's up to a question of how much of a priority are you for the attackers?

A secondary action is layers and layers of security. But good luck deploying new layers if you're not good at deployment.

3 more comments...

No posts

Ready for more?