Why cyber sovereignty will be a struggle

0
1
Data security abstract background with locks, key, numbers, world map and abstract circles. Used clipping and opacity masks.

By Rob Demain, CEO of e2e-assure

 For a limited period, Europe got to see what it feels like to be excluded from the party when it comes to AI. The temporary export ban brought in by the US government on Anthropic’s Mythos 5 and Fable 5 frontier models was initially met with disbelief and saw European politicians double down on their commitments to develop home-grown alternatives. That renewed vigour is warranted given that approximately 75% of the world’s total compute capacity for AI rests in the USA’s hands, versus 15 percent in China and just 10 percent in Europe, according to the Tony Blair Institute for Global Change.

The same report also declares that France leads the way in terms of the most developed AI solution, with an AI sovereignty lab that uses the Mistral frontier model run over state-owned super computers and local data centres. But it’s the UK and Germany that are championing the use of AI for defence, with both sinking billions into AI from their defence budgets. They’re all too aware of not just the potential but also the threat advanced models posed; a threat the Five Eyes Alliance voiced in July when it warned frontier models are just months away from having the capability to launch devastating attacks against businesses, critical infrastructure and governments.

Join The European Business Briefing

New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.

Subscribe

What the Cyber Shield will comprise 

In the UK, the government has proposed the invention of a ‘Cyber Shield’ to fight fire with fire. This new national cyber defence capability “will hardwire cutting-edge agentic AI into machine-speed cyber defence”, states GCHQ Director, Anne Keast-Butler, the idea being to partner with network defenders to test and deploy new capabilities. AI controls are expected to include federated agents, automated vulnerability discovery and mitigation, coordinated detection and response, and automated scanning and mitigation at a national level, according to the NCSC

However, while partnering with the private sector would appear to make sense, few cybersecurity vendors have the R&D to invest the time and resource in developing these capabilities. Most of the AI Security Operations Centres (SOCs) available today have done little more than bolt AI onto existing workflows, for example, when what needs to happen is for the solution to be re-engineered completely. AI has the potential to completely rewrite the rulebook on how we approach cyber defence for the better. But to get there will require a complete re-examination of the threat detection and response (TDR) process. 

Why AI can’t be bolted on

The standard SOC treats TDR as an alert-driven process. An event occurs, an alert is triggered, a case is created and the analyst then begins an investigation. AI expedites the process by assisting with triage, enrichment, summarisation, correlation and recommendations but it acts after the fact. The reality is that, by the time that alert is triggered, the events that produced it have already happened and been captured in a chain of causation. The analyst is then behind the curve and racing against the clock because AI-driven attacks are shrinking the TDR window.

In contrast, if we insert AI higher up the chain, AI reasoning happens closer to the event stream. Behavioural detection can then run continuously rather than being recreated on demand when the alert is triggered. Detection engineering also happens earlier, allowing rules to express patterns on the stream as well as against the store. This is transformative as it means hunting can be carried out continuously instead of at a given point-in-time.

Where we put AI opens up new opportunities

Restructuring the SOC in this way also paves the way for some innovative approaches. It’s possible to use a council of AI models, for instance, with each focused on one element of TDR to provide a collective interpretation of events. Should the agents disagree, the analyst can then see exactly where and why, before making a judgement.

Or in critical national organisations such as utilities or manufacturing or highly regulated ones such as finance, AI can be deployed locally to handle environment-specific detection and analysis and a frontier model used for non-sensitive enrichment and analytical tasks to provide a truly sovereign AI solution. It’s even possible to stand-up a digital twin in these environments to enable safe attack simulations, identify risks and to preserve analytical integrity.

But perhaps one of the most exciting developments a reorganisation of the SOC makes possible is Zero-Day detection. Putting AI closer to events means live or new threat intelligence can be applied immediately as detection rules. That then gives the organisation the ability to eliminate the risk posed by emerging threats and to prevent incidents from happening in the first place.

This is not theoretical; these capabilities are with us today. But we won’t see this type of re-engineering of security solutions happen without steerage so governments need to be more focused on what they are trying to achieve while the cybersecurity industry needs to be not just commercially but nationally invested in devising true AI-native solutions. If that doesn’t happen, we risk the Cyber Shield becoming little more than a pipe dream, consigned to the history books. And with it will go hopes of cyber sovereignty, increasing our dependence on foreign frontier models.

 

LEAVE A REPLY

Please enter your comment!
Please enter your name here