Can artificial intelligence revolutionize IT security?
Digitization is changing the way businesses operate, offering vast opportunities but also significant challenges. Since the number of cyberattacks has grown dramatically over the past few years, ensuring IT security is crucial. Can AI help?
Key takeaways
Key takeaways
- Cyberattacks are becoming not only more and more frequent but also increasingly sophisticated, posing a serious threat to companies and individuals.
- The ever-increasing number of IT security alerts puts a strain on professionals responsible for early detection and quick response to IT security risks.
- The use of AI, particularly in areas such as security analytics, app security, vulnerability management, and data protection, has the potential to become a key milestone in ensuring IT security.
The digitization of our society is a megatrend that we believe is only going to accelerate in the next few years, leaving businesses and individuals susceptible to cyberattacks. The so-called “attack surface”1, which is the number of possible points where an unauthorized user can access a system and extract data, has broadened, mainly due to increased connectivity, 5G, and the Internet of Things (IoT) in our view. In addition, working from home or, in fact, from anywhere, is becoming a natural part of our daily life, giving hackers more opportunities to exploit vulnerabilities. Cybercriminals are using more and more sophisticated methods, such as social engineering or supply chain attacks, to infiltrate networks.
What are the main IT security challenges today?
What are the main IT security challenges today?
With the attack surface expanding, it is becoming more challenging for organizations to block potential threats quickly. IT security teams must focus on precise and rapid detection of cyberthreats, while also improving their response capabilities. The following factors are challenging IT organizations:2
- Overburdened IT security analysts are forced to triage a flood of security alerts. According to a survey, nearly half of the analysts reported a false-positive rate of 50% or higher.
- 56% of large organizations deal with 1,000 or more security alerts daily.3 That puts IT security analysts in a difficult position because they can typically review only around ten security alerts per day.
Not surprisingly, IT security teams are at risk of getting fatigued and understaffed, which further adds to staff turnover. In addition, the amount of time needed to resolve cyberattacks is rising: according to a survey conducted among more than 1,000 team members of security operations centers worldwide, 46% said the average time needed to detect and respond to a security incident has increased over the past two years and more than 80% said that manual investigation of threats slows down their overall threat response times.4
The situation is further exacerbated by the fact that cyberattacks have significantly intensified over the past few years, with attacks becoming more frequent and sophisticated.
Cyberattacks are on the rise
Cyberattacks are on the rise
Increasing volumes of cyber incidents are continuing to threaten businesses.
- The average duration of downtime after a ransomware attack between Q1 2020 and Q2 2022 increased by 60% from 15 days to 24 days.5
- In 2022, 83% of organizations had multiple data breaches and ransomware attacks increased by 13%, which is a rise equal to the last five years combined.6
- Data from Checkpoint Research shows a 7% global increase in weekly cyberattacks during Q1 2023. During this time, 310 cyber incidents were publicly disclosed.7
- Over one billion malware programs are circulating with an estimated 560,000 new instances discovered daily. Every minute four businesses get attacked by ransomware.8
- Cyber incidents can cause publicly listed companies to lose an average of 7.5% of their stock price and it takes 46 days to recover if they are able to do so at all.9
What is the cost of a data breach?
What is the cost of a data breach?
According to IBM, the average global cost of data breach reached USD 4.45 million in 2023, which represents a 2.3% increase from the 2022 average cost of USD 4.35 million. It can include everything from ransom payments and lost revenues to business downtime, remediation, legal and audit fees.10 Since 2020 (when the average total cost of a data breach was USD 3.86 million), this number has increased by 15.3%. The United States topped the ranking of regions with the highest data breach costs for the 13th consecutive year, with the cost totaling USD 9.48 million, more than double the global average, followed by the Middle East and Canada (chart 1).
Chart 1: Cost of an average data breach by country or region, in million USD
Chart 2: Cost of an average data breach by sector, in million USD
When looking across industry sectors, the healthcare segment reported the highest costs of a data breach, followed by the financial and the pharmaceutical industry. Over the past three years, the average cost of a data breach in healthcare has grown by 53.3%. According to the authors, the main reasons are that healthcare faces higher levels of industry regulation and is considered a critical infrastructure by the US government. The healthcare industry has seen notably higher average data breach costs (chart 2)11, particularly since the start of the COVID-19 pandemic.
AI to ease the workload of cybersecurity teams
AI to ease the workload of cybersecurity teams
We believe that the use of AI has the potential to become a critical solution in IT security by helping to detect cyberthreats and increase response time, thus acting as an “assistant” to IT security analysts. According to Acumen Research & Consulting, the market size for AI in the cybersecurity market accounted for USD 14.9 billion in 2021 and is estimated to reach a market value of USD 133.8 billion in 2030, which represents a compound annual growth rate (CAGR) of 27.8%. This trend is powered by the surging use of social media for business operations, growing government investments in AI adoption as well as technological advancements in security systems to combat the increasingly sophisticated cyberattacks.12
The idea behind AI in IT security is to use AI-enabled software to augment human expertise in rapidly identifying new types of malware traffic or hacking attempts. Because of recent advances in computing power, AI in IT security is now becoming a reality with comparatively small datasets. AI solutions can ease the workload of cybersecurity teams and effectively remove false positives by quickly drawing correlations and insights from vast datasets across assets. It can further automate low value tasks and allow IT security teams to focus on higher priority threats.
According to the IBM Institute for Business Value, AI is already reducing the costs of cybersecurity responses.13
- The companies at the forefront of adopting AI have reported a 15% reduction in overall cybersecurity costs.
- The average expense of data breaches can be reduced by over USD 3 million.
- AI has the potential to improve the incident response time. Historically, it took an average of 230 days to detect, respond to, and recover from a cyberattack. With AI implementation, it can cut that time by up to 99 days.
Historically, cybersecurity was designed to look at a specific domain and resolve threats under a particular scenario. However, the increasing sophistication of cyberattacks demands unified solutions. While AI use is not new to security in cases such as anomaly detection, we think generative AI (GAI) is a step-function improvement, given its ability to generate recommendations and automate manual, ad hoc tasks previously performed by IT security professionals. It enables aggregating and correlating data across many isolated products that comprise an organization's security stack. IT security teams are then able to strengthen their defense by identifying patterns and connections that humans find difficult to detect across business verticals and locations.
A recent report published by the Cloud Security Alliance (CSA) finds that GAI models substantially improve vulnerability scanning: the OpenAI’s Codex platform, which is based on ChatGPT, was able to detect and scan vulnerabilities in software code written in various programming languages. According to CSA, this technology might become an integral component in IT security responses. Interestingly, the report remarks that GAI is able to detect and watermark AI-generated text. This could improve the detection of phishing emails and become part of email protection software. Such technology could check for unusual email sender addresses, domains, or links to malicious websites.14
Accelerating the cybersecurity arms race
Accelerating the cybersecurity arms race
Attacks on IT security are becoming more systemic and more severe. Although short-term impacts of a cyberattack on a business can be quite severe, the long-term structural impact can be even more dramatic for an organization, including even the potential loss of competitive advantage. While the broad use of AI is not new in the field of IT security, we think generative AI specifically can offer a step-function improvement, given its ability to quickly generate content and recommendations. This offers real benefits for applications such as security analytics, app security, vulnerability management, and data protection.
In our view, the IT security theme is becoming omnipresent in our daily lives and the implications for the integration of AI are becoming more critical. Leading IT security companies are making great strides in integrating AI solutions into their products. We believe that both the good and the bad actors will surely use GAI in the cybersecurity arms race, forcing businesses and governments to upgrade their IT security infrastructure. Therefore, as long-term-orientated and patient investors, we are shareholder of innovative companies that are providing cutting-edge solutions, such as GAI security analyst programs, AI for IT operations, or AI-driven threat detection platforms.
Dr. Patrick Kolb
Senior portfolio manager, Thematic Equities
Patrick Kolb (PhD), Managing Director, has been a Senior Portfolio Manager for the Security Equity strategy since 2007. In 2005, he joined Credit Suisse Asset Management, now part of UBS Group, where he initially focused on the industrials and technology sectors. Patrick graduated from the University of Zurich with a major in Finance and then worked as a research assistant at the Institute of Banking and Finance at the University of Zurich before earning his PhD in Financial Economics.
Make an inquiry
Introducing our leadership team
Meet the members of the team responsible for UBS Asset Management’s strategic direction.