Why AI Isn't Threatening the Cybersecurity Industry but Scaling It Exponentially: Insights from the RSA Conference
Key point
AI is widening the attack surface and accelerating attack speed, exponentially scaling the cybersecurity industry.
Details
AI isn't threatening the cybersecurity market—it's expanding it. Every time a new model is released, more AI agents, APIs, and autonomous workloads that bypass human review are created, simultaneously widening the Attack Surface.
The shift on the attacker's side is also extreme. AI-powered attacks have shortened breakout time from 48 minutes to 27 seconds, and Zero-day development time from 40 days to virtually instant. The recent LiteLLM hack was recorded as a representative case in which AI agents were actually used in a supply chain attack.
However, it was a human developer, not AI, who first discovered this LiteLLM attack. This suggests that LLMs alone have limits in defense. Due to their Stochastic nature, LLMs can find numerous vulnerabilities across massive codebases, but struggle to determine which of them are actual threats.
As a result, companies are shifting to a Layered Approach that combines the following three elements:
- LLM-based detection: Quickly scanning massive codebases to capture a broad range of threats
- Deterministic Verification: Confirming whether detected vulnerabilities actually exist and finalizing priorities
- Human judgment: Identifying sophisticated attacks and making final decisions and taking action
Another key challenge discussed at the RSA Conference is permission management for AI agents. How to finely control the tools and Blast Radius of permissions that agents use to achieve their goals, and how to solve Alert Fatigue caused by surging security alerts, are expected to be key issues for the security market going forward.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.