Chronicle/Policy & standards

UK NCSC blog argues defenders cannot use agentic AI as attackers do and proposes a five-dimension action risk framework

PolicyGuidanceSignificance assistant-drafted

Dave Chismon, the NCSC's CTO for Architecture, argues that offensive problems are mostly technical with clear success states while defensive problems are mostly organizational, so defenders cannot put AI to work as attackers can and agentic defense may struggle to keep pace with AI-enabled attacks. He proposes rating a defensive action's riskiness on five dimensions (potency, scope, criticality, rollout confidence, recoverability) and starting with low-potency tasks where AI advises a human. The post also says the NCSC and DCMS are working on a national-scale agentic cyber defence ecosystem called Cyber Shield and that the NCSC seeks research on proving low-risk actions are low risk.

Why it matters

It gives a national cyber agency's stated reasoning and a scoring scheme for deciding which defensive actions to automate first, though it is an author's argument and not a measurement or formal guidance.

Key facts

As stated in the sources, with where to find them.

  • The author states three principles from existing detection practice: technology drives detection while humans respond with actions, detection must not harm the organization, and technological response is tightly controlled and scoped (for example to a single account or computer).How can defenders make better use of AI?
  • Proposed risk framework rates a defensive action on five dimensions, each with levels 0 to 4: potency (advice to a human up to executing code or changing runtime), scope, criticality, rollout confidence, and recoverability.Framework table
  • Suggests lowest-risk candidates first: tasks where AI provides explainable advice to a human (potency 0), such as summarizing threat intelligence, and systems that are easy to recover and redeploy ('cattle, not pets').How can defenders make better use of AI?
  • Says the NCSC and DCMS are jointly working on Cyber Shield, a national-scale agentic cyber defence ecosystem, and that the NCSC will publish an 'AI for Cyber Defence' problem book; it names as needed research ways to deterministically prove that low-risk actions really are low risk.Unlocking the potential of agentic AI actions
  • States that organizations should not wait for agentic defense and should keep improving security the traditional way. It cites CETaS work on Autonomous Cyber Defence, commissioned by the NCSC.How can defenders make better use of AI?; final paragraph

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records