Special Reports
A special report is content that is edited and produced by the special reports unit within The Irish Times Content Studio. It is supported by advertisers who may contribute to the report but do not have editorial control.

AI is accelerating cyberattacks. Can defenders keep up?

Cyber resilience is not about avoiding every incident but being able to continue operating and recover predictably when they occur

For smaller companies the issue is whether essential services, business operations and decision making can continue when disruption happens at speed and scale. Photograph: iStock
For smaller companies the issue is whether essential services, business operations and decision making can continue when disruption happens at speed and scale. Photograph: iStock

One of the more frightening aspects of artificial intelligence (AI) is its ability to turbocharge cyberattacks and to put advanced hacking technology into the hands of a wide array of nefarious actors, even those without high-level IT skills or resources. In the current landscape, who holds the tactical advantage: the malicious actors using AI to automate attacks, or the defenders using AI to neutralise them?

“Threat actors have the immediate tactical advantage because AI helps them move faster, scale activity and make phishing and social engineering more convincing,” says Len McAuliffe, partner, cybersecurity practice, PwC Ireland. “It lowers the skill needed to carry out reconnaissance, phishing and basic exploitation. Defenders can regain the advantage, but only where they have clear visibility of their systems, a strong understanding of normal business activity and well tested response processes.

“AI is most useful in defence when it is built on solid security foundations. Without those foundations, it can add more noise than value.”

For threat actors, the biggest shift is the emergence of AI agents that can carry out a sequence of tasks rather than simply answer a prompt, McAuliffe explains. That means researching a target, drafting messages, testing approaches and adjusting as they go. For defenders, the biggest step forward is AI that can join the dots across alerts, logs, identity activity and cloud systems. “The real value is helping teams see what matters quickly and to respond before an incident spreads,” he says.

The increasing pervasiveness of AI is creating new dangers that require greater levels of vigilance.

As Dani Michaux, EMA cyber leader, KPMG Ireland, observes, AI is no longer sitting at the edges of any organisation. It is writing code, analysing data, supporting decisions and automating activities that were previously human-led. In many cases, it has become part of “how work gets done” before organisations have fully agreed how it should be used, challenged or governed.

“This spread of unsanctioned AI use – sometimes also called shadow AI – creates blind spots that are difficult to detect until risk has already materialised. This changes the nature of risk. Exposure is no longer confined to system failures or cyber vulnerabilities. It now increasingly sits in how people trust AI outputs, where over-reliance can quietly replace critical thinking, and fundamental reasoning is applied less rigorously than before,” she says.

Dani Michaux, EMEA cyber leader, KPMG in Ireland
Dani Michaux, EMEA cyber leader, KPMG in Ireland

At the tactical level, malicious actors currently hold the advantage, especially because AI facilitates speed, agrees Puneet Kukreja, resilient nation leader and head of cyber, EY Ireland.

“AI allows attackers to automate reconnaissance, generate more convincing social engineering, identify exposed systems, adapt attack paths and scale campaigns at a pace that many traditional security operating models were not designed to match. The issue is not that cyber risk is entirely new; it is that AI is compressing the time between vulnerability, exploitation and impact.”

However, that does not mean attackers always hold a strategic advantage. Defenders can regain that advantage if they shift from a narrow model of cyber protection to being adequately “resilience engineered” by designing, testing and evidencing that critical services can continue, degrade safely and recover under pressure, he says.

Puneet Kukreja, resilient nation leader and head of cyber, EY Ireland
Puneet Kukreja, resilient nation leader and head of cyber, EY Ireland

“The real test is not whether every attack can be prevented, but whether essential services, business operations and decision making can continue when disruption occurs at speed and scale; as such, today, attackers currently have the speed advantage, but defenders can have the resilience advantage.”

Open-source AI is shifting the balance of power because it creates cyber capability at scale, Kukreja adds. Tools that once sat with specialist teams, large corporations or state-level actors can now be copied, adapted and deployed by a much wider group, including malicious actors.

“For attackers, that means faster reconnaissance, phishing, code generation, vulnerability testing and automation. The real concern is the digital Covid effect: vulnerability can become exposure, and exposure can become impact, and all faster than traditional governance, patching and response cycles were designed to handle.”

But open-source AI is not only a threat. It can also help smaller organisations level the playing field, supporting log analysis, vulnerability triage, threat intelligence, incident preparation and basic security automation. The difference is whether AI is used casually, or as part of a controlled and tested resilience model.

Smaller businesses should not try to match the spending of large enterprises on security. Instead, Kukreja says, they should aim to become harder to disrupt, faster to recover and less attractive as easy targets.

This means identifying what must keep working, what can degrade temporarily; what must be restored first; which systems, suppliers, people and data those services depend on; and whether recovery has actually been tested.

Len McAuliffe, partner, cybersecurity practice, PwC Ireland
Len McAuliffe, partner, cybersecurity practice, PwC Ireland

“Resilience is not a luxury [reserved for] for larger organisations. It is the operating discipline that enables smaller organisations to survive AI-accelerated disruption. A resilient smaller business is not one that avoids every incident, but the one that can continue operating, degrade safely and recover predictably,” says Kukreja.

PwC’s McAuliffe agrees that smaller organisations are not necessarily at more of a disadvantage than their larger counterparts, as long as they are proactive.

“Smaller businesses should focus on the controls that reduce the most risk. Identity and access should be tightly managed, critical systems should be kept up to date, important data should be recoverable, and third-party access should be understood and controlled,” he says.

“They also need a clear incident response plan so decisions can be made quickly if something goes wrong. They don’t need to replicate the complexity of large multinationals, but they do need strong execution of the basics and access to specialist support where required.”

Frank Dillon

Frank Dillon is a contributor to The Irish Times