-

AI in Cybersecurity: How to Cut Through the Overhype and Maximize the Potential

New ISACA guide explores how AI, ML and DL are most—and least—effective in cybersecurity

SCHAUMBURG, Ill.--(BUSINESS WIRE)--Artificial intelligence (AI), machine learning (ML), and deep learning (DL) are often applied in cybersecurity, but their applications may not always work as intended. ISACA’s new publication, AI Uses in Blue Team Security, looks at AI, ML and DL applications in cybersecurity to determine what is working, what is not, what looks encouraging for the future and what may be more hype than substance.

Leveraging interviews with some of the engineers behind these technologies, firsthand examination and use of some of the related products, and observations of chief information security officers (CISOs) and chief information officers (CIOs), AI Uses in Blue Team Security seeks to determine whether marketing tactics obscure reality when it comes to new security technology.

Of the 13 engineers who commented for this publication, none felt that the marketing associated with the products they were working on was completely accurate with respect to advertised capabilities. However, the engineers were optimistic about the direction they were heading and the technologies they would be creating as they relate to ML and DL.

The publication outlines the three areas in cybersecurity where the engineers believe that ML helps most significantly:

  1. Network intrusion detection/security information and event management (SIEM) solutions: Keeping an intrusion detection system (IDS) up to date can be a manual and time-consuming process. In the market today, ML capabilities are helping to enhance and reimagine the IDS methods of signature-based intrusion detection and anomaly-based intrusion detection.
  2. Phishing attack prevention: There are bots and automated call centers that pretend to be human; ML solutions such as natural language processing (NLP) and Completely Automated Public Turing tests to tell Computers and Humans Apart (CAPTCHAs) help prove whether users are human or a machine, in turn detecting potential phishing attacks.
  3. Offensive cybersecurity application: ML is being applied to help with phases of penetration testing, specifically in reconnaissance, scanning and fuzzing/exploit development.

On the other hand, there are a few areas where ML is overused. Developers may be using ML for problems that do not require it, or in some instances, ML solutions may be ineffective. The paper explores those areas as well as malicious uses of ML and DL, specifically in social engineering and phishing.

“Machine learning’s gradual adoption in cybersecurity has led to good results, and there are innovative products in the market that should take ML and DL to new levels,” says Keatron Evans, principal security researcher, Infosec, and lead developer of the publication.

“However, it’s possible cybercriminals may be outpacing the cyber defenders when it comes to developing and employing new technologies, and not all ML/AI-based products are as innovative as they claim to be. Cybersecurity professionals need to continuously educate themselves to be able to not only stay on top of the latest developments, but also discern which technology tools will best meet their needs.”

AI Uses in Blue Team Security is available as a free download at www.isaca.org/ai-blue-team-security. For more emerging technology resources, visit www.isaca.org/resources/emerging-technology-resources.

About ISACA

For more than 50 years, ISACA® (www.isaca.org) has advanced the best talent, expertise and learning in technology. ISACA equips individuals with knowledge, credentials, education and community to progress their careers and transform their organizations, and enables enterprises to train and build quality teams. ISACA is a global professional association and learning organization that leverages the expertise of its more than 150,000 members who work in information security, governance, assurance, risk and privacy to drive innovation through technology. It has a presence in 188 countries, including more than 220 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation that supports IT education and career pathways for under-resourced, under-represented populations.

Twitter: www.twitter.com/ISACANews
LinkedIn: www.linkedin.com/company/isaca
Facebook: www.facebook.com/ISACAGlobal
Instagram: www.instagram.com/isacanews

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Bridget Drufke, communications@isaca.org, +1.847.660.5554

ISACA


Release Versions

Contacts

Emily Van Camp, evcamp@isaca.org, +1.847.385.7223
Bridget Drufke, communications@isaca.org, +1.847.660.5554

Social Media Profiles
More News From ISACA

New Security Debt Index Model from ISACA Helps Organizations Track Overall Debt Posture

SCHAUMBURG, Ill.--(BUSINESS WIRE)--As businesses accelerate their adoption of cloud technologies and artificial intelligence (AI), security debt— the accumulated risk created by outdated systems, deferred remediation, unpatched vulnerabilities, and under-resourced programs—has become one of the largest threats to enterprise resilience. Unpatched systems, weak identity and access management, siloed monitoring and alerting, and gaps in governance and oversight are just some examples of security d...

ISACA Digital Trust Workforce Development Program to Prepare More than 130 Learners for Tech Jobs in 2026

SCHAUMBURG, Ill.--(BUSINESS WIRE)--ISACA and the ISACA Foundation are expanding the ISACA Digital Trust Workforce Development Program in select cities across the United States. The expansion was made possible thanks to a grant from the Caterpillar Foundation to the ISACA Foundation. The ISACA Digital Trust Workforce Development Program helps individuals build practical, job-ready skills and earn ISACA certificates that support entry into the IT workforce. The program’s courses, which are suppor...

AI Use Accelerates, While Governance and ROI Lag, Says New ISACA Research

SCHAUMBURG, Ill.--(BUSINESS WIRE)--While 90 percent believe employees are using artificial intelligence in their organization, only 22 percent say AI return on investment (ROI) has met or exceeded their expectations, according to ISACA’s new 2026 AI Pulse Poll. With responses from more than 3,400 digital trust professionals across IT audit, governance, cybersecurity, privacy and emerging technology roles, ISACA’s poll finds that AI has become embedded in day-to-day work; however, governance and...
Back to Newsroom