A representative study by G DATA CyberDefense highlights the changing perception of the IT security landscape
Artificial intelligence is changing and exacerbating the cyber threat landscape. Almost 40 per cent (38 per cent) of German employees assume that an attack involves AI support. This is one of the findings of the representative study “Cybersicherheit in Zahlen” by G DATA CyberDefense, Statista and brand eins. One in five respondents has even experienced several attacks which, in their opinion, were supported by artificial intelligence. This includes, for example, the automatic development of ever-new attack variants. Companies should continue to prioritise awareness-raising and training measures.
Cybercriminals are increasingly relying on artificial intelligence in their attacks. This makes phishing and social engineering more targeted and harder to detect. However, the perpetrators also use AI to evaluate large volumes of data, analyse code and identify security vulnerabilities, whilst simultaneously generating the appropriate exploit (‘door opener’). This development has not gone unnoticed by staff in German companies. Fewer than half of those surveyed (47 per cent) in “Cybersicherheit in Zahlen” have not yet noticed artificial intelligence being used in attacks. One in six are unsure whether AI was involved. This highlights the challenge: it is often almost impossible to tell whether artificial intelligence has been used.
“AI makes attacks cheaper above all else: what used to require specialist knowledge and a great deal of time can now be done in a very short space of time. Employees cannot intercept these on their own, nor can technology alone. Both are needed: people who remain vigilant, and systems that detect suspicious activity at an early stage – so that a company can respond before an initial breach turns into serious damage”, says Andreas Lüning, co-founder and member of the board at G DATA CyberDefense AG.
Artificial intelligence makes the perpetrators’ work easierGenerative AI offers cybercriminals new ways to prepare and scale their attacks. It enables them to rapidly create ever-new variants of existing malware, or to automatically collect and analyse publicly available information about the target in order to exploit it. Even convincingly worded and personalised phishing emails can be developed in a very short space of time. Voices generated using artificial intelligence are also being used. Signs of these attacks are difficult to detect. Linguistic anomalies such as spelling mistakes or impersonal forms of address, which used to serve as indicators of fraudulent messages, are consequently becoming less significant.
Need for actionOrganisations should adapt their security awareness measures to the changing threat landscape. At the same time, awareness can only be one part of a comprehensive cyber defence strategy. Technical safeguards must also be able to detect and contain attacks. It is crucial to identify suspicious activity as early as possible, establish links between individual incidents and respond swiftly in the event of an emergency.
Cybersicherheit in Zahlen – download here
“Cybersicherheit in Zahlen” has been published for the sixth time and is characterised by a wealth of information and particular methodological rigour. As part of a representative online survey, more than 5,000 employees in Germany were questioned about cybersecurity in both a professional and private context. The experts at Statista closely oversaw the survey and, thanks to a sample size that far exceeds the industry standard, present reliable and valid market research findings in the magazine “Cybersicherheit in Zahlen”. Furthermore, this reference work provides figures, data and facts drawn from more than 300 statistics covering all aspects of IT security.
Anyone interested can download “Cybersicherheit in Zahlen” here.