AI and Cybersecurity: Don’t forget the basics

AI Basics


DTP’s report reveals why cybersecurity fundamentals need to be at the forefront of countering the AI ​​hype.

While the cybersecurity industry is investing heavily in artificial intelligence and advanced threat detection, the harsh reality remains that most successful cyberattacks exploit the same fundamental weaknesses that should have been solved a decade ago.

According to analysis by Guy Hawkridge, head of IT and security at DTP Group, the cybersecurity crisis is not about advanced attacks. Instead, it’s about neglected basics.

Cyber ​​attackers no longer need to break in, they just need to log in,” Hawkridge said. digital journal. “Most breaches are completely preventable, and tools already exist to stop them, they just aren’t being deployed effectively.”

The unpleasant truth about modern cyber attacks

The cybersecurity industry has historically not had as many tools, technology, and talent at its disposal, but breaches continue to accelerate. Hawkridge’s analysis points to a fundamental disconnect. This means that organizations are being compromised by issues that represent basic cyber hygiene deficiencies rather than advanced persistent threats.

For example, the Sophos 2025 Active Adversary Report highlights this reality, revealing that 65% of compromised organizations lack multi-factor authentication (MFA), a dramatic increase from just 22% in 2022. This trend reflects what Hawkridge describes as the “commoditization” of ransomware through Ransomware-as-a-Service platforms.

Cloud adoption trumps security strategy

As organizations accelerate their migration to the cloud, security strategies often fall behind, creating a significant attack surface. Hawkridge identified misconfigured cloud services, particularly exposed AWS S3 buckets containing sensitive data such as payroll information and credentials, as a significant blind spot.

Recent high-profile cases support this assessment. The Snowflake breach that affected Ticketmaster and Santander stemmed from a single legacy demo account that was left without multi-factor authentication (MFA) protection, an account that was supposed to be temporary but was not disabled.

AI hype creates dangerous distractions

Perhaps most controversial is Hawkridge’s argument that the industry’s focus on AI-powered security solutions is dangerously diverting attention from basic protection measures that actually work.

This concern centers on organizations reallocating budget and attention to AI tools before addressing the fundamental security flaws in their environments.

Not-so-glamorous security practices that actually work

Hawkridge advocates for a simplified cybersecurity approach that focuses on fundamental practices such as comprehensive asset discovery, universal MFA implementation, systematic patch management, privilege separation, and proper legacy systems management.

Industry Outlook: More of the same

Looking ahead, Hawkridge doesn’t expect the threat landscape to change dramatically. “We’re still seeing the same problems we encountered five years ago,” he said. “Breaches occur because of outdated software, missing patches, and lack of MFA. Attackers know this pattern and continue to exploit it.”



Source link