
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

IT security is a team sport.
Summary
It requires companies to work together to ensure IT systems remain secure, says Rudra Mitra, vice president of security services at AWS. Mitra. Looking at AWS he says: “AWS does a fantastic job of both providing security solutions itself and also working with a rich ecosystem.” Speaking to Computer Weekly during the AWS London Symposium, which focused on financial services, one of the areas discussed at the event was the future of IT security “I think the topic du jour is very much not just AI, but the speed at which security attacks are now moving,” he says.
The reason, as Mitra sees it, for greater attention being placed on IT security is what he calls “the post Mythos era”. Anthropic’s Mythos model demonstrated how effective a frontier model can be at attacking IT systems, which means finding vulnerabilities and weaponising those vulnerabilities can be achieved at an accelerated rate due to advances in AI. “In the ‘post Mythos’ world, the time to find and weaponise vulnerabilities has accelerated dramatically.
It's incredible how with these frontier AI models, it’s getting supercharged. You can find vulnerabilities that scale much faster and it's much cheaper,” he says. The good news according to Mitra, AI has the potential to help IT security professionals tackle these new risks.
“We've got to have a response for security that also moves at machine speed.” However, the idea of running IT security operations at “machine speed” has implications for IT security teams and ethical hacking. It requires a very different approach to the best practices IT security professionals have used in the past to secure enterprise IT systems. If an AI can scan the attack surface and spot security holes far quicker than a human, what role does the cybersecurity specialist play in enterprise IT security operations?
Mitra says: “I think security today looks like it's human centred with AI assisting.” This, he says is the “state-of-the-art and implies that the speed of a response to a cyberthreat is very much governed by the humans, where the IT security operations team still relies on monitoring security dashboards, assesses the risk and takes appropriate actions. Moving forward with machine speed requires guardrails and a human in the loop , Mitra says the goal should be to ensure humans can still apply judgment in AI-based systems. “The machines are geared around machine speed response to find vulnerabilities, developing patching and deploying them.
But I think we still guard rails to decide what systems should be tested with AI or what responses can be applied with AI and should you do this to a production system.” For Mitra, the goal is to push forward with machine speed security overlaid with human judgment. This is something he believes may require a rethink of how organisations tackle cybersecurity . AI, he says, should not simply be bolted onto existing IT security operations.
“I wonder if we should be thinking about redesigning security completely for machines,” he adds. It is a question IT security leaders will inevitably need to address as agentic AI systems are increasingly deployed to perform tasks in application software and on websites that were previously done by humans.
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.