The emergence of artificial intelligence sparked a wave of excitement about its capabilities and future potential. Today, AI-based solutions and tools are used across many areas of life and business. Their penetration into workplace and business processes continues to grow every year. At the same time, however, malicious actors are increasingly using AI as well. This presents serious challenges for both global and Ukrainian companies and forces them to respond to new risks.
According to various sources, 50% to 70% of corporate data is already stored in or processed by cloud and AI services. This naturally raises an important question: how can organizations protect the confidentiality of corporate information in such conditions? I believe not every company fully understands the risks involved.
In our work, my team uses external AI services very cautiously—mostly in the form of assistants. This kind of AI assistance helps speed up the analysis and response to cybersecurity incidents.
At the same time, we understand that AI solutions are still at an early stage of development. If you look at the Gartner Hype Cycle, every tool or product goes through a certain lifecycle before it reaches maturity. Full-fledged artificial intelligence in cybersecurity solutions is still a 2030s prospect.
Right now, we are at the stage where AI services are developing and gaining momentum. Some time still needs to pass before these tools can deliver real value to cybersecurity specialists and businesses.
Every day, cyberattacks are becoming more sophisticated and targeted. About two years ago, we encountered deepfakes in the corporate environment for the first time. AI technologies make it possible to convincingly, professionally, and accurately fake the voice and even the video of a manager or executive.
Attackers call employees using such deepfakes and ask them to answer certain questions or even perform specific actions, putting the company and its internal systems at risk of data leakage. These cases are becoming more frequent, and in most situations, the victim responds. Just imagine the scenario: the call comes from your manager, and the voice, face, and video are all 100% convincing. What reason would there be to doubt it?
In practice, it is extremely difficult to distinguish a fake voice or video from a real person. Today, reality can be manipulated with ease. That is why our company places major emphasis on comprehensive team training: how to recognize threats, what to pay attention to, what should raise suspicion, and which cyber hygiene practices should be followed. This is no longer a matter of trend. It is a matter of security and the company’s survival.
Controlling the data users upload into external AI services is the foundation of security for any company. The problem is that IT teams and cybersecurity departments find it very difficult to control exactly what information employees exchange with these services.
At our company, we have developed a clear strategy for working with AI solutions:
We are already implementing AI assistance into our solutions to respond proactively to attempts to attack the company’s corporate network and web services. AI helps cybersecurity specialists detect attacks at the stage when they are only beginning to take shape. In simple terms, the attack has not started yet—it is only emerging, and our specialist is already able to see its likelihood and its potential impact on business processes and the company’s resilience.
A key class of solutions that will gain momentum in the near future is AI firewalls designed to protect the company’s own AI models. The logic is simple: with unusual prompts, an attacker may discover vulnerabilities in the model or trigger a DDoS attack. An AI firewall will prevent the attacker from hitting the jackpot by breaking into the corporate network and gaining access to all corporate data. I believe we will see effective solutions in this category within the next one to one and a half years.
Another direction is automating routine work with AI assistants. The reality is that the full-scale invasion caused a significant staffing shortage in Ukraine. But the shortage of experienced cybersecurity specialists is also relevant in Europe and the United States. This is a global problem.
That is why some of the tasks that were previously performed by specialists can now be handled by AI. Today, copilots embedded in security solutions are already widely used in day-to-day work, helping automate routine tasks. In my view, by 2030–2032, a large share of typical routine operations will be delegated to AI. This will allow us to optimize security processes and free up specialists’ time for more important, strategic priorities.