...
Skip to content

AI proves useful to defend against cybercriminals

CHICAGO – Artificial intelligence is being used both as an offensive tool by threat actors and to bolster defenses at business and other organizations, Kyle Lutterman, vice president, cybersecurity risk engineer, at Arch Insurance Group Inc., said Wednesday at the Risk & Insurance Management Society Inc.’s Riskworld 2025 conference.

Cybercriminals are using their models for reconnaissance, scanning potential target networks for vulnerabilities to map an organization’s “attack surface,” Mr. Lutterman said.

Similarly, threat actors can use AI to scan security update software patches to identify the updated code with an eye toward exploiting any potential vulnerabilities, Mr. Lutterman said.

Cybercriminals are thus able to identify a virtual private network and “understand what the patching is on that VPN to see what potential vulnerabilities could be exploited for the threat actors to get access onto those networks,” he said.

On the defensive side, organizations can leverage machine learning to detect potentially dangerous emails. “Email is probably one of the most common ways attackers get onto a network,” Mr. Lutterman said.

AI can also be used to help enforce multifactor authentication and login protocols. Scanning networks for unusual or anomalous logins, which fall outside an employee’s usual login patterns, can help prevent bad actors from accessing systems via email systems.

“I think it is a very compelling way to give you a very strong return on investment here, because inboxes are probably one of the most vulnerable spots in the entire organization, and if you can keep all of the junk out of that, it puts you in a much better spot to be able to defend,” Mr. Lutterman said.