AI Threats Evolve
As businesses look to invest in AI, there is a need to stay alert to best practice and evolving AI-related risks. There has, for example, been a recent increase in AI being used to create real-time deepfakes (generate videos): a Hong Kong finance employee thought he was speaking to his boss on a video call and sent HK$200 million to a threat actor. AI voice cloning can now mimic a person’s voice with near-perfect accuracy, often fooling both humans and voice authentication systems.
Looking ahead, insurers see AI as the next main cyber threat; not only in relation to its video/voice generative capability but also in its ability to identify vulnerabilities in a business network and accelerate vulnerability exploitation and attack development. Threat actors are using computing literature posted online and running it through AI to produce new ways to infiltrate networks. What would've taken a hacker weeks of work can now be done in hours.
Other evolving threats on the increase include business email compromise (BEC), payment diversion fraud (PDF) via social engineering, distributed denial of services attack (DDOS) and loss of protected data (via an error or rogue actor).
What Your Business Should Consider
- Review policy language. Older policies might refer to breaches committed by any “natural person” which would not cover an AI-related breach.
- Prepare for AI-driven threats. Train staff to recognise deepfakes and fake communications. Consider additional controls for financial transactions.
- Increasing losses from phishing, vishing and smishing, often with limited sub-limits in policies, means your business should check the level of cover for these threats.
- AI should also be used as a security control, enhancing threat detection, response, and prevention through continuous monitoring and intelligent automation.
This is a chance to get ahead by establishing dedicated leadership roles responsible for managing these new risk exposures (e.g. focused on new and evolving threats) as well as continuously monitoring developments in the underlying technologies.