Skip to Main Content Subscribe

Intelligence CIOs Warn AI Agents Could Accelerate Cyberattacks

Share

IC CIOs warn AI agents are accelerating cyber threats and pushing agencies to automate patching and strengthen network defenses.

3m read
Written by:
Doug Cossa, IC CIO and primary IT advisor to the Director of National Intelligence, speaks in Portland in 2023.
Doug Cossa, Intelligence Community CIO and primary IT advisor to the Director of National Intelligence, speaks in Portland in 2023. Photo Credit: Petty Officer 2nd Class Wade Costin/DIA

Intelligence Community CIOs are preparing for a cybersecurity environment in which AI agents can identify vulnerabilities, launch attacks and exploit weaknesses in network defenses at speeds humans cannot match.

Technology leaders from across the intelligence community discussed the growing threat from AI-enabled cyberattacks and the steps agencies need to take to strengthen their defenses Monday at the DoDIIS Worldwide conference in Tampa, Florida.

Defense Intelligence Agency CIO Edacheril Mathew pointed to a recent AI cybersecurity incident as an example of the risks technology leaders should study closely.

Mathew was referencing recent incidents from three major AI companies where sandboxed AI systems tasked with passing a cybersecurity test broke out of their containment to gather additional information and communicated with multiple AI systems. More concerning, he said, those systems independently communicated with one another to share information.

Mathew warned that future major cyberattacks may not be carried out directly by humans; rather, “it will be AI agents,” he said.

That possibility poses particular challenges for the Intelligence Community because its networks are highly interconnected. Mathew noted that roughly 600 organizations connect to the Joint Worldwide Intelligence Communications System, or JWICS.

As agencies deploy AI across those interconnected environments, Mathew said they need to establish clear boundaries for how autonomous systems can operate. Without those controls, actions taken by one system could have cascading effects across connected networks.

AI Forces Agencies to Respond Faster

Adversaries are also using widely available AI tools to identify vulnerabilities in U.S. systems and software more quickly, putting pressure on federal agencies to detect and patch vulnerabilities at unprecedented speeds, said Roger Greenwell, director of enterprise integration and innovation and CIO of the Defense Information Systems Agency.

The growing volume and speed of cyber threats is placing additional pressure on agency IT teams and increasing the potential for service disruptions during a crisis.

“We can’t afford the downtime,” Greenwell said.

Maintaining availability is particularly important for national security organizations, where senior leaders need access to information to make decisions faster than adversaries. Greenwell said the Intelligence Community is working with industry to develop capabilities that can dynamically patch systems as vulnerabilities emerge.

National Geospatial-Intelligence Agency CIO Mark Chatelain said NGA has successfully integrated AI into its mission, but incorporating the technology into cyber defense presents additional challenges.

That includes using AI to detect threats within network telemetry and enabling systems to respond within microseconds when malicious activity is identified.

“We’ve got to have a pacemaker basically built into our systems,” Chatelain said.

Automation Raises New Change Management Challenges

Technology alone will not solve agencies’ cybersecurity challenges, according to Intelligence Community CIO Douglas Cossa, who said many IT problems stem from organizational culture rather than technical limitations.

One example is employees making unauthorized or uncoordinated changes to systems and networks. Strong change management practices can help agencies prevent those actions while also understanding how modifications could affect other parts of an interconnected environment.

AI could magnify that challenge because automated systems can make thousands of changes in a short period of time. As agencies automate vulnerability remediation, Cossa said they will also need to automate aspects of the change management process.

That capability will become increasingly important as agencies race to respond to newly discovered vulnerabilities.

“We’re going to be in this process of surging patches for at least two years,” Cossa said.

Cyber Defense Starts With Network Visibility

Keeping pace with AI-enabled threats will also require agencies to have a comprehensive understanding of their technology environments, Cossa said.

Organizations need accurate inventories of their hardware and software and visibility into where those assets operate across their networks.

“That is one of the most fundamental questions we need to understand to get our security right,” Cossa said.

Agencies also need to understand where systems are in the IT lifecycle because aging software may no longer be supported or able to receive security patches. At the same time, automating patching and remediation will be increasingly important as the pace of vulnerability discovery accelerates.

Ultimately, Cossa said, agencies cannot take advantage of more advanced cybersecurity capabilities without first establishing basic cyber hygiene, maintaining visibility into their environments and ensuring incidents are reported to the appropriate organizations.

“If you don’t have the foundational cybersecurity principles in your environment, then you can’t operate,” Cossa said.

Related Content