Easier to build, faster to launch and more destructive than ever before, cyberattacks are getting a significant boost from frontier artificial intelligence (AI) models.
Virkkunen raised concerns that advanced AI models can now build cyber exploits in minutes or hours, posing a direct threat to the security of critical infrastructure and society at large.
While AI is a powerful asset for attackers, it is also a powerful tool for defenders.
Rene van Haaster, vice president EMEA North, Elastic
There is, thankfully, another side to the story. While AI is a powerful asset for attackers, it is also a powerful tool for defenders. Organizations are leveraging AI to reduce their mean time to detect, respond and recover, and to stay ahead of advanced attacks.
The EU’s Action Plan on Cybersecurity and AI not only outlines a coordinated strategy for responding to AI-driven attacks, but also proposes a blueprint for structured access to advanced AI models for the use of IT security teams working within public authorities and private companies.
Adapt and survive
This is an important step forward but, in today’s AI-fueled threat landscape, there are three areas that EU organizations need to consider if they want to keep hackers in check. In short, they must adapt to survive.
The first is control and sovereignty. This is particularly important in Europe, where technological sovereignty has become an increasingly strategic objective.
Organizations need the ability to understand where their data has been created, moved and stored. This is central to their ability to retain meaningful control over the technologies they depend on. In practice, this means avoiding architectures that lock them into specific providers or limit their ability to integrate new capabilities and retaining the freedom to move data in, between, and out of vendors and service providers as their needs evolve. Vendor lock-in is a procurement concern, and one that many organizations seek to escape from.
Open source can help address this challenge. It enables organizations to reduce dependence on any single supplier, combine multiple technologies, switch providers, maintain systems independently or engage local service providers to do so on their behalf. This contrasts with most closed-source IT security products, where continuity of service is by no means a given, especially as vendors can change their commercial terms or exit the market altogether.
Additional advantages lie in code being publicly available for inspection and modification. Open-source technologies are continuously reviewed, maintained and improved by a global development community of people working together to make updates, address gaps, fix bugs and test security tools. They are built by the community for the community and the benefit of the industry.
The second consideration is economics. Typically, implementing IT security technologies involves a range of structural costs and licensing penalties from vendors that make little sense in a world of rising threats and stagnant or even shrinking budgets.
Some of these costs introduce unnecessary risk, like per-device fees that may force organizations to leave lower-priority endpoints unguarded. Some organizations also pay extra costs associated with add-on technologies for automating security processes to coordinate response workflows. Others are dealing with the considerable financial risks involved in using large language models (LLMs) that don’t adequately explain or keep a record of decisions for auditing purposes. During incident response, there are also the high costs and delays attached to retrieving historical data for analytical purposes.
Fragmented tools and restrictive pricing models force IT security teams into a risky game of balancing protection and cost. The objective should therefore be to make comprehensive security economically sustainable.
To achieve this, many teams are looking toward platforms that consolidate monitoring, alerting and response, where pricing is based on compute power and storage.
Organizations are embedding AI agents across the cyber stack, automating high-volume and repetitive tasks. This is not to replace human analysts, but to free them for the work that demands human judgment.
Technology architecture matters too. Sprawling estates of disconnected security tools create operational and financial costs. Bringing logs, signals and alerts together in a unified platform can give teams a full, real-time picture of all activities and behaviors occurring across an IT architecture. The best of these platforms will incorporate AI capabilities to identify threats and automate analytical and management tasks, including reverse-engineering malware, compiling actionable case summaries and predicting future vulnerabilities.
The third consideration is readiness for innovation: agentic security. AI agents can take the pressure off overwhelmed security operations center (SOC) analysts by automatically handling tasks such as data collection, threat prioritization, alert correlation and response planning.
The transition to an agentic SOC is already underway. Organizations are embedding AI agents across the cyber stack, automating high-volume and repetitive tasks. This is not to replace human analysts, but to free them for the work that demands human judgment.
In an agentic SOC, instead of spending hours manually triaging across multiple consoles just to reconstruct the full picture of a threat, analysts will increasingly delegate it to AI agents. This avoids slower response times and longer exposure windows, reducing cyber risks to the organization. Analysts can focus their time and skills on supervision, governance, context and the high-impact decisions for which human expertize remains essential.
Vrije Universiteit Brussel (VUB), a public research university in Belgium, illustrates the value of getting that foundation right. Academic freedom has resulted in a highly decentralized IT estate supporting thousands of researchers running their own systems, sensitive research and personal data. Just three engineers are able to operate detection and investigation across 64 billion events and more than 300 servers, because VUB has centralized its data, normalized it for analysis, and built detection and investigation capabilities on a foundation it can control.
Clear-eyed assessment
Getting these fundamentals right will be vital as the EU forges ahead on its stated ambition of scaling up Europe’s AI-driven cybersecurity capabilities. In fact, a clear-eyed assessment of how an organization stands on these issues today is a prerequisite to that organization getting the best from AI-based cybersecurity in the future.
Multi-cloud architectures, expanding volumes of data and increasingly complex digital estates have revealed serious gaps in tried-and-tested ways of protecting digital systems.
There is also a compliance dimension. The EU Action Plan explicitly connects its ambitions with Europe’s existing cybersecurity and technology framework, including the AI Act, the NIS2 Directive and the Cyber Resilience Act.
Yet, the environment these rules are designed to protect is itself changing. Multi-cloud architectures, expanding volumes of data and increasingly complex digital estates have revealed serious gaps in tried-and-tested ways of protecting digital systems. Now, a growing onslaught of AI-enabled attacks adds another dimension, as adversaries can discover vulnerabilities, develop exploits and operate at a speed and scale that human-only security processes will struggle to match.
The answer to this cannot be to leave AI in the hands of attackers.
Europe is right to explore how advanced AI can be put to work for defenders too. But access to powerful models will only deliver results if organizations have first established the control, data foundations and operating models needed to use them effectively.
Attackers are moving toward machine-scale cybersecurity. Defenders need to be ready to do the same.
It’s time to fight fire with fire.
Disclaimer
POLITICAL ADVERTISEMENT
The sponsor is Elastic
The political advertisement relates to the EU’s Action Plan on Cybersecurity and Artificial Intelligence and advocates for greater adoption of AI-powered cybersecurity, arguing that Europe and its organisations need stronger technological foundations, greater control over data and infrastructure, and increased use of AI to defend against increasingly sophisticated cyber threats.
PARIS — After a summer of extreme, climate change-driven heat, France must spend billions of euros to help the country rebuild and ensure it is better prepared the next time the mercury rises and records fall.
Money, however, is hard to come by.
France is sitting on more than €3.5 trillion in public debt, which is becoming increasingly expensive to finance and is well above the European Union’s limit. Paris has already committed to billions in increased defense spending over the next several years, ruled out significant tax hikes and promised to slash its budget deficit, which came in at 5.1 percent of gross domestic product last year, to 3 percent by 2029 to comply with EU rules.
Crafting a budget for next year that can achieve those goals while also allocating enough resources to prepare France for the next summer of extreme heat that cooks livestock alive, plunges the country into drought and fuels wildfires that drive thousands from their homes is like trying to square the circle. But getting a hung parliament to agree on spending in the run-up to a presidential election will make the exercise even more difficult.
“We need billions — let’s be clear-eyed about this,” said Sophie Panonacle, a centrist, pro-government lawmaker who represents the fire-hit southwestern Bassin d’Arcachon area. “We really must urgently consider this issue of adaptation. We are making no progress at all on this matter.”
Budget crunch, meet climate crisis
Visiting the southwestern town of La Porge on Monday, where hundreds of people saw their homes go up in flames last month, Prime Minister Sébastien Lecornu listed a series of measures crafted to help residents rebuild their homes and keep businesses hit hardest by the fires afloat.
These included a total of €12 million in direct assistance for the two local administrationsmost affected by the fire, Gironde and the Landes, as well as rebates on property taxes and social security contributions in those areas and more funding to replant forests. Later that evening, President Emmanuel Macron announced that the proposals would also apply to the southern region of Var.
Lecornu said the measures would add up to €100 million, though it’s unclear whether that figure covers costs only in the towns he visited or also in the Var region.
Ecological Transition Minister Monique Barbut said last week that the total immediate cost of the summer’s heat, including lost homes and incomes, could reach €10 to €15 billion — the equivalent of 0.5 percent of GDP — though she cautioned that those figures were a rough estimate. When asked by French daily Libération about Barbut’s estimate, Economy Minister Roland Lescure later said it was too early to quantify the damage.
Whatever the final total comes to, there’s little doubt it will be difficult to pay given the need to get the country’s finances in order.
In a report commissioned by the French finance ministry, top economists last month said France must cut spending and raise taxes by €125 billion by 2032 to prevent its budget deficit from reaching 7 percent of GDP by the end of the decade.
A comprehensive strategy
Critics of the government say it has failed to provide specific details on how it intends to fund immediate and future budget needs for adaptation and climate change mitigation, frustrating lawmakers.
Monique Barbut said last week that the total immediate cost of the summer’s heat , including lost homes and incomes, could reach €10 to €15 billion. | Lou Benoist/AFP via Getty Images
“We need to respond to climate-related events, but first we need a comprehensive strategic review regarding resources already allocated and promises made around fighting wildfires,” said Jean-François Husson, the Senate’s budget watchdog. “We’re addicted to making announcements which aren’t followed by results, and meanwhile the debt levels are spiraling.”
Husson said that he intends to summon government officials to provide clearer figures in the coming days.
“They cannot treat Parliament the way they do, specifically regarding budgetary matters,” Husson said.
That criticism cuts across party lines. Eric Coquerel, the left-wing head of the finance committee in the French National Assembly, has asked the government to urgently present a revised version of this year’s budget to parliament to address the need for more funds.
With state coffers so depleted, Barbut floated in an interview with Libération tapping private savings to help cover costs, as the French rank fairly high among EU countries in terms of savings but, like the rest of Europe, don’t invest much in stocks and bonds.
Panonacle, the centrist lawmaker, is one of 50 MPs pushing a proposal to use €50 billion in private savings to fund costly adaptation policies, including making buildings more resilient to extreme heat, installing more air conditioning in public facilities, and reinforcing flood defenses.
However, that money is already used to finance public projects, particularly social housing, and the economy ministry last year shot down a similar proposal to use money from a popular savings account to bolster defense spending.
Some ministries are focusing on efficiency gains. Interior Minister Laurent Nuñez will present a bill in September meant to modernize France’s civil security providers for example by rethinking its emergency dispatch system so firefighters are no longer deployed for every minor emergency. “It’s not just about the amounts allocated, but also about how you use resources,” said an interior ministry official, who was granted anonymity to speak candidly.
Once summer ends, the clock starts ticking. Lecornu’s government is expected to present lawmakers with a draft budget to be debated by October. The goal is to get the process done by the end of the year — a goal lawmakers failed to meet in 2024 and 2025.