
Nick Walker at NetSPI explains the importance of proactive security in the face of AI-powered criminals
There have been 2.29 million cyber-attacks on UK businesses in the last 12 months, with ransomware attacks increasing by 70%. Alongside this, 75% of security professionals said they have seen an uptick in attacks, with the majority (85%) attributing the rise to bad actors using generative AI.
These shocking figures not only highlight the growing scale of cyber-threats but also that businesses are becoming increasingly vulnerable to them in the face of AI-powered criminals.
It’s clear that cyber-security is no longer confined to the realm of IT departments and tech experts; it has become a concern for every individual in the organisation. In fact, PWC’s Global Digital Insights survey found that cyber-security budgets in 2024 are increasing at a much higher rate than last year, as “mega breaches” rise in number, scale and cost.
When security can’t keep up with the pace of innovation, the ability to deliver bottom-line results is at stake. To innovate with confidence and counter the threat of AI, organisations need proactive security at the core of their cyber-security programme. But what exactly is proactive security, why is there a growing need for this approach, and how can organisations use this approach to combat the growing threat of AI-powered attacks?
What is proactive security?
Traditionally, many businesses tend to operate cyber-security defensively or reactively. For instance, patching vulnerabilities or implementing a new security tool after experiencing a breach. This is especially the case for organisations that belong to an industry with significant regulatory or government compliance pressures, such as financial services or healthcare. This approach is no longer fit for purpose – that’s where proactive security comes into play.
Contrary to a reactive approach, dedicated security teams will focus on the entire scope of an organisation’s security posture – specifically how to identify, protect (against), detect, and respond to risk.
Let’s also clarify what proactive security is not – it is not a collection of disjointed, temporary solutions that are one trick ponies. This sentiment only creates more confusion and tool fatigue, and it may give a false sense of security if those solutions aren’t properly configured or validated.
Proactive security is also not knee-jerk reactions to cyber-threats – gone are the days of one-off escalated events, too many alerts, and flashing screens. Security teams do not need to respond to everything in their systems; we must be more strategic than that.
What is driving the need for proactive security?
In today’s threat landscape, hackers are finding new ways to breach the security of corporations and one of the tools they are using is AI. AI, specifically generative AI such as ChatGPT and the like, has become a powerful tool in their arsenal, using the technology to automate incidents, create convincing phishing messages, develop more evasive malware or crack passwords.
These AI-powered tactics make cyber-attacks extremely difficult to detect and stop with legacy tools. While AI can help cyber-defenders, it also means an expanded attack surface across the organisation which can leave assets exposed and vulnerable to adversaries.
Alongside this, businesses have had to address the growing demand for cloud computing infrastructure, as well as adopt new digital identity technologies to not only satisfy customer needs but continue innovating at record speed.
How to approach cyber-security holistically
To counter the growing AI threat, organisations need to look beyond AI alone. Despite the large investments many companies have made in detective controls, they often struggle to detect tactics, techniques, and procedures (TTPs) used by real-world threat actors during sustained and sophisticated attack campaigns.
On top of this, the expanding attack surface and ever-changing parameters puts security controls to the test so gaining visibility into external-facing assets, vulnerabilities and exposures is a time-consuming and difficult challenge.
The goal is to help businesses address these issues more easily with a combination of right technology and right people to provide expert, tailored guidance. While there isn’t a one size fits all approach and the pace of change in AI can be impossible to keep up with, here are the steps to ensuring a holistic approach to your proactive security programme:
As well as this, investing in AI-powered cyber-security solutions is vital. These tools can analyse network traffic, identify unusual activity, and flag potential risks in real time. This provides organisations with a crucial edge in the fight against AI-powered attacks.
With AI-powered cyber-crime on the rise and only 15% of UK businesses having a formal cyber-security incident management plan – there has never been a better time to get proactive about security.
As AI continues to infiltrate organisations and cloud computing continues to evolve, business leaders must gain a better understanding of their IT stack and overall security posture to minimise potential gaps and exposures. Innovation – and business success – depends on it.
Nick Walker is Regional Director EMEA at NetSPI
Main image courtesy of iStockPhoto.com and Dilok Klaisataporn
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543