ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Safeguarding CNI from hackers

Professor Kevin Curran at Ulster University asks whether AI is up to the job of protecting critical national infrastructure

 

Generative artificial intelligence (GenAI) has quickly become an integral part of everyday --security defences. Security teams now rely heavily on the technology due to its scalability, cost efficiency, predictive analytics, automated threat detection and faster response times. 

 

However, this growing reliance raises concerns, particularly when it comes to safeguarding the UK’s critical national infrastructure (CNI). GenAI is still in its early stages, is increasingly being integrated into the UK’s CNI and vital security systems. This leads to a critical question: can AI alone be trusted to protect essential cyber-security assets? 

 

Balancing AI with human intelligence

While AI can detect and respond to threats in real-time, there are valid concerns over its reliability when operating autonomously. A single AI system failure could leave critical services vulnerable and lead to nationwide disruption. The high costs of setup and maintenance pose additional challenges for public sector and CNI organisations that typically have limited budgets. 

 

Human intelligence (HI) and oversight are needed, even with the most advanced tools, to ensure optimal performance. AI is well-suited for handling data-intensive tasks, but critical thinking and experience are non-negotiable when making decisions or prioritising certain tasks.

 

For now, security teams will need to use their judgement. AI should still be seen as a co-pilot, with humans making the final decisions. A hybrid decision-making model that includes a ‘human in the loop’ can provide additional security by verifying AI-driven analyses and recommendations. 

 

This approach is generally referred to as ‘reinforcement learning with human feedback’ (RLHF), where a model is refined based on human responses. Alongside RLHF, Constitutional AI uses a separate model to rank and monitor the enterprise model’s outputs, ensuring their reliability and safety.

 

Transparency and training

Transparency is key to the success of AI systems—they must be designed so users can easily understand them. Continuous training is essential for a workforce to operate effectively alongside AI, while oversight mechanisms like audits and compliance checks help maintain ethical and performance standards.

 

AI must integrate smoothly with existing security frameworks and consistently guard critical infrastructure against sophisticated threats. However, trying to understand how GenAI systems arrive at their conclusions can be difficult. This lack of transparency may obscure potential biases or security risks. Generative AI systems are particularly vulnerable to data poisoning and model theft.

 

If organisations cannot explain how these systems function or how they reach their conclusions, accountability becomes an issue, and it can be difficult to identify other potential risks.

 

To address this, organisations should consult data protection experts, stay informed on regulatory changes and develop robust security strategies. This ensures ethical AI practices and data integrity, while also encouraging teams to use their judgement and avoid over-reliance on the technology.

 

Best practices include minimising and anonymising data, establishing robust governance policies, conducting regular audits, securing data environments and regularly reminding staff of security protocols.

 

AI vs AI: the future of cyber-security

By automating routine tasks such as log analysis and system updates, AI reduces human error and allows cyber-security teams to focus on more pressing tasks. AI defence mechanisms will improve overall threat detection accuracy, significantly reducing false positives and freeing teams to focus on other important tasks.

 

AI chatbots have already been used to analyse smart contract code for weaknesses. In the future, AI could play a role in cyber defence training, providing realistic simulations and real-time feedback for security professionals. Over time, chatbots could even serve as mentors.

 

However, given the rate at which AI is evolving, adversarial techniques will follow suit. Threat actors will harness the latest tools to outmanoeuvre security mechanisms, necessitating more sophisticated AI-driven countermeasures and protocols. CNI leaders must keep pace, regularly reviewing and upgrading their defences. That being said, will still need to use their better judgement and evaluate each AI application carefully as it is adopted and implemented within their security systems.

There have been instances of AI chatbots being used to analyse smart contract code for any weaknesses or exploits. In theory, AI could be applied in cyber-defence training, providing realistic simulations for security professionals to respond to and offer suggestions in real-time. Over time, a chatbot could act as a mentor. 

 

In short, AI will impact and influence the way organisations protect themselves in the coming years. AI’s capabilities will continue to evolve and grow, and in turn, AI tools will become more intrinsic to everyday cyber-security measures.

 

However, given how rapidly artificial intelligence has been employed by security teams and threat actors, CNI leaders will need to tread carefully as they adopt more comprehensive data protection strategies and tools to secure their systems.

 

The reality is that AI will significantly influence how organisations protect themselves in the years to come – and as its capabilities grow, it will become more embedded into everyday cyber-security measures.

 

Yet, with the rapid adoption of AI by both security teams and threat actors, CNI leaders must proceed with caution, ensuring they adopt robust protection strategies to secure their systems effectively.

 


 

Kevin Curran is an IEEE senior member and professor of cyber-security at Ulster University. He is an independent cyber-security expert who has made significant contributions to advancing the knowledge and understanding of computer networking and systems, evidenced by over 800 published works

 

Main image courtesy of iStockPhoto.com and Schroptschop


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543