Software

Dresden Institute for Data Protection: The Impact of Artificial Intelligence on Cybersecurity

July 27, 2026. Since artificial intelligence (AI) has permeated many areas of our lives, our society has also undergone changes in many ways as a result of AI’s use. One area that is increasingly being transformed by the use of AI is IT security. It is evident that cyberattacks, in particular, have undergone a transformation. Attacks are occurring more rapidly and have also become more sophisticated. The Federal Office for Information Security (BSI) has now issued an explicit security advisory on this topic. In this warning, the BSI emphasizes, among other things, that “AI significantly reduces the effort, time required, and barriers to entry for offensive cyber capabilities.” In today’s blog post, we’d like to take a closer look at the key points from this security advisory.

Share this Post
Stock image: Data security / Photo by Dan Nelson on Unsplash

Contact info

Silicon Saxony

Marketing, Kommunikation und Öffentlichkeitsarbeit

Manfred-von-Ardenne-Ring 20 F

Telefon: +49 351 8925 886

redaktion@silicon-saxony.de

Artificial Intelligence Is Changing the Cybersecurity Landscape

The “starting point” is relatively clear. Whereas attackers—or, in the words of the BSI, “malicious actors”—used to require enormous amounts of time and financial resources in the past—for example, to compose phishing emails—AI systems are now breaking into entirely new realms. Within extremely short time frames, it is possible to analyze software and thereby identify new vulnerabilities and so-called exploits.

Furthermore, attackers benefit “to a particular degree from speed, scale, and automation.”  The BSI even goes so far as to state that AI is changing “the dynamics of vulnerability discovery, exploit development, and attack operations so drastically that previously viable defense assumptions are coming under considerable pressure.” This does not, of course, mean that all security strategies and approaches developed to date are obsolete. Nevertheless, adjustments are necessary—particularly with regard to processes and response mechanisms—to address the significantly more complex threat landscape.

What risks and opportunities exist?

First and foremost, a new dynamic is emerging. The use of AI results in a much higher speed and, consequently, a much greater need for action when it comes to detecting and responding to attacks: “One of the key developments is that, on the one hand, more vulnerabilities are being discovered, but on the other hand, the time between vulnerability discovery and potential exploitation is shrinking dramatically or even turning negative—so-called zero-day attacks.”

In addition, social engineering is playing an increasingly significant role due to AI-driven automation of attacks: “AI can serve as a tool for attackers to carry out efficient, targeted, and difficult-to-detect phishing campaigns.” Furthermore, publicly available information from corporate websites or social media can serve as additional fodder or be used for personalized attacks.

Last but not least, AI systems themselves naturally also provide a gateway for attackers. The BSI points out that large language models (LLMs) in particular—and AI systems based on them—exhibit new classes of vulnerabilities, such as so-called prompt injections and indirect prompt injections: “In these attacks, attackers either use direct requests to AI systems to change configurations or even execute code on (internal) systems, or they hide instructions—for example, on websites, in documents, or in emails—which are then unwittingly (indirectly) passed on to the model and can specifically influence its behavior.”

However, AI also offers new opportunities for organizations. For example, it provides the ability to check one’s own IT infrastructure for security vulnerabilities, update inventory lists, and create synergies to compensate for a lack of material or human resources. However, in all considerations, it must always be kept in mind that AI tools should only serve as a supplementary measure, never as a replacement.

What measures does the BSI recommend?

The first—and most important—aspect is for the private sector and public administration to address these new challenges: “Organizations must adapt to the new threat landscape in the short term and implement targeted measures.” The security measures listed below and outlined by the BSI are not newly developed, but they are becoming increasingly important.

  • Identify and minimize attack surfaces: “IT security managers should have a fundamental overview of all IT systems and applications operated within the organization so that, when new vulnerabilities arise, they can immediately assess how their organization is affected and identify general attack vectors targeting their organization.” Recommendations include creating an asset inventory (incidentally, this is a component of every information security management system), identifying and auditing exposed services and other access points, as well as network segmentation and regular penetration tests.
  • Patch Management: Efficient patch management is essential simply due to the increased number of vulnerabilities. Here, the BSI lists classic aspects of a patch strategy: assess and understand resources, utilize automation, prioritize systems, regularly review evaluation criteria, ensure the organization’s accessibility, and be aware of end-of-life and end-of-support dates for software and hardware products. 
  • Expand detection and incident response: The BSI notes that, with the simplified and significantly accelerated development of exploits enabled by AI, the exploitation of zero-day vulnerabilities is increasing substantially. This also increases the importance of detecting suspicious events. Among other things, it is recommended to review and strengthen monitoring of the network and IT systems in order to detect attacks early and initiate countermeasures. It is also of greater importance to continuously log both network traffic and events in order to detect attacks and determine the scope and duration of a compromise. SIEM (Security Information and Event Management) solutions are also recommended for the automated analysis of log data, issuing alerts in the event of anomalies, and for the immediate analysis of and response to potential IT security incidents. Similarly, IT security solutions for detecting and preventing attacks—such as EDR, XDR, and AV solutions—can offer effective approaches. It is also of central importance to be able to analyze, plan, and provision incident response capabilities in advance.
  • Implement standard measures: Last but not least, best practices regarding products and basic IT security measures should be verified and implemented. These include, for example, reviewing access rights, using and enforcing multi-factor authentication, operating and testing a backup management system, raising employee awareness, etc.

Conclusion

The IT security landscape—and above all, cybersecurity—is changing at an ever-faster pace, and the use of AI systems is contributing to this to a particularly significant degree. The pace at which vulnerabilities can be discovered and exploited is reaching new heights. Organizations are well advised to view developments surrounding AI not merely as a trend, but as a lasting change in the IT security landscape. Furthermore, it is time to review their own security processes and adapt them to the new circumstances in order to keep pace with the growing dynamics of the threat landscape.

About the Author: Alexander Weidenhammer is an attorney and serves as an external data protection and information security officer at the Dresden Institute for Data Protection. His consulting services focus in particular on law firms, tax advisory firms, small and medium-sized enterprises, and associations. 

– – – – –

Related Links

👉 www.dids.de 
👉 Artificial Intelligence 
👉 Keywords: Federal Office for Information Security (BSI), Cybersecurity, Artificial Intelligence

Photo: unsplash

You may be interested in the following

Contact info

Silicon Saxony

Marketing, Kommunikation und Öffentlichkeitsarbeit

Manfred-von-Ardenne-Ring 20 F

Telefon: +49 351 8925 886

redaktion@silicon-saxony.de