Part VI: AI in attack and defense
Claims about AI in cybersecurity require separate evidence for attacker assistance, defensive value, and deployment cost.
Claims that AI helps an attacker or defender need a comparison with work performed without that assistance. Chapter 17 separates demonstrated capabilities from evidence of actual attacks. Chapter 18 measures defensive benefit and errors while retaining analyst judgment and service authorization. Chapter 19 compares model and hosting choices for a fixed task, required quality, permissions, and operating budget. A result from one task or deployment does not settle the other comparisons.
Chapters in this part
- AI-assisted attacks: Different evidence supports capability, observed AI use, prevalence, and measured improvement, guiding controls for verified attack paths.
- Evaluating AI for defense: A defensive AI assessment measures useful security work while keeping human judgment, data access, and action authority visible.
- Comparing AI deployment options: A deployment comparison holds task, data access, quality target, and action limits constant, then measures results and full operating cost for each option.