Skip to Main Content

Want to stay up-to-date with the latest IT news?
Subscribe to our mailing list to hear the latest news, events, free resources, and more for your industry.

Sign up now
Blog

The current state of cyber security and AI

3 minute read

Phoenix Software

October 8th, 2025

The current state of cyber security and AI

3 minute read

Phoenix Software

October 8th, 2025

As organisations rush to implement AI solutions, many are inadvertently creating new vulnerabilities in their infrastructure. Let’s examine the current state of cyber security and AI, with a focus on what you actually need to do to protect your AI investments.

Most organisations are excited about what AI can do for their security posture. Fewer are asking the critical question: how do we secure the AI itself?

AI platforms are fundamentally different from traditional applications. They require massive datasets, complex model architectures, and often operate with elevated privileges across your network. This creates attack surfaces that traditional security controls weren’t designed to handle.

The three pillars of cyber security and AI

If you’re deploying AI, whether for security purposes or broader business applications, you need to think about protection across three key areas:

  • Model security: your AI models can be attacked directly through adversarial inputs designed to manipulate their decisions. Attackers can also extract your models through repeated queries, essentially stealing your intellectual property and identifying weaknesses to exploit
  • Data security: AI systems are only as trustworthy as their training data. Data poisoning attacks can corrupt your models during training, while data exfiltration risks are amplified because AI platforms often need access to sensitive information across multiple systems
  • Infrastructure security: the compute environments running your AI need robust protection. This includes securing API endpoints, managing access controls for model deployment, and ensuring your AI workloads are properly isolated from other systems

Practical steps to secure your AI platforms

Good security in AI comes down to applying controls across your entire AI lifecycle. Start with access controls, use role-based access and least privilege principles for anyone interacting with models or training data. Monitor your AI systems continuously for unusual query patterns or sudden drops in prediction confidence that might signal attacks.

Your training data needs validation and tracking. Know exactly where it comes from and use anomaly detection to spot potential poisoning attempts. Treat your model deployment pipeline like critical code with version control, security reviews, and isolated environments for development, testing, and production.

Build adversarial resilience into your models through adversarial training and input validation. Encrypt models at rest and in transit, they contain valuable IP and sensitive patterns. For highly sensitive applications, explore federated learning or homomorphic encryption.

The skill gap challenge

You need people who understand machine learning, adversarial AI, data science, and traditional cyber security to secure your AI effectively.

Your options are to train existing staff, hire specialists, or partner with managed service providers who’ve already built this capability. There’s no shame in the third option, it’s often the most pragmatic choice.

Making it manageable: start small, scale smart

Don’t try to secure everything at once. Start with your highest-risk AI implementations. If you’re using AI for security decisions, access control, or processing sensitive data, those systems get priority.

Create a security framework specifically for AI that sits alongside your existing information security policies. Document your AI assets, classify them by risk, and apply controls proportionally. Not every machine learning model needs military-grade protection, but you need to consciously make that decision.

Find out more about cyber security and AI

The question isn’t whether AI will be part of your infrastructure, it already is. The question is whether you’re protecting it properly. Read our whitepaper on securing AI to find out more.

Phoenix Logo

About the author

Phoenix Software

Phoenix enables digital transformation in the workplace, empowering UK public sector organisations to innovate and transform with cloud and hybrid infrastructures, data, AI, security, and collaboration tools. By understanding its customers’ goals, Phoenix delivers outcome–focused IT solutions that make a difference to the lives of employees, service users, and communities. 

Follow Phoenix Software on LinkedIn.