Skip to Content
  • Standorte

    Standorte

    North & Latin America
    • Atlanta
    • Austin
    • Bogota
    • Boston
    • Buenos Aires
    • Chicago
    • Dallas
    • Denver
    • Houston
    • Lisbon
    • Los Angeles
    • Mexico City
    • Minneapolis
    • Monterrey
    • Montreal
    • New York
    • Rio de Janeiro
    • San Francisco
    • Santiago
    • São Paulo
    • Seattle
    • Silicon Valley
    • Toronto
    • Washington, DC
    Europe & Africa
    • Amsterdam
    • Athens
    • Berlin
    • Brussels
    • Copenhagen
    • Düsseldorf
    • Frankfurt
    • Helsinki
    • Istanbul
    • Johannesburg
    • Kyiv
    • Lisbon
    • London
    • Madrid
    • Milan
    • München
    • Oslo
    • Paris
    • Rome
    • Stockholm
    • Warsaw
    • Wien
    • Zürich
    Middle East
    • Doha
    • Dubai
    • Riyadh
    Asia & Australia
    • Bangkok
    • Beijing
    • Bengaluru
    • Brisbane
    • Ho Chi Minh City
    • Hong Kong
    • Jakarta
    • Kuala Lumpur
    • Manila
    • Melbourne
    • Mumbai
    • New Delhi
    • Perth
    • Seoul
    • Shanghai
    • Singapore
    • Sydney
    • Tokyo
    Alle Standorte Anzeigen
  • Alumni
  • Presse
  • Newsletter
  • Kontakt
  • DACH-Region | Deutsch

    Wählen Sie Ihre Region und Sprache

    Global
    • Global (English)
    North & Latin America
    • Brazil (Português)
    • Argentina (Español)
    • Canada (Français)
    • Chile (Español)
    • Colombia (Español)
    Europe, Middle East, & Africa
    • France (Français)
    • DACH-Region (Deutsch)
    • Italy (Italiano)
    • Spain (Español)
    • Greece (Elliniká)
    Asia & Australia
    • China (中文版)
    • Korea (한국어)
    • Japan (日本語)
  • Saved items (0)
    Saved items (0)

    You have no saved items.

    Inhalte, für die Sie sich interessieren, werden hier gespeichert und können später gelesen oder weitergeleitet werden.

    Explore Bain Insights
  • Branchenkompetenzen
    Hauptmenü

    Branchenkompetenzen

    • Luft- und Raumfahrt, Verteidigung
    • Agrarwirtschaft
    • Chemieindustrie
    • Infrastruktur und Bauwirtschaft
    • Konsumgüter
    • Finanzdienstleistungen
    • Gesundheitswesen
    • Maschinen- und Anlagenbau
    • Medienwirtschaft
    • Metallindustrie
    • Bergbau
    • Öl und Gas
    • Papier- und Verpackungsindustrie
    • Private Equity
      Branchenkompetenzen
      Private Equity
      • Due Diligence
      • Exit Planning
      • Firm Strategy & Operations
      • Portfolio Value Creation
    • Öffentlicher Sektor und Sozialwesen
    • Einzelhandel
    • Technologie
    • Telekommunikation
    • Transportwesen
    • Reise- und Freizeitbranche
    • Versorgung und erneuerbare Energien
  • Managementkompetenzen
    Hauptmenü

    Managementkompetenzen

    • Customer Experience
    • ESG
    • Innovation
    • M&A
    • Operations
    • People & Organization
    • Private Equity
    • Sales & Marketing
    • Strategie
    • KI, Einblicke und Lösungen
    • Technologie
    • Transformation
  • Digital
  • Publikationen
    Hauptmenü

    Publikationen

    • Branchenthemen
    • Managementthemen
    • Bain-Bücher
    Alle Publikationen
    Ausgewählte Themen
    • Resilienz in der globalen Krise
    • M&A Report
    • Private Equity Podcast
    • Midyear Private Equity Report
    • Agile
    • Engineering Report
    • Digital Transformation
    • Elements of Value®
    • Firm of the Future
    • Nachhaltigkeitsstudie
    • Macro Trends
    • Future of Consumption
    • Weltwirtschaftsforum (WEF)
  • Über uns
    Hauptmenü

    Über uns

    • Was wir bieten
    • Unser Ansatz
    • Unser Team
    • Game Changer Award
    • Female Allstar Board
    • Messbare Ergebnisse (EN)
    • Auszeichnungen
    • Globale Partnerschaften
    • The Mission
    Further: Our global responsibility
    • Vielfalt & Chancengleichheit
    • Soziale Verantwortung
    • Sustainability
    Erfahren Sie mehr zu "Further"
  • Karriere
    Hauptmenü

    Karriere

    • Dein Einstieg
      Karriere
      Dein Einstieg
      • Find Your Place
      • Unsere Arbeitsbereiche
      • Unsere Teams
      • Angebote für Studierende
      • Praktika & Programme
      • Recruiting-Events
    • Arbeiten bei Bain
      Karriere
      Arbeiten bei Bain
      • Blog: Inside Bain
      • Karriere Stories
      • Unsere Bainies
      • Office-Standorte
      • Weiterentwicklung
      • Affinity Groups
      • Deine Benefits
    • Impact Stories
    • Deine Bewerbung
      Karriere
      Deine Bewerbung
      • Das erwartet dich
      • Der Interviewprozess
    FIND JOBS
  • Standorte
    Hauptmenü

    Standorte

    • North & Latin America
      Standorte
      North & Latin America
      • Atlanta
      • Austin
      • Bogota
      • Boston
      • Buenos Aires
      • Chicago
      • Dallas
      • Denver
      • Houston
      • Lisbon
      • Los Angeles
      • Mexico City
      • Minneapolis
      • Monterrey
      • Montreal
      • New York
      • Rio de Janeiro
      • San Francisco
      • Santiago
      • São Paulo
      • Seattle
      • Silicon Valley
      • Toronto
      • Washington, DC
    • Europe & Africa
      Standorte
      Europe & Africa
      • Amsterdam
      • Athens
      • Berlin
      • Brussels
      • Copenhagen
      • Düsseldorf
      • Frankfurt
      • Helsinki
      • Istanbul
      • Johannesburg
      • Kyiv
      • Lisbon
      • London
      • Madrid
      • Milan
      • München
      • Oslo
      • Paris
      • Rome
      • Stockholm
      • Warsaw
      • Wien
      • Zürich
    • Middle East
      Standorte
      Middle East
      • Doha
      • Dubai
      • Riyadh
    • Asia & Australia
      Standorte
      Asia & Australia
      • Bangkok
      • Beijing
      • Bengaluru
      • Brisbane
      • Ho Chi Minh City
      • Hong Kong
      • Jakarta
      • Kuala Lumpur
      • Manila
      • Melbourne
      • Mumbai
      • New Delhi
      • Perth
      • Seoul
      • Shanghai
      • Singapore
      • Sydney
      • Tokyo
    Alle Standorte Anzeigen
  • Alumni
  • Presse
  • Newsletter
  • Kontakt
  • DACH-Region | Deutsch
    Hauptmenü

    Wählen Sie Ihre Region und Sprache

    • Global
      Wählen Sie Ihre Region und Sprache
      Global
      • Global (English)
    • North & Latin America
      Wählen Sie Ihre Region und Sprache
      North & Latin America
      • Brazil (Português)
      • Argentina (Español)
      • Canada (Français)
      • Chile (Español)
      • Colombia (Español)
    • Europe, Middle East, & Africa
      Wählen Sie Ihre Region und Sprache
      Europe, Middle East, & Africa
      • France (Français)
      • DACH-Region (Deutsch)
      • Italy (Italiano)
      • Spain (Español)
      • Greece (Elliniká)
    • Asia & Australia
      Wählen Sie Ihre Region und Sprache
      Asia & Australia
      • China (中文版)
      • Korea (한국어)
      • Japan (日本語)
  • Saved items  (0)
    Hauptmenü
    Saved items (0)

    You have no saved items.

    Inhalte, für die Sie sich interessieren, werden hier gespeichert und können später gelesen oder weitergeleitet werden.

    Explore Bain Insights
  • Branchenkompetenzen
    • Branchenkompetenzen

      • Luft- und Raumfahrt, Verteidigung
      • Agrarwirtschaft
      • Chemieindustrie
      • Infrastruktur und Bauwirtschaft
      • Konsumgüter
      • Finanzdienstleistungen
      • Gesundheitswesen
      • Maschinen- und Anlagenbau
      • Medienwirtschaft
      • Metallindustrie
      • Bergbau
      • Öl und Gas
      • Papier- und Verpackungsindustrie
      • Private Equity
      • Öffentlicher Sektor und Sozialwesen
      • Einzelhandel
      • Technologie
      • Telekommunikation
      • Transportwesen
      • Reise- und Freizeitbranche
      • Versorgung und erneuerbare Energien
  • Managementkompetenzen
    • Managementkompetenzen

      • Customer Experience
      • ESG
      • Innovation
      • M&A
      • Operations
      • People & Organization
      • Private Equity
      • Sales & Marketing
      • Strategie
      • KI, Einblicke und Lösungen
      • Technologie
      • Transformation
  • Digital
  • Publikationen
    • Publikationen

      • Branchenthemen
      • Managementthemen
      • Bain-Bücher
      Alle Publikationen
      Ausgewählte Themen
      • Resilienz in der globalen Krise
      • M&A Report
      • Private Equity Podcast
      • Midyear Private Equity Report
      • Agile
      • Engineering Report
      • Digital Transformation
      • Elements of Value®
      • Firm of the Future
      • Nachhaltigkeitsstudie
      • Macro Trends
      • Future of Consumption
      • Weltwirtschaftsforum (WEF)
  • Über uns
    • Über uns

      • Was wir bieten
      • Unser Ansatz
      • Unser Team
      • Game Changer Award
      • Female Allstar Board
      • Messbare Ergebnisse (EN)
      • Auszeichnungen
      • Globale Partnerschaften
      • The Mission
      Further: Our global responsibility
      • Vielfalt & Chancengleichheit
      • Soziale Verantwortung
      • Sustainability
      Erfahren Sie mehr zu "Further"
  • Karriere
    Häufige Suchanfragen
    • Agil
    • Digital
    • Strategie
    Vorherige Suchanfragen
      Zuletzt besuchte Seiten

      Content added to saved items

      Saved items (0)

      Removed from saved items

      Saved items (0)

      Technology Report

      Generative AI and Cybersecurity: Strengthening Both Defenses and Threats

      Generative AI and Cybersecurity: Strengthening Both Defenses and Threats

      Breakthroughs in technologies built on large language models will accelerate the arms race between hackers and companies.

      Von Syed Ali und Frank Ford

      • Min. Lesezeit
      }

      Report

      Generative AI and Cybersecurity: Strengthening Both Defenses and Threats
      en
      Auf einen Blick
      • Generative artificial intelligence (AI) should strengthen cybersecurity, particularly in threat identification, although it’s unlikely to lead to full automation anytime soon.
      • Bad actors are also exploring generative AI’s potential to aid cyberattacks through innovations such as self-evolving malware.
      • Through a range of moves today, both buyers and providers of cybersecurity services can take advantage of the new technology while remaining protected.

      This article is part of Bain's 2023 Technology Report.

      Explore the report

      Only months after its public breakthrough, generative AI has shown the potential to transform cybersecurity products and operations. After the launch of ChatGPT and other products powered by large language models (LLMs), the cybersecurity industry is planning for generative AI to become a key tool. And that’s despite the launch challenge generative AI faces in cybersecurity—namely, the sensitive and siloed nature of security data, which makes it hard to get high-quality, comprehensive datasets to train and update an LLM model.

      So far, threat identification is the hot spot. When we analyzed cybersecurity companies that are using generative AI, we found that all were using it at the identification stage of the SANS Institute’s well-known incident response framework—the biggest uptake in any of the six SANS stages (preparation, identification, containment, eradication, recovery, and lessons learned). That fits our assessment that threat identification holds the greatest potential for generative AI to improve cybersecurity (see Figure 1). Generative AI is already helping analysts spot an attack faster, then better assess its scale and potential impact. For instance, it can help analysts more efficiently filter incident alerts, rejecting false positives. Generative AI’s ability to detect and hunt threats will only get more dynamic and automated.

      Figure 1
      Threat identification holds the most potential for generative AI to improve cybersecurity—and that’s where industry adoption has been strongest so far
      Threat identification holds the most potential for generative AI to improve cybersecurity—and that’s where industry adoption has been strongest so far
      Threat identification holds the most potential for generative AI to improve cybersecurity—and that’s where industry adoption has been strongest so far

      For the containment, eradication, and recovery stages of the SANS framework, adoption rates vary from about one-half to two-thirds of the cybersecurity companies we analyzed, with containment most advanced. In these stages, generative AI is already narrowing knowledge gaps by providing analysts with remedy and recovery instructions based on proven tactics from past incidents. While there will be more gains through automation of containment, eradication, and recovery plans, full automation is unlikely over the next 5 to 10 years, if at all. The longer-term impact of generative AI in these areas is likely to be moderate and will likely always need some human supervision.

      Generative AI is also being used in the lessons-learned stage, where it can automate the creation of incident response reports, improving internal communication. Crucially, the reports can be reincorporated into the model, improving defenses. For example, Google’s Security AI Workbench, powered by the Sec-PaLM 2 LLM, converts raw data from recent attacks into machine-readable and human-readable threat intelligence that can accelerate responses (under human supervision). But while the quality of generative AI–powered incident response reports should keep improving, human involvement is still likely to remain necessary.

      A double-edged sword

      Of course, generative AI can also be used as a cyberattacker's tool, giving them similar capabilities as defenders. For example, less experienced attackers can use it to create more enticing emails or more realistic deepfake videos, recordings, and images to send to phishing targets. Generative AI also allows bad actors to easily rewrite a known attack code to be just different enough to avoid detection.

      Generative AI has certainly become a trending topic for malicious actors. Mentions of generative AI on the dark web proliferated in 2023 (see Figure 2). It’s common to see hackers boasting that they’re using ChatGPT. One hacker posted that he was able to use generative AI to recreate malware strains from research publications, such as a Python-based stealer that can search and retrieve common file types (.docx, PDF, images) across a system.

      Figure 2
      The use of generative AI for nefarious purposes has become an increasingly popular topic on the dark web after the launch of ChatGPT
      The use of generative AI for nefarious purposes has become an increasingly popular topic on the dark web after the launch of ChatGPT
      The use of generative AI for nefarious purposes has become an increasingly popular topic on the dark web after the launch of ChatGPT

      The threat from bad actors will only increase as they use generative AI to standardize and update their tactics, techniques, and procedures. Generative AI–assisted dangers include strains of malware that self-evolve, creating variations to attack a specific target with a unique technique, payload, and polymorphic code that’s undetectable by existing security measures. Only the most agile cybersecurity operations will stay ahead.

      Actions to take now

      Corporate leaders should:

      • understand that generative AI won’t rid cybersecurity of its operational and technical complexities;
      • make generative AI and cybersecurity a recurring agenda item for board and C-suite meetings; and
      • avoid a narrow focus on controls or certain risks—cybersecurity demands a holistic approach.

      Chief information officers/chief information security officers should:

      • get security operations (SecOps) leaders to validate generative AI output, particularly threat-detection algorithms updated by generative AI;
      • train new and junior SecOps employees to hunt threats with and without generative AI to avoid dependence; and
      • where possible, avoid relying on a single vendor or generative AI model across the cybersecurity stack.

      Cybersecurity companies should:

      • hire the right mix of talent to bring generative AI capabilities into their products; and
      • guard against generative AI–created false information (hallucinations) and external tampering with generative AI algorithms and models that might create backdoor vulnerabilities.

      Generative AI will rapidly advance, and it’s essential that all stakeholders from cybersecurity providers to enterprises continuously update their specialist knowledge and strategy to take advantage—and stay protected.

      Read the Next Chapter

      Taking the Hyperbole Out of the Metaverse

      Read our 2023 Technology Report

      Download the PDF Explore the report
      Autoren
      • Headshot of Syed Ali
        Syed Ali
        Partner, Houston
      • Headshot of Frank Ford
        Frank Ford
        Partner, London
      Kontaktieren Sie uns
      Verwandte Branchen
      • Cybersecurity
      • Technologie
      Ähnliche Beratungsangebote
      • Digitalisierung
      • Informationstechnologie
      Wie wir Sie unterstützen können
      • Artificial Intelligence
      Technology Report
      Quantum Computing Moves from Theoretical to Inevitable

      Quantum will likely become part of a mosaic, working with classical computing to solve big problems.

      Mehr erfahren
      Technology Report
      Will Agentic AI Disrupt SaaS?

      Disruption is mandatory. Obsolescence is optional.

      Mehr erfahren
      Artificial Intelligence
      Four Ways Leaders Can Make AI Redesigns Stick

      As companies redesign to scale AI, these four lessons help leaders ensure their organizations actually live the new operating model.

      Mehr erfahren
      Artificial Intelligence
      Reimagining Merchandising in the Era of Agentic AI

      The future of merchandising is not better analysis, but faster, smarter execution—and agentic AI is what makes that possible.

      Mehr erfahren
      Technology Report
      State of the Art of Agentic AI Transformation

      Tech-forward enterprises have cracked the code on ROI for AI. Falling behind is riskier than ever as the next wave of agentic AI raises the stakes.

      Mehr erfahren

      Value Evolution

      • Creating Value in Tech Throughout the Life Cycle

      • Preparing for Exit: A Buyer’s Market Is Coming for Tech Assets

      • AI Investors: Act Fast, Act Wisely

      • Technology Enters Its Post-Globalization Era

      Strategic Battlegrounds

      • You’re Out of Time to Wait and See on AI

      • How AI Is Recoding the Software Business Model

      • Generative AI and Cybersecurity: Strengthening Both Defenses and Threats

      • Taking the Hyperbole Out of the Metaverse

      • The Untapped Value at the Intelligent Edge

      • After the Chip Shortage, Fears of a Capacity Glut Are Overblown

      Operational Transformations

      • Digital Innovation: Getting the Architecture Foundations Right

      • The Talent Implications of Generative AI

      • How Enterprise Sales Can Supercharge Product-Led Growth

      • How Your Revenue Can Grow Faster Than Your Salesforce

      • Decarbonizing Technology Supply Chains

      First published in September 2023
      Markierungen
      • Artificial Intelligence
      • Cybersecurity
      • Digitalisierung
      • Informationstechnologie
      • Technologie
      • Technology Report

      Wie wir unsere Kunden unterstützt haben

      Nachhaltigkeit Can Microchips Turbocharge Sustainability Improvement?

      Kundenbeispiel lesen

      Digitalisierung How a Data-Driven Mindset Powers McAfee’s Growth

      Kundenbeispiel lesen

      Kundenstrategie und Marketing Increased sales productivity frees selling time and saves millions

      Kundenbeispiel lesen

      Möchten Sie mit uns in Kontakt bleiben?

      Wir unterstützen Führungskräfte weltweit, die kritischen Themen in ihrem Unternehmen zu adressieren. Gemeinsam schaffen wir nachhaltige Veränderungen und Ergebnisse.

      Bain Insights. Unsere Perspektive auf die kritischen Themen, mit denen sich international agierende Unternehmen konfrontiert sehen, finden Sie monatlich in Ihrem Postfach.

      *Ich habe die Datenschutzerklärung gelesen und akzeptiere sie.
      Bitte lesen Sie die Datenschutzerklärung und akzeptieren Sie diese.
      Bain & Company
      Contact us Sustainability Accessibility Rechtliche Hinweise Impressum Datenschutz Cookie-Richtlinie Sitemap Log In

      © 1996-2026 Bain & Company, Inc.

      Kontaktieren Sie Bain

      Wie können wir Ihnen helfen?

      • Business inquiry
      • Career information
      • Press relations
      • Partnership request
      • Speaker request
      Alle weltweiten Büros