Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Lawscot Foundation

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Our logo and branding

    • Equality and diversity

  1. Home
  2. For members
  3. Journal Archive
  4. Issues
  5. November 2023
  6. Cyber risks in a world of AI

Cyber risks in a world of AI

In association with Mitigo: Artificial intelligence will expand the capabilities of cybercriminals, and the need for safeguards
13th November 2023

AI is a hot topic. Many professional service firms are already using AI or exploring its potential to revolutionise the way they deliver their services. But it’s not all good news. Cybercriminals are also interested in the benefits of AI and how it can make their activities more profitable. Here, we discuss the potential impact of AI from a cybercrime perspective, and provide some tips on how to mitigate the risk AI presents.

Here are three aspects to consider.

Local unauthorised use of AI tools

Staff members may already be using ChatGPT and other AI to make their work more effective. In our cybersecurity assessments, we often see a significant footprint of AI tools that are being used locally on the employee’s computer. This is largely invisible to the business and the person who is responsible for IT or cybersecurity.

The issues here are:
  • Downloading of applications that aren’t subject to the appropriate level of due diligence.
  • Uploading business information and data into hosted AI engines where control is lost.
  • Loss of effectiveness of existing controls, e.g. anti-virus software will be blind to these new processes.
Takeaway actions:
  1. Start with a policy that defines legitimate use, and make sure it is published and understood.
  2. Create a process to assess and approve/decline existing use cases.
  3. Ensure local admin rights and anti-virus settings prevent the download of applications to devices.
  4. Toughen browser and anti-virus settings to flag use of AI websites or websites with low trust scores.

Poor development and implementation of AI

The core focus of development and implementation of AI will be the benefit
it can bring to a business, e.g. by reducing costs or increasing efficiencies. Therefore, at the design stage, security elements can often be overlooked, which in turn can lead to vulnerabilities.

The issues here are:
  • The development process will require you to experiment with different services and providers. This has an inherent risk as cybercriminals will move fast to insert malicious code into services (this is already happening).
  • You are introducing a new supplier and processes into your supply chain and these need to be controlled.
  • The attack surface of your organisation has changed and potentially grown. You need to ensure you design appropriate controls and security.
Takeaway actions:
  1. A separate environment should be created for the development/experimentation process to reduce the risk of a malicious actor connecting to your business-as-usual network.
  2. A due diligence process should be designed and carried out on new suppliers.
  3. Existing policy needs to be updated to include the new technology and processes. For example, how are software patches identified and updated?
  4. Your control framework needs to be updated. What controls, monitoring and alerts need to be created to secure the new business process?

Increased sophistication of cyberattacks powered by AI

The adoption of AI by cybercriminals to launch attacks and exploit vulnerabilities is arguably the biggest threat to a business. This includes enhanced ability to get round cyber training and control measures.

Some examples:
  • Spotting flaws in emails and websites has long been a protection against cybercrime. AI will enable greater sophistication. Social engineering can be taken to a new level as multiple approaches can be coordinated to entrap a victim.
  • Impersonation is often a key part of attacks. Imagine deep fakes of images and voices, and think about what the criminals could do with those.
  • Speed of development will increase. Every time a control stops a malicious bit of code, AI will have the ability to instantly analyse and code a solution for the criminals.
Takeaway actions:
  1. Simulated attacks on staff need to be more frequent and mimic the new approaches.
  2. Authentication and conditional access need to be improved to make the stealing of credentials ever more difficult for the criminals.
  3. Layers of defence will be essential. If a human gets duped, ensure that there is sufficient control and alerting to stop the progression of an attack.
  4. Assessment and assurance will become increasingly important. Frequent assessment by experts will be required to keep you hardened against the increasing sophistication and scale of attack.

The Author

This article was produced by the Law Society of Scotland’s strategic partner Mitigo. Take a look at their full cybersecurity service offer.
For more information, contact Mitigo on 0131 564 1884 or email lawscot@mitigogroup.com

Share this article
Add To Favorites
https://lawware.co.uk/

Regulars

  • People on the move: November 2023
  • Book reviews: November 2023
  • Reading for pleasure: November 2023

Perspectives

  • Opinion: Alison Hook
  • President's column: November 2023
  • Editorial: Just causes
  • Profile: James Bryden
  • Viewpoints: November 2023

Features

  • Time for due diligence on debt recovery
  • Bringing FAIs under review
  • Can we talk about periods at work?
  • Conference for change
  • "The future is now"

Briefings

  • Civil court: Cases for the connoisseur
  • Employment: ICO issues guidance on workers’ health data
  • Family: Lack of resources no longer a trump card
  • Human rights: When can we still call something “law”?
  • Pensions: Amendment void without actuary confirmation
  • Scottish Solicitors' Discipline Tribunal: November 2023
  • In-house: Life after GC

In practice

  • Public policy highlights: November 2023
  • Covid Inquiry: playing our part
  • Risk: Register of Overseas Entities – an update
  • Walking, in (almost) all weathers
  • Ask Ash: Work still means office

Online exclusive

  • Developers' casting vote as good as gold
  • It’s an emergency! A guide to time off for dependants
  • Early marriage: any need for action?
  • Manifestly unreasonable: the first QOCS disapplication

In this issue

  • Denovo’s legal software innovations in 2023
  • Cyber risks in a world of AI
  • Pioneering the future of Legal IT
  • Investment jargon busting: what you really need to know
Dec 2023
Nov 2023
Oct 2023
Sept 2023
Search the archive

Additional

Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: lawscot@lawscot.org.uk
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2025
Made by Gecko Agency Limited