The relationship between artificial intelligence strategy and cyber resilience was highlighted during the fireside chat “When AI Strategy Meets Cyber Resilience”, featuring Demetris Skourides, Chief Scientist for Research, Innovation and Technology, and moderated by Michalis Kassinis, former ISACA Board Member, ISACA, as part of the 6th Cyber Security Conference.
The discussion placed particular emphasis on the real-life conditions of pressure that an organisation faces when it is called upon to make critical decisions within minutes. Demetris Skourides raised the crucial question of what a business does at two o’clock in the morning, precisely when a serious incident occurs. He noted that, in Cyprus, regulations and instructions at board level sometimes lack flexibility, adding that simply assigning responsibility to one person is not enough.
The question is whether the individual concerned possesses the appropriate knowledge to carry out a meaningful analysis of threats and risks in order to manage the situation. Linking his position to the presentation by the Commissioner of Communications, he stressed that training is critical, but that in the age of artificial intelligence, a deeper understanding of additional factors is required.
At the same time, he addressed the risks associated with the use of artificial intelligence solutions, examining the conditions required for secure, reliable and resilient digital systems. Demetris Skourides stressed the need for companies to know exactly which artificial intelligence model is being used in the applications that serve them, since there is always a possibility that such a solution could be breached, begin reproducing inaccurate data or behave uncontrollably. Most organisations do not analyse the extent of their dependence on, and entrapment by, a particular provider, and do not have alternative options available.
Although many businesses are turning to open-source software, the question remains as to what happens when such a solution comes under attack, particularly when it is not supported by maintenance cycles or binding support agreements.
In conclusion, the importance of understanding threat actors was highlighted, along with the need to cultivate a new mindset so that employees view cybersecurity and resilience as something of exceptional value, rather than as a merely theoretical issue.
The Chief Scientist praised the comments made by the Commissioner of Communications, who earlier highlighted the real value and impact that a breach has on a business, reminding attendees that the damage extends far beyond the purely financial cost.





