Intelligent security tools: are they a smart choice for you?
What you need to know before buying artificially intelligent security products
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

The availability of cheap data storage and processing has made artificial intelligence commercially viable. As a result, it's everywhere. Working out your route home, filtering your email, selling you stuff online... But, is AI a good fit for cyber security?
We recently published some new guidance on intelligent security tools, designed to help you answer this question for yourself.
In this blog post I'd like to outline some of the questions we ask in that guidance and say a few words about how AI has become the 'next big thing' in cyber security.
Cyber security has seen tremendous growth in the number and types of products that are using AI. From checking for intruders to weeding out malicious emails, the idea of these tools is to allow the human beings working on security to make the best use of their time.
Using AI to support security in this way should be of great benefit, so long as the tool itself is well suited to the job. That's why it's important to realise that AI is not one single technology. An intelligent tool that works for one situation might not work for another.
If you want to be confident that an intelligent tool is the right fit for you, you need to ask the right questions.
With that in mind, once we've introduced the topic of AI, and busted some jargon, our guidance asks a series of questions. The first of which is, 'do you really need an intelligent tool?'
While this may seem like a strange question, it's important to know that you’re solving a real problem and that an intelligent tool will help. This involves knowing your security priorities and what the market can offer, as well as how any given tool fits within the structure of your organisation.
If you can establish that there's a need for the intelligent tool, then you should start thinking about the data needed to drive it. Trying to power an intelligent tool without the right data is asking for trouble, giving inaccurate answers to important security questions.
The next question is about who will interact with the tools. You should ensure you have enough support and training to make an intelligent tool work and that the outputs can be acted upon. Getting this kind of support can turn a seemingly ineffectual tool into a powerful component in the defence of your system.
Even doing everything right, there are still limitations on the defensive capabilities of AI.
The field is ever changing, so it's tough to nail down what the technical limitations are at any given time. Things we thought were impossible a few months ago are now part of common AI tool kits.
Staying on top of developments in AI isn't simple. But you don't need to be an expert. If the claims made for a tool seem too good to be true, all you have to do is ask a few questions.
We hope that the guidance we’ve written provides a useful starting point for you and your organisation as you begin the process of assessing intelligent security tools.


