Modern understandings of cybersecurity are based on concepts and practices systematized over decades. They are the result of an upgrade aimed at reflecting the rapid changes in technology and the methods used to commit cybercrime. The internet, constructed as an open system for the free exchange of information, was not created with a priority on security. The need for security in cyberspace, however, became apparent almost immediately.
The first malicious actions following the free distribution of the internet to users were documented in the 1980s. The nature of these actions illustrates that online security is not a one-time act and an established state, but an insecure balance requiring constant effort. The emerging need for a systemic approach to digital security is at the heart of the many modern rules, policies, and guidelines recommended and imposed by governments, international institutions, and expert organizations. The principal requirements underlying cybersecurity have a universal character, and their knowledge and application mark the boundary between relative security and potential losses.
With new technologies and circumstances, the principles of cybersecurity are also undergoing dynamic changes. They are not a static property[1], but their development is occurring to some extent with insufficient speed and efficiency. The lightning-fast entry of AI into almost all spheres introduces its own specificity to the qualitative changes in cybersecurity practices. They cease to be merely an escalating set of technical standards and take on the role of ethical and strategic guidelines. Through them, answers are sought to the dilemmas caused by automation with the spread of AI. In this chapter, the main principles of cybersecurity and their change caused by generative AI will be analyzed.
Confidentiality, Integrity, and Availability (CIA) of information are the cornerstone of the modern understanding of cybersecurity. Violating any of these states of information would mean compromise and losses. They are important because they reflect a specific state, imperative for digital security, where information is a primary asset and its protection is a priority. Confidentiality concerns protecting information from unauthorized access and ensuring it is available only to subjects with appropriate access rights. Integrity concerns the completeness of information, which can only be modified by authorized subjects according to prescribed rules. Availability should ensure access to information at any time when needed by those authorized to access it.
The three principles are an indivisible whole in the context of cybersecurity, where there is a wide range of measures to protect them from traditional and asymmetric threats. The emergence of generative AI, however, has introduced new uncertainty into cyberspace. Regarding the principle of confidentiality, it has been established how generative AI models can reproduce confidential information with which they have been trained[2]. Furthermore, generative AI exerts pressure on guaranteeing integrity due to the ability of models to create program code, images, and information indistinguishable from the original.
This makes possible the rapid spread of false information that penetrates official channels and causes confusion. Such risks provoke proposals by some authors for the introduction of so-called “trust chains” through which to algorithmically track the sources of any information[3]. Information availability is a particularly vulnerable and attackable circumstance, because through generative AI numerous vulnerabilities can be exploited for the purpose of taking down sites or databases. Some of the example methods are blocking access to information via DDoS[4] attacks and writing malicious programs.
In this regard, the National Institute of Standards and Technology (NIST) recommends dynamic risk management related to safeguarding the security of the CIA triad[5] and applicable against threats stemming from the misuse of AI. Generative AI poses new challenges to the CIA triad, but simultaneously underscores its importance and relevance, and provokes the development of new protection methods. This principle remains fundamental in the effort to increase cybersecurity and serves as a basis for the development of physical infrastructure, which is the focus of the analysis in the next principle.
[1] ENISA, Best Practices For Cyber Crisis Management, February 2024, https://www.enisa.europa.eu/publications/best-practices-for-cyber-crisis-management
[2] ENISA, ENISA Threat Landscape 2023, October 2023, p.83 https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023
[3] Whitman, M. E., & Mattord, H. J. (2009). Principles of information security (p. 656). Boston, MA: Thomson Course Technology.
[4] Distributed Denial of Service
[5] NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023, AI Risk Management Framework | NIST


