TechnologyUK NCSC

One does not simply defend agentically

One of my favourite cybersecurity maxims is Halvar Flake’s observation that “All offensive problems are technical problems, and all defensive problems are political problems.”

For an attacker conducting offensive cyber actions, the problems that need to be solved are largely technical. They might be:

Do I have an exploit for this vulnerability?
or
How do I avoid detection?

Whilst defenders also have technical challenges, they mostly wrestle with what Halvar describes as ‘political’ problems (which for the purposes of this discussion can be framed as organizational problems). Problems such as:

‘Can we get budget to replace this end-of-life system or invest in a more secure option?’

‘How do I get IT operations to make time for patching?’

‘How do we get a change request to put in firewall rules approved?’

In other words, defenders are most restricted by their organizational policies, whilst most attackers are restricted by technical hurdles. The reason for this difference becomes clear when you compare the core purposes of attackers and defenders.

For attackers, their core purpose is ‘to conduct cyber offense,’ and success will cause their employer to profit. Whether that’s stealing money from organizations, extorting victims, or exfiltrating information. Cyber offense is their raison d’être.

For the defenders, their mission is to help their organization avoid loss. Their employer’s mission isn’t cyber defense; it will depend upon whatever activity that organization does (such as developing products, treating patients, or providing digital services). Cyber defense is effectively ‘a cost of doing business,’ one of many priorities that the organization has to manage.

This means the cost of cyber defense has to be rigorously assessed to make sure it does not harm the organization’s competing priorities:

‘Could that money earmarked to replace the end-of-life system be better used on marketing?’

‘Will that patch take down the VPN?’

‘How sure are we that the firewall rule will not break a business function that relies on that connectivity?’

Some board members may see little difference between a DoS attack taking down the organization’s IT, or a poorly implemented action by the cyber defense team that does the same thing. Except that the board can’t shout at an attacker over the phone …

Agentic tooling can be used for cyber offense, because AI is good at helping with technical problems with a clearly measurable success state. Offensive problems are mostly technical and usually have a clear success state (the target program crashes, your malware calls home). But defensive problems, as we’ve established above, are not mostly technical. Nor do they always have a clear success state.

Using AI automation for defense therefore quickly becomes a matter of organizational politics, and someone needs to be responsible for the action taken. Defenders simply cannot put AI to work in the same way attackers can. This is an inconvenient truth, as it suggests that the threat from AI-enabled cyber attacks will grow, whilst autonomous/agentic cyber defense might struggle to keep up unless we approach things differently.

Source: UK NCSC (Cyber) (21 September 2026)

Related Articles

Back to top button