Most cyber security tools are designed to react.
Something suspicious happens, the system detects it and tries to stop the damage before it spreads.
That’s incredibly important.
But what if AI could find the security weakness before an attacker does?
That’s what Microsoft is exploring with a new system called MDASH.
AI hunting for vulnerabilities
MDASH uses more than 100 specialised AI agents working together to search for security vulnerabilities within Windows.
Rather than relying entirely on security researchers to manually investigate enormous amounts of code and potential attack paths, these AI agents can examine different parts of a system, test for weaknesses and identify potential vulnerabilities automatically.
In simple terms, Microsoft is using AI to hunt for security holes at a scale that would be extremely difficult for humans to achieve alone.
And the early results are interesting.
During testing, Microsoft says the system uncovered previously unknown vulnerabilities affecting important Windows components, including vulnerabilities that could potentially be exploited remotely.
Some were classed as critical.
These are exactly the kinds of vulnerabilities security researchers want to discover before cyber criminals do.
Finding real problems, not just creating noise
There’s another important part to this.
One of the challenges with automated security tools is false positives.
Finding hundreds of possible vulnerabilities isn't particularly useful if security teams then have to spend huge amounts of time discovering that most of them aren't genuine threats.
Microsoft says MDASH has shown promising results in identifying genuine vulnerabilities while keeping false positives relatively low.
That could make this type of technology particularly valuable.
Instead of AI simply generating more alerts for security teams to investigate, it could help researchers focus their attention on vulnerabilities that actually matter.
Does this mean AI will solve cyber security?
Not quite.
MDASH is currently a Microsoft research project, and technology like this doesn't suddenly make the everyday fundamentals of cyber security less important.
Because for most businesses, attackers don't need to discover a sophisticated new Windows vulnerability if there's already an easier way in.
That could be:
An unpatched computer
A compromised password
A convincing phishing email
An account without multi-factor authentication
Excessive user permissions
Poorly configured security
Inadequate backups
Those everyday weaknesses remain extremely important.
AI will become another layer of defence
The really interesting part of MDASH is what it tells us about where cyber security could be heading.
In the future, we could see intelligent security agents continuously looking for vulnerabilities, analysing suspicious behaviour and identifying weaknesses before attackers have an opportunity to exploit them.
For large and complex IT environments, that could become a powerful additional layer of protection.
But there's an important word there: additional.
AI isn't a replacement for getting the fundamentals right.
Keeping systems patched, protecting accounts with MFA, controlling access, maintaining reliable backups and helping employees recognise cyber threats will continue to form the foundations of good business security.
AI might make those defences considerably smarter.
Unfortunately, criminals will also continue finding ways to use AI to make attacks faster, cheaper and more convincing.
So the technology on both sides will keep evolving.
But the principle behind good cyber security remains remarkably simple:
Reduce the opportunities available to attackers and make your business harder to compromise.
If you're not sure where the weaknesses are in your business, we can help.
Get in touch and let's take a look at your current cyber security.