* [![perspectives](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com.au/perspectives)
* Fighting Fire with Fire: GenAI and Enterprise Security

# Fighting Fire with Fire: GenAI and Enterprise Security

![Fighting Fire with Fire: GenAI and Enterprise Security](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/05/perspectives-Fighting-fire-with-fire-hero-banner-1536x672-1.jpg)  
**By [Haider Pasha](https://www.paloaltonetworks.com.au/perspectives/author/haider-pasha/ "Posts by Haider Pasha")** | **6 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Fighting Fire with Fire: GenAI and Enterprise Security\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com.au%2Fperspectives%2Ffighting-fire-with-fire-genai-and-enterprise-security%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com.au/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com.au/perspectives/fighting-fire-with-fire-genai-and-enterprise-security/?pdf=download&lg=en&_wpnonce=4139c4630b "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/02/haider-pasha-1.jpg)  
  Haider Pasha is VP \& Chief Security Officer, EMEA at Palo Alto Networks. Over the course of his 20 year IT career, Mr. Pasha has held various certifications, including CCNP, CCSP, CISSP, CCIE (Security) and CEH. ...

[Learn more](https://www.paloaltonetworks.com.au/perspectives/author/haider-pasha/)

## IN THIS ARTICLE

Listen to the Discussion

*This article was originally published in the* [*Economist*](https://impact.economist.com/new-globalisation/targeted-approach-ai/precision-ai/)\*under the title: "\*Gen AI and enterprise security: fighting fire with fire."

It's a call that no CISO wants to get: After an uptick in phishing emails, the SOC at a European manufacturer reports unusual network traffic across the organisation. Hundreds of rank-and-file employees are now locked out of their workstations. Soon, a controller in the Manchester office receives a demand for an anonymous bitcoin transfer. It's an [Akira ransomware attack](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/). In seconds, the lives of the entire cybersecurity team are turned upside-down as they scramble to restore access and prevent another attack.

While this account is fictional, the scenario plays out thousands of times every year. Ransomware attacks are on the uptick, as are phishing expeditions and other exploits. These threats are set to be supercharged by a new wave of generative AI (GenAI) tools proliferating on the Dark Web.

While GenAI is not yet able to create novel malware from scratch, it is already being used as a copilot capable of writing basic code and even impersonating existing malware such as the [BumbleBee webshell](https://unit42.paloaltonetworks.com/bumblebee-webshell-xhunt-campaign/).

For ransomware, if you want to customize something for your victim, that used to take roughly 12 hours to code. In today's environment, there are tools available on the Dark Web that can actually reduce that time to as low as three hours using tools like [WormGPT](https://unit42.paloaltonetworks.com/using-llms-obfuscate-malicious-javascript/).

The situation will become more dire as the technology improves. Michelle Abraham, research director, security and trust at IDC, notes that GenAI has already proved to be a game changer for phishing. Five years ago, phishing emails were usually written in English (of varying quality), because that is where the most profit could be made. Not anymore.

"The threat actors didn't write phishing emails in other languages," Ms. Abraham explains. "Now, that's changing. You just get GenAI to translate for you, and still come up with good language." This has not only increased the quality of phishing emails, but also the quantity of attacks.

Zero-day attacks that exploit an unknown vulnerability are another area of concern. Security agencies comprising the Five Eyes intelligence alliance (the United States, Britain, Australia, Canada and New Zealand) recently documented a sharp increase in the number of zero-day attacks, adding that the majority of the most frequently exploited vulnerabilities were initially exploited as a zero-day in 2023, compared to less than [50% the year prior](<https://blog.google/technology/safety-security/a-review-of-zero-day-in-the-wild-exploits-in-2023/#:~:text=Commercial%20surveillance%20vendors%20(CSVs)%20lead,separately%20exploited%20another%20four%20vulnerabilities.>).

The sheer number of zero-day attacks is staggering: Data gathered by Palo Alto Networks found between [2.3M and 2.5M zero-day attacks](https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-launches-new-security-solutions-infused) every day. This is in part due to hackers leveraging AI to design and launch attacks. What used to take eight weeks now just requires a few days---or even less.

Using AI to actually understand the vulnerability, build the code, run the exploit, and actually do it in an automated fashion, can be brought down to less than an hour.

## Cybersecurity's AI Toolbox

CISOs are quickly learning that the cybersecurity playbook of the 2010s is no longer capable of handling the threat landscape of the 2020s.

"There's so many different parts of your IT environment, and they produce a lot of data," says IDC's Ms. Abraham. "It's too much for humans to analyze."

Fortunately, they have access to their own AI-enabled tools to fight back. Machine learning (ML) has long been part of the cybersecurity arsenal to help identify anomalies that could indicate attacks or probes. What is different now is the ability of GenAI to provide context and help to focus the attention of human analysts---and to make better use of their limited time.

"The ability to ask systems questions in natural language, rather than needing to learn the specific search language of the tool allows analysts who aren't as familiar with a particular tool's language to more easily query," Ms. Abraham says.

Palo Alto Networks [PrecisionAI](https://www.paloaltonetworks.com/precision-ai-security)^®^ leverages ML and GenAI to automate threat detection. Deep learning enables predictive threat assessments. PrecisionAI can bring in data from other vendors' security applications, as well as Palo Alto Networks library of 4,000 ML models.

To identify and respond to threats, we can process 9 petabytes every day, gleaned from our own solutions as well as third-party data. The system can autonomously respond to 90% of threats, and notify the SOC of more complicated threats that require human intervention.

When PrecisionAI finds an incident and goes to an analyst and says, 'this incident is bad,' and gives it a certain score, say from zero to 100, it can explain exactly why. We know that it's 100% accurate in that assessment. We have confidence in our data, and we believe that we can help our customers on that journey.

## The Shadow AI Problem is Real

The human element can confound the best of well-laid cybersecurity plans. It might be Felix in logistics tapping a link in a text message from an unknown sender, or Emma in R\&D installing an open source Mistral model on a local dev machine.

"It's like everything with security," says Ms Abraham. "You can train people on what they should do, but it is not always possible to make sure --- absolutely sure --- that they don't."

Shadow AI follows the established Shadow IT phenomenon. It runs the gamut from employees using personal devices to upload corporate data to ChatGPT ("summarize this Q1 sales report") to proof-of-concepts involving experimental AI apps.

Multiple surveys have found high levels of unsanctioned AI in enterprise environments. Salesforce data published in late 2023 showed [45%](https://www.salesforce.com/news/stories/ai-at-work-research/) of respondents in Britain reported using unapproved GenAI tools at work, while 15% reported using banned AI tools.

The fast-evolving cybersecurity landscape, fuelled by the rise of GenAI and the persistent problem with Shadow AI, underscores the urgency for organisations to adapt their defences to counter these threats more effectively.

There really needs to be a very strong governance framework as well as an enforcement point. In many cases, I think attackers will continue to surprise us. As such, we will have to work even harder to stay ahead of those challenges.

Curious about what else Haider has to say? Check out his other articles on [Perspectives](https://www.paloaltonetworks.com/perspectives/author/haider-pasha/).

* [AI](https://www.paloaltonetworks.com.au/perspectives/all-articles/?cat=ai)
* [Staying Ahead of Evolving Threats](https://www.paloaltonetworks.com.au/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)

## Related Content

![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://www.paloaltonetworks.com.au/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://www.paloaltonetworks.com.au/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://www.paloaltonetworks.com.au/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://www.paloaltonetworks.com.au/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://www.paloaltonetworks.com.au/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://www.paloaltonetworks.com.au/perspectives/weaponized-intelligence/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* AU  
  Select your language
