Sicra Header Logo
  • Careers
  • About us
  • People
EnglishNorsk
Talk to us
  1. Knowledge
  2. Insights
  3. Blog
Blog
24.09.2026
min read

Cyberattackers use AI, so cyber defense needs AI too

The attackers have been inside your systems for a year. You just don't know it yet. 
<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Cyberattackers use AI, so cyber defense needs AI too</span>
Editorial staff
Editorial staffAuthor

– I promise you, while we're talking right now, data is being stolen from many Norwegian companies without them realizing it. It may take another year before they discover that sensitive data has been compromised and they are hit by ransomware, says Vegard Gerotti Slåttelid at Arctic Wolf.

As you read this, cybercriminals are extracting data from companies across Norway. Quietly, patiently and invisibly. The companies have no idea that malware has been installed in their systems, and they do not know that a year from now, their files may be encrypted by ransomware or other crypto-malware.

As part of Sicra's 10th anniversary, we interviewed our security partner, Arctic Wolf, one of the world's largest cybersecurity companies.

Read what they say defines today's cyberattacks, and how you can protect your business.

  • Sicra 10 years: Read our interview with attorney Hedvig Moe about the future of cybersecurity, upcoming legislation and the risks associated with AI.

  • Sicra 10 years: Read our interview with Sicra CEO Gaute Lien about why security leadership is key to building a resilient organization.

Cybersecurity experts Vegard Gerotti Slåttelid and Alexander Ervik Johnsen paint an unsettling picture when we meet them. Both work at Arctic Wolf, one of the world's leading providers of cybersecurity services, including SOC services (Security Operations Center). Arctic Wolf has 4,000 employees and more than 12,000 customers worldwide. Every day, more than one quadrillion security events captured by over 7 million agents are logged and analyzed. This gives Arctic Wolf up-to-date insight into the threat landscape on a scale few others have access to.

Ransomware isn't what it used to be

– What is the biggest trend in cyberattacks right now?

– Cyberattacks have been around for decades, but artificial intelligence (AI) is driving a major shift right now. Attacks have become much more sophisticated and harder to detect, says Vegard Gerotti Slåttelid, Account Executive at Arctic Wolf.

He adds that the fundamentals remain the same. It usually starts with people. Someone clicks on something that sets events in motion. But AI is one of the reasons these attacks continue to succeed. Attempts to deceive people have become much harder to spot.

– Ransomware used to happen very suddenly. The attackers had their encryption malware in place, and bang, the ransom demand arrived. The trend now is for attackers to start with what we call data exfiltration. The criminals get in, but they don't encrypt anything. Instead, they quietly begin stealing data over time. This can continue for months. Then they encrypt the data. At that point, the criminals have twice the leverage: they have sensitive data they can use for extortion or sell on, and they have also locked the company's systems, Gerotti Slåttelid continues.

AI has to fight AI

Artificial intelligence makes threats harder to detect. Phishing emails are no longer characterized by poor Norwegian and obvious mistakes. Senders, and even phone calls, can appear completely plausible.

– Today, you can receive a phone call that appears to come from the CFO's number, using the CFO's voice, asking you to transfer NOK 100,000. It has become so sophisticated that you really have to stay alert and ask yourself, “Is this something the CFO would actually ask me to do?” It's important to stop, call back and verify the request before you click the link or transfer any money, says Gerotti Slåttelid.

– Standalone antivirus solutions, firewalls, systems and people don't detect these attacks until it's too late. You need strong security platforms with robust AI capabilities built in. AI has to fight AI. But AI alone isn't enough either. It's the combination of a solid platform, powerful artificial intelligence and knowledgeable people that provides real protection. That's why it's important to have a competent partner such as Sicra, says Gerotti Slåttelid.

According to Alexander Ervik Johnsen, Senior Sales Engineer at Arctic Wolf, this is where one of the most important differences between security providers comes into play: the quality of the data used to train their AI.

– Many vendors have trained their systems on synthetic data. That means data that doesn't reflect the real world as it actually is. It's like asking AI to write a wedding speech when all you know are the names of the bride and groom. We can't afford to play guessing games in our line of work, says Alexander.

Arctic Wolf has spent 14 years training its platform on real-world customer events. This means that when a new attack technique appears somewhere in the world, the system is already familiar with the pattern by the time it reaches the next victim.

What does it take to protect yourself?

– What security measures do organizations need in place to protect themselves today?

– You need the fundamentals of IT security in place, such as a good EDR solution (Endpoint Detection and Response), antivirus, robust firewalls, two-factor authentication and email security, all the basic elements. On top of that, you need a solution that monitors whether those fundamental security controls are actually doing their job, a solution that sees the bigger picture and has automated processes that can stop attacks quickly. There are many vendors out there making big promises, but their solutions can fall short as attacks become increasingly sophisticated.

Geopolitical instability and advanced cyber threats have made cybersecurity a rapidly growing industry, with many new players entering the market.

– The cybersecurity market has become a jungle, and it can be difficult to understand the difference between provider A, B and C. Everyone can look like a world champion in PowerPoint. What enables Arctic Wolf to stop more attacks than its competitors is the size of our dataset, which we have been building for more than 14 years.

– Whoever has the most data wins. That's why it doesn't cost extra to log events from every source in the Arctic Wolf platform. We're also vendor-agnostic when it comes to what we integrate with the platform. We don't care what your firewall is called or who supplied your network. With many other platforms, logging costs extra, and integrating all your different systems and solutions can be difficult. That makes it easy to lose the comprehensive visibility you need to stop cyberattacks effectively, says Gerotti Slåttelid.

Cyberattacks aren't a matter of bad luck

Ervik Johnsen is frustrated by executives who explain an attack after the fact as bad luck, for example by saying that an employee simply happened to click the wrong file.

– Attackers will find a way to get to you if they're determined enough. The question isn't whether someone will try to attack you, but whether you have the mechanisms in place to detect that you've been compromised quickly enough. To avoid serious consequences, you need the right mechanisms, the right alerts and the right products in place so you can respond as quickly as possible. If you don't, you'll be hit and you'll pay a high price afterward to clean it up, both in terms of cost and resources, says Ervik Johnsen.

– With a SOC from Arctic Wolf and a competent partner such as Sicra, you become significantly more resilient than you would be with a partner that, for example, just makes a few adjustments to a firewall or something similar. Because at the end of the day, it comes down to how much data you have, how much threat intelligence you have and how good the built-in AI capabilities are, Gerotti Slåttelid continues.

It was recently revealed that the Russian cybercriminal group Clop had breached and stolen data from major corporations including General Electric (GE), Shell, Philips and around 50 others.

– These companies have all the money in the world to invest in the best possible IT security. Yet they still get hit. That's why response time matters. With the technologies we use, we can recognize the attempt because we've already seen similar attacks against other organizations. That means we can act faster and more automatically than many of our competitors can, Ervik Johnsen concludes.

Vegard Gerotti Slåttelid is an Account Executive and Alexander Ervik Johnsen is a Senior Sales Engineer at Arctic Wolf, which delivers security operations through Sicra.

Need Assistance?

We are happy to have a non-binding conversation. 
Contact us

Explore more

The future of cybersecurity: More regulation and three AI risks
Blog

The future of cybersecurity: More regulation and three AI risks

Hedvig Moe on growing regulation and three AI risks shaping cybersecurity.
Gaute Lien: What makes organizations resilient to cyberattacks?
Blog

Gaute Lien: What makes organizations resilient to cyberattacks?

Gaute Lien on the security work that builds digital resilience.
Digital sovereignty must be measured in recovery time, not by the flag on the vendor’s website
Blog

Digital sovereignty must be measured in recovery time, not by the flag on the vendor’s website

Digital sovereignty is measured by how quickly critical services are restored.
How to choose the right SOC services in 2026
Blog

How to choose the right SOC services in 2026

Seven questions to ask before choosing a SOC service and managed SOC provider.

Stay updated
Receive the latest news

Links
SustainabilityFAQPartnersCertifications and awardsCareerPress & brand
Contact
Tel: +47 648 08 488
E-mail: firmapost@sicra.no

Drammensveien 151, 0277 Oslo

Follow us on Instagram

Follow us on LinkedIn
Certifications
iso27001-white
ISO 27001 compliance
miljofyrtarnlogo-hvit-rgb
Eco-Lighthouse
iso9001-white-removebg-preview
ISO 9001 compliance
Sicra Footer Logo
Sicra © 2025
Privacy Policy