For years, cyber security has largely focused on finding threats once something suspicious happens.
A security system detects unusual activity. An alert is raised. Someone investigates. The business responds.
That approach remains essential. However, AI cyber security could change how organisations identify risks in the first place, helping security teams find weaknesses before an attacker has the opportunity to exploit them.
Microsoft is already exploring what this could look like with a system called MDASH.
What is Microsoft MDASH?
MDASH stands for Microsoft Security Multi Model Agentic Scanning Harness. It uses more than 100 specialised AI agents to analyse complex software and search for potential vulnerabilities.
Rather than asking one AI model to look through code and identify problems, MDASH uses multiple specialised agents to investigate different areas, challenge potential findings and assess whether vulnerabilities could actually be exploited.
The scale is significant.
Microsoft says MDASH has already helped identify 16 previously unknown vulnerabilities across the Windows networking and authentication stack. Four of those vulnerabilities were rated critical and could potentially allow remote code execution.
That matters because discovering a vulnerability before criminals discover it can give defenders something incredibly valuable: time.
Could AI cyber security make protection more proactive?
The most interesting part of this development is not simply that AI can find security weaknesses.
It is the potential shift from reacting to attacks towards continuously looking for opportunities an attacker might use.
Think about the difference.
A traditional security tool might identify an attempted attack and help stop it. An AI powered vulnerability discovery system can instead examine the underlying technology and ask a different question:
Where could an attacker get in?
That is a much more proactive approach.
Microsoft has reported strong results from MDASH, including finding all 21 deliberately planted vulnerabilities in one private test with zero false positives. The system has also been used against real Microsoft code, with its findings contributing to security updates.
This is where AI in cyber security becomes particularly interesting. Rather than simply responding to alerts, AI can potentially help security teams investigate enormous amounts of information and identify risks that could otherwise be difficult to spot.
What does this mean for businesses?
It is easy to look at developments like MDASH and assume the future of cyber security will simply involve more AI.
The reality is more complicated.
AI is likely to become an increasingly important part of the security landscape. It could help organisations analyse information, identify vulnerabilities more quickly and prioritise the risks that actually matter.
At the same time, attackers are also gaining access to increasingly capable AI tools.
For businesses, that makes the fundamentals even more important.
Strong passwords, multi factor authentication, regular patching, appropriate access controls, secure backups and effective staff awareness training still provide the foundations of a resilient security strategy.
AI does not remove those responsibilities.
In fact, as technology becomes more sophisticated, understanding where your organisation is exposed becomes even more important.
The future of AI cyber security is not just about better tools
MDASH is a fascinating example of where AI cyber security could be heading.
The ability to use AI agents to continuously investigate complex systems and uncover vulnerabilities at a scale that would be difficult for humans to achieve alone could give defenders a significant advantage.
However, technology is only one part of the picture.
For most businesses, the biggest security improvements will not come from chasing the newest development. They will come from understanding their risks, closing known gaps and making sure the basics are consistently managed.
That is the real lesson from developments such as MDASH.
The future of cyber security may be powered by AI, but strong security still starts with knowing what you need to protect.
If you are unsure whether your current security strategy is keeping pace with the risks facing your business, we can help you understand where the gaps may be and what to prioritise next.
Get in touch with the Amshire team.