Security1 publisher2 min readPublished
NCSC's Chismon puts the limit on agentic cyber defence at the damage a wrong action does
Dave Chismon argues that offence gets a pass/fail signal and defence does not, so every automated remediation still needs a person to weigh it and answer for it, even as his agency builds Cyber Shield.
The Watch · Security desk

What happened
- Dave Chismon, the NCSC's chief technology officer for architecture, wrote in a blog post Monday that defenders cannot yet put AI to work as freely as attackers can.
- He expects AI-enabled cyberattacks to grow on that imbalance, with automated defences struggling to keep pace.
- The NCSC is building Cyber Shield, a capability meant to deploy agentic AI systems to discover and fix weaknesses across government networks and critical national infrastructure.
- Chismon called making autonomous defensive actions safe enough to deploy an unsolved problem, and said the agency will soon publish an "AI for Cyber Defence" research agenda.
- Software makers have patched at record rates since the June Five Eyes warning, and a comparable rise in cyberattacks has not yet been observed.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint What caps automated defence is the cost of a wrong action on a production network, so a more capable model does not raise the ceiling; the sign-off stays with a person who can be held to it.
- decision Buyers weighing agentic remediation now have a five-part state test to hold a vendor pitch against, and the jobs that clear it today are read-only ones such as summarizing threat intelligence.
- contradiction Operators are told autonomous defensive action is not yet safe while the same agency aims agentic fixes at the networks least able to absorb a bad one, and the research meant to close that gap is not out.
Chismon's case turns on what an automated system can be told it achieved. An exploit works, or malware "calls home", which gives automated tooling an unambiguous signal [4]. He opened with a maxim he credited to security researcher Halvar Flake: "All offensive problems are technical problems, and all defensive problems are political problems." [3]
Defence has no equivalent signal. Defensive work "doesn't always have a clear success state" to tell an automated system whether it worked, Chismon wrote [5]. Defensive actions also land on the live systems they are meant to protect, and his examples of a wrong move are a patch that takes down the VPN and a firewall rule that breaks a business function [6]. Because the downside is that steep and success that hard to measure, he wrote, a human has to weigh each action and answer for it [7]. Some board members, he added, would see little difference between an attack that takes down a company's IT and a botched defensive action that does the same, "except that the board can't shout at an attacker over the phone" [8]. Defenders "simply cannot put AI to work in the same way attackers can," he wrote, calling it "an inconvenient truth" [9].
The offensive advantage he describes is a forecast. In June the Five Eyes alliance, which includes GCHQ, the agency NCSC sits inside, warned that frontier AI could transform offensive and defensive cyber operations within months rather than years [10]. Over the summer, models from Google, Anthropic, OpenAI and Meta reached real-world systems during security evaluations, and in most of those cases they got in through basic means including reusing exposed credentials [11]. The chair of the G20's financial stability board and the Chinese Communist Party's top intelligence official have raised similar concerns, and what the "fundamental transformation" actually consists of is still unclear [12].
So the practical advice is about scope, not capability. Start with low-risk uses such as having AI summarize threat intelligence for human analysts, Chismon said, and judge automation by its reach, impact, criticality, predictability and reversibility [16]. Those five criteria are the framework the NCSC blog publishes [19]. He also wrote that there is much defenders can do to unlock the potential of agentic cyber defence [20].
For the interval, he told defenders to keep doing the slow work. Agentic defence is not ready to be relied on and building it "will take time, effort, and research", Chismon cautioned [17]. Organizations "cannot risk just waiting for agentic defence to roll in and protect them" and should keep improving their security "the traditional way," he wrote [18].
What to watch
- The "AI for Cyber Defence" research agenda the NCSC says it will publish soon, and whether it sets a testable safety bar for autonomous action.
- Whether Cyber Shield's agentic systems are allowed to fix weaknesses on live government and CNI networks or stay advisory.
- Whether the record patch rate since June is eventually followed by a measured rise in AI-enabled intrusions.