Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC warns mistaking AI vulnerability could lead to large-scale breaches

Security

NCSC warns mistaking AI vulnerability could lead to large-scale breaches

The National Cyber Security Centre (NCSC) – a part of GCHQ – has shared critical insights cautioning cyber security professionals against comparing prompt injection and more classical application vulnerabilities classed as SQL injection.

Image by frank60 / copyright Shutterstock

A new blog advises that, contrary to first impressions, prompt injection attacks against generative artificial intelligence applications may never be totally mitigated in the way SQL injection attacks can be.

Unlike SQL mitigation techniques, which hinge on enforcing a clear separation between data and instructions, prompt injection exploits the inability of large language models (LLMs) to distinguish between the two.

Advertisement
ODU RT

Without action addressing this misconception, the NCSC warns, websites risk falling victim to data breaches exceeding those seen from SQL injection attacks in the 2010s, impacting UK businesses and citizens into the next decade.

Backing proactive adoption of cyber risk management standards, the NCSC challenges claims that prompt injections can be ‘stopped’.

Advertisement
Leonardo animated rectangle

Instead, it suggests efforts should turn to reducing the risk and impact of prompt injection and driving up resilience across AI supply chains.

As AI technologies become embedded in more UK business operations, the NCSC calls on AI system designers, builders and operators to take control of manageable variables, acknowledging that LLM systems are “inherently confusable” and their risks managed in different ways.

Advertisement
Babcock LB Babcock LB
Tyron Runflat set to establish UK centre of excellence

Defence Security

Tyron Runflat set to establish UK centre of excellence

16 December 2025

Tyron Runflat has invested in doubling its facility with the ambition of creating its first UK centre of excellence within the next five years.

Spaceport Cornwall and National Drone Hub launch UAS project

Aerospace Defence Security Space

Spaceport Cornwall and National Drone Hub launch UAS project

15 December 2025

The UK's first licensed spaceport, Spaceport Cornwall, has commenced work on a groundbreaking project with the National Drone Hub to establish a unique testing environment for uncrewed aerial systems (UAS).

Smiths Detection’s SDX 100100 DV HC on TSA ACSTL

Aerospace Security

Smiths Detection’s SDX 100100 DV HC on TSA ACSTL

15 December 2025

Smiths Detection's SDX 100100 DV HC X-ray scanner has been added to the Transportation Security Administration’s Air Cargo Screening Technology List (ACSTL), enabling its use by regulated operators across the US air cargo sector.

JFD Global to enhance Polish Navy

Defence Security

JFD Global to enhance Polish Navy's submarine rescue capability

11 December 2025

James Fisher (JFD Global) has secured a contract with PGZ Stocznia Wojenna, which will see JFD Global integrate a combined, hyperbaric and saturation diving system into the Polish Navy’s new salvage and rescue vessel, Ratownik.

Advertisement
ODU RT
RISC appoints Paul Lincoln as Chair

Security

RISC appoints Paul Lincoln as Chair

11 December 2025

The Security and Resilience Industry Suppliers Community (RISC), today announces the appointment of Paul Lincoln CB OBE VR as its new Chair.

Avon Protection receives European order for FM50 respirators

Defence Security

Avon Protection receives European order for FM50 respirators

11 December 2025

Avon Protection has received a new European order for FM50 respirators and FM61EU filters via the NATO Support and Procurement Agency (NSPA) contract vehicle.

Advertisement
Leonardo animated rectangle