Cybersecurity work that can support either defence or offence depending on how it is used. Threat modelling, adversarial simulation, and exfiltration analysis all fall into this category. In practice, the key issue is not the technique itself, but whether the work is governed, reviewed, and restricted to defensive security objectives.
Expanded Definition
Dual-use cybersecurity work refers to methods, workflows, and tooling that can legitimately support defensive security outcomes while also enabling harmful operations if redirected. The term is especially important in incident response, threat intelligence, adversarial simulation, exploit validation, and AI-assisted security analysis, where the same technical steps may be used for protection, reconnaissance, or abuse. For that reason, the relevant question is not whether a technique is “advanced” or “sensitive,” but whether it is governed with clear purpose limitation, review, and access restrictions.
Usage in the industry is still evolving, and no single standard governs this yet. In practice, organisations often anchor decision-making to internal policy plus public guidance such as CISA cyber threat advisories, which frame activity around defensive readiness and threat awareness. The same logic applies when AI tools are involved, because model outputs can accelerate both detection and abuse. The most common misapplication is treating dual-use work as automatically permissible, which occurs when teams assume defensive intent alone is enough to justify tools, datasets, or simulations that exceed approved scope.
Examples and Use Cases
Implementing dual-use cybersecurity work rigorously often introduces approval overhead and documentation burden, requiring organisations to weigh faster testing and richer intelligence against tighter governance and fewer ad hoc investigations.
- Threat modelling for a new application may reveal attack paths, credential misuse routes, and data exposure points that help defenders harden controls, but those same findings can also be operationalised by an attacker.
- Adversarial simulation and purple-team exercises can validate detections and response playbooks, especially when using techniques mapped to resources such as the MITRE ATLAS adversarial AI threat matrix for AI-adjacent scenarios.
- Exfiltration analysis can help security teams confirm whether data-loss controls are working, yet the same analysis may expose sensitive pathways that require strict scoping and logging.
- Security research into agentic AI behaviour can identify prompt injection, tool abuse, and data leakage risks, but it must be bounded so that findings do not become a blueprint for misuse.
- Defensive validation of malware indicators, command-and-control patterns, or payload behaviour can improve detection engineering, while uncontrolled reproduction of those artefacts increases operational risk.
In mature programmes, dual-use work is usually routed through a formal review process, separated from production systems, and documented with explicit defensive objectives. Where AI is involved, the risk is amplified because a single workflow may automate reconnaissance, summarisation, and action generation, which is why authorities increasingly discuss these scenarios in terms of misuse potential and containment. Recent reporting such as Anthropic — first AI-orchestrated cyber espionage campaign report illustrates how quickly defensive analysis techniques can be repurposed when governance is weak.
Why It Matters for Security Teams
Security teams need a precise understanding of dual-use work because it sits at the boundary between legitimate defence and possible facilitation of harm. Without guardrails, a normal defensive activity can become a source of data leakage, unsafe tooling, or inappropriate operational knowledge transfer. That is especially relevant in identity and access operations, where reconnaissance of tokens, secrets, privileged workflows, or recovery paths can rapidly cross from validation into exposure. For NHI and agentic AI programmes, the risk is even sharper: an evaluation that tests whether an agent can reach a system may also demonstrate how an attacker could chain tool access, so the review process must consider both intent and exploitability.
Governance should therefore focus on role-based approval, least privilege, logging, environment isolation, and explicit permitted-use boundaries. Teams also need escalation paths for higher-risk research, especially when work touches live credentials, production telemetry, or adversarial AI techniques. Organisations typically encounter the consequences only after an investigation, a security incident, or a postmortem reveals that a well-intended test produced reusable offensive artefacts, at which point dual-use governance becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | Risk governance frames when security research needs review and approval. |
| NIST AI RMF | GOVERN | AI RMF governs AI use with accountability, oversight, and risk controls. |
| OWASP Agentic AI Top 10 | Agentic AI guidance addresses tool abuse, prompt injection, and unsafe action chains. | |
| CSA MAESTRO | MAESTRO focuses on secure orchestration and governance for agentic systems. | |
| NIST SP 800-63 | IAL2 | Identity assurance matters when dual-use work touches privileged or verified access. |
Classify dual-use activities in risk registers and require governance review before execution.
Related resources from NHI Mgmt Group
- Who should be accountable for verifying high-risk dual use security work in AI-assisted testing?
- How should teams use cybersecurity benchmark reports in identity governance planning?
- What breaks when employees use browser sync for work credentials?
- What breaks when employees use shadow AI for work tasks?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org