bg
Cybersecurity
20:53, 01 September 2026
views
12

GigaChat 3.5 Ultra Neural Network Successfully Passes Cybersecurity Exam

It passed a 250-question test and scored 14% above the passing threshold.

When artificial intelligence was first introduced into corporate workflows, it was largely viewed as an assistant that could be tasked with a broad range of questions. Today, however, even general-purpose large language models have become sophisticated enough to handle highly specialized tasks, including those related to cybersecurity.

Validating Knowledge

Recently, specialists from Sberbank and the Information Security Training Center evaluated the cybersecurity knowledge of the Russian large language model GigaChat 3.5 Ultra. The AI successfully answered 250 questions from a professional retraining program in information security, scoring 14% above the passing threshold.

The test included both theoretical and practical cybersecurity questions. Topics covered regulatory and legal requirements, technical protection against unauthorized access and data leaks, cryptographic data protection methods, information-system certification, and much more.

A Reliable Information Resource

“Validated knowledge enables GigaChat 3.5 Ultra to handle practical information-security tasks, including preparing draft internal regulatory documents and providing guidance on incident management and other issues. This level of knowledge makes GigaChat a practical tool for a range of scenarios. Information-security professionals can get a quick consultation on a work-related question or assistance preparing documents,” Sber’s press service said.

GigaChat 3.5 Ultra could be particularly useful for small businesses that do not have a dedicated information-security professional on staff. The model can be used for guidance on data protection. It can also help people who want to enter the cybersecurity field by providing a roadmap for understanding the knowledge and skills required to become a highly qualified information-security professional.

Training on 300,000 Documents

To equip the neural network with cybersecurity knowledge, experts trained the model on more than 300,000 documents covering information-security best practices, legislation, vulnerability descriptions, and the tactics and techniques used in cyberattacks.

For now, of course, GigaChat 3.5 Ultra cannot be considered a full-fledged cyberthreat defense system or be trusted to conduct incident investigations on its own. It can, however, serve as a reference resource for recommendations on responding to attacks. This approach could reduce the workload of human employees who need a reliable source of information while dealing with security incidents.

Notably, the latest test was far from GigaChat’s first serious assessment of its knowledge. In May 2026, the model passed undergraduate-level exams in Power Engineering and Heat Power Engineering at the National Research University Moscow Power Engineering Institute, receiving a “good” grade. At the time, it became the only Russian neural network to pass academic assessments in several engineering disciplines at once. In February 2026, it demonstrated its knowledge of real estate at the Nizhny Novgorod State University of Architecture and Civil Engineering, and in April, it was assessed in the energy sector at the National Research University Moscow Power Engineering Institute.

AI Is Already Fighting Cyberattacks

In August, Sberbank revealed that it had begun deploying artificial intelligence in its cyberattack defense processes. Its team developed multimodal AI agents to combat phishing and integrated them into the bank’s internal cyberintelligence platform. The new system operates on an AI-versus-AI principle and replaces manual work. Four specialized agents independently examine four data layers of a website: text, code, infrastructure, and imagery in the form of a screenshot. The resulting artifacts form an evidence base that an “agent prosecutor” and an “agent defense attorney” use in a simulated dispute to identify contradictions, while an “agent judge” makes the final decision based not on a single classification label but on a verifiable chain of evidence and arguments.

Most likely, GigaChat and other Russian-developed general-purpose large language models will soon be used as a kind of copilot for information-security professionals, helping with search, analysis, document preparation, initial threat classification, and recommendation generation. It is too early to talk about fully replacing people because the potential cost of an error is too high. Moreover, major companies today generally view AI as a tool to assist people, not replace them.

In my view, the first thing an organization needs to do to remain secure and cyber-resilient is to bring order to its IT infrastructure. The better that infrastructure is documented and accounted for, the stronger the cybersecurity processes that can be built on top of it. Many organizations do not pay enough attention to this issue when building their protection systems. Second, of course, is deploying AI technologies across all aspects of cybersecurity. In today’s world, malicious actors are already using AI to accelerate cyberattacks and make them more sophisticated. A person cannot counter this alone, without AI support
quote
like
heart
fun
wow
sad
angry
Latest news
Important
Recommended
previous
next