Every week there’s another headline about AI. There is so much noise that most people are lost, and keep focusing on the AI itself. have no idea where they stand.
- AI can write code.
- AI can replace jobs.
- AI can find vulnerabilities.
- AI can now launch cyber attacks.
Every week businesses ask me the same question in relation to cyber security:
“How worried should we be about AI?”
I think that’s the wrong question, because the risk isn’t AI. The risk is what AI has removed, the human capacity constraint.
For years, cyber criminals were limited by the one thing: time.
They had to research businesses, write convincing phishing emails, look for vulnerabilities, test stolen passwords and then move carefully through networks.
That required patience, people and it required skill.
AI now does this all for them. Attacks that once took days can now take minutes and one attacker can now target thousands of businesses simultaneously instead of a handful in a day.
This is not because AI invented a new way to compromise organisations, it has automated the old ones.
That’s the part businesses should be paying attention to. The criminal hasn’t become smarter, they’ve become faster. The attacker no longer needs to have any skills.
This changes the scale of the problem.
A few years ago, an attacker might decide whether your business was worth targeting. Today, they don’t have to decide, their AI decides.
It finds the easiest route into a business and then moves on to the next one.
Your business wasn’t chosen; it was simply available.
That’s a very different world and it’s why I believe businesses are still focusing on the wrong thing. We’re debating AI policies and pretending that our users are not using ChatGPT. You are writing AI governance documents. These are all important conversations, but none of them reduce the likelihood of a cyber attack.
The truth is that whether an attack is launched by a person or an autonomous AI agent, the business impact is exactly the same.
Your Microsoft 365 account is still compromised. Your customer data is still stolen. Your production systems still stop. Your reputation is still damaged. The attacker doesn’t need a new attack method.
They still target the same five areas every organisation depends on:
- Users
- Data
- Machines
- Internet
The difference is that AI gives them more opportunities to find the one weakness you’ve missed, at scale.
That’s why the conversation shouldn’t be about AI. It must be about resilience.
- Can you see suspicious behaviour across your environment?
- Would you know if credentials had been stolen?
- Could you detect unusual access to sensitive data?
- Can you respond before a compromise becomes a business crisis?
Those are the questions boards should be asking, not because AI changes everything, because it changes one thing that matters more than almost anything else.
The speed at which attackers can find your weaknesses.
Technology will continue to evolve, and the headlines will continue to change. The businesses that succeed won’t be the ones chasing every new AI story.
The ones that succeed will be the ones that build resilience across the whole environment.
Cyber resilience isn’t about preparing for artificial intelligence, it’s about ensuring that whether the attacker is human or machine, they meet the same outcome.
They don’t get in.
The attacker evolves. The principles of cyber resilience don’t.