There’s been a lot of discussion recently about AI becoming capable of launching cyber attacks autonomously.
It’s an extraordinary development.
Researchers have demonstrated AI systems capable of planning attacks, identifying weaknesses, chaining exploits together and achieving objectives with minimal human intervention and the freaky part is that this was during a “controlled evaluation”. This tells us how quickly AI capabilities in offensive cyber operations are evolving.
For many business owners, that sounds like something from a science fiction film. It isn’t.
But here’s the thing… I don’t think that’s the real story.
The real story is that the attacker has changed, but the way we defend our businesses hasn’t.
That is what you should be scared of.
For years, cyber criminals have been limited by one thing – time. They have been constrained by human capacity.
If they wanted to attack your business, they needed to research your organisation, identify weaknesses, build convincing phishing emails, look for exposed systems and test stolen credentials.
AI removes much of that effort. Instead of targeting ten businesses, attackers can target ten thousand. Instead of spending hours writing convincing phishing emails, AI can generate thousands in minutes.
Instead of manually looking for weaknesses, AI can automate reconnaissance, identify exposed systems and search for paths into an organisation at a speed no human team can match.
The barrier to entry is gone and attackers don’t need to be experts anymore.
That’s why I believe businesses are asking the wrong question.
They’re asking: “How do we defend against AI?”
The better question is: “Would our business detect an attacker, regardless of whether it’s a person or an AI?”
Because here’s the reality. An AI doesn’t invent an entirely new way into your organisation. It still needs to compromise identities. It still relies on phishing. It still abuses stolen credentials. It still looks for vulnerable devices. It still searches for exposed data. It still exploits weak security controls.
In other words, the criminals (robots or people) attack the same five areas every cyber criminal has always targeted:
- Users
- Data
- Machines
- Internet
The difference is that AI reaches those opportunities faster, more often and at a scale we’ve never seen before.
The foundations of cyber resilience haven’t changed, if anything, they’ve become even more important.
To be cyber resilient we must have the visibility necessary to protect identities, keep email secure, provide rapid detection, keep things up to date and monitor continuously.
These aren’t yesterday’s controls. They’re the controls that stop both human attackers and AI-powered ones.
Technology will continue to evolve as will your attackers. Businesses shouldn’t be chasing every new headline or buying the latest security product every time the industry invents another acronym.
They should focus on building resilience. This is because the organisations that thrive over the next decade won’t be the ones with the most tools, they will be the ones that know what’s happening across their business, can identify suspicious behaviour quickly and respond before an incident becomes a crisis.
At J2, that’s exactly how we approach cyber resilience. Not by preparing for one type of attacker, but by helping organisations build visibility and resilience across the five areas of digital risk.
No matter if the attacker is an AI robot or a human on a keyboard, the outcome businesses care about is exactly the same.
Did you see it?
Did you stop it?
Is the business able to keep operating?
Those are the questions that matter.