AI Is Raising the Stakes for Cybersecurity
The warning is fairly stark. The group argues that organizations have a limited window to prepare before AI-enabled cyberattacks become significantly more widespread and sophisticated.
Just as importantly, though, it makes another point: the same technology increasing the pressure on defenders can also help them respond.
It would be easy to read this as another warning about AI and move on.
CISOs shouldn’t.
The bigger issue isn’t whether AI suddenly creates an entirely new category of cyberattack. It’s what happens when capabilities that already exist become faster, cheaper, easier to automate, and available at much greater scale.
That changes the job of the defender.
AI Changes the Economics of Cyberattacks
Most organizations already have weaknesses attackers can exploit.
Unpatched software. Excessive privileges. Misconfigurations. Weak authentication. Technical debt that’s been sitting untouched because replacing the system behind it is difficult, expensive, or operationally risky.
AI doesn’t need to invent a revolutionary attack technique to make that problem worse.
Think about what happens when an attacker can reduce the time required to analyze an exposed service, adapt a script, generate convincing social engineering content, process large volumes of stolen information, or test multiple attack paths.
Tasks that previously required time and specialist knowledge can increasingly be accelerated.
For defenders, that has an important consequence: time matters even more than it did before.
An alert that waits in a queue for hours is a very different proposition when the attacker can move through the next stages of an intrusion in minutes.
More Alerts Aren’t the Answer
The instinctive response to a faster threat landscape can be to collect more data, deploy more tools, and generate more alerts.
But most security teams don’t have a shortage of alerts.
They have a shortage of context.
Endpoint telemetry might show unusual process execution. Identity systems might flag suspicious authentication. Cloud infrastructure might generate a configuration alert. Network monitoring might spot unexpected traffic.
Individually, each signal may or may not matter.
The difficult part is connecting them quickly enough to understand whether you’re looking at noise, an isolated event, or the early stages of a real attack.
That’s where security operations need to evolve.
Detection can’t simply be a process of waiting for a known indicator to trigger and handing the resulting alert to an analyst.
Teams need detection engineering that reflects current attacker behavior, threat intelligence that adds context, proactive hunting for activity that hasn’t triggered an obvious alert, and the ability to move from investigation to containment quickly.
This is one of the reasons Managed Detection and Response has become such an important part of modern cyber resilience.
Kudelski Security’s MDR approach brings together 24/7 monitoring, detection engineering, proactive threat hunting, investigation, and response.
The goal isn’t simply to escalate more alerts. It’s to identify the activity that matters and give security teams the context and support needed to act.
MDR Has to Be About Context, Not Just Coverage
Visibility still matters. You can’t defend an environment you can’t see.
But visibility alone doesn’t solve the problem.
Modern organizations generate security data across endpoints, identities, cloud environments, SaaS applications, on-premises infrastructure, and, increasingly, operational technology and cyber-physical systems.
Kudelski Security’s MDR model is designed to work across those environments while combining threat intelligence, business context, and expert analysis.
The important word there is context.
A privileged login at 2 a.m. might be perfectly legitimate.
The same login from an unusual location, followed by privilege escalation, suspicious cloud activity, and access to sensitive systems tells a very different story.
Good detection is about understanding those relationships.
As AI accelerates both legitimate activity and malicious behavior, that ability to distinguish meaningful signals from background noise becomes even more important.
Get More From the Security Stack You Already Have
There’s another practical challenge for CISOs: most organizations aren’t starting from scratch.
They’ve already invested heavily in security platforms, telemetry, identity controls, endpoint protection, and cloud security.
Many have built significant parts of their security operations around ecosystems such as Microsoft.
The answer to an AI-accelerated threat landscape can’t simply be another cycle of ripping out existing technology and replacing it with something new.
MDR should help organizations get more from what they already have.
Kudelski Security’s approach is designed to integrate with existing security investments rather than force a rip-and-replace strategy.
Its MDR services work with leading security platforms and extend internal teams with continuous monitoring, investigation, hunting, and response expertise.
That matters because resilience isn’t built by owning the largest collection of security products.
It’s built by making the technology, people, intelligence, and processes you already have work together effectively.
AI Can Strengthen the Defender Too
There’s a positive side to this story that shouldn’t get lost.
The industry call isn’t asking organizations to retreat from AI.
Quite the opposite.
AI can also help defenders identify and fix weaknesses faster, improve information sharing, accelerate investigations, and strengthen security operations.
That’s an important distinction.
The future of security operations isn’t humans trying to manually keep pace with machines.
Nor is it handing every security decision to AI.
The opportunity lies somewhere between the two.
Automation can help process telemetry, enrich signals, accelerate investigation, and reduce repetitive work.
Experienced analysts bring something different: knowledge of the organization, understanding of attacker behavior, the ability to challenge assumptions, and judgment when the consequences of a response matter.
That combination becomes particularly important when containment could disrupt production systems, critical services, or business operations.
Speed matters.
So does knowing when to slow down.
What Should CISOs Do Now?
There’s no single product that solves the AI security challenge.
For security leaders, the priorities are more fundamental.
- Reduce known exposure. Patch what can be patched, address excessive privilege, strengthen authentication, and understand where technical debt is creating exploitable risk.
- Improve detection context. Make sure telemetry across identity, endpoint, cloud, network, and other critical environments can be correlated and investigated quickly.
- Hunt proactively. Don’t assume every attack will arrive with a clean indicator or trigger an existing detection rule.
- Prepare to respond at speed. Define containment workflows before an incident happens and make sure responsibilities, escalation paths, and decision-making authority are clear.
- Use AI deliberately. Take advantage of automation where it improves speed and coverage, while keeping experienced people involved in decisions where context and consequences matter.
Those aren’t radical changes.
That’s partly the point.
AI is raising the stakes, but many of the fundamentals of good cyber defense remain exactly that: fundamentals.
The difference is that organizations may have less time to get them right.
Building Cyber Resilience for What Comes Next
The message from more than 100 organizations is difficult to ignore: the status quo won’t be enough.
But that doesn’t have to be a pessimistic message.
AI gives attackers new capabilities, but it also gives defenders an opportunity to strengthen how they find weaknesses, detect threats, investigate suspicious activity, and respond.
The organizations that benefit most will be the ones that combine those capabilities with strong security fundamentals, experienced people, and the ability to act quickly when something goes wrong.
For CISOs, that’s what cyber resilience increasingly comes down to: seeing what matters, understanding it quickly, and being ready to respond.
Strengthen Your Detection and Response Capabilities
Kudelski Security helps organizations strengthen cyber resilience with Managed Detection and Response that combines continuous monitoring, proactive threat hunting, expert investigation, and response.














