Council Post: You're AI-Ready, But Is Your Security Posture?

Michael Flannery is President of Uniti Solutions.

getty

​Many executives are debating whether AI is better for cyberattackers or cyberdefenders, but that question misses the more essential concern: Are the controls a business has in place, like their identity models, visibility into the network and ability to respond, ready for a threat environment that AI has made faster and more convincing?

I don’t think AI is inherently a defender’s tool or an attacker’s tool. It’s both, and pretending otherwise can lead to bad security strategy in either direction.

Why The Ledger Has Two Sides​

​On the defensive side, AI is already changing how security teams operate. Pattern recognition across massive log volumes, automated triage of alerts and faster incident response are now operational realities at many organizations.

Security teams that used to spend hours separating signal from noise can now do it in minutes.

But the same underlying capability accelerates the offense. Social engineering, or the entry point for most breaches, has gotten cheaper, faster and more believable. The 2026 Verizon Data Breach Investigations Report found the human element still factors into 62% of breaches, and that share hasn’t shrunk as AI tools have become more accessible to attackers.

Voice cloning that once required a production studio can now be done with a short audio sample and consumer-grade tools. Phishing emails once flagged for their stilted language are now personalized, context-aware and generated on a much larger scale.

Anthropic’s recent actions are instructive here, precisely because they come from the company building the models. Its Project Glasswing initiative launched earlier this year in partnership with organizations including AWS, Microsoft, Google and CrowdStrike. The project gave a restricted frontier model to defenders specifically because Anthropic had observed that the same coding capability that finds software vulnerabilities for patching could, in the wrong hands, find them for exploitation. The partners in that program have since surfaced thousands of high-severity flaws.

That’s a case study in the dual-use nature of the technology, coming directly from the source: The same capability that hardens systems is the capability that could be turned against them.

Why Zero Trust Has Stopped Being A Buzzword​​

This environment has pushed Zero Trust from a buzzword into an essential operating principle. The premise of Zero Trust was always sound, but the cost of not using it has risen dramatically.

Companies have been attempting to adopt Zero Trust for years, but maturity has long lagged behind adoption. As of 2023, Gartner’s research found that a majority of organizations had some form of Zero Trust initiative underway, yet they projected that only a small fraction of large enterprises would have a genuinely mature, continuously verified program in place by 2026, or this year.

The gap between having a Zero Trust initiative and having Zero Trust actually instrumented across identity, devices and data is exactly where AI-accelerated attacks find room to operate. An attacker using a cloned voice to impersonate an executive on a call to the help desk isn’t defeated by a Zero Trust slide deck. They’re defeated by a policy that requires verification regardless of how convincing the caller sounds.​

The Operator’s Question​

None of this means the sky is falling, and I’d be skeptical of anyone telling you it is.

Most organizations are not going to be undone by a single dramatic AI-driven attack. They’re going to be tested, repeatedly, by attacks that are marginally more convincing, arrive marginally faster and target the gaps between departments and systems that were always there. AI just makes them easier to find and exploit.

So I’d recommend every security and business leader ask a set of more specific questions than “Is AI dangerous?”

Does your identity model assume a voice or a familiar name is sufficient verification, or does it require something harder to fake? Does your team have visibility into what’s actually happening across the network, or just what’s supposed to be happening? When something looks wrong, how long does it take your organization to notice, and how long after that to respond?

AI didn’t create these questions. It raised the stakes of answering them honestly. Businesses that treat Zero Trust as a checkbox will find that AI-accelerated threats route around the checkbox. Businesses that treat it as a continuously verified operating model, or one that assumes every request could be the one that isn’t legitimate, will find that the same AI tools reshaping the threat landscape are also reshaping their ability to detect and respond to it.

The technology isn’t the deciding factor. Readiness is.​​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?