
Organizations are already embedding AI into everyday operations to move faster, improve efficiency, and scale decision-making. Attackers are doing the same. By using AI to accelerate reconnaissance, craft more convincing social engineering, and automate parts of the attack lifecycle, cybercriminals can operate with greater speed, scale, and precision. AI also lowers the barrier to entry for less sophisticated actors, making attacks more varied, more frequent, and harder for overstretched security teams to anticipate.
Over the next 12 months, organizations should prepare for an increase in the volume and sophistication of phishing and social engineering campaigns, including identity-based compromises, adversary-in-the-middle attacks, and credential theft. As AI capabilities further mature, these attacks will likely become even more personalized, convincing, and scalable. For example, deep-fake audio, synthetic video and AI-generated communications are likely to be increasingly used to impersonate executives, suppliers, and trusted partners alike.
Organizations should expect attackers to leverage AI to automate reconnaissance, identify vulnerabilities, develop malicious code, and accelerate attack operations. Defenders will need to move equally quickly and may consider utilizing AI defensively for detection, triage, and response while maintaining human oversight of critical decisions and ensuring compliance with the evolving landscape of AI regulations.
Supply-chain disruption is also likely to remain a strategic concern. Organizations should expect increased volatility across technology procurement, cloud services, hardware availability, and software licensing. Geopolitical tensions, trade restrictions and economic uncertainty may increase technology costs while simultaneously increasing dependency on a smaller number of strategic suppliers. When those strategic suppliers become victims of cyber-attacks, the downstream ripple effects can be significant.
Software supply chains, a frequent cyberattack target, will also continue to come under pressure. Open-source projects, code repositories and software development environments are attractive targets because they provide trusted access into multiple organizations simultaneously. Secret theft, token compromise, and attacks on development pipeline are likely to increase as threat actors seek scalable methods of compromise.
The information environment is likely to become more saturated with misinformation and disinformation. AI-generated content will make it more difficult for organizations to distinguish fact from fiction during a crisis. The next major organizational incident may involve manipulation of public perception and stakeholder trust using only synthetic, falsified media without any underlying technical compromise, and organizations may suffer significant reputational and financial consequences.
How can CEOs and boards prepare for the increased risks posed by AI?
The CEO’s role is increasingly centered on organizational trust and resilience. Cybersecurity needs to be viewed as a core business continuity priority at the center of an organization’s overall strategy rather than just a peripheral technology issue. Executive leadership teams should understand which services are critical, which suppliers present material risk and how quickly the organization could recover from a major disruption.
Organizations should ensure that crisis management, communications, legal, technology, and operational teams are integrated into a single resilience framework and that incident response processes and procedures are memorialized in an incident response plan that is tested via tabletop exercises at a minimum annually, and potentially more frequently for technical teams of organizations that are frequent targets of cyber-attacks.
The organizations that perform best during crises are often those that communicate clearly, make decisions quickly and maintain trust throughout uncertainty. In an era of proliferating disinformation and misinformation, rapid communication and the preservation of stakeholder confidence become critical leadership capabilities.
In parallel, boards should recognize that geopolitical instability, cybersecurity, operational resilience and organizational reputation are becoming increasingly intertwined. The board’s responsibility is not to manage technical controls, but to ensure that management understands risk, dependencies, and resilience. For example, boards should seek assurance that management understands supplier concentration risk, cloud dependencies, data exposure, crisis response capability and recovery arrangements. They should challenge whether resilience has been tested under realistic conditions and whether lessons learned have resulted in measurable improvement. Most importantly, boards should ask whether the organization could continue delivering its mission if key suppliers failed, critical services became unavailable or misinformation significantly affected stakeholder confidence.
What can CISOs do to protect organizations’ identities, data, and trust?
CISOs should focus on one clear objective: stop attackers from turning trust into access, and contain the impact when they do.
That starts with identity. Phishing-resistant multi-factor authentication (MFA), Conditional Access, Privileged Identity Management, and Identity Threat Detection and Response should be treated as core controls, not optional enhancements. Help-desk verification also needs regular scrutiny, because many modern attacks bypass technical defenses by manipulating support processes and exploiting human trust.
Data security must be equally disciplined. Organizations need a clear view of where critical data sits, who can reach it, and how it could be removed. Classification, labelling, monitoring, and exfiltration detection are no longer back-office hygiene; they are central to protecting enterprise value.
CISOs should also broaden incident response beyond technical breach scenarios. Exercises should test supplier compromise, executive impersonation, AI-generated misinformation, cloud disruption, and combined cyber-operational events, so teams can make fast, trusted decisions under pressure.
The future will be defined by trust
The next phase of cybersecurity will be about defending trust as much as defending systems. Attackers will target identities, suppliers, software, information, and leadership credibility because those are the foundations organizations depend on to operate.
The strongest organizations will be those that know their dependencies, protect trusted access, secure critical data, verify information quickly, and keep operating when confidence is under attack. In the age of AI, resilience will depend not just on better tools, but on the ability to preserve trust when it matters most.
















