AI isn’t reinventing cyber-attacks, it’s making them happen faster.

That was one of the key messages from our recent AI, Identity and Trust webinar, where Quorum Cyber’s Richard Holland, Jack Alexander and Alan Coburn explored the findings of our 2026 Global Cyber Risk Mid-Year Review and what they mean for security leaders.

Organisations are embedding AI into everyday operations to improve efficiency, accelerate decision-making and scale growth. But threat actors are also taking advantage of the technology, by create convincing social engineering, automate attack activity and operate with greater speed and precision. While lowering the barrier to entry, making attacks more frequent, varied and difficult for overstretched security teams to anticipate. The discussion highlighted an important point: as threats evolve, getting the security fundamentals right matters more than ever.

Watch AI, Identity and Trust on demand.

AI is accelerating the attack chain

Jack Alexander, Global Intelligence Lead at Quorum Cyber, highlighted in the foreseeable future, supply-chain disruption will remain a strategic concern. Geopolitical tensions, trade restrictions, and economic uncertainty may increase technology costs and dependency on fewer strategic suppliers. When those suppliers suffer cyber-attacks, the effects can quickly spread across multiple organisations. Software supply chains are particularly attractive targets, with open-source projects, code repositories and development environments offering trusted access at scale. Secret theft, token compromise, and attacks on development pipelines are likely to continue.

It’s becoming clear that the information environment will also become more difficult to navigate as AI-generated misinformation and disinformation make it harder to distinguish fact from fiction. Organisations could face significant reputational and financial damage through synthetic, falsified media, even without a traditional technical compromise.

How can CEOs and boards prepare?

Cyber security should be treated as a core business continuity and resilience priority. Executive teams need to understand which services are critical, which suppliers present material risk and how quickly the organisation could recover from major disruption.

As Alan Coburn, Head of Cyber Resilience at Quorum Cyber, explained during the webinar, crisis management, communications, legal, technology and operational teams should work within a unified resilience framework. Incident response plans must be documented and tested through regular tabletop exercises, including scenarios involving supplier compromise, executive impersonation, cloud disruption, and AI-generated misinformation.

Boards are not responsible for managing technical controls, but they must ensure management understands risk and what it takes for the business to bounce back from an attack. They should challenge whether resilience has been tested sufficiently, and whether supplier concentration is understood and whether lessons learned have led to measurable improvement. They should also ask whether the organisation could continue delivering its mission if key suppliers failed or stakeholder confidence was undermined.

What can CISOs do?

CISOs should focus on preventing attackers from turning trust into access, while limiting the impact when they succeed.

Field CISO, with over 25 years’ experience in the industry, Richard Holland, stated identity must be foundational. Phishing-resistant multi-factor authentication (MFA), Conditional Access, Privileged Identity Management and Identity Threat Detection and Response should be treated as core controls. Help-desk verification processes also require regular scrutiny, as attackers increasingly exploit human trust to bypass technical defences.

Organisations need a clear view of where critical data resides, who can access it and how it could be removed. Classification, labelling, monitoring, and exfiltration detection are central to protecting enterprise value.

The future will be defined by trust.

The next phase of cyber security will be about defending trust as much as systems. The strongest organisations will protect trusted access, secure critical data, understand their dependencies, verify information quickly, and continue operating when confidence comes under attack.

To learn more about how Quorum Cyber secures the foundations of AI, download our free 2026 Global Cyber Risk Mid-Year Review. You can also watch our insightful webinar, AI, Identity and Trust: Secure the Foundations of Cyber Resilience in 2026, in full, or watch our Field CISO Richard Holland’s advice in a four-minute video.

If you would like to understand what these findings mean for your environment, contact us to speak to our team.

Further Insights from Quorum Cyber.

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content