
Artificial intelligence is accelerating the scale, speed and sophistication of cyberattacks, according to Juan Gomez-Sanchez, vice president of cyber resilience at McLane Co., Temple, Texas.
Gomez-Sanchez spoke about understanding cyber risk and resilience at CSP and Informa Connect’s Outlook Leadership event, held in Rancho Palos Verdes, California.
Emerging AI platforms can autonomously identify weaknesses, generate exploits and adapt attacks in near real time, he said.
In addition, traditional attack timelines measured in weeks can now occur in hours or minutes. Identity compromise remains the No. 1 attack vector, but AI amplifies phishing, credential theft and lateral-movement effectiveness, he said.
Organizations face increased risk from zero-day vulnerabilities and AI-enabled threat actors. Zero-day is an unknown security flaw in hardware or software.
Cyber risk is shifting
Modern cyber risk is shifting from human-scale attacks to machine-scale attacks, Gomez-Sanchez said.
Attackers can weaponize AI faster than most organizations can manually respond, Gomez-Sanchez said. AI increases the volume and believability of system vulnerability exploitation, phishing, impersonation and credential attacks. Detection and response capabilities must evolve beyond traditional rule-based security measures, he said.
In the past, it took weeks and sometimes years from the time a system identified a vulnerability to the vulnerability being exploited at scale, Gomez-Sanchez said, “the newest approximation into the time that it takes from understanding a vulnerability to it actually now being exploited is minutes."
Living in today’s world, in which vulnerabilities are bound to happen every day, means organizations must address the potential problems, he said. People should ask their organizations or even influence how their organizations are dealing with this problem.
“This is a problem, and it’s a problem that is coming to you real fast, and you need to be able to actually go and sustain that,” Gomez-Sanchez said. “If you’re thinking through resilience levels, you start thinking about what happens if a supplier cannot supply? Do I have second-level suppliers? What happens if the system is not there? Well, where are my backups? What happens if my POS system goes down? Can I have alternative methods of actually accepting payment?
“Those are all the things that you need to start thinking about,” he said. “The concept is not new. The way it’s impacting organizations today is different.”
Members help make our journalism possible. Become a CSP member today and unlock exclusive benefits, including unlimited access to all of our content. Sign up here.
