Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Enterprise ServicesLogical Security

AI Risk Is Here, but Not in the Way You Might Expect

By Vishaal ‘V8’ Hariprasad
Computer
Boicu Andrei via Unsplash
October 2, 2026

The dominant headlines of the past month have alerted the world to the unprecedented risk of AI-native cyberattacks. Multiple AI models have carried out autonomous attacks, illustrating how quickly AI risk is evolving. 

That’s not the only AI risk that organizations need to prepare for. The technology also enhances human threat actors’ attacks, making them more sophisticated and harder to identify. What’s more, AI creates vulnerabilities from within a business when employees use unapproved or unregulated tools on company devices. It can be challenging to read these headlines and not feel like the sky is falling. 

But when Resilience reviewed insurance claims data from the first half of 2026, it couldn't find a single claim involving an AI-native attack vector. In fact, it’s quite the opposite. In the first six months of 2026, 83.3% of financial losses in our portfolio stemmed from attacks exploiting human error (including phishing, social engineering, and transfer fraud). 

While your organization is trying to prevent AI from tearing your security system apart, it’s incumbent upon us to remember that overindexing on AI and forsaking all else will only lead us to ignore the risk areas that actually lead to business disruption. Yes, AI threats are here. Yes, AI-driven risk must be taken into account. But what we’ve found is that focusing solely on AI, and not what AI will become a force multiplier of, won’t help us minimize loss and disruption.  

Overwhelmingly, our claims in the first half of this year identify human error as the point of failure driving losses. AI is likely playing a role here by making social engineering far more convincing. Previously, phishing emails would come from an obviously foreign address or be littered with spelling errors, making it fairly easy for most employees to identify them as spam. Now, voice cloning and deepfakes can make it seem as though the attack is actually coming from someone the employee trusts — often someone with disproportionate influence and power, like their CEO. 

With so much unknown, it can be challenging to understand how AI is actually moving the needle when it comes to cyber risk. I recommend that we think of AI as an accelerant for threat actors’ existing strategies. Think of how AI is helping threat actors find vulnerabilities to exploit faster than organizations can patch them. According to Mandiant’s 2026 frontline data, the average time-to-exploit is negative seven days. That means exploitation is now happening before a patch even exists. 

Findings like these drive home the point that organizations have to take control of cybersecurity basics right now, before AI complicates things even more than it already has. It’s important to get ahead of potential AI risk hurtling toward us, but overindexing on that threat in a silo and ignoring the areas leading to real financial losses would be a mistake.

Instead, perfecting cybersecurity fundamentals is the best way to prepare for AI risk, regardless of the shape it takes next. 

For instance, as AI evolves social engineering, it’s important to take existing employee phishing training one step further. Click rates in phishing training don’t matter when threat actors increasingly use a deepfake of a CEO’s voice to gain access. Better verification training and ensuring every part of the organization is fully enrolled in multi-factor authentication are great and easy ways to mitigate AI-enhanced social engineering. 

The bottom line is that organizations should absolutely be prepared for agentic attacks, but shouldn’t spend the entire budget on defending only against them. AI is changing the cybersecurity landscape, but it’s not driving losses today. As such, the most secure organizations will take a risk-first approach to their cyber plans, identifying the areas that lead to the biggest losses and mitigating those risks. Implement the basic controls that work, and be safer for it. 

KEYWORDS: artificial intelligence (AI) Artificial Intelligence (AI) Security risk risk and resilience risk management

Share This Story

Vishaal hariprasad headshot

Vishaal ‘V8’ Hariprasad is CEO at Resilience. Image courtesy of Hariprasad 

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Healthcare supplies

3 Healthcare Breaches in Quick Succession Raises Concerns

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man driving

150M Driver’s Licenses Exposed, Security Experts Discuss

Police lights

Family of Fatally Shot Security Guard Seeking Answers

Stressed woman

Ransomware Doesn’t Just Break Systems. It Breaks People.


AlertMedia sponsored webinar

Events

October 7, 2026

Modernizing Travel Risk Management: How Security Teams are Strengthening Duty of Care

LIVE: October 7, 2026 at 2 PM EDT Learn how security teams have strengthened travel risk management for a global workforce. Move beyond manual monitoring to earlier, verified awareness and a more defensible approach to security operations.

October 20, 2026

Beyond the Camera: How AI Is Transforming Physical Security

LIVE: October 20, 2026 at 2 PM EDT AI can connect security systems to detect threats earlier, validate incidents in real time, & accelerate response. Move from passive monitoring to proactive, intelligence-led security while maximizing existing tech investments.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing