As cyber threats become more sophisticated, organizations are having to think differently about where they may be exposed. AI is giving attackers new ways to deceive people, while organizations increasingly rely on outside technology and partners that can introduce risks of their own.
No organization can account for every possible threat. It can, however, be useful to understand what’s changing and where your current approach may deserve another look. Here are four areas to consider.
1. Global Conflicts Can Offer an Early Look at Cyber Risk
Conflicts around the world can offer an early look at how new technology is changing cyber risk. As tools become cheaper and easier to use, smaller groups can gain access to technology that once required far more money, resources, or specialized knowledge.
Former NSA Director and U.S. Cyber Command Commander Paul Nakasone points to recent conflicts as a place to see how these technologies are being used. Rather than waiting years to understand their impact, he sees value in looking at what’s happening now and what it could tell us about the risks organizations may face in the future.
For organizations, that raises a few questions to be considered:
- How could a familiar technology be used differently? A tool that seems well understood can create new risks when it is put to another use.
- How quickly could a new use spread? What starts in one setting can be adopted elsewhere, giving organizations less time to adjust.
- Where could a new risk have a wider impact? A problem with one system, supplier, or partner can affect other parts of an organization that depend on it.
2. Cybersecurity Gaps Aren’t Always Technical
Security tools are only part of what can leave an organization vulnerable. How people use them and how responsibilities are assigned can create gaps of their own.
Former Acting National Cyber Director Kemba Walden looks at cybersecurity through three connected areas: technology, people, and what she calls “doctrine,” or the rules that determine who is responsible for what. Attackers, she explains, tend to look for the easiest way in. If systems are well protected, they may turn to people through tactics such as phishing or look for gaps in responsibility.
For leaders, that makes it worth looking at where responsibility could be unclear. Systems that cross departments or involve outside vendors can make it easier for one group to assume someone else is handling a security issue. Changes within the organization can create similar gaps if responsibilities aren’t revisited.
Walden puts the issue simply: “If we don’t know who’s responsible for what, then the bad guys will walk right through.”
3. AI Is Making Familiar Signs of Identity Less Reliable
A familiar voice on the phone or a recognizable face on a video call used to provide some reassurance that you knew who you were dealing with. As AI-generated audio and video become more convincing, those familiar signs of identity are becoming less reliable.
Former NSA Director of Cybersecurity Robert Joyce recommends using a second method to verify important requests, especially when money or sensitive information is involved. He calls this “out-of-band authentication,” which means confirming a request through a different channel.
For organizations, a few details can make that extra check more useful:
- Use contact information you already trust. If a request seems unusual, the second check is more useful when it goes through a phone number, email address, or other contact method already known to the organization.
- Have a process in place before it’s needed. Employees are less likely to have to figure out what to do in the moment if they already know how sensitive requests should be handled.
- Set the expectation that sensitive requests can be verified. When verification is a standard part of the process, employees don’t have to decide in the moment whether it’s appropriate to question a request from someone senior.
4. Information Integrity Is More Important Than Ever
As organizations introduce new systems and AI tools, they may use data in ways it wasn’t originally intended for. That can raise new questions about whether the information is reliable enough for those uses.
Former Principal Deputy Director of National Intelligence Sue Gordon encourages organizations to consider the quality of that information, including who is responsible for it. She points out that organizations already have large amounts of information that may not be well managed or may have been manipulated.
AI can make those problems harder to spot. As AI systems use existing information to produce something new, it may become more difficult to understand the quality of the information they started with. Gordon compares this to layers of technology being built on top of one another until it becomes difficult to know everything underneath.
For leaders, it can be useful to ask what information a new system will rely on and what they know about its quality. That can bring potential problems into view before the data is used in a new way.
Find the Right Cybersecurity Speaker with Leading Authorities
No matter what kind of cybersecurity topic your organization wants to explore, the right expert can help your audience understand what’s changing and what it could mean for them.
Leading Authorities works with cybersecurity speakers who cover a wide range of issues, from emerging threats and national security to AI, information integrity, and organizational preparedness. Our team can help you find a speaker whose experience and perspective fit your audience and the conversation you want to have.
To learn more or find a cybersecurity speaker for your next event:
- Call us at 855-827-9635
- Email [email protected]
- Start a live chat
- Fill out our contact form






