Latest blogs
New threats: focus on the fundamentals
Why the latest developments in AI-enabled threats require organisations to think differently about cyber risk
Titania CTO Andrew Woodford explains why the most effective response to AI-driven cyber risks is to focus on the fundamentals: network segmentation, limiting access, reducing exposure through hardening and continuous monitoring. Getting these right will mean that when you are attacked, you’re better prepared.
When the story broke that an AI-powered solution had found exploitable vulnerabilities in software that was over 25 years old, the top two technology issues on the boardroom radar collided – and the fallout was predictable.
Cybersecurity hit the front pages: a rare occurrence for anything other than a major outage. Alarmed leaders called their security teams in, demanding both explanation and assurances that their networks didn’t hold such aging risks.
Regulators have also responded: the European Central Bank (ECB), apparently concerned that financial services organisations weren’t taking the risks sufficiently seriously, convened an urgent summit.

How AI is (really) changing the threat landscape
But while it’s undoubtedly true that AI is changing the threat landscape, we need to be clear about how. With that knowledge, organisations can respond appropriately.
Firstly and crucially, there are no signs as yet that AI has created new attack vectors. Instead, the biggest impact we’re seeing so far is in terms of speed.
AI enables attackers to automate and broaden their probing for vulnerabilities like misconfigurations, unchanged defaults and control gaps. That almost inevitably means it can find such opportunities faster than before: faster too than established patching processes will ever be able to keep up with.
So while responsive, regular and comprehensive patching remans vital, focusing – as the ECB advised – on accelerating the deployment of patches will not mitigate the threats AI creates.
The US Cybersecurity and Infrastructure Security Agency (CISA) agrees: its latest recommendation is to “patch smarter, not harder.” In the UK meanwhile, the Five Eyes cyber security agencies advises accelerating the patching process, but more importantly adds “Prioritise security updates accordingly to manage risks.”
AI vs AI: it’s not a fight worth having
Some may be thinking about using AI as a defensive solution to find the vulnerabilities first. However, there is a practical problem: without context. it will find too many. The example of Anthropic’s Claude Mythos demonstrates this. The information that it has uncovered 10,000 critical flaws is staggering, but almost unresolvable from the business perspective. No organisation could seriously tackle remediation on that scale.
Look deeper, and it becomes clear that many of these vulnerabilities are to all practical extents unexploitable – because they’re hidden away behind multiple layers of security – or largely irrelevant, because they’re on systems that are inaccessible.
What’s left, after context is applied, is a relatively small number of exploitable and high-risk vulnerabilities, the majority of which are already known within cyber circles. AI can help pinpoint them, but so can many existing tools.
This leaves us with an uncomfortable truth that businesses need to adapt to: if no organisation can patch away vulnerabilities fast enough to stay safe, then every organisation is vulnerable. And every large organisation – especially those operating in regulated sectors – is likely to face attacks.

The need for a shift in mindset
So instead of focusing all our efforts on prevention, it’s time to shift the mindset and focus on how to proactively minimise the impact of an attack. As the Five Eyes security agencies recommend: “Test response plans, train and prepare teams, and assume breaches will occur. Focus on fast containment and recovery.”
That means returning to what may be deemed cybersecurity basics: consistent device hardening, well thought-through network segmentation, access controls that are robustly enforced, a comprehensive backup schedule that is meticulously adhered to, and a well-practised recovery plan.
Applied together, these approaches combine to shrink the attack surface, minimise lateral movement on the network following a breach, limit what attackers can actually access and facilitate a swift and safe restoration of service.
Embracing continuous monitoring
But in a world where attackers can be using AI at any time, there’s a further vital dimension: continuous monitoring, not only for potential incursions but also to confirm your controls are operating as they should be.
Many regulated organisations have already adopted some form of Zero Trust or Least Privilege Access model, as compliance regimes increasingly demand. But putting solid policies in place is only the start; it’s vital to keep checking that only the right users have access to the right systems and that there are no inconsistencies or exceptions.
One thing we regularly encounter is when access is granted to a specific legacy tool for a short-term purpose but is then forgotten and never rescinded. Another issue is when new rules or requirements are introduced on a group-wide basis, without recognising the exposures that this could create if one user has additional privileges.
These inadvertent control gaps can be addressed through regular reviews but given that an AI attack can penetrate in minutes, waiting till next month’s review feels high risk.
Instead, opting for continuous monitoring, as part of a continuous threat exposure management approach, provides the confidence that the boardroom and regulators urgently need.
Back to basics
Defending against AI-powered threats doesn’t demand a pure AI solution. It requires the consistent and diligent application of fundamental cybersecurity practices – a back-to-basics approach – while organisationally recognising that being attacked and even breached isn’t a catastrophe… as long as you’ve taken the right steps to minimise the potential impact attackers can have.

Reduce AI-driven cyber risks with Nipper solutions
Nipper solutions can help you get back to basics – hardening your network, enforcing segmentation and reducing the attack surface.
Find out more about our exposure management platform for network security teams.
Alternatively, book a demo to see our solutions in action.