Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

N-Able: AI-Driven Threats & Modern Security Strategy

N-able
08/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


today. He is an esteemed vice president and leader in the cybersecurity thought leadership field, and he comes from the Futurum Group. So thank you so much for taking the time to speak with us today. Oh my God, it's a pleasure. As we were preparing for this presentation, I kept telling myself, oh, this is so great. I get to talk to Nicole, which is awesome. And I had the pleasure of attending Empower a few weeks ago, and saw the other people at Enable. Oh my God, it was a wonderful time. Just a couple of quick words for context, as far as analysts go, at the Futurum Group, we cover multiple areas of technology. I lead our cybersecurity coverage. We have more of a forward-leaning look into what's changing the world, and in this day of AI, oh my goodness, we're having fun. I do want to mention that we do both quantitative and qualitative research, and we speak with end users, with buyers, with vendors, and everyone in that space. And what we're going to share here is that it's some of the research that we've done over the past. So some of our research includes relatively large user surveys, where we collect multiple data points, and so we'll talk about some of those here, and yeah, it's a pleasure to be here. Thank you very much. Yeah, I can't wait to learn. So with that, why don't we actually pop right into the first bit of information that you collected. So all of this is research that our teams put together and that you brought forward, and it's really quite incredible. So the first thing that shocked me was that there's been a strong rise in AI-driven attacks, and more than 38% of your respondents actually agree that the threat landscaping is already shifting to be AI-driven. Can you tell us a little bit about this? Absolutely. So again, for context, so this is research that it was fielded back in October, November timeframe. So it was published in December. We're actually right now in the process of creating the new one, of gathering the results from fields from the new one, and the sample size is relatively large. This was about 1,000 respondents worldwide, split between the usual split we see, like a little bit more in the Americas, and then somewhat even between EMEA and APJ, and covering companies of all sizes, and covering respondents, both practitioners, both like individual contributors, mid-level management, senior level management. And what's really interesting about this is that 38% is... So the framing for this particular question was, we were asking people, how do you agree with or disagree with statements? 38% strongly agreed that they had seen in the past 12 months a significant rise in attacks. So this is strongly agree. The people who said they agree, right? So when you put these together, we're actually over 60%, I think it was about 63, 64% agree or strongly agree that they've seen this rise in AI-driven attacks. And then this is where we're being asked to do more. It's the usual of being asked to do more with less. But now there is a forcing function, right? So we are looking at AI as a major forcing function for upgrading security programs. And one of the things that we talk about often is, if you look at the broad trends in industry, there is a significant maturing of cybersecurity as a practice throughout. And we see AI as a forcing function for a lot of that. What's really interesting is this is before... So if you're talking six months ago, this is before the explosion or widespread adoption of AI agents. Yes. AI agents is a six-month... They've existed for longer than that, but really in the market, it's just the last six months. So what do you anticipate seeing in this next round? Because 60% agreeing or strongly agreeing, it's a wild number. 38% strongly agreeing, that's a huge indicator. What do you got around the next... I expect numbers to be... So there's two interesting points. There's two diverging points. I can see a point for both. I can see the number rising, right? Because yes, more people are seeing this. I can also see the number diminishing because it's now assumed to be... I don't like the expression, but it's now assumed to be the new normal, right? So it's interesting. I've seen this kind of quirks in response data sometimes. Yes, of course, it's obvious, right? But I definitely expect to see the effect persist, right? We're not going back. This toothpaste is not getting back into the tube. Is there something like threat fatigue? Like it's almost as if AI is absolutely a threat vector. They're going to continue to use it to drive attacks. And at this point, I'm not even surprised by it anymore. Yeah, I think that there is. And there is a nuance here that I think we're going to touch on throughout the presentation. But there is a nuance here that the mature response or the effective response to this problem overall, right? And this is where we see security programs going is a level of maturity in terms of, yes, the threats are happening. Yes, we will deal with them, right? It's a feedback loop of, okay, this is a problem. We're going to deal with it. It's not the end of the world, right? So what we see is that the more effective security programs have this assume breach mentality, right? And they respond to that. We can dive into nuances about behavior quirks about how we feel about those. But there is definitely, even if there is threat fatigue, right? There is also the realization that we will deal with this problem as it comes and keep going. Yeah, we've been here before. We will succeed again. Yeah, I'm trying to remember the quote that the, I'm horrible with quotes right now. And the quote that the master's sails, the master's sailor uses their superior skills to avoid putting themselves in the problem where they, in the situation where they need their superior skills. I love that. I have to get the proper. The sailor avoids the typhoon. Yes, exactly. Yeah, completely agree. So we have the threat. We both acknowledge 100% this is real, regardless of whether or not we feel overwhelmed by it. So what is wrong with how we're currently approaching these threats? What is wrong with our security models? I think that there's a combination of things, right? It's a factor of our own success in a way, right? I think that the way technology has evolved over the past 30 years or so, by the way, I've been in industry for about 30, 35 years, right? The gray hair comes from being around for a while. And one of the things like technology won, right? I mean, there was the paper, there was the quote by Mike Andreessen, 2011 software is eating the world. Yes, it has. 100%, right? We now can't live without technology and that's fine, right? But that explosion of technology, it happened across two dimensions, right? So from a security perspective, there's more, but it happened across a couple of dimensions. First, there is more technology everywhere, right? You can't have, if you're having a conversation on pretty much any area of business, there's a technology angle to that. So there's an expansion in that sense. There's also an expansion in the different types of things, right? It's not that we are asking, it's not that the same technology implementation, instead of doing it 500 times, you need to do it 5,000. It's that you're doing 5,000 implementations of whatever, but half of them are one thing, one third of them are something else. So there's a cognitive explosion as well. So security teams are stretching because one minute they are dealing with, I'm going to say, network firewalls. The next minute, they may be asked to deal with SaaS implementations. Then they have, oh, look, there's identity management coming around. Of course, within larger teams, they specialize a bit, but not everybody has a large team, right? So the poor security teams are stretched in that sense, like just from a knowledge perspective. And then you factor in that there is a human coordination aspect to these things that they struggle with as well, right? And because technology is everywhere, right, IT operations, security operations, they need to have tremendous coordination with the rest of the business, if you will. And that is an evolving area, both for organizations themselves and, frankly, for practitioners too, right? You start your career as a very specialized practitioner in something, and you only pick it up over time. So I think that it's a combination of more technology, different technology, right? The need for coordination, right? And while all of this is happening, right, you end up, the fact that the adversaries, I personally don't like the word, I'm one of those people who say, like, hacking is not a crime. Like, I'm old school in the sense that I prefer to use adversaries or bad actors or whatever. Yeah, but listen, again, I'll accept if people say hackers, that's fine. I just don't. But the adversaries, they are very adept at applying technology as well, right? And even before the explosion of AI capabilities, right, machine learning and AI capabilities, they have always been very adept at using automation more broadly, right? So AI accelerated, so the attackers now operate at machine speed. Yes, the word now, it's probably like they have been operating at machine speed. They just have more, they're just able to accelerate faster sometimes. Yeah, and across more context types. Precisely. Yeah. One of the interesting things about AI is that it gives people with a very small amount of knowledge the ability to create a lot of things that do impressive outcomes, right? And so when you're a hacker and you have this area of specialty or an adversary, I imagine that you were pretty good at one type of attack. And now with the explosion of the tools available, you can actually be pretty good at multiple types of attack and put those all out simultaneously. Yes, and this is fascinating because there is also another aspect to this, is that the cost of a mistake that somebody makes with AI for the organization is different than the cost of the mistake for the adversary, right? You know what? If you, quote unquote, vibe code a bad application and you have production issues because of it, your company suffers, right? The cost for an adversary of vibe coding something that, yeah, might not be as efficient, might have a couple of mistakes here and there, they are not the ones necessarily taking the onus of that impact. Of course, they have a little bit, but bottom line is that this gives adversaries more freedom to explore. Yeah, you know what? I messed up this particular host. I'll go to the next one, right? Yep. Yeah, it's fantastic for prototyping and for attacking. Oh my God, yeah. So we talked a little bit about fatigue around alerts and we talked a little bit about threat fatigue and there's the cognitive fatigue that you mentioned. Can you just talk a little bit more about what that looks like? So this comes up in our research in multiple places, right? This comes up in... So in our surveys, we ask different questions about incidents and about challenges for particular areas and about how your organization behaves and what are you looking for and so on and so forth. And it comes up across multiple data points. But one of them is that when we ask people, what are their key hurdles to closing security vulnerabilities, right? And the top three that come up are the lack of skilled resources, right? The high volume of alerts that they have to deal with and ineffective communications with other teams, right? Survey data is always interesting. I make the joke that everyone who deals with surveys should say thanks to George Box, a famous statistician who said that all models are wrong, but some are useful, right? In the context that it gives us directionality. So whether it's 53% versus 54%, that might not be material in the context. So these top three answers, like the key hurdles, like people fatigue or skilled resources, high volume of alerts and ineffective comms, they're all in the like the 50% range, give or take. The next one down is in the 45% range. So there's a difference there, right? But what this comes up with is the fact that we are asking those security teams to handle things that may not necessarily be within their control, right? Particularly when you figure out, oh, okay, if the current plan is to have the security team handle the identification of a vulnerability and the patching of that vulnerability, no, that patching should go to somebody else, right? Or that, and the user communications around that, those, I mentioned it before, that human communication in there is struggling a little bit. And we find that actually when people ask, one of the questions we ask is about the rising security platforms and how people are choosing platforms, what they want out of platforms. One of the things people want is the easier integration of security platform. I don't have to go from place to place to place. I don't have to deal with multiple vendors to deal with and so on. So this is a common condition across multiple teams. And I think that we as an industry are moving towards that, but it's taking a while. Thank you. All right. We're going to do a poll. For the people on the call, have you experienced a security incident in the past 12 months? These numbers look awfully familiar. Including the not sures. And we did have one question come in. Oh, did we lose it? So the answer, okay, there we go. So hopefully you can see, so what happened was 59%, I'm sorry, 56% of you, I don't have my glasses on, 56% of you said that you have actually experienced a security incident in the last 12 months. 31% have not and 13% just don't know. So that's pretty close to what we're seeing in these results. So we see, yeah, go ahead, talk to them. Oh, no, no, absolutely not. Go ahead, talk to them. Oh, no, no, absolutely. It was interesting because here we asked, again, sample size about 1,000. If we break this down by, we asked SMBs, which we define as 2,500 users and below. And our cutoff, our Warren cutoff was about 100 users, so between 100 and 2,500. And in that case, we asked them about three or more incidents, and 46% of them indicated they had three or more incidents. When I look at the original, yeah, when I look at, what's that? So not just an incident, they had three or more incidents. No, no, no. That's brutal. It is brutal, but you know what? This is the point, I go back to what we were talking about, what we mentioned earlier. The more, I think that the better approach moving forward is working with the expectation that your organization will have security incidents. It's about how you respond to them. I joke that, or I mentioned that I used to do martial arts for a few years, karate for many years. And in martial arts, they have the saying, you sweat in the gym so you don't bleed in battle or in the rink, right? And how well you practice, right? You prepare for the attacker's blow, right? You learn to defend, right? And you don't go into a competition, you don't go into a sparring expecting that, oh, well, like if somebody hits me, it's over, it's done, I lost. No, you take the blows and you absorb the blows and you keep fighting, right? I see the same thing with security programs. I think in the beginning, right? We were very- Now connected. Sorry, my alarm, in the beginning, we've always had this expectation or we've had this conversation where, oh no, if something, if a bad thing happens, it's over, it's done, right? Personally, I'm not a fan of the quote, people use it that defenders have to be right every time, attackers have to be right once. Disagree, right? I think it's the other way around, right? In the modern world, defenders just need to catch, they need to detect and somewhere in their environment, the attackers are the ones who are trying to evade things. But anyway, I'm babbling as usual, but anyway, on the incident front, it was interesting. We had a lot of responses around records, ransomware as the number one concern people have and malware, non-ransomware malware as others as well. Anyway, let's keep going. Yeah, and that's supported by, so 62% of mid-market organizations say AI-driven phishing and deepfake scans were increasing. And even more surprisingly, 75% of all alerts were going unreviewed. Clearly these people do not have MDR at Illumina from Enable, but so 75%, that's a pretty significant number. Yeah, so the way that we looked at this, we had a few conversations on this, is that I think it has become a sort of a practice that people will pay more attention to the criticals, the criticals and the high, and the mediums and the lows, the alerts, they just kind of accumulate there and people will work on them later, and later becomes later. A story like, one story from my earliest days as a security consultant during assessment of customer environments, I spent inordinate amounts of time as a pen pastor or whatever term you want to use, right? When I would present my reports, it was interesting because I present a finding with, I don't know, let's say that there were 50 findings, right? Out of my 50 findings, there were 20 high, 20 mediums and 10 lows, or I'm just making up the numbers of course, right? I would spend more time with people on the other side, not arguing about, I'd spend more time defending the fact that my 20 highs were actually highs because there was a thing that, you know what? If it's just a medium, we don't have to report it up to the board, right? We don't have to report it up the food chain, right? So perverse incentives in organizations is a problem and it kind of comes up here a little bit. One of the challenges we see is that modern attacks sometimes become little mediums and lows stitched together. Which really does drive us into, how do we approach this, right? So I think we are all in wild agreement, there is a problem. We all see the problem with alerts and definitely I agree, a lot of the attacks that I've seen come in are, you know, really tiny things happening across many systems and they wouldn't raise an alarm on any one system. So if you're not doing a correlation, you've got an issue. So talk to me about what it means to shift to resilience in this new threat environment. I think that I've kind of alluded to before, it's this notion that, sorry, it's this notion that we have, we have to think about our programs more broadly, right? We have to assume, I know people don't like the expression, this is the one I like, the assume breach scenario, right? You build your organization, assuming there is going to be a breach, assuming that in some cases you, when you are a little more mature, you can even assume that there is already an attacker in your environment, how do you find them? That's a threat hunting as a discipline, right? But of course it's difficult to prove it, it's impossible to prove a negative, right? So you keep trying, right? But I think that this shift to resilience, and it's funny that we bring this up, right? Because we actually renamed our practice here at Futurum, it used to be cybersecurity, now it's cybersecurity and resilience, right? Because we find that there's such an important aspect of the conversation, which is you prepare, right? You prepare and you plan the before, the during and the after, what are you going to do to minimize your exposure before? We all know that prevention is important, minimizing your attack surface, make sure your environment is as well configured as possible, right? Then in the during phase, sorry, you have to detect it as soon as possible and contain the blast radius as soon as possible, right? This is the point where I mean that the attacker has to be right every time to move around, once you detect them, how quickly can you reduce that impact? And then the after is, yes, this is a bad thing, it happened, right? How do we quickly minimize the broader impact to our business, right? To me, I'm the king of bad analogies, but the analogy I like to use is if you think about like a warship, like a warship has containers and it's segmented so that if something blows up, if there's damage to one part of the ship, it's been isolated and it doesn't mean that the ship leaves that part ever damaged, they repair it, right? So how quickly do you repair it to get back into things? So that's the maintaining continuity part a little bit. Yeah, we think about this deeply at Enable. So we actually have what we call resilience AI and for the before aspect, it's all about Ed Luman monitoring detection and response, making sure nothing can come in. And also for the endpoint management, making sure everything is patched and doesn't have vulnerabilities as best you can. And then in the during aspect, we also do Ed Luman for how do you do immediate response and isolation? So can you find the device or the process that's causing the problem and actually isolate it so the blast radius is contained? And then for after that's really where disaster recovery comes into play with the co-product lines. So how do you understand when you should roll back to, how do you remediate the systems that were impacted? How do you make sure that you have that instant recoverability and failover? So those are really important with DRAS. I just love the paradigm that you've set up here, that three-legged stool. Okay, so the implications. Talk to us a little bit about. So implications, this is the kind of thing where when we speak to practitioners and it's the kind of thing that practitioners already have. They've already internalized this. Sometimes it's about communicating this to other stakeholders, right? This is where I think that we have here prevention alone is no longer enough, right? Prevention is absolutely important. Protection and prevention, absolutely important, but it's not enough, right? I mentioned assume breach as a posture. It's not that we're giving up, right? It's that we are making ourselves more resilient to when the issue happens. And I think that security practitioners have a hard time here, not so much with the concept themselves. They need help for the non-security stakeholders to internalize this. Because if you're not a security practitioner, you have the expectation that, oh my goodness, we're going to be 100% secure all the time. And that doesn't fly, right? It's a communications issue. It's a strategic relationship to your board for your board to understand that, look, let me show you how we have a security program that can withstand the shocks, right? And I think that's one key message from this. The other message that we see is that we have here reactive workflows, right? Where can you automate this? Both automation in terms of, I'm going to say deterministic, just what we used to call robotic process automation or just regular automation or SOAR. But where can we now leverage more capabilities from machine learning and AI? I'm one of those peers that still have machine learning. I lost the debate, I know. I'm with you. I like to fight. Yeah, it's okay, it's okay, it's okay. I'm not hurt, no. But this is one of those areas where we are expecting AI to help in many, many ways, right? Both from an enabling practitioner's perspective, as well as acting autonomously on its own right. Yeah, I think one of the really interesting things that we talk about, and we've had a conversation about this, is how do you know what the real risks are? Because when you have alert fatigue and when you have threats coming in that are at that medium and low risk in isolation, how do you know what to prioritize? Like, what is the real risk? Do you have any tips or tricks? I do. If there is one, like, over the past couple of years in research, I think that if you do a text analysis on stuff I write, I think that the word context comes up way more often than... Sure, now the word context is a little polluted by the context engineering element of AI. Sure, I'll give you that. But it's more than that. It's about real risk for organizations. It is you taking a better view of how you connect your IT environment to the rest of your business. And of course, these are fusing. Like, technology is everywhere and we can't escape it, right? We don't want to. But it's the idea that you bring into your security program as much as you can from how your business operates. The example I always like to use is, oh, you found a vulnerability in a web server. Like, I'm old school, I still say web server. But you found a vulnerability on a web server, right? Is that web server your kitchen cafeteria server with the menus for the week? Or is that web server your company financials portal the day before earnings release, right? Those are radically different things, right? And so you need to bring the business context for those into your security program, right? And you need to connect those things. Oh, look, your endpoint management program is telling you that, oh, we just onboarded a bunch of new devices. Great, if we see alerts, like, do we treat those new devices as something new? And so they may fluctuate a little bit in the types of behavioral profiling that we do or not. So if we see a behavioral profile alert, okay, are we taking into account the fact that they are new? Are we taking into effect the fact that it's the impossible travel thing? Oh, it's for a laptop for somebody who's been traveling around the world and now they were seeing strange VPN connections from weird places or not just VPN or the zero trust access or what have you. Anyway, I'm babbling as usual. My point is it's about paying attention to what's going on. There's the quote, it's misattributed to Thomas Jefferson, right? Eternal vigilance is the price of liberty or variations thereof, right? You have to watch over your systems and stay on top of things. There is definitely a cycle here, right? It's make sure you have the recovery processes in place before anything happens. Make sure you have done all of the work to reduce the possible risk vectors or the threat surfaces. Make sure everybody's communicating across your entire team, your entire organization so that you don't have visibility issues and then continually improve that signal collection so that you can make better informed decisions. I do wanna point out there are two materials that are in the material section. Everybody here should have access to them. The first is an AI governance 101 white paper and that was written in conjunction with the legal teams at Enable to give you a baseline structure of how you approach AI within your organization to close those visibility gaps and to make sure that you have the right approach in place. So please take a moment to download that. That's really a high value piece of content. And the second one that's in there is actually the future report where we get even more thoughts from Fernando on what each of these results mean and how you can bring it into your environment. Do you have anything else you want to add on the what to do next? Yes, I love how you're thinking about this in a comprehensive way. The AI governance paper is really interesting too. And I tell practitioners that what you want to think about here is you're thinking about the process that you're running. Like, and I love this framing of reduce manual response, close visibility, improve signal, validate and you keep going. This is a variation of Kaizen, right? The method of continuous improvement, right? So I think that if you frame, there's two cycles that I think are really useful here. One is this notion of continuous improvement from Kaizen and the other is for those who are familiar with John Boyd, the OODA loop that people may have come across the term. It's how do you make sense of what's going on and how do you respond? It's the observe, orient, decide and act, right? So look at your environment, make sense of where you are, make decisions based on best practices and doctrine for your organization and you act quickly, right? And if you use that as the foundation of your security program, as the foundation of your incident response, right? That gives you the best chance of having the kind of fast response and resilience to those incidents. And I think, again, remember that it's a combination of how quickly you can respond to incidents and how well you communicate them with the rest of your organization. Realistically, these are the kinds of things that will happen. Yes, we are containing those incidents. Yes, we're responding quickly. Yes, we blocked all of those things from even happening in the first place. But it's about that assume breach mentality. You know what? We can handle this. Yes, there will be problems. You saw the stats on the people who have incidents. Incidents shouldn't be, they shouldn't be, oh my goodness, my hair is on fire type of emergency, right? You should plan for those. You should be ready. Like it's, you're validating the recovery process. You know what? If this happens, we have the means to recover that part of the business. Okay, let's, steady as she goes, Captain. All right, a quick poll. So we are going to open up for questions now. So please feel free to submit questions. The poll is, where would you like to see our second conversation go? Do you want us to look at reducing risk before an attack, improving protection and response, strengthening recovery, or evaluating overall security strategy and priorities? So we're happy to take the conversation where you would all like to go. And we'll have a whole nother conversation around it. So I'm quite excited about that. Oh, I love that. So a very strong contingent so far. Oh, it's a race. Quite a few of you want to evaluate your overall security strategy and priorities. Yeah, that is a great conversation. Followed closely by improving detection and response during an attack. If you're not familiar with some of the MDR technologies that Enable has, that's worth looking up. And then reducing risk before an attack, right? A lot of endpoint management capabilities there. Yeah, it's such an important area, right? You want to avoid the problem in the first place, right? Go back to martial arts, right? The best defense is to not be there to take the blow you get. Right. So I also practice martial arts and we do conditioning where, you know, you'll hit each other in a friendly environment so that when you do get hit, you're not shocked by it. And you can recover and hopefully avoid the next hit, but. Which will come. Yes, exactly. And sometimes the most frustrating thing for an adversary is when they go for that kick or that punch and you're just not there. It's like you moved and you parry the other way. It's fascinating. All right, let's open it up for questions. Okay, so my first question is, do you have a favorite attack? Do I have a favorite? The favorite, you know, threat that you've ever seen actually come through, like was one particularly clever? I've always admired the, and this is where like, you respect your adversary, right? I admire the way that ransomware has evolved, right? In terms of the adversaries are quickly moving from, okay, we started encrypting single laptops, to multiple, to then we're doing extortions, to how this has been codified as a service. I think that the entire field, like one of my interests is the economics of cybersecurity, right? And it's fascinating how ransomware as a general topic changed the externalities of poor security practices. In economics, the concept of externality is that if you, it's a consequence that happens, it's a consequence to decisions that you are making, I'm simplifying, it's consequences to decisions that you're making that you don't feel the impact of, right? Typical example is something like environmental pollution, right? And it was interesting that before ransomware, there were no immediate consequences to poor security practices, right? Ransomware brought those chickens home to roost, and now that your organization is affected. So more than any one specific attack, I think that the broad class of ransomware, which by the way, I deeply dislike as a term, right? I know again, another battle I lost, but it's not ransomware, it's not a threat, it's not a threat, it's not a threat, it's not ransomware, it's not just ransomware, right? If you think about it, if I tell you that you have a problem with malware, if I tell you that you have a problem with spyware, right? The immediate response that you have is, oh, okay, I'm going to get some anti-malware software for my end point, I'm gonna get some anti-spyware component, sorry, for my end points, right? So you sort of say, oh, okay, that's a security problem, pass it over to security, they'll handle it. The problem I have with ransomware is that that's what you will immediately do, oh, you know what, security people, you handle ransomware. I'm sorry, the proper name for ransomware should be a multi-stage extortion campaign against your entire organization, it's a mouthful, right? Because it requires your entire organization to act, right? It's about how does security coordinate with legal or coordinate with comms, and so it's a much bigger problem. So I think I'm on the record saying that I don't like ransomware as a term, even though I respect it very much. I like that answer. I do have a lot of respect for people who do clever things, even if I don't like what they do. We have a great question from Silke, which is how can we use the information for sales purposes? And the response is pretty straightforward. We saw in the future research, 38% of all SMBs that responded have had three or more attacks, right? So it is absolutely inevitable that they will be impacted by threats. And when you stand up that three-legged stool, like how do you actually put things forward about protecting yourself from the attack initially, and that is using the user endpoint management, UEM products like Insight and then Central to make sure that everything is up to date, to make sure that you have patches out everywhere, to make sure you understand the software that's installed on everything. We have vulnerability detection in there as well. And then for the during an attack, how do you actually know when there's a threat actor in your mist? That's where AdLumen comes in, because it can actually look at incidents that come in at a low level and roll them up and correlate them to raise those as incidents within our SOC. So we can assist you in discovering new issues. We also have some shadow AI detection capabilities that are coming out very soon on that. So that's the during, how do you do the detection and response? You use something like an MDR like AdLumen. And then for that recovery, that's where Cove comes in. Because if you have set up backup and point-in-time management across your systems, we have things like automatic boot detection to make sure that you do have good backups and you are able to recover those critical systems within your environments. So you can use this as a driver for the consumption of the three legs of the stool, all of which Enable provides as a software solutions. It's a great question and thank you. Here's one for you. So how do you monitor all of the CVE releases? Can you explain to us, for the layman, what is a CVE release? CVE is a common vulnerability and exposure. To make a very long story short, right? Remember that explosion of technology we spoke about? Every technology has vulnerabilities and it has been a significant coordination problem. How do you normalize between vulnerability reports from the multitude of software vendors out there, right? If somebody says, oh, I found a particular buffer overflow in one piece of code, you don't want 500 people, 500 security researchers always saying the same thing under different names, like I'm simplifying. So the common vulnerability and exposure is something that the industry came up with years ago as a method to coordinate, to assign indicators to vulnerabilities so that people can refer to them the same way. Now, there has been significant, I'm gonna say turbulence in the CVE ecosystem, way too much to get into here. But suffice to say that there is currently a problem with, okay, are we assigning CVEs fast enough? Are we giving enough information on those CVEs and whatnot? Why are they important? Well, they are important because lots of organizations use those CVEs as notifications that, oh my goodness, there's a problem with the kind of software that I run and I need to go ahead and patch, right? This, the short answer is how do you keep up with all the CVEs? You don't, you can't, right? There are tens of thousands, hundreds of thousands of, I think there are hundreds of thousands of CVEs out there and they are published by hundreds or thousands in a very short period. What you do is on one hand, remember that continuous improvement process, right? You stay on top, you work with your security partners who tell you, oh, you know what? Those CVEs, we've actually have further indication that they have been exploited in the wild, right? So you know what? That's a CVE with a little bit of a higher priority, right? There's a separate list called the KEV, the known and exploitable vulnerabilities, right? That you can use. These are things that security researchers and government organizations around the world have seen in the wild. So these are things that you should fix, right? So you prioritize and that prioritization comes from, comes again in a continuous loop of, you look at vulnerabilities that affect your environment, you patch them as quickly as you can. And remember the preparation phase that we talk about. If you strengthen your environment, if you minimize your attack surface so that a particular vulnerability may exist within a system, but that system is protected in some other way, you still need to fix it, but it's not as high a priority, right? So I say that the way you stay on top of these is by working with your MDR, working with your, staying on top of which vulnerabilities matter to you and then fixing those. That's the continuous process of this. And this is where, again, automation and AI can play a part, can help you with parsing what those vulnerabilities might be and how they apply to your environment and so on. It's a long conversation. That's a great lead into the next question. This question is actually very pertinent and something I think about a lot. It says, how much do you expect to see AI versus AI with regards to prevention versus breach? If anybody has seen the latest Tron, it is an exceptional example of AI versus AI and it made me laugh and I thought, I'm living this. Feels like iterations of breach routes and parameters for detecting and preventing these routes is a race to the top that leaves us behind. I wonder if you could speak to the possibility of more and more cybersec ending up flat boxed from even experts behind the machine learning adversarial escalation. This is a person after my own heart because I think about and talk about this quite a bit as part of the education work that I do, which is if you build things that aren't verbose and self-explanatory and well audited and well understood, you will end up with an instance of having built and released something which you can't explain, right? And that's a big threat. I'm going to break the chain here and say that we've managed to survive 50 minutes of a podcast or of a webinar without bringing up Mythos, right? Oh, I do, yes. Okay, Glasswing, here we come. Yeah, no, I just wanted to say that if anybody's playing bingo with their presentation. But it's a phenomenal example of when we wrote about Mythos a few weeks ago, we actually called out that it's a natural evolution of something we've seen before, like the cyber, the AI, the DARPA cyber challenge before, right, and you can go back even to fuzzing, like fuzzing as a technique started back in 1989, right? So we've been at this for a while. So it's a natural evolution. And I definitely see a world where it's not that, it's that we rely on automation to address things that can be addressed. But to your point, those things should be generating enough telemetry that we can go look into them and fix them if need be. But as a security, as you better understand your environment, as you better understand the domain, so there's two things, it's understanding your environment well enough, having your environment automated or able to be automated well enough, your processes and so on, and understanding the domain, the domain of cybersecurity problems, what can we automate out of that understanding and putting those kinds of things together, right? AI can help beautifully there, provided that you have the capabilities to go in and to your point, explain what happens, right? I'm not, let me use a different example. How many people here are, we're not gonna do a poll, but for those of you who've been around, remember the early days of Wi-Fi, right? Very, very early days of Wi-Fi. The best technique that we had for securing Wi-Fi was hard coding the hardware addresses of the wireless cards into, these are the only ones that can connect, right? And then eventually we moved up the stack, if you will, in terms of, you know what, as long as people authenticate with better authentication protocols for wireless. We did that in part because no wireless engineer was going to stay hard coding Mac addresses all day long in their applications, right? It doesn't mean that the Mac addresses went away, that telemetry is still there if you want to look, but you're using the higher value, the expensive wireless engineer to do different things now. I think about that in the context of AI. We are going to have things that, that some vulnerabilities will be closed automatically by AI, but you better have the skills and the knowledge and the process to look into what those fixes are and correct where things go wrong, right? So it's very emergency. The bad actors will have black box AI, no question about it. We will not understand what they do, we will not understand how they do it. They probably won't understand it either, but from the defense and detect perspective, we actually know how to design AI agents and implementations where we are actively registering every agent ID, and we can manage those like an identity, understand their run books and play books exactly like we understand the behavior of our employees and software. And we can also make sure that we have, you know, wild verbosity, governance, death dates, all of the things that we need to understand exactly what that system's doing. Now that said, it's still non-deterministic, meaning that it will follow a series of run books and it will be able to extrapolate on those run books, but it's going to act within a set of guardrails. And we will understand what those guardrails are if we design these things correctly. And I think that the discipline of designing AI agents has gotten much better and it will continue to improve just like we see in Wi-Fi, so that everybody can understand the layer of abstraction where we end up for how we define and manage these agents. Absolutely. And I loved your leadership on this and like when you were presenting at Empower, like where you were taking AI within Enable, it's fascinating to watch. Well, thank you. Okay, so we've just run out of questions. Fernando, this has been absolutely delightful. I truly appreciate your time and your research and your expertise, but just a wonderful way to spend my morning. Oh, this was fun. And like I said, I love the work that you do. I remember all the conversations we've had, it's been phenomenal. And I'm really looking forward to what you're bringing up in Enable and how this evolves. All right, and everybody, don't forget to go grab those free giveaways that the governance report does give you information on how to properly set up agents so that you can track them and make sure that they're effective within your organization as well. So have a wonderful day.

TL;DR

  • Over 60% of security professionals report seeing significant increases in AI-driven attacks, with adversaries leveraging automation to operate at machine speed across multiple attack vectors simultaneously
  • Traditional security models are failing because technology expansion has stretched teams across both volume and cognitive dimensions, while reactive workflows can't keep pace with automated threats
  • Effective security requires a three-phase approach: prevention (EDR, patch management), response (isolation, containment), and recovery (disaster recovery, instant failover)
  • Context is critical for risk prioritization—the same vulnerability represents different threats depending on business impact, requiring integration of business context into security programs
  • AI governance must balance automation with explainability, ensuring defensive AI agents operate within guardrails while maintaining comprehensive audit trails and human oversight capabilities
  • The 'assume breach' mentality represents security program maturity, focusing on resilience and recovery rather than the unrealistic expectation of 100% prevention

The Rise of AI-Powered Cyber Attacks

Fernando Montenegro from the Futurum Group presents research showing that over 60% of security professionals have observed a significant rise in AI-driven attacks over the past year, with 38% strongly agreeing to this trend. This data, collected from approximately 1,000 respondents worldwide in late 2023, reveals that AI has become a major forcing function for upgrading security programs across organizations of all sizes. The research highlights how adversaries are leveraging AI and automation to operate at machine speed, creating attacks across multiple context types simultaneously. What's particularly notable is that this data predates the widespread adoption of AI agents, suggesting the threat landscape has likely intensified further in recent months.

Why Traditional Security Models Are Failing

The conversation explores how the explosion of technology over the past three decades has stretched security teams beyond their limits. Organizations face challenges across two critical dimensions: the sheer volume of technology implementations and the cognitive load of managing diverse technology types. Security teams must now coordinate across network firewalls, SaaS implementations, identity management, and countless other domains, often without the luxury of large specialized teams. This complexity is compounded by the need for coordination between IT operations, security operations, and business stakeholders. Meanwhile, adversaries have become adept at using automation and AI to exploit these stretched resources, operating at machine speed while defenders struggle with manual processes and reactive workflows.

The Three-Legged Stool: A Comprehensive Defense Framework

Montenegro introduces a maturity model based on three critical phases: before, during, and after a security incident. The 'before' phase emphasizes prevention through endpoint monitoring, detection and response (EDR), and comprehensive patch management to eliminate vulnerabilities. The 'during' phase focuses on immediate response and isolation capabilities, containing the blast radius when incidents occur. The 'after' phase centers on disaster recovery, understanding rollback points, system remediation, and ensuring instant recoverability and failover. This framework reflects an 'assume breach' mentality that acknowledges prevention alone is insufficient. Organizations must build resilience across all three phases, with each leg supporting the others to create a stable security posture that can withstand inevitable attacks.

Context-Driven Risk Prioritization and AI Governance

A key theme throughout the discussion is the critical importance of context in determining real risk. Montenegro emphasizes that the same vulnerability on different systems represents radically different threats—a vulnerability on a cafeteria menu server versus a financial portal before earnings release requires completely different prioritization. Effective security programs integrate business context, endpoint management data, behavioral profiling, and continuous monitoring to make informed decisions about which threats matter most. The conversation also addresses AI governance, with Montenegro stressing that while AI agents will increasingly handle automated responses, organizations must maintain explainability, verbosity, governance, and audit capabilities. Defensive AI should be designed with guardrails, agent identity management, and comprehensive telemetry, ensuring human experts can understand and correct automated actions when necessary.

Chapters

0:00 - Introduction and Context
1:43 - Research on AI-Driven Attacks
7:42 - Why Security Models Are Failing
12:29 - AI Amplifying Human Mistakes
26:36 - Three-Legged Stool Framework
28:10 - Assume Breach Posture
30:03 - Context-Driven Risk Prioritization
47:26 - Vulnerability Management Strategy
48:37 - AI vs AI and Explainability
54:54 - Closing Remarks

Key Quotes

3:20 "... 38% strongly agreed that they had seen in the past 12 months a significant rise in attacks. So this is strongly agree. The people who said they agree, right? So when you put these together, we're actually over 60%, I think it was about 63, 64% agree or strongly agree that they've seen this rise in AI-driven attacks."
4:17 "We see AI as a forcing function for a lot of that. What's really interesting is this is before... So if you're talking six months ago, this is before the explosion or widespread adoption of AI agents."
8:23 "I think that the way technology has evolved over the past 30 years or so... technology won, right? I mean, there was the paper, there was the quote by Mike Andreessen, 2011 software is eating the world. Yes, it has. 100%, right? ..."
11:46 "The adversaries, they are very adept at applying technology as well, right? And even before the explosion of AI capabilities, right, machine learning and AI capabilities, they have always been very adept at using automation more broadly, right? ..."
28:00 "Prevention alone is no longer enough, right? Prevention is absolutely important. Protection and prevention, absolutely important, but it's not enough, right? I mentioned assume breach as a posture. It's not that we're giving up, right? It's that we are making ourselves more resilient to when the issue happens."
31:37 "You found a vulnerability on a web server, right? Is that web server your kitchen cafeteria server with the menus for the week? Or is that web server your company financials portal the day before earnings release, right? Those are radically different things, right? ..."

FAQ

How should organizations prioritize vulnerabilities when there are thousands to address?

Focus on vulnerabilities that are actively being exploited in the wild and affect your specific environment. Prioritization should incorporate business context—the same vulnerability on a cafeteria menu server versus a financial portal requires different urgency. Work with your MDR provider, stay current on which vulnerabilities matter to your environment, and leverage automation and AI to help parse which vulnerabilities apply to your systems. Remember that strengthening your environment through attack surface reduction can lower the priority of certain vulnerabilities even if they still need fixing.

What does 'assume breach' mean and why is it important?

Assume breach is a security posture that acknowledges prevention alone cannot guarantee 100% security. Instead of trying to prevent every possible attack, organizations build resilience to withstand and recover from inevitable incidents. This means investing equally in detection, response, and recovery capabilities alongside prevention. It's not giving up on security—it's being realistic about threats and building programs that can handle shocks. The challenge is often communicating this mindset to non-security stakeholders who expect absolute protection.

How can organizations ensure AI-driven security tools remain explainable and auditable?

Design AI agents with comprehensive governance from the start: register every agent ID like an identity, understand their runbooks and playbooks, implement guardrails that define acceptable actions, and ensure wild verbosity in logging. While AI agents may act non-deterministically within their parameters, they should operate within well-defined boundaries that security teams can audit and understand. Maintain the skills and processes to review automated fixes and correct issues when they arise. The goal is to leverage AI for automation while preserving human oversight and explainability.


Categories:
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Threat Intelligence
  • AI & Machine Learning
  • Security Operations
  • Best Practices
  • Technical Deep Dive
  • Webinar
  • AI-driven cyber attacks
  • Security program maturity
  • Assume breach methodology
  • Endpoint detection and response
  • Disaster recovery
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: N-Able: AI-Driven Threats & Modern Security Strategy

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Aug
                  13

                  Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                  08/13/202612:00 PM ET
                  More events

                  Upcoming Webinar Calendar

                  • 08/13/2026
                    12:00 PM
                    08/13/2026
                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                    https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                  • 08/27/2026
                    01:00 PM
                    08/27/2026
                    Becoming Agent Ready with Cyera: Essential Strategies and Insights
                    https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                  • 09/02/2026
                    12:00 PM
                    09/02/2026
                    Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                    https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                  • 09/30/2026
                    04:00 AM
                    09/30/2026
                    AI Command Center: Optimizing Visibility and Control in Your Operations
                    https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                  • 11/19/2026
                    01:00 PM
                    11/19/2026
                    360View: Govern, Secure & Recover Your Microsoft 365 Environment
                    https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                  Truth in IT
                  • Sponsor
                  • About Us
                  • Terms of Service
                  • Privacy Policy
                  • Contact Us
                  • Preference Management
                  Desktop version
                  Standard version