Back to Insights AI Security

Haven’t experienced an incident in the past year? Think you’re protected? You likely haven’t fully internalized the threats posed by AI.

The Strongest Organizations Remain Exposed: High Resilience, but AI Blindness

A new report from LevelBlue highlights a surprising paradox: even organizations considered highly resilient to cyberattacks are failing to identify risks arising from the use of Artificial Intelligence (AI) tools. While these organizations adopt a proactive approach—investing in supply chain security, increasing social engineering awareness, and deploying advanced threat detection tools—the vast majority do not accurately assess the risks that unmonitored AI may pose.

Although 94% of resilient organizations reported no security breaches in the past year, only about one-third of executives believe that adopting AI tools increases supply chain risk—a figure that points to a critical awareness gap.

AI in the Service of the Organization – or Against It? Adoption Speed Outpaces Defense
The adoption of AI tools is occurring at a much faster pace than the evolution of regulatory systems or oversight and defense mechanisms. The implication: an expansion of the organization’s potential attack surface and an increased risk of disruption, data leakage, or supplier compromise.

According to the report, organizations exhibit overconfidence in implementing AI solutions while failing to sufficiently consider the security consequences. This gap between management’s sense of security and actual risks could make them an easy target for attackers, particularly regarding systems or applications that have not been properly tested and validated.

Effective Response: Moving Beyond Reactivity
Comprehensive Readiness and a Holistic Business View
A resilient organization is not just one that knows how to recover, but one that identifies, alerts, and responds in advance. Such an approach requires risk mapping, exposure management, building business continuity plans, and performing periodic stress tests for extreme scenarios.

According to experts from Tenable and ExtraHop, corporate defense today is a shared responsibility of the entire executive leadership—not just the CISO. Full coverage of the entire network must be ensured, including endpoints, cloud, network equipment, and third-party interfaces, as advanced threats can bypass traditional defenses by impersonating internal entities.

Recommendations from IPVs Security Experts:
* Ongoing Review of Supply Chain and Vendors: Including risk level analysis and implementation of security requirements.
* Defining AI Implementation Policies: Examining risks, permissions, and regulatory requirements prior to deployment.
* Conducting Risk Assessments and Penetration Testing: For early identification of vulnerabilities, including those in AI interfaces.
* Comprehensive Leadership Responsibility: Management involvement in information security contributes to resilience, effective response, and rapid recovery.
* Strengthening Network Monitoring and Access Point Inspection: Ensuring threats do not fly under the radar due to impersonation or mask as internal traffic.

In Conclusion
The LevelBlue report clarifies: organizational resilience is a fundamental prerequisite, but not a total guarantee against AI risks. The way forward requires a combination of technological robustness, leadership awareness, and continuous management of rapidly evolving new risks. Organizations that place blind trust in technology may discover too late that it exposes them to the very threats they sought to defend against.

For further information: https://www.darkreading.com/cyber-risk/even-resilient-organizations-bind-ai-threats

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation