Getty Images/iStockphoto

The CISO dilemma: Why AI speed makes security basics essential

Insights from the CyberRisk Alliance Summit reveal that AI hasn't rewritten the threat landscape -- it has simply erased the time defenders have to fix basic operational flaws.

Enterprise security leaders are routinely inundated with vendor hype claiming their AI tools will single-handedly rewrite the Security Operations Center. In the trenches, however, defenders are still fighting broken identity and access management systems, unpatched web app vulnerabilities and third-party supply chain exposure.

This operational reality took center stage at the CyberRisk Alliance Cybersecurity Summit in Bellevue, Wash., yesterday (Oct. 1), where panelists and practitioners concluded that AI speed doesn't replace security basics -- it magnifies every existing flaw.

AI revitalizes 20-year-old vulnerabilities

A common misconception across boardrooms is that AI empowers adversaries to launch entirely novel classes of attacks. In practice, AI simply drops the barrier to entry for adversaries to deploy decades-old attack vectors at unprecedented speed and scale.

As Johnny Wong, principal consultant at Veracode, highlighted during the CyberRisk Alliance event, LLMs trained on public code repositories are actively reintroducing 20-year-old OWASP Top 10 vulnerabilities -- such as SQL injection and cross-site scripting -- at enterprise scale. Non-developer employees drafting shadow scripts using AI prompts are drastically expanding this attack surface, he said.

In social engineering, too, AI is making classic attack tactics more effective, accessible and scalable, said Mario Villatoro, vice president and CISO at Jamf.

"Many of us remember when we used to give the advice to look for grammatical errors, look for out-of-context emails," he said. "That doesn't work anymore. What we have seen is how AI can build a phish kit within minutes. It doesn't really take any skill. AI has really impacted the barrier to entry."

While Villatoro noted that AI can also act as a powerful "force multiplier" for defense, he stressed that security teams must start with solid operational foundations. To cut through vendor hype, he advised CISOs to apply a simple filter: evaluate whether a new capability measurably mitigates a specific risk, how it alters an attacker's actual leverage, and what real impact ignoring the tool would have on the organization's posture over the next 12 to 18 months.

The real perimeter: Identity, backups and zero trust

The foundational defense against accelerated threat velocity isn't a speculative automated vender offering -- it is disciplined execution of core security practices. Opening the CyberRisk Alliance summit, RJ Niesen, cybersecurity state coordinator for CISA, provided a reality check on organizational readiness.

Niesen noted that CISA's incident response calls across the state of Washingtonfrequently reveal that organizations lack immutable or off-site backups or fail to conduct annual restoration testing.

"When folks tell me they haven't tested their backups in two years, imagine getting hit tomorrow -- and then telling your CIO, 'We'll just restore from backup,' and then you realize nothing's there. If you're not doing the basics, stop looking at investing in robots." 

Beyond offline resilience, Villatoro singled out identity and access management as a non-negotiable architectural baseline.

"One of the common mistakes organizations are still making is that they treat identity as an IT provisioning problem when it's really not. Identity is at the core of security," he said.

Crucially, the rise of autonomous AI agents makes zero trust architecture more vital, not less. As Villatoro explained, continuous authorization and network segmentation are the primary mechanisms to prevent compromised credentials or rogue non-human agents from moving laterally.

"If you have a segmented network, that reduces your blast radius," he said. "If you have strong visibility, you know what the agents are doing. And then if you have continuous access, continuous validation, you're not going to have an unfettered agent going all over the place."

Governance, trust and the 'human-in-the-loop'

As security teams integrate AI into operational workflows, data highlights a significant gap between technical capability and institutional trust.

Presenting findings from Torq’s "2026 AI SOC Leadership Report," the company's Briana Clark noted that while 97% of security leaders expressed confidence that AI can handle alert triage, only 35% have actively deployed it for that purpose. Furthermore, 92% of security leaders report an explicit "trust barrier" holding back broader AI adoption.

This hesitation is directly tied to the severity of the threat and the demand for algorithmic transparency.

"Seventy-two percent are very comfortable passing low and medium severity alerts to an autonomous solution," she said. "That number was much lower when we started talking about high and critical [issues]. In those cases, they really still expect a human to be involved in those escalations, those investigations, especially the response."

Clark stressed that enterprise SOCs demand complete transparency over "black box" engines. AI can dramatically accelerate incident enrichment and slash defender dwell times, but final accountability rests with people.

This demand for human oversight was echoed from a development perspective by Veracode's Wong, who emphasized that automated code assistance never relieves engineers of personal responsibility.

"I don't care if you use ChatGPT or Claude or whatever to produce the work, but it's your name on it," he said. "I'm holding you responsible for whatever happens."

As enterprise security teams weigh the promise of autonomous SOCs and AI speed, the takeaway from the CyberRisk Alliance event was that AI isn't an escape hatch from operational discipline. Whether reviewing AI-generated code, securing identity or triaging alerts, enterprise resilience still hinges on execution, continuous verification and human accountability.

James Walker is lead editor at TechTarget Cybersecurity.

Dig Deeper on Security Operations & Management