Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Defending against AI-fuelled attacks: there’s no need to reinvent the wheel (Page 5)
Cyber resilience

Defending against AI-fuelled attacks: there’s no need to reinvent the wheel

March 15, 20245 Mins Read
A cyber hygiene button on a computer keyboard

By Darren Guccione

We’re entering a new and novel frontier of cyber attacks, thanks to artificial intelligence (AI). AI has provided cybercriminals with a sophisticated toolkit of advanced weaponry that can be used for nefarious purposes ranging from fraud to advanced social engineering. Recently, for example, a company worker in Hong Kong paid out £20m in a deepfake conference call scam, exemplifying the believability and very real consequences of these kinds of attacks. It’s no wonder new research has revealed that AI-powered attacks and deepfake technology were ranked by IT security leaders as the top two most concerning cyber attack vectors for 2024.

This ‘AI toolkit’ adds another string to the bow of cybercriminals: a convenient convergence of tools to launch their attacks. A generative AI tool can be used to write legitimate looking phishing emails, for example, which is both fast and cost-effective for opportunistic cybercriminals. AI impersonation, similarly, helps provide a level of feigned legitimacy which can be exploited in social engineering attacks.

Ultimately, AI-generated collateral is looking increasingly more ‘human’ and harder to identify. So, how can businesses protect themselves?

Internal controls and privileged access

Privileged access management allows businesses to secure and tightly control access to accounts and systems that hold sensitive information, such as IT admin accounts. If the wrong person were to gain access to these accounts, sensitive information could be stolen, leaked or used in double extortion attempts.

Business leaders need to reconsider who has access to networks and accounts which provide the keys to their organization’s most sensitive information. A sophisticated deepfake impersonating a C-suite executive would be less effective in targeting a mid-level employee if, for example, that employee was unable to access systems that hold the sensitive data cybercriminals seek.

Education and awareness training that evolves with the times

Research has shown that global IT leaders believe phishing, malware, and ransomware are the fastest-growing cyber attack vectors. AI has, undoubtedly, made these attacks even easier (and quicker) for cybercriminals.

As threats evolve, awareness training should too. By educating employees on the new ways cybercriminals are targeting organizations – including AI-based attacks – employees can spot and report anything that looks suspicious. However, organizations should also have a robust and stacked cyber security program that does not solely rely on end-user education.

Keep software and devices up to date, secure accounts

Another way organizations can secure accounts and reduce the likelihood of being targeted by AI attacks is by regularly updating software and devices as soon as updates and patches are made available. Being efficient when it comes to patching security flaws and vulnerabilities can reduce the window of opportunity that hackers have to exploit them.

Additionally, all data should be backed up. In the event of a malware attack, backed-up data protects an organization from losing its information permanently. For extra security, encrypted back-up services can be beneficial for organizations.

Avoid giving out personal or sensitive information

Common AI attacks include AI-generated phishing emails, AI impersonation and deepfakes. Cybercriminals leverage AI to make scams more believable. When it comes to AI impersonation, for example, scammers can use AI algorithms to analyse large amounts of data, generating a fake persona. A technique called synthesis can even impersonate someone’s voice. Combined, these techniques can create a convincing impersonation. Deepfakes are similar in this way, leveraging AI to alter a person’s face or body to look like someone they’re not.

What all these techniques have in common is that they help cybercriminals look and act more legitimate than ever. That’s why it’s important to exercise caution when giving out personal or sensitive information to anyone online, even if they appear ‘real’. It’s important to ask yourself if the request is unusual or out of the blue. Consider a second form of verification before you think about sending any sensitive information and consider sending anything sensitive using an encrypted service so it’s only seen by the person it’s intended to be seen by.

Implement strong password practices

One of the most common ways AI is being leveraged by cybercriminals is through AI-based password cracking. Password cracking is a technique commonly used by cybercriminals to hack passwords. Specialist password-cracking software can automatically attempt brute force entry into an account using variations of commonly used passwords and trying every possible variation until it’s successful. AI has made this process radically quicker and more successful.

The importance of using strong passwords can never be overstated. As AI gets more sophisticated and quicker at guessing passwords, businesses must ensure that employees are practising good password hygiene. But with multiple accounts and multiple passwords to remember, employees may be inclined to reuse passwords or write them down, which is equally as dangerous. One way organizations can reduce password reuse and enforce strong password creation is by implementing a secure password manager.

There’s no need to reinvent the wheel

When it comes to evolving attack vectors, there’s often a focus on creating a new solution. However, the fundamental rules of protecting yourself and your organization remain as relevant as ever.  Basic cyber security measures, such as creating strong and unique passwords, enabling multi-factor authentication, training employees, and keeping software up to date, are frequently overlooked but exceptionally important, no matter how evolved the threat landscape becomes.

The author

Darren Guccione is Co-Founder and CEO of Keeper Security.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticlePandemic planning: UKHSA announces research to develop vaccines against henipaviruses
Next Article EU Artificial Intelligence Act creates new compliance challenges

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A digital twin test bay showing a large screen displaying a virtual boiler model synchronised with the physical unit during operational testing.

International cyber agencies publish guidance for isolating critical infrastructure systems during times of crisis

July 29, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?