Back Cybersecuritydive Don’t let AI distract from cybersecurity basics, officials and executives warn
Simple attacks remain far more consequential than anything AI is doing, government and industry leaders said.
WASHINGTON — Advances in artificial intelligence aren’t changing the fact that simple cybersecurity failures remain the most consequential, government and industry leaders warned on Tuesday.
“What will prevent the attacks in the 18 months are the same things that would have prevented the attacks of yesterday,” Jason Bilnoski, a deputy assistant director in the FBI’s Cyber Division, said during a panel here at the Billington Cybersecurity Summit.
Core practices such as identity management, perimeter monitoring, cyber hygiene and strong multifactor authentication remain as essential as ever, Bilnoski said.
“Speed and capability is certainly increasing with the use of AI, but the end state is still the same,” he said. “How actors are compromising, whether it’s criminal or nation-state, still stays the same.”
The FBI recently urged organizations to fix basic security failures as part of its Operation Winter Shield campaign . “Implementing them can be hard at times, depending on your organization,” Bilnoski told the audience, but “if we can harden up those top 10 controls … it would certainly reduce the risk of both criminal and nation-state targeting [of] our environments.”
Senior officials from other members of the Five Eyes intelligence-sharing alliance echoed Bilnoski’s points during another session.
“Understanding your assets, getting rid of legacy tech, speeding up patching cycles so that we are responding to vulnerabilities as fast as we can — all of that helps, irrespective of the adversary,” said Catriona Robinson, the head of New Zealand’s National Cyber Security Centre.
Richard Horne, the chief executive of the UK’s National Cyber Security Centre, added that “what AI is doing is shining a spotlight on those organizations that haven’t focused on the basics.”
David Imbordino, the director of the NSA’s Cybersecurity Directorate, made a similar point.
“The basics are no longer boring,” he said, “and AI can’t outrun the basics.”
Understanding the environment
One of the best ways for businesses to stay ahead of adversaries is to understand what’s on their networks, speakers said during the Billington discussions.
Matthew Shallbetter, the director of strategy for the federal civilian portfolio at cybersecurity vendor Armis Federal, said organizations should ask questions such as, “Where are the devices on my network? Where [are they] coming from? Do I know the supply chain?”
Businesses should watch for employees installing untrusted technology that could expose their networks to serious supply-chain security risks . “They might put a camera on there from some vendor you don’t want,” he said.
“You have to know what you have,” Shallbetter added. “You have to know how it’s interconnected.”
That is important not only for securing one’s own network, he said, but also for preventing an attack from spreading to vendors and suppliers. “Being able to be a good steward of your part of the internet is critical to make sure that the entire internet is secure.”
Network mapping can help a business understand “what’s at risk if those systems are compromised, and then what can an adversary do when they’re in the environment?” Bilnoski said.
“Of course, [it’s] important to focus on who could be targeting you,” he added, acknowledging that the FBI prioritizes attribution in its investigations. But what matters more, he said, is “understanding the adversary’s intent once they get there.”
The conversations at Billington took place as organizations struggle to understand how seriously they should worry AI — and how extensively they should adopt it for their defensive strategies .
Speakers mostly advised businesses not to let the current AI hype cycle distract them from the basics of cyber hygiene.
“Be swift but not hasty,” New Zealand’s Robinson said. “Resist the breathless rush to grab the sexy new tools.”
At the same time, several Five Eyes officials acknowledged that AI was transforming how they did cyber defense.
“AI is giving us [an] opportunity to go through that volume and noise to get to the signal a lot quicker,” Imbordino said. “The future of analysis [is AI] looking at disparate pieces of information to get things that humans can act on much more quickly.”
During another session, Imbordino predicted that AI would become “a game changer for defense.”
Rajiv Gupta, the head of the Canadian Centre for Cyber Security, said AI has augmented humans’ cybersecurity work with “a 10x, 20x, 100x type of improvement.”
At the same time, even sophisticated threat actors are getting modest boosts from the technology.
David Liebenberg, the head of nation-state threat tracking at Cisco’s Talos Labs, said he had seen state-backed groups use AI to dramatically improve the social-engineering attacks they’ve been performing for years.
“Just a few years ago, it would have been unthinkable that a state- group could not only get an interview with a Fortune 500 [company] or a defense contractor, [but] they could use AI-generated video to ace that interview and actually secure a position,” Liebenberg said. “We’re seeing that across every stage of the attack life cycle, and I only see that intensifying in the 18 months.”
Company Announcements
Want to a company announcement with your peers?
Deep Dive Auto sector faces historic cyber threats to business continuity A catastrophic cyberattack at Jaguar Land Rover is forcing governments and industrial leaders to address urgent demands for business resilience and accountability. By David Jones • Oct. 16, 2025
Auto sector faces historic cyber threats to business continuity
A catastrophic cyberattack at Jaguar Land Rover is forcing governments and industrial leaders to address urgent demands for business resilience and accountability.
Layoffs, reassignments further deplete CISA Some CISA staffers have been pushed out, while others are being told to move across the country for jobs outside their skill sets. By Eric Geller • Oct. 14, 2025
Layoffs, reassignments further deplete CISA
Some CISA staffers have been pushed out, while others are being told to move across the country for jobs outside their skill sets.
Don’t let AI distract from cybersecurity basics, officials and executives warn By Eric Geller
Nvidia’s $12.9B Hugging Face deal could benefit enterprises By Paige Gross
OpenAI pledges $1B to provide resources, training for frontline cyber defenders By David Jones
Government lacks ability to verify AI labs’ claims, experts say By Eric Geller
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
