Dennis van Halteren
Cybersecurity Specialist
The Next Two Years Will Determine Who Falls Behind
AI in Cybersecurity Recap at Riding the Waves
During the North Sea Regatta, I recently hosted a session on AI and cybersecurity for relations of our sister company, Beyonder. The sea was calm. The questions that followed were anything but.
Afterwards, I spoke with several people who all asked the same thing: should we be excited about AI, or should we be worried? My answer is always the same: both. AI offers immense opportunities, but the exact same technology is being actively weaponized by cybercriminals. AI is making cyberattacks smarter, faster, and harder to detect. That is not a future prediction. That is what we are seeing right now.
In this blog, I share the developments I am currently observing and what organizations must prepare for over the next 12 to 24 months.
AI Makes Malware Smarter
AI-driven malware first learns what normal behavior looks like. Then, it strikes. Traditionally, security solutions look for anomalies. When a user or system behaves differently than usual, an alarm goes off. But what happens if malware first learns what constitutes "normal"? That is exactly what we are seeing. This malware analyzes users, systems, and processes before taking action, subsequently adapting its behavior. This makes detection significantly more difficult. Attacks deliberately hide amidst normal business activities. Noticeable anomalies are no longer the norm.
Cyberattacks Are Automated
Cybercriminals use AI to work faster and more efficiently. Scouting for vulnerabilities, analyzing systems, executing attacks: it is all automated. What used to take hours now takes minutes. This means organizations have less time to respond once a new vulnerability becomes public. The window between a flaw being disclosed and the first exploits occurring has been shrinking for years. Now, it is sometimes a matter of hours.
AI Discovers Flaws Humans Missed for Years
AI is being deployed for code analysis. Software that was considered secure for years suddenly turns out to contain vulnerabilities. Not because developers didn't do their jobs well, but because AI recognizes patterns that are incredibly difficult for humans to spot. The question that always follows is: how did nobody see this before? The answer is simple: AI looks at software differently than we do.
Why Traditional Phishing Training is No Longer Enough
Many organizations train employees to recognize suspicious links. While that remains relevant, the nature of the attack has changed. A phishing email increasingly contains no link at all. Instead, an attacker initiates a conversation. As soon as someone responds, AI generates highly credible replies tailored to the recipient's specific situation. The attack doesn't start with a click; it starts with a conversation. Awareness training must evolve accordingly. Employees need to know not just when not to click, but also when to be critical of requests that seem perfectly normal at first glance.
Deepfakes Are a Risk for Every Organization
Voices are cloned. Faces are realistically generated. Video calls are convincingly manipulated. This technology is affordable and widely available. Many organizations think this is strictly an enterprise-level problem, but we are seeing deepfake attacks target SMEs. When an employee believes they are speaking with an executive, supplier, or client during a video call, relying on visual confirmation alone is no longer enough. Verification must become standard practice.
Data Poisoning: When AI Learns the Wrong Information
More and more organizations are using AI for research, analysis, and decision-making. With this, a new attack vector has emerged. Cybercriminals inject incorrect information into the datasets and knowledge bases that AI systems rely on. This is known as data poisoning. The goal is not to shut systems down, but to manipulate the output. This makes the threat highly elusive. When false information is presented convincingly, organizations make wrong decisions based on it. Remain critical of AI outputs and verify vital information through multiple sources.
Prompt Injections: A Priority for Every Security Team
Virtually every organization utilizes AI chatbots, virtual assistants, or AI features within existing applications. This has created a new attack surface. Attackers manipulate AI systems via prompt injections: they bypass security rules or force systems to perform unauthorized actions. Since AI is deeply integrated into business processes, security teams need to have this firmly on their radar.
Four Measures That Work Right Now
Invest in awareness. People remain a crucial link. Ensure employees understand how phishing, deepfakes, and AI attacks work in practice.
Ensure continuous monitoring. The faster suspicious activity is detected, the smaller the impact of an incident.
Test for vulnerabilities regularly. Don't just do this during the design phase. Have applications, infrastructure, and software tested by independent specialists.
Keep software up to date. A large percentage of successful attacks exploit known vulnerabilities for which patches are already available. Patch management is one of the most effective security measures in existence.
The Question is Not If AI Changes Cybersecurity
Clients regularly ask me if AI is truly having such a massive impact on cybersecurity. That impact is already here. Cybercriminals are using AI today to make malware smarter, automate attacks, personalize phishing, and uncover vulnerabilities. At the same time, AI provides organizations with better capabilities to defend themselves.
The next two years will determine who falls behind and who doesn't. Organizations that invest now in awareness, monitoring, and resilience will build a competitive advantage. Those that wait will face threats that traditional measures can no longer answer.
How well prepared is your organization?
Dennis van Halteren - Defenced
Meet up with Dennis
The next two years will determine who falls behind. Where does your organization stand?
Don’t wait for traditional security measures to fail against AI-driven threats. Schedule a complimentary 30-minute security consultation with Dennis to evaluate your current defense strategy and identify potential blind spots.