Gadgion
techradar.com

Why C-suite leaders are the weakest link in AI-era cyber defense

Former GCHQ analyst Julian Richards explains why executive complacency fuels breaches, and how upskilling at the top beats any firewall.

Source material: techradar.com

Why must C-suite executives personally understand AI threats?

Because when a breach happens, the board takes the hit — legally and reputationally — yet most executives still treat cybersecurity as someone else's problem. Julian Richards, a former GCHQ senior analyst, says this attitude is increasingly untenable. AI has collapsed the skill gap between ordinary criminals and state-sponsored groups. Tactics like ETERNALBLUE, once stolen from the NSA and resold on the dark web, are now available to anyone. Executives who cannot distinguish a real threat from a false alarm will either overreact or freeze. The answer is not delegating, but hands-on training: crisis workshops, simulated ransomware exercises, and regular briefings on how AI tools like Claude Mythos and GPT-5.5 can both defend and attack. Without that layer of personal competence, the rest of the organization's security culture crumbles.

Abstract digital human face. Artificial intelligence concept of big data or cyber security
Abstract digital human face. Artificial intelligence concept of big data or cyber security (Image credit: Shutterstock)

What is the biggest blind spot business leaders have about cyber threats?

Complacency — the belief that a breach happens to other firms, not yours — remains the most intractable problem, says Richards. He identifies two persistent blind spots: that one, and a failure to grasp the human factor as the biggest threat vector. Even with advanced AI defenses, a single phishing click or a misconfigured internal protocol can undo everything. The 2025 IBM report quantified the stakes: a 44% increase in attacks exploiting public-facing applications, a 40% rise in vulnerability exploitation, and a 50% jump in active ransomware operators since 2025. These jumps stem from attackers adopting AI to automate reconnaissance, refine malware, and scale their operations, meaning even smaller firms are now in scope. Leaders who assume their industry or size protects them are precisely the targets AI-equipped attackers seek. Training, awareness, and crisis rehearsals feel tedious but remain the core defense, particularly because AI-enabled attacks often exploit human error rather than pure technical flaws.

How is AI changing the speed from vulnerability discovery to exploitation?

AI has compressed the window between when a vulnerability is disclosed and when it's weaponized from months to days or even hours. Richards notes that threat actors now use AI to automate reconnaissance, modify malware, and chain exploits at industrial scale. But the reverse also holds: defenders can use AI to map and analyze attacks in real time, even as they mutate. This dynamic race means static security measures fail. Companies can no longer rely on patching within a quarterly cycle. The shrinking timeframe also pressures governments to rethink threat disclosure rules — compliance legislation, Richards says, moves far slower than technology. He advocates for allowing post-facto disclosure in fast-moving situations, so organizations aren't penalized for prioritizing containment over immediate public reporting.

Is the age of stockpiling vulnerabilities for future attacks over?

No — and Richards points to cryptography as a parallel world where exploits remain valuable for years after exposure. He introduces a widened notion of 'harvest now, exploit later,' alongside the established HNDL (harvest now, decrypt later). Attackers collect vulnerabilities and data now, waiting for the right moment or for AI to make decryption feasible. This means defenders must adopt a dynamic, diversified strategy that goes beyond technical fixes into human-layer planning. Instead of hoarding defensive secrets, businesses can use AI to continually map their own attack surface, simulating how an exploit might evolve. The lesson: don't assume a patched vulnerability is gone for good; threat actors may have already harvested it and will use it when a new connection is exposed.

What challenges do businesses face implementing active defense on legacy infrastructure?

Legacy systems often lack the APIs and data formats needed for AI-driven active defense, forcing companies to choose between incompatible tools. Richards cautions that there are 'good and bad products on the market' and many bad investment decisions are made in desperation. The core challenge is tailoring the defense strategy to the business's scale and shape — a one-size-fits-all suite will fail on aging infrastructure. He advises dealing with 'honest and adept brokers' who understand your environment, not just the latest AI hype. Practical steps: audit which legacy components can be monitored, invest in network segmentation to isolate AI tools from critical old systems, and prioritize patching for systems that are internet-facing. Without these, active defense like automated threat hunting can break more than it protects.

How should threat disclosure legislation adapt to AI-era speed?

Richards predicts that court cases will be brought to challenge overly stringent threat disclosure penalties, with subsequent precedents eventually balancing organizational protection against the need for rapid response. This will require leveraging advanced cyber expertise in law and legislation, so businesses should ensure their legal teams understand AI threat dynamics and can navigate evolving legal frameworks. Documenting incident response decisions remains a prudent safeguard. Because AI accelerates the window between vulnerability discovery and exploitation, a rigid disclosure deadline can force companies to reveal vulnerabilities before they have patched them, or to risk penalties for waiting. Compliance legislation moves much more slowly than technology, so these windows will become increasingly outdated. Drawing on intelligence practice of selective disclosure for national security, commercial bodies may need creative regulation that allows for post facto disclosure in fast-moving situations. Until precedents emerge, legal teams should track evolving case law and build flexible response protocols that prioritize stakeholder safety while preserving evidence.

Where can executives get reliable support for incident response decisions?

C-suite leaders need to upskill themselves first, says Richards — but they should also build relationships with reputable threat intelligence suppliers who offer triangulated data. For real-time incident response, he recommends working with analysts who have experience in intelligence, such as those from GCHQ backgrounds, rather than generic consultants. Larger organizations can create a dedicated cyber threat intel role that reports directly to the CEO. Small businesses should seek vetted MSSPs (managed security service providers) that specialize in their sector. Crucially, executives must participate in crisis exercises alongside their technical teams — deciding when to shut down systems, when to pay ransom (rarely advised), and when to contact authorities. The goal is to make decisions under pressure, not to rely on third-party advice alone.

Where this came from. This breakdown is based on source material published at techradar.com. Images above are used with the credits shown beneath each one.