Organizations can strengthen their cyber resilience by managing risks and adapting cyber strategies to meet the challenge of an accelerating threat landscape.
October is Cybersecurity Awareness Month, sponsored by the Cybersecurity and Infrastructure Security Agency and the National Cybersecurity Alliance. This annual initiative, now in its 23rd year, focuses on helping organizations and the public to enhance their awareness of cybersecurity, reduce risk, and address cyberthreats. In this interview, Crowe cyber specialists explore the forces shaping today’s cyber landscape and the priorities organizations should consider as they prepare for what comes next.
Cyber and business leaders are confronting an expanding and accelerating threat landscape. AI gives threat actors new ways to identify vulnerabilities, develop malware, and mount attacks at unprecedented speed, which lowers barriers to entry and compresses organizations’ response time. Meanwhile, the move beyond the traditional network perimeter toward cloud platforms, third-party ecosystems, and distributed resources has added complexity and widened the attack surface. Regulatory demands from state, federal, and international entities also continue to grow.
As part of our annual participation in Cybersecurity Awareness Month, Crowe is examining some of the cyber issues business leaders face today and the steps organizations can take to strengthen their security and cyber resilience. Throughout the month, we’ll address topics including collaboration platform vulnerabilities, European cyber resilience requirements, deepfake impersonation risks, and ransomware response.
In the following interview, Angie Hipsher-Williams, managing partner of cyber consulting at Crowe, and Michael Lucas and Josh Reid, partners in cyber consulting, discuss the business priorities shaping cyber and cybersecurity. Their conversation covers the changing threat landscape, the expanding role of chief information security officers (CISOs), regulatory pressures, cyber readiness, and the balance between AI capabilities and human judgment.
Angie Hipsher-Williams: For me, it comes down to speed. AI has changed the game by enabling threat actors to do in hours what used to take humans much longer. The zero-day clock has gone from years to months to hours to exploit a vulnerability. That shift has accelerated dramatically in just the last four to six months, and it is forcing every organization to rethink how fast it can actually respond. It’s no longer a strategic planning question for CISOs. It’s an operational one.
Michael Lucas: From a threat actor standpoint, the most dramatic change is that adversaries are no longer limited by human brain cycles. AI automates the work of finding vulnerabilities and weaknesses in a company’s infrastructure and can churn away at attempts to compromise it without human effort. Fortunately, companies can use AI to defend themselves. However, while AI helps both threat actors and defenders, I think the advantage at present lies with the threat actors.
Josh Reid: Threat actors can be much more nimble than traditional organizations because they don’t have to operate through governance committees, audit committees, and other corporate structures. AI has also lowered the barrier to entry. With today’s frontier AI models, a threat actor with relatively little experience in computer networking or software development can still create sophisticated malware and vulnerability chains. As a result, a much broader range of threat actors can access capabilities that once required significant technical expertise.
Michael Lucas: I don’t think threat actors are inherently better at using AI. Right now, though, AI gives them an advantage over organizations defending their infrastructure. The technology allows threat actors to create software and automate workflows at a pace that would have required much more time and effort in the past. Defenders need to close that gap, but as with cybersecurity more broadly, that’s a never-ending journey.
Josh Reid: The attack surface is expanding and becoming more complex to manage. Organizations have more entry points and more sensitive data to protect, and they’re making greater use of cloud platforms and third-party software vendors. As businesses grow, their attack surfaces tend to grow with them, which creates more opportunities for threat actors.
Michael Lucas: I agree. For years, companies approached defense by bringing everything inside their network and building strong perimeter defenses. But that perimeter is disappearing. Our clients’ networks are now a mashup of internal infrastructure and cloud providers, and many employees can operate with an internet connection that gives them access to all the resources they need. As a result, to Josh’s point, their environments are more complex, and the attack surface is bigger.
Josh Reid: Over the past several years, we’ve also witnessed an evolution in the role of the CISO. The fairly recent emergence of the term “CISO 2.0” reflects greater demand for CISOs to understand the business at a much broader, strategic level. Boards and C-suite leaders expect CISOs to serve in an advisory role and help leadership factor cyber risk into strategic decisions, such as mergers and acquisitions, expansion into new regions, and bringing new products and services to market. Cyber risk plays a significant role in all of those decisions.
Michael Lucas: Another development that is top of mind for me is the California Consumer Privacy Act of 2018 that, beginning on Jan. 1, 2026, requires companies subject to that law to evaluate their cybersecurity. We’re seeing more requirements for companies to assess their cybersecurity posture. Europe also has laws, including the European Union’s Digital Operational Resilience Act, that require financial services organizations to strengthen their cyber resilience. As adversaries strengthen their capabilities, regulators are raising the bar as well.
Angie Hipsher-Williams: We’re also encountering a lot of demand tied to Cybersecurity Maturity Model Certification (CMMC) as companies pursue compliance so they can keep contracting with the government. But CMMC is just one example of a broader pattern. Nearly every industry has security and assurance requirements that companies have to meet to keep doing business, especially given the high reliance on third parties. We’re starting to see some movement in the other direction, too. I’m hearing more clients talk about bringing work back in house, largely because third-party risk and trust are harder to manage when threat actors move so fast.
Angie Hipsher-Williams: It’s a combination of things, but here’s an analogy I keep coming back to: If bubble gum gets stuck to your face, the fastest way to get it off is with more bubble gum. I think AI is similar. Everybody’s going to have to fight AI with AI. Practically, that means evaluating which tools can keep pace, helping clients implement those tools, and making sure they integrate cleanly with the rest of their environment. None of the fundamentals go away. The difference is the speed at which organizations can execute those fundamentals, and fighting technology with technology seems like the way forward.
Michael Lucas: The answer could be simpler than we think. To me, it starts where it always has: assessing where organizations are from a cyber posture standpoint, building road maps for improvement, monitoring and managing risk, and improving risk reporting and visibility. The classic, day-to-day work remains the foundation of cyber readiness and resilience and, quite literally, it’s the goal of all our client engagements. We need to continue improving how we help clients prepare for AI-enabled threat actors, but much of the answer lies in doing the fundamental work we’re already doing and helping our clients advance their cyber programs.
Josh Reid: I was on a recent cyberthreat briefing with one of our banking clients, and we discussed several of the areas you mentioned, Michael. One item involved defining the right cyber metrics, specifically key risk indicators (KRIs) that align with the overall business strategy. Organizations need to determine where they need to raise the bar. Updating KRI metrics to account for emerging AI threats can help build alignment and understanding across leadership.
Michael Lucas: That is critical, Josh. The bar must keep getting higher. The fundamentals remain important, but organizations also need to raise their expectations as adversaries expand their capabilities.
Angie Hipsher-Williams: Whatever else changes, I don’t think that we can afford to forget the human element. No matter how advanced the technology gets, someone still has to be in the room at the worst hour of an incident and make the call about whether to pay the ransom, keep systems running or take them down to rebuild clean, or a dozen other calls. A computer’s not going to make those decisions for you.
The question I keep coming back to is: How do we keep our people’s skills sharp? No matter how far AI takes us, we’re always going to need people with the skills and judgment who can make those decisions.