Closing the capability gap: Cybersecurity in the age of AI-powered adversaries

2026-06-22

Never bring a knife to a gunfight. AI just gave cybercriminals a cannon. Here's how to fight back.

...

Let's be real. If a nation-state actor wanted to breach your network, they probably could. Very few organisations have the resources to keep an attacker of that calibre out.

This is an uncomfortable starting point but one that reveals something fundamental about cybersecurity: at its core, cybersecurity is a contest of capability, and you cannot consistently defend against adversaries whose resources and capabilities vastly outweigh your own.

What's changed and what should genuinely worry you is who now counts as that kind of adversary.

AI didn't create new threats. It multiplied existing ones.

AI has fundamentally changed the threat landscape by serving as a force multiplier for cybercriminals. Actors once considered low-skill nuisances can now use AI chatbots and agents to carry out sophisticated attacks that previously required far greater expertise and resources.

The bar for technical skill has collapsed, and you do not need to look far for evidence of how rapidly frontier AI capability is advancing in this space. In June 2026, Anthropic was forced to pull two of its most advanced models, Fable 5 and Mythos 5, offline just days after launch after the US government issued an export control directive citing national security concerns.

This policy response reveals just how powerful AI systems have become in finding and exploiting software flaws and is backed up by the numbers: CVE disclosures have nearly doubled since AI chatbots went mainstream in 2022, from just over 25,000 published to over 48,000 in 2025, and 2026 is on pace to push past 50,000.

As vulnerabilities are discovered faster and in greater numbers, every organisation's attack surface is expanding—along with their risk exposure.

On the human side, phishing is becoming more personal. AI has made it trivial to craft hyper-personalised phishing emails that read like they were written by someone who actually knows the target. Even the best mail filters are not foolproof, and the economics favour the attackers who only need one person to click once whereas defenders need to avoid clicking every single time.

How do we close the capability gap?

To answer this, we must acknowledge a harsh baseline: cybersecurity teams already felt outgunned before AI came into the picture. High stress levels, complex operating environments, and chronic under-resourcing have been longstanding problems within the profession. Whilst AI did not create that pressure, it is definitely intensifying it.

But it is not all doom and gloom.

At a strategic level, defence in depth matters more now than ever before. It demands deeply integrated controls that bridge people, process, and technology. While existing tools remain valuable, their true power is unlocked when combined into a broader ecosystem. Automation is vital to manage the growing volume and complexity of cyber threats.

In practice this means:

  • Patch faster. Monthly or quarterly patching cycles are a liability now — exploits get built faster than these windows allow. Aim for fortnightly at minimum, with continuous patching as the goal.
  • Train like it's real, because it is.Annual tick-box awareness training does not cut it against AI-crafted phishing. Run continuous, scenario-based training, and simulate AI-generated phishing internally so your people build real muscle memory, not just compliance records.
  • Deploy MFA, full stop. If you have not rolled out multi-factor authentication across the board yet, this is still one of the highest-ROI controls available to you. There's no good reason left to wait.
  • Lock down what you feed your LLMs. Anything sensitive that goes into a chatbot prompt can come back to bite you. Put data-loss prevention controls in place and train staff not to upload sensitive information into AI tools, internal or otherwise.
  • Audit your third parties. Your security programme is only as strong as your weakest supplier. Vendor risk assessments are not optional anymore — they are load-bearing.

As for AI, with the right data and context, it is arguably more powerful for defenders. At the most basic level, security teams can offload the analytical grind of log analysis and threat hunting processes which are slow and error-prone for humans but exactly what AI is good at. It goes further than that: many vendors have already built AI into their platforms, helping shift detection away from static, signature-based approaches toward something far more dynamic and adaptive.

Lastly, none of this works in the long run without policy underpinning it. Policies are the centrepiece of any cybersecurity strategy — they set the baseline expectations that every control, every training programme, and every audit is measured against. Get the fundamentals right, keep them current, and the rest of the programme has something solid to stand on.

The capability gap is real, and AI has widened it, but it can be closed. The key is not reinventing the wheel, but applying stricter discipline in operating the controls you already have, augmented by AI to navigate the new reality.

AI has widened the capability gap.

Closing it takes more than tools — it takes strategy. That's what a vCISO is for. Book a free security consultation

Get started