Skip to content

AI Changed the Economics of Attack, Not the Attacks

AI is not creating novel cyberattacks. It is changing the economics of them.

Published:

For most of the last two years, a CISO could treat AI-driven attacks as tomorrow's problem. The demos were impressive, the threat reports were speculative, and the backlog of unpatched systems and unfinished projects felt more urgent than a class of attack nobody had clearly seen yet. That framing collapsed last month. The cyber security agencies of the Five Eyes alliance, the United States, United Kingdom, Canada, Australia, and New Zealand, took the rare step of a joint statement warning that AI is transforming cyber risk on a timeline of months, not years. When five of the world's most capable cyber defense agencies speak with one voice, the message is not that something might happen. It is that the ground has already moved.

The most useful reframing of that warning comes not from the statement itself but from someone living inside it. "These capabilities are not developing novel cyberattacks," says Alfredo Hickman, CISO at Kai and former CISO at Obsidian Security. "They are changing the economics of them." That distinction is the whole argument, and it is more actionable than the headline. The threat is not a wave of exotic new attacks that no defense anticipates. It is the same attacks, made cheaper, faster, and dramatically more scalable.

Welcome to Issue 02 of InfoSec Leadership by InfoSec Relations, featuring Alfredo Hickman. You can also watch our full conversation on the operational realities of defending against AI-driven threats here. Let's get started.

The Threat Isn't New. The Economics Are.

A CISO and former military intelligence officer on how AI rewired the cost of attack, and what that changes for your defense.

The first thing Hickman wants leaders to register is why this particular statement carries weight that most advisories do not. The Five Eyes agencies rarely speak with one voice in public, and when they do, it is a deliberate move to cut past the noise. "This is a joint statement that they use in this forum to really cut through the noise and cut through some of the political posturing," he says, "to warn people that from this very privileged perspective, we see an evolution in the risk and in the threat landscape that is really substantial." The alliance holds intelligence capabilities that no single organization possesses, and it chose to convert part of that assessment into plain, unclassified language aimed at boards and executives rather than the cleared officials who normally receive it.

That choice is the signal. Speaking from over a decade in the military and the defense establishment, where he worked counterterrorism and counterinsurgency before crossing into cyber operations, Hickman reads the statement as a wake-up call that transcends the local politics of any member nation. The agencies do not co-sign a document at director level to repeat what the field already knows. They do it when the pace of change has outrun the channels they normally use to communicate, and they decide to go direct.

Same Attacks, Cheaper and Faster

The heart of the argument is economic, and it reaches everyone. "The economics impact everybody," Hickman says. "From the wealthiest governments and nation states and organizations to everything in between, we all have budgets." He knows the constraint firsthand, because even the military and the intelligence community operate against budgets. What AI does is lower the barrier to entry and broaden the pool of talent that can run a serious cyber operation. The work that once required a small number of very expensive specialists can now be spread across a much wider base.

The effect runs in two directions at once, which is what makes it dangerous. The most proficient operators become more specialized and more strategically leveraged, while the funnel widens to admit people who could never have mounted a full-scale campaign before. "They are reducing the barrier to entry, they are accelerating the velocity, they are amplifying the volume," he says, "and they are making it much more simple to execute full-scale cyberattacks from beginning to end in a much more compressed time cycle than ever before." The disclosure-to-exploitation window shrinks, the volume of credible attackers grows, and the cost of trying collapses. None of it is hypothetical to him. He is blunt that the months-not-years framing was generous, because AI-enabled attacks are already happening in the wild.

Chasing the Frontier Is a Losing Game

The instinct in a moment like this is to buy, and Hickman argues against it. The frontier itself moves too fast to chase. "If you go and speak to the engineers developing the frontier models, they will tell you themselves, we don't know where the tech is going to be in the next 12, 24, 36 months, because it's evolving so rapidly." Chasing the technology is a losing game, because the thing you tool up against will have changed by the time you deploy. The durable move is to anchor on the principles that hold no matter how the landscape shifts.

Those principles are not new, which is precisely the point. Architect for resilience, because attacks and breaches and outages will happen and recovery is the real test. Solve for identity, human and non-human, which matters more in an agentic world than it ever has. And apply zero trust to the new reality that AI systems demand implicit trust to connect, move data, and act. "AI is demanding that we implicitly trust all of these agents and systems to connect and move data and make decisions now," he says, and the answer is to compartmentalize that trust rather than grant it wholesale. The fundamentals that mattered a generation ago matter more now, and pairing them with AI-native capability is what gives a program a real chance in this era.

Train, Retool, and Bring People With You

Asked what a CISO with a short runway should actually do, Hickman sorts it into three buckets, and the first is the one organizations most often skip. Train the workforce. He finds the private sector's neglect of training genuinely strange after a military career built on it. "In the military, when you're not deployed, you are training all the time to develop the education, the skills, the proficiency to be excellent in your work." AI is now disrupting every function, not just engineering, so the workforce across the whole business has to be equipped to use these tools effectively and safely.

The second move is to retool for the era, and he frames it as an industrial transition rather than a product upgrade. Each major economic shift, from agrarian to industrial to information, forced a retooling to match the times, and this is another. "The previous generation of tooling was built for a very different era, and we are in a new era now." Purpose-built, AI-native capability replaces tools designed for a threat model that no longer describes reality.

The third move is engagement, and it is the one that decides whether the first two get funded. Security touches every part of the business, so it has to be built by partnering across all of it. "In the military, we called this by, with, and through, because everything we do is by, with, and through our partners," he says, and that includes leadership and the board. A security program that brings its stakeholders into a shared vision of a secure, viable organization is the one that succeeds.

Boards Care Now. Use That.

Something has changed at the board level, and Hickman finds it striking. For most of his career, boards stayed out of technical procurement decisions. Now they are leaning in, asking directly what the organization is investing in AI and how fast it is moving. The reason is that these systems make decisions with material risk attached, and boards have started to grasp that. "They really care, they want to realize the value from these investments," he says, "but they also understand this is very different, and security and safety are paramount." The opening this creates is rare, and the job is to convert it, matching every dollar of investment in the technology with a dollar of investment in securing it.

The opening is not universal. Many boards still receive all of this as a technical memo, filed and forgotten until an incident makes it real. Human nature treats safety as an afterthought until the moment it stops being one. Some boards are further along, alert to the regulatory exposure now attached to AI systems, and some will wait for their own breach to wake up. The leaders who do the translation work now, turning the Five Eyes assessment into a business conversation, are the ones who will not be waiting.

Don't Outsource Your Judgment

For all the emphasis on adopting AI, Hickman draws a firm line at outsourcing judgment. The search engine changed how we retrieve knowledge, but a human still had to read and make sense of what came back. Generative AI removes that step, and does the thinking too, which is exactly where the risk sits. Models return confident output that is sometimes fabricated, sometimes biased, and sometimes deliberately poisoned. "We must not check our brains," he says. "We must exercise critical thought."

The organizational version of that discipline is a quality-assurance fabric around any AI-fed decision. Data used to drive a choice, whether a human makes it or an agent does, has to be checked for manipulation and error before anyone acts on it. He points to real cases where organizations moved large sums on AI-generated information that turned out to be wrong. As agents begin to act autonomously, that verification layer stops being good hygiene and becomes the thing standing between a bad input and a material loss.

Move Now, or Wait for the Incident

Hickman closes on a historical parallel he has lived through once already. He recalls a forum of nearly a hundred CISOs, split almost evenly. Half saw the shift as inevitable and were moving to get ahead of it. Half wanted to delay, buried in backlog, calling it a fad. "The only historical parallel in my lifetime that is similar to this is when the internet first started to really take off," he says. Plenty of people called that a fad too, sure it would blow over. By the late 1990s nobody was asking the question anymore, because the world had already changed.

That is the assumption to operate on. The shift is here, not coming, and the split among security leaders is really a split between those who act now and those who wait for the incident that forces them to. "For those who can see what's coming, it's obvious," Hickman says. For everyone else, the moment they cannot ignore it is not far off.


CISO Action Plan

The Five Eyes warning sets the timeline, but defense happens inside your own organization. Here are the moves Hickman recommends security leaders should make now, before the incident that forces them.

For the engineering view of the same shift, our Offensive Engineering issue 'Machine-Scale Cloud Security' distills how attacks and defense are now operating at machine speed, from a four-hour advisory-to-exploitation window to the trust gap holding back automated response.


Thank you for reading InfoSec Leadership.

If you found this analysis useful, please subscribe to the InfoSec Leadership newsletter so you never miss an update.

Lead with clarity, defend with purpose.

S Pattnaik Technical Contributor and Volunteer Host

More in InfoSec Leadership

See all

More from S Pattnaik

See all