Nobody's sending out a press
release about it. There's no big rebrand, no splashy announcement that
"we've overhauled our security posture for the AI era." But talk to
enough CISOs and security directors at mid-size US companies right now, and
you'll notice the same thing happening underneath the surface: budgets are
shifting, training programs are getting rewritten, and old verification habits
are quietly being replaced with new ones.
This isn't a response to some
single dramatic breach. It's a slower, steadier reaction to a threat landscape
that's changed shape faster than most security teams' documentation has kept up
with.
The old playbook assumed a
human on the other end
Traditional security training
spent years teaching employees to spot phishing emails by them tells — awkward
grammar, mismatched logos, a sender address that's almost right but not quite.
That training is losing relevance fast, because generative AI has removed most
of those tells. A phishing email written by a language model doesn't have
typos. A voice message asking someone to authorize a wire transfer doesn't
sound robotic anymore — it sounds exactly like the CFO, because in a growing
number of documented cases, it was built from a few seconds of real audio of
that person.
The World Economic Forum's
analysis of the deepfake threat landscape lays this out clearly: voice cloning that once
required minutes of source audio now works from a handful of seconds,
and convincing video impersonations can be produced with freely available tools
in under an hour. That's not a future risk. It's already shown up in real
incident reports involving finance teams wiring money after what looked and
sounded like a legitimate executive request.
What "rebuilding"
actually looks like inside a company
It's rarely one big initiative.
It's a handful of smaller, less visible changes stacking up.
Finance teams are adding
out-of-band verification for anything involving a payment or account change —
meaning if a request comes in by email or a video call, someone has to confirm
it through a completely separate channel, like a phone call to a number that
was already on file, not one provided in the message itself. Security awareness
training is shifting away from "spot the fake email" toward
"pause before anything urgent," because urgency, not sloppiness, is
now the biggest tell in an AI-generated scam.
Some organizations are also
rethinking their own AI tools as part of the attack surface, not just as
productivity boosts. That shift reflects a broader concern documented by
Deloitte's research on generative AI risk, which points out that gen AI can be
used to study patterns in an
organization's legitimate communications and produce phishing attempts that
mimic them convincingly — meaning the same technology company
employees use to draft emails faster is available to whoever's trying to
impersonate them.
Why this is happening quietly
instead of loudly
Part of the reason nobody's
making noise about these changes is straightforward: admitting you're
rebuilding your defenses invites the question of what you were defending
against, and few companies want to publicly connect their security overhaul to
a near-miss or an actual incident. There's also a practical reason. Much of
this work is happening inside existing security budgets, folded into normal
update cycles rather than announced as a new initiative, which makes it look
incremental from the outside even when it represents a real shift in
priorities.
There's a technical layer to this
too. NIST's research on adversarial machine learning gives security teams a
shared vocabulary for a threat category that didn't have consistent terminology
a few years ago — attacks that target the AI systems themselves, not just the
humans using them. Their taxonomy covers everything from data poisoning during model
training to prompt injection attacks against deployed generative AI systems,
which matters more every quarter as companies plug AI tools directly into
customer-facing workflows.
The shift that matters most
The companies handling this well
aren't necessarily spending more. They're spending differently — putting money
into identity verification and process redesign rather than just another
detection tool bolted onto the existing stack. Technology alone doesn't catch a
well-executed voice clone. A finance employee who's been trained to hang up and
call back on a known number does.
That's the quiet part of this
rebuild. It's less about new software and more about rebuilding the habits and
verification steps that AI has made obsolete, one workflow at a time.

Comments
Post a Comment