Artificial intelligence, secured with strategy
Generative AI has increased both the frequency and sophistication of cyber threats. (Axios.) Cybercriminals now wield AI to launch faster, smarter and more scalable attacks, without needing deep technical skill.
The question isn’t if AI will be used against you. It’s how prepared you’ll be.
$35 million, one phone call
In 2020, scammers used deepfake audio to impersonate a CEO. The voice was indistinguishable. The wire transfer went through. The money was gone. That’s not a future scenario, it already happened, and the tools to do it are cheaper and better today than five years ago.
The tactic keeps evolving. In one case, an attacker impersonated an IT manager on a phone call, warning a network team: “Pull the plug, we’re being hacked!” Under pressure, the team reset credentials exactly as instructed. Minutes later, the attacker logged in with the very credentials that panic had just created.
Deepfakes don’t just bypass humans. They bypass voice-biometric authentication, video-call verification, and identity controls designed for a pre-AI world. Zero Trust principles, verify explicitly, assume breach, remain the foundation. AI just makes the why louder.
How attackers are using AI today
Three tactics are already in active use, not roadmap, not theory, and cheap to buy: dark-web attack kits start at $50, feeding a $14B cybercrime-as-a-service market that needs no real skill to operate.
Deepfakes at scale
Real-time voice cloning from a 30-second sample, synthetic video calls and fabricated identities bypass biometric and video-call verification built for a pre-AI world.
Weaponised phishing
LLMs scrape LinkedIn, GitHub and breach dumps to write spear-phishing emails indistinguishable from a colleague’s, hitting click-through rates as high as 54%.
Recon, cracking & malware
AI agents map a target’s people and tech stack in minutes, crack 60% of 8-character passwords in under an hour, and drive ransomware that adapts to what it finds.
AI is the new attack surface
Prompt injection, model theft, unauthorised API access, training-data leaks: AI systems bring risks Zero Trust already has an answer for. Most environments we assess show AI deployed without segmentation, models and datasets reachable company-wide, and access controls nobody can clearly explain.
See what AI is actually doing
Full visibility into model usage, data flows and API calls, so shadow AI and unsanctioned agents surface before they become the incident.
Contain what you can’t fully trust
AI systems and the data they touch get the same protect-surface treatment as any other critical asset, isolated, not bolted onto the flat network.
Access on a need-to-know basis
Least-privilege, just-in-time access for every model, agent and integration, so one compromised AI component can’t reach everything else.
Fight fire with fire
AI isn’t only a threat, it’s also how we fight back. Since 2010 we’ve built Zero Trust architectures for a living, AI is now part of that stack, not a bolt-on.
Cut through the noise
AI correlates events across the stack, so real incidents surface first.
Bridge the silos
Security, IT and the business, plus the CFO, CIO and CISO, share one picture of AI risk and opportunity.
“Only 20% of companies feel very prepared to defend against AI-powered cyberattacks, while 56% say generative AI has increased both the frequency and sophistication of cyber threats.”
Accelerate response
Automation shortens the gap between detection and action. See incident response.
Speak business
AI-driven reporting turns technical risk into language a board can act on.
Move with innovation
Zero Trust applied to AI-driven detection and response, backed by continuous team education.
Articles on AI & cybersecurity
Real incidents, real lessons, on how AI is changing both sides of the fight.

Zero Trust for AI Agents
AI agents now outnumber human identities 10:1. Least privilege, just-in-time access and assume-breach keep them from becoming an attacker’s dream infrastructure.

The Modern SOC Was Not Built for AI-Speed Threats
AI-driven attacks now move faster than traditional SOC workflows can follow. Closing that gap takes 24/7 correlation, not another dashboard.

AI Just Found the Bugs. We Just Patched Yours.
When an agentic security model helped disclose real vulnerabilities, every affected ON2IT customer was already patched before the advisory went public.

Your Security Culture Will Fail. That’s Not the Problem.
Security culture always breaks under deadline pressure. The fix isn’t more training, it’s Zero Trust architecture that contains the blast radius when people cut corners.

Cybersecurity in 2025: AI Attacks, Ransomware at Scale, and Board-Level Risk
2026 marks the shift from reactive alert-chasing to preemptive prevention, as AI-powered attacks expose that fundamentals decide who wins.
Map your AI exposure, then close it
A 45-minute AI Readiness session is free, with no commitment to follow up. We look at where AI is in your environment today, where the unmanaged risk sits, and what step makes sense next.