Cybersecurity Experts Warn of AI-Powered Attacks, But Miss a Crucial Point
In a recent open letter signed by over 100 technology companies, including OpenAI, Anthropic, Microsoft, and Google, the warning was clear: artificial intelligence (AI) is about to make sophisticated cyberattacks cheaper and more common. The signatories urged that we have a limited window to strengthen our defenses before it’s too late. However, in their haste to sound the alarm, they missed a crucial point – who exactly will be doing the attacking?
The threat of AI-powered attacks is not hypothetical. In August, five US federal agencies documented threat actors using AI-generated exploitation scripts against exposed Siemens S7 controllers, which are used in critical infrastructure such as water treatment plants and power stations. These tools can disguise themselves as legitimate monitoring software, making it easier for attackers to gain access to vulnerable systems. The good news is that this type of attack requires specialist knowledge, but the bad news is that the moat around many small utilities has been drained, leaving them exposed.
The letter’s authors are correct in highlighting the threat posed by AI-powered attacks. However, they seem to be underestimating the ingenuity and adaptability of attackers. According to a recent assessment by RUSI, Britain’s oldest defense think tank, “criminal innovation is a response to a revenue stream closing, not to a new technology opening a window.” In other words, threat actors are focused on what pays, rather than what impresses. They are curious about money, and will adapt their tactics accordingly.
The recent water-sector campaign, which was documented by the US federal agencies, is a prime example of this. Rather than being a sophisticated AI-powered attack, it appears to be reconnaissance and pre-positioning, with attackers using patient staging and old misconfiguration techniques to gain access to vulnerable systems. This is not about exploiting new vulnerabilities, but rather about exploiting existing weaknesses.
So what does this mean for defenders? The plan outlined in the letter is vague on specifics, but emphasizes the need to strengthen our defenses and raise the bar on what we buy, build, and deploy. However, the evidence points to a more fundamental issue – the lack of trained operators who can effectively defend against these attacks. The assignment does not specify who will be performing these tasks, nor does it acknowledge that every recommendation is a verb performed by a person.
The gulf between defenders who have the resources to implement effective security measures and those who do not is measured in people, not products. Consider the defenders named as most exposed: hospitals, water utilities, and small operators of critical infrastructure. Their single most effective mitigation – taking Internet-facing controllers off the Internet – may be unglamorous, but it’s a task that requires trained personnel to perform.
In conclusion, while the letter highlights the threat posed by AI-powered attacks, it fails to acknowledge the crucial role of human operators in defending against these threats. To truly strengthen our defenses, we need to focus on building capacity and training more security professionals, rather than relying solely on products and technologies. As the RUSI assessment noted, “it’s not about what impresses, but what pays.” By prioritizing people over products, we can bridge the gulf between defenders and attackers, and stay ahead of the threat.
Source: Dark Reading — 2026-09-03