Cyberattacks are becoming increasingly sophisticated and automated, testing an organization’s security maturity like never before. To stay ahead of these emerging threats, it’s essential to treat resilience as a dynamic operational objective that requires constant attention.
Artificial Intelligence (AI) is playing a significant role in the evolution of cyberattacks. AI-powered tools are automating key components of the attack chain, such as reconnaissance and vulnerability scanning, allowing attackers to compress time-to-exploit from days to mere hours. This means phishing emails will become more convincing, voice and video deepfakes will be harder to distinguish from real conversations, and synthetic identities built on stolen information will be increasingly difficult to detect.
The use of AI-generated deepfakes is already a reality, as seen in May 2026 when scammers used such technology to impersonate Singapore’s prime minister during a Zoom meeting, defrauding a business professional SGD 4.9 million. To mitigate AI-driven attacks, organizations must take stock of their existing security tools and consider replacing those that can’t keep pace with the evolving threat landscape. Implementing AI-based detection capabilities that catch anomalies early on is crucial, as is strengthening incident management to address attacks before they cause significant damage.
Another area of concern is third-party and supply chain risks. A typical organization relies on a complex web of vendors, cloud providers, and partners, creating a potential domino effect in the event of a breach. Attackers often hide behind backdoors in vendor software or exploit unmanaged apps and APIs, which can have devastating consequences for both the primary organization and its larger supply network. For example, a cyberattack on Australian manufacturer Mackay Sugar forced 1,300 farms to pause harvesting after shutting down two mills.
To address these risks, organizations must prioritize transparency and continuous monitoring of their vendor relationships. Building a vendor ranking scorecard based on data sensitivity is essential, as is prioritizing security resources for high-risk vendors with the most necessary access privileges. Insisting on robust security-centric contracts and hard metrics that track third-party risk exposure is also critical.
Furthermore, organizations should be aware of the emerging threat of quantum computing. While capable of breaking widely used public-key encryption like RSA and ECC are still years away, the “Harvest Now, Decrypt Later” (HNDL) risk with long-lived data such as health records, financial information, and intellectual property is a pressing concern. Preparing for this scenario requires immediate attention, as post-quantum cryptography migration will take 5-7 years for small enterprises and 12-15+ years for large organizations.
Given the long timeframe for migration, it’s essential for organizations with sensitive data to plan their transition to post-quantum cryptography immediately. Mapping how and where encryption is used across the business and preparing a phased roadmap for migrating to quantum-resistant cryptography is crucial.
Lastly, geopolitical tensions are increasingly threatening critical infrastructure in energy, transport, and finance. Nation-states and their proxies are targeting industrial control systems, not just conventional IT networks. In 2026, Iran-affiliated hackers hit U.S. energy, water, and government infrastructure, highlighting the need for organizations to prioritize resilience and preparedness.
In conclusion, staying ahead of emerging cyber threats requires a proactive approach that prioritizes resilience as an operational objective in constant flux. Organizations must address AI-driven attacks by implementing AI-based detection capabilities and strengthening incident management. They should also focus on vendor and supply chain oversight, building robust security-centric contracts, and tracking third-party risk exposure. Finally, they should prepare for the post-quantum cryptography migration by mapping their encryption usage and creating a phased roadmap for transitioning to quantum-resistant cryptography.
Source: SecurityWeek — 2026-09-29