AI Cuts Cyberattack Times from Months to Minutes
With guest Christopher Hetner, Eleven Canterbury Consultant, Senior Cyber Risk Advisor, and Dan Martin, Eleven Canterbury Program & Relationship Manager
SUMMARY
Three years ago, a sophisticated cyberattack could take months to plan and execute. Today, AI can cut cyberattack time from months to minutes. While attackers have embraced AI at unprecedented speed, many organizations are still relying on cybersecurity strategies and tools designed for a very different threat landscape.
Chris Hetner explains how AI is reshaping both cyberattacks and cyber defense, why cybersecurity has become a boardroom issue, and what executive teams and directors should do differently to prepare for a new era of cyber risk in this episode of Conversations With the Experts.
Drawing on his experience as former Cybersecurity Advisor to the SEC Chair, Cyber Risk Advisor to the National Association of Corporate Directors (NACD), and Chief Cyber Advisor at World Wide Technology, Chris discusses why boards need greater cyber expertise, why automation must become part of modern cyber defense, and how organizations should rethink governance, capital allocation, and enterprise risk in the age of AI-powered attacks.
Topics include:
- How AI is accelerating cyberattacks
- Why many cyber-defense strategies are struggling to keep pace
- What boards and executive teams should be asking about cyber risk
- The role of AI in both cyberattacks and cyber defense
- Supply chain risk and operational resilience
- Why cybersecurity is now a strategic business issue, not just an IT issue
About Conversations With the Experts
Hosted by Dan Martin, Conversations With the Experts features thoughtful discussions with global leaders whose experience is shaping business, technology, law, healthcare, finance, government, and other industries.
TRANSCRIPT
Dan Martin: The topic today is cybersecurity, which has really been in the news recently. My son, a college professor, told me that his learning management system, Canvas, was breached and held up for ransomware. I read about quantum computing maybe messing up encryption.
There is all kinds of activity in the area. Luckily, we have Chris Hetner with us today to talk about cybersecurity. It’s hard to envision someone who is more prepared, more ready, or better for this conversation. Chris is the Cyber Risk Advisor to the NACD, the National Association of Corporate Directors.
He was a former Cybersecurity Advisor to the SEC Chair. He worked at the US Treasury and the Banking Information Infrastructure Committee, and he’s now the Chief Cyber Advisor at Worldwide Technologies. Welcome, Chris.
Chris Hetner: Thank you, Dan.
Dan Martin: Cyber-attacks are everywhere. Have things changed? Are they more active? What’s going on?
Chris Hetner: Well, it’s certainly moving at rapid speed. And, fortunately, with the adoption of artificial intelligence, it has capabilities that bring productivity to the enterprise.
It has the ability to sort through copious amounts of data in a very efficient way. It adds value in terms of expediting any type of research related to cancer treatment drugs, and it just creates an incredible capability. But the other side of the coin is that it could be used for nefarious means.
So, with that, the deployment of these frontier AI models, including Mythos as an example, has now compressed the timeline for an adversary to execute a cyber-attack using the tools at their disposal. Dating back three years, it would typically take three to four months between an adversary identifying their target, exfiltrating data, hiding their tracks, and then the cyber-attack being complete.
Now, that compression timeline is down to minutes. So, as a community, we are still operating with the tooling and risk management capabilities, including our technology, that were addressing the cyber issues or threats from 20 years ago. And that not only addresses the day-to-day operational layer but also our ability to govern these advancements at the enterprise risk and board levels.
So, we have to really think about retooling ourselves to deal with the current and the emerging acceleration of these artificial intelligence-empowered platforms that, quite frankly, are in the hands of the adversary, whether it be a nation state or a criminal syndicate or just any individual rogue person that’s looking to do harm to gain illicit financial returns.
We’re really at a pivot point here, where we need to evaluate our ability to address the emergence of these advanced technologies and how that deals with day-to-day operations all the way up to the boardroom. But the short answer is, that was the long answer, the short answer is that our backs are against the wall, and it’s time to reevaluate and retool for speed.
Dan Martin: So, there are really new approaches from our adversaries that have very powerful tools, and if we don’t change, it’s like ignoring the invention of drones on the battlefield, right? The playing field and the rules have all changed. How do you keep up? What do you do if you’re in charge of protecting a large organization? What are the best steps?
Chris Hetner: Well, this is an opportunity to kind of take a pause on the deployment of AI throughout the enterprise. Again, a ton of value has been realized, and boards of directors are being pressured by the investor community to deploy artificial intelligence. That’s getting pushed down to the CEO. The CEO now pushes that down to the technology teams, and they’re ill-prepared to govern these automated capabilities.
So now is the time to reevaluate: why are we doing this? Why are we pursuing artificial intelligence from an adoption perspective? What problems are we trying to solve for? What types of gains are we going to realize from a corporation perspective? And then on the adversarial side, it’s evaluating the threats that are most likely going to impact our financial condition, our ability to operate as a business, our operational resiliency, evaluating our supply chain exposure, because a lot of our suppliers now have this exposure as well, and then resetting the tools to make sure that we’re creating automated capabilities to combat these automated attacks.
So right now, we have automated agents augmenting attacks delivered to the corporation, but our tooling and capabilities are still a very manual process. So the way to combat that is to evaluate the exposure across the enterprise. You know, it sounds cliché, but where are our key assets? Where are our crown jewels? Where are our most heavily exposed suppliers that can really bring down our business if they’re unavailable? And then what type of tooling capability do we have to combat that threat? And like I said, unfortunately, we’re still dealing with the tooling that was addressing the threats 20 years ago.
So now it’s time to revamp for automation. And what we’re going to see now and in the near future is almost an agentic layer of cyber defense to address the automation speed of the agentic attack. And obviously, as an operator, ensure that you have that candid, transparent conversation with the executive suite and the board of directors to ensure that the right level of capital and resources are allocated to defend against these exposures.
Dan Martin: It seems like doing this is a bit like an investment in infrastructure that you need to have a secure operation. And the thing that interests me is that I have a background in IT, and you would often hear from business that they thought of infrastructure or IT as overhead, or just plumbing. But, from personal experience, a plumbing disaster can be messy. I think you’re saying it’s really important for boards and senior executive management to take this seriously. It’s protecting the company’s assets. What is reasonable? How do these people, the management and the executives, get educated to take reasonable defense? And do they know what reasonable is?
Chris Hetner: That’s a great question, and, you know, we as a cybersecurity community need to really level up our communications with the executive management teams and the boards to make sure that we contextualize these threats to business operational and financial exposure.
At the board level, we’re also talking about fiduciary responsibility, accountability of support. Now, one could argue: do we have the right level of expertise in the C-suite and the board? That’s a question that we should ask ourselves. Do we have a cyber expert? Do we have an AI expert? Do we have a technology individual that sits on the board? That’s a question that needs to be asked amongst us as a boardroom community. But further to that, are we delivering the right level of visibility to the C-suite and board so they have transparency into how these threats can manifest, how they can disrupt our business motion, and what we are doing about them? Do we have the right capital deployment?
So I would start looking at evaluating that effectiveness and skill set in the boardroom and the C-suite. If there’s a glaring gap, a decision needs to be made whether to hire a dedicated technologist to the board. And if that’s not a decision point that’s willing to be made, then perhaps you have a suite of advisors.
This is a lot of the work we do with the NACD, the NASDAQ Center for Board Excellence, and Worldwide Technology. We offer our boards very targeted, precise, and efficient access to cyber and AI experts to deliver insights and to provide an independent view of whether they have the right defenses. They work with the management teams, whether it be the CISO, the CIO, the CTO, to engage with enterprise risk management so that you have not only that top-down view, but you have that bottom-up view that everyone’s on the same page.
Let’s say you have a $100 million cybersecurity budget. The question is: Are we allocating that capital effectively? And I will tell you, working with thousands of board members and technologists in the cybersecurity community, there’s an opportunity to reset that capital allocation to now address the need for speed.
Dan Martin: Speed is one of the key things that’s happening now. The threats are more frequent and faster. It takes time to react. And you mentioned being controlled by AI agents. It would seem to me that there are risks of your own AI agents not being perfect or doing something wrong, too. Is there a way to get a handle on your side as well?
Chris Hetner: Well, you know, like I said, the investor community is really mandating everyone to adopt some type of AI, right? Whether you’re a technology company, whether you’re in the industrial space for manufacturing, we’re all adopting AI at extreme speed.
And, we had a summit through the NACD last fall where we had a couple roundtables with CEO and boards members, and it’s all top priority. The analogy I use is we’re in this motion where we’re shooting first, aiming second, and so we’re entering into an AI minefield where we’re deploying these agents to automate various processes, whether it be, onboarding new clients, ingesting data about insurance claims, whatever it may be.
Great efficiency, right? I can reduce potentially 70% manual labor to do this in a very efficient way. But I argue that do we have the right safeguards and controls to monitor the agent? And so there’s always a human in the loop that requires governance. There’s a governance and risk management body that should be required and mandated to understand where are our agents, right?
How many agents do we have? Do we have five? Do we have 10? Do we have 100? What task are they performing? No different than a human would have a task. So, think about the agent as an employee of the company, and then you manage that risk through the lens of potential agent failure. No different than if we have human failure.
And that becomes a layer of governance and risk management that should be, again, top-down, bottom-up. But the way to manage the day-to-day operations of the agents is to really have an agent. So, it’s almost agents monitoring agents. We’re almost entering into The Terminator, right? But that’s really the only way.
Obviously, we need a human in the loop, but the human can’t keep up with the speed of the agent. And so you need an agent to monitor the agent to ensure that they’re performing their set tasks, and if there is, for instance, any leakage of data or a process has gone sideways in terms of transacting and reconciling funds, that there’s that agentic capability in the loop that can stop it, or at least alert somebody that, “Hey, by the way, this agent just released ten million records. I think we should stop the bleeding.”
We live in interesting times, and it’s going to be challenging to keep ahead and keep control and, keep monitoring. But it seems to me that what you’ve said is it’s really important that this be treated as a strategic part of the business, be given the proper attention, and be viewed as, how do we deploy our capital to control and manage the risk?
Well, what an interesting conversation, Chris. I can see us coming back in probably a short time as more things and more threats come about. I’d love to talk to you sometime about quantum computing and encryption. But thank you for your time today.
Thank you, Dan. It’s always great to have a conversation with you.