Skill floor, not new capability
The most accurate summary of AI’s effect on offensive security is that it removed the skill floor from things that were already possible. Convincing phishing copy, voice impersonation, and malware variants all existed before. What changed is that producing them at volume no longer requires expertise, time, or budget.
What is operational now
Synthetic voice and video. Voice cloning from a short public sample is cheap and effective. Attacks typically pair it with urgency and authority: a call that sounds like a senior executive requesting an unusual payment. This defeats awareness training that teaches people to scrutinise written messages, because the request never arrives in writing.
Fluent, targeted phishing at scale. The traditional advice to look for poor grammar is now actively misleading. Messages can be personalised using public professional information and written in fluent local idiom.
Faster reconnaissance. Mapping an organisation’s people, technology, and public exposure is significantly quicker with AI assistance, compressing the timeline between an attacker choosing a target and acting on it.
What remains overstated
Fully autonomous AI agents independently breaching well-defended networks are not the realistic current threat. Agentic tooling assists human operators; it does not replace them. Treating speculative autonomy as an immediate risk tends to divert attention from the mundane vectors that actually cause incidents.
Defensive adjustments that work
- Out-of-band verification for financial and access requests, on a channel the requester did not choose
- Process controls that do not depend on recognising a voice or a face
- Awareness training updated to cover voice and video, not only email
- Dual authorisation for high-value transactions, which resists impersonation regardless of quality
Related in the Knowledge Base
- Social Engineering: Why People Remain the Reliable Attack Path
- IAM and PAM: Controlling Who Can Reach What
- AI Governance and Shadow AI: Two Problems That Share a Solution
Know what an attacker sees before they do.
A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.
Free PDF · No spam · Unsubscribe anytime