In this session, attendees explored how cyber threats are evolving, the financial and legal considerations organizations must navigate, and practical strategies for strengthening cybersecurity, governance and incident preparedness. Drawing on perspectives from cyber insurance, incident response and privacy law, the discussion highlighted the growing complexity of today’s cyber risk environment.
Passcode: Cyberdeepfake26!
Cyber Risks Are Evolving Faster Than Ever
While ransomware, phishing and business email compromise remain among the most common cyber threats, attackers are using AI to make these tactics faster, more scalable and increasingly difficult to detect.
Key trends:
- Increased use of identity-based attacks and stolen credentials
- Greater legal and regulatory exposure following cyber incidents
- Expanded risk through vendors and third-party relationships
AI Is Reshaping the Threat Landscape
AI is lowering barriers to entry for cybercriminals while enhancing traditional attack methods.
Emerging concerns:
- More convincing phishing and impersonation attacks
- Faster development of malicious tools
- Increased use of AI to analyze stolen data
- Growing risks associated with “Shadow AI,” or unauthorized AI tools
Deepfakes and Social Engineering Are Creating New Challenges
Deepfakes and AI-driven social engineering are creating new challenges for organizations of all sizes. Attendees observed a live deepfake demonstration that illustrated how convincing these impersonations have become and why traditional verification methods may no longer be enough.
Common warning signs:
- Urgent requests requiring immediate action
- Changes to payment instructions
- Requests to bypass established procedures
- Communications that encourage secrecy or confidentiality
Building Cyber Resilience
Although the threat landscape continues to evolve, many effective risk management practices remain unchanged.
Key focus areas:
- Identity and access management
- Employee awareness training
- Formalized policies and procedures
- Cyber tabletop exercises and incident response planning
- Vendor risk management
Key Takeaway
Technology plays a critical role in cybersecurity, but resilience ultimately depends on people, processes and governance. Organizations that invest in employee awareness, strengthen internal controls and consistently enforce policies are better positioned to manage risk and respond effectively as threats continue to evolve.