AI Is Accelerating Cyber Risk, but the Fundamentals Still Matter
AI has made cyberattacks faster, cheaper, more scalable, and more convincing than ever before. Sharad Rai, Vice President of Cyber Security Product Management at State Street, explains how CISOs should counter this shift.
AI may be transforming the cybersecurity landscape, but Sharad Rai believes CISOs should be wary of assuming that every AI-enabled threat requires tearing up your defensive playbook.
For Rai, Vice President, Cyber Security Product Management at State Street, the more significant change is how AI alters the economics of existing attacks.
“AI is not inventing new threats,” he says. “It is the same attacks, but the speed, scale, and complexity have increased tremendously.”
Attackers can now develop sophisticated tools faster and at a lower cost, while adapting techniques for different organizations and industries more quickly.
That creates a cybersecurity environment in which established attack methods can be deployed at a pace and scale that would have been unthinkable just a few years ago.
Familiarity Is No Longer Verification
Social engineering, for example, has been around for a long time, but is an area in which the shift is already highly visible.
Conventional phishing awareness has taught employees to look for warning signs like poor grammar or suspicious formatting. Generative AI increasingly removes those obvious indicators.
“Phishing is no longer about identifying bad spelling, bad grammar, or suspicious-looking emails,” Rai says. “Attackers can reproduce the language, tone, and context of a business conversation.”
Combine those capabilities with information available publicly about employees, alongside voice cloning and synthetic video, and impersonation becomes significantly more convincing.
Rai argues that this requires CISOs to rethink how to verify sensitive actions. As a result, high-risk activities such as payment authorization may need independent checks.
“Verification can no longer be based on familiarity. Knowing the person or recognizing their voice is not enough.”
Security culture matters here, too. Employees should feel empowered to slow a process down when something looks unusual, particularly when a request uses urgency to push them toward immediate action.
A few extra minutes spent independently verifying a sensitive request may become an increasingly important security control.
AI Security Is a Supply Chain Challenge
Increasingly, AI and its supply chain are a cause for concern for CISOs.
Rai cautions against thinking about an AI model as a standalone technology that can be secured independently from the rest of the enterprise.
“AI is not one entity or one ‘box’,” he says. “When you bring AI into the organization, it becomes part of the ecosystem.”
Modern AI applications can depend on cloud infrastructure, container images, open-source libraries, APIs, models, enterprise datasets, and data pipelines. Each dependency introduces questions about where components came from, whether they can be trusted, and how securely they interact.
CISOs need visibility into where upstream components come from and controls that prevent untrusted or vulnerable software from moving through development environments.
The objective is not only to protect the organization and the model. It is to establish trust across the ecosystem surrounding it.
Start Governance with Visibility and Ownership
That ecosystem can become difficult to govern quickly, particularly as AI adoption spreads across individual business functions.
Rai suggests CISOs start with a deceptively simple question.
“How many AI models are actually in your organization? Does the CISO know? If not, start from there.”
Organizations should develop an inventory of AI models and use cases, assign clear technical and business ownership, establish what data each system can access, and classify applications according to their risk.
That risk-based approach also helps prevent governance from becoming a barrier to innovation.
“Don’t treat AI with fear,” Rai says.
Not every low-risk experiment should be subjected to months of approval processes. Instead, governance should reflect what an AI system can access and the consequences of what it can do.
This becomes particularly important as organizations move from AI systems that primarily generate information to autonomous agents capable of taking actions.
Apply Familiar Security Principles to AI Agents
One of the key selling points for AI agents is their ability to act with more autonomy than other autonomous systems.
However, that increased autonomy makes the principle of least privilege critical.
Rai argues that organizations should carefully assess which permissions an agent genuinely needs, avoid permanent privileged access where possible, and use just-in-time access for sensitive activities.
He also suggests that separation of duties should also be applied to autonomous systems.
Rai compares the concept with traditional financial controls, where one person may prepare a check, another reviews it, and a third approves it. Giving a single autonomous agent the ability to analyze an event, decide what should happen, and execute a consequential action may create unnecessary risk.
“If agentic AI is too powerful, break it down and segregate it.”
For highly sensitive actions, human oversight may remain essential.
At the same time, AI can help defenders address one of the long-standing challenges inside large enterprises: fragmented security telemetry.
An identity system may identify one unusual event, while an endpoint platform detects another and network infrastructure records something else. Viewed independently, none may look significant. Connected into a single sequence, however, they may reveal an attack.
AI can help security teams correlate those signals and construct a clearer chain of events, giving defenders another tool for operating at the speed increasingly demanded by the threat landscape.
As Rai prepares to join fellow cybersecurity leaders at CISO New York, he is particularly interested in comparing how organizations are addressing AI security, software supply chain risk, and longer-term developments such as quantum computing.
He also wants to understand how approaches differ between large enterprises and smaller organizations.
That exchange is increasingly important because AI security is still evolving. The technology may be changing the speed and scale of cyber risk, but Rai’s perspective suggests that CISOs do not need to abandon the principles that have long underpinned effective security.
The challenge now is applying those fundamentals at a speed that can counter an AI-enabled threat landscape.
__
Join your peers at CISO New York, September 24 to explore how leading CISOs are building practical frameworks for secure AI adoption, balancing innovation with resilience, and redefining what effective cybersecurity leadership looks like in the AI era.

