Amid AI hype, cyber officials urge focus on ‘fundamentals’ | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


While artificial intelligence fears continue to dominate headlines, government cybersecurity leaders say organizations should focus on foundational security practices to manage AI risks, rather than chasing new tools and technologies.

Top cyber officials, speaking at the Billington Cybersecurity Summit last week, emphasized how AI hasn’t necessarily created new cybersecurity challenges. Rather, the technology has accelerated age-old challenges like software patching and vulnerability remediation.

“What it’s done is it’s dragged to the surface problems that have been latent in this space for decades,” National Cyber Director Sean Cairncross said Thursday. “There’s been under-resourcing and de-prioritization of basic cyber hygiene and cybersecurity. You don’t necessarily need the newest, sexiest tool. You need to clean up the basics in a lot of these enterprises, and so that needs to be raised to the top of the chain in everyone’s organization.”

While AI is quickening the pace and scale of cyber attacks in some cases, leaders say hackers continue to find success targeting basic weaknesses in critical networks.

“As much as we talk about evolving and sophisticated attacks, much of what we see is really foundational,” Andrew McClure, director of the Energy Department’s Office of Cybersecurity, Energy Security and Emergency Response (CESER), said at Billington. “The ability to defend against what are rudimentary attacks, rotating default passwords, disconnecting your OT systems from your IT systems. Those are problems that fundamentally have been solved from a technology perspective, and it’s around people and process to help implement.”

Frontier AI models have advanced rapidly over the past 18 months in their ability to find and exploit cyber vulnerabilities. Frontier AI labs have been working with government agencies and industry on vulnerability clearinghouses to address AI-discovered bugs and exploits.

But Rajiv Gupta, head of the Canadian Centre for Cyber Security, said that presents “an amazing opportunity for us to deploy those same offensive tools to scan our own networks to understand the basics, to understand the gaps.”

“Organizations have been patching only the most critical vulnerabilities because that’s what they can afford to do, and then leaving the others sitting there as debt that’s been accumulating for decades at this point in time,” Gupta said. “How do we actually take advantage of those similar, offensive … AI capabilities to make sure that the basics are done, and that the risks of the gaps in the basics are really clearly articulated, so that organizations focus on it.”

While cyber leaders say defensive AI and automation are needed to keep up with attackers, they warned against the urge to believe AI agents can simply be deployed to solve an organization’s cybersecurity weaknesses.

“We all better understand the fundamentals, such that when we do employ agentic-based capabilities, we understand the constraint model, we understand the modifications, we understand the second- and third-order impacts,” Army Lt. Gen. Paul Stanton, director of the Defense Information Systems Agency, said at Billington. “Let me be clear: we must automate. We must use agentic capabilities, but we have to set the conditions ahead of time. And if you don’t have the fundamentals, go back to your self-study, your self-improvement to make sure that you do.”

Leaders emphasized that cyber standards are crucial to also securing the use of AI across enterprises. Stephanie Crowe, head of the Australian Cyber Security Centre within the Australian Signals Directorate, said AI models need to be deployed with specific security harnesses.

“We are having a lot of conversations around, how do we make sure that those standards are really clear? How do we encourage safe and secure adoption of AI for those purposes?” Crowe said. “But again, going back to network owners, the basics are the way that you stop some of those unintended consequences [from] emerging.”

Staying ahead of AI-enabled cyber risk will require organizations to “be swift but not hasty,” Catriona Robinson, deputy director-general for cyber security, at New Zealand’s National Cyber Security Centre.

“Resist the breathless rush to grab the sexy, new tools,” Robinson said. “Think about your own business, the outcomes you need to achieve, and the tools that you can use to achieve those outcomes. Resist the thoughtless assumption that inputs equals outcomes. Don’t talk about how many tokens you’ve spent, how many millions of dollars you’re going to need to blow. Think about what the task is in front of you, and your technical leaders can help you with that. And then where to go to get tools to achieve the outcome that you’re looking for.”

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.