Key Takeaways
- AI in cybersecurity is accelerating both cyber-attacks and cyber defence.
- Cybercrime has evolved into a service-based ecosystem with specialised attack roles.
- AI tools are making phishing, malware development, and reconnaissance faster and more scalable.
- AI systems are creating new attack surfaces for organizations.
- Security teams must adapt to the speed and complexity of modern threats.
AI in Cybersecurity
“It became much easier to become a cybercriminal, because you don’t have to do all this hacking yourself.” – Geri Revay, Fortinet
Cybercrime has changed dramatically over the past decade. What once required deep technical expertise and extensive preparation can now be carried out through a structured ecosystem of services. Tools, infrastructure, and expertise that were once scarce are now available through underground marketplaces.
In this episode of Shielded: The Last Line of Cyber Defense, Geri Revay from Fortinet, and Haon Park from AIM Intelligence explore how AI in cybersecurity is transforming both cyber attacks and cyber defense.
The conversation reveals how cybercrime has become industrialized, how artificial intelligence is accelerating the pace of attacks, and why the rapid deployment of AI systems is creating entirely new security risks.
Cybercrime Has Become a Supply Chain
Cyber attacks no longer rely on a single individual performing every step of an operation. Instead, the work is divided among specialized actors who focus on different stages of the attack process.
Lower barriers to entry for attackers
Some groups concentrate on gaining access to corporate networks. These initial access brokers sell that access to other attackers. Other groups develop ransomware tools that can be deployed against compromised systems. Some even specialize in negotiating ransom payments.
This division of labor lowers the barrier to entry for cybercriminals. An attacker no longer needs to develop malware, conduct reconnaissance, and manage payment negotiations alone. Each component of the attack chain can be purchased as a service.
The result is a cybercrime ecosystem that operates more like a business supply chain than an isolated hacking operation.
AI is sccelerating the speed of attacks
Artificial Intelligence is adding another layer of acceleration to cybercrime. AI tools allow attackers to generate malware variants, craft phishing emails, and automate reconnaissance faster than ever before. Even tasks that previously required skilled developers can now be assisted by AI driven tools.
How AI benefits defenders
However, AI does not only benefit attackers. Security teams collect enormous volumes of telemetry from networks, endpoints, and cloud infrastructure. AI systems can analyze this data to identify behavioral anomalies and emerging threats.
Over time, this data advantage may strengthen defensive capabilities. The key difference lies in time horizons. Attackers might gain a short-term advantage through speed, while defenders may gain a long-term advantage through data.
Operational Technology Changes the Security Model
Cybersecurity strategies that work in traditional IT environments often do not translate directly into operational technology environments.
Industrial systems control physical infrastructure such as manufacturing equipment, energy systems, and transportation networks. In these environments, availability and safety are often more critical than protecting data.
Many devices remain in operation for decades and cannot be patched frequently. Even routine network scanning can disrupt sensitive systems. Because of these constraints, organizations must rely on alternative security approaches such as monitoring, segmentation, and deception technologies rather than frequent updates.
AI Systems are becoming the next attack surface
The rapid deployment of AI models and agents is introducing a new category of cybersecurity risk. Enterprises are deploying AI powered chatbots, internal assistants, and automated decision systems across their operations. These systems often have access to internal data, workflows, and business processes.
If attackers manipulate inputs or exploit vulnerabilities in these models, they may influence how the system behaves. This could lead to data exposure, operational disruption, or incorrect automated decisions.
Automated AI red teaming
To address these risks, Haon Park’s work focuses on automated AI red teaming. Instead of relying solely on human testers, AI driven attacker agents simulate large numbers of potential attacks to identify vulnerabilities before they are exploited.
When AI moves into the physical world
One of the most significant emerging risks involves AI systems that interact with the physical world. Autonomous vehicles, drones, and robotics rely on multimodal inputs such as images, audio, and sensor data to interpret their environment. If attackers manipulate these signals, they may influence how the system behaves.
Beyond traditional cybersecurity
Unlike traditional cybersecurity incidents, failures in physical AI systems could result in real world consequences. As AI systems move beyond software and into infrastructure, cybersecurity must expand to address risks that affect both digital and physical environments.
Conclusion and the future of AI in cybersecurity
The cybersecurity landscape is evolving in two parallel directions. On one side, cybercrime has become faster and more scalable through specialization and automation. On the other, organizations are deploying new technologies such as AI agents and autonomous systems that introduce entirely new security challenges.
Adapting to modern threats
Defending against these threats requires more than traditional security practices. It requires adapting security strategies to match the speed, scale, and complexity of modern cyber threats. As AI in cybersecurity continues to evolve, organisations must prepare for both the opportunities and risks that artificial intelligence introduces across the threat landscape.
Listen to the full conversation
You can hear the full conversation with Geri Revay and Haon Park on Shielded: The Last Line of Cyber Defense, available now on Apple Podcasts, Spotify, and YouTube.
https://open.spotify.com/episode/018sZwUc9d6FMwMtJDLXX1?si=u8bK_bVHSBiA-G1II6jhCA
https://youtu.be/mx9b9cVwrRY?si=rWl9ruZeMENpTQ1t
If you’d like to learn more about PQShield’s approach to emerging cyber threats and post-quantum security, get in touch with our team.
About the Guests
Geri Revay
Geri Revay is a Principal Security Researcher at Fortinet’s FortiGuard Labs. With more than fifteen years of experience in security research, ethical hacking, malware analysis, and penetration testing, he focuses on threat intelligence and advanced attack techniques that affect enterprises, governments, and critical infrastructure.
Haon Park
Haon Park is Co-Founder and CTO of AIM Intelligence. His work focuses on securing AI agents and enterprise AI systems through automated red teaming, policy driven guardrails, and continuous risk testing across multimodal AI systems.
Frequently Asked Questions
What does ‘AI in cybersecurity’ mean?
AI in cybersecurity refers to the use of artificial intelligence technologies to identify threats, detect anomalies, automate security operations, and improve cyber defense capabilities.
How are cybercriminals using AI?
Cybercriminals use AI to automate phishing campaigns, generate malware variants, improve reconnaissance activities, and increase the speed and scale of attacks.
How does AI help cybersecurity teams?
AI helps security teams analyse large volumes of data, detect unusual behaviour, identify emerging threats, and respond to incidents more efficiently.
Why are AI systems becoming a cybersecurity risk?
AI systems often have access to sensitive business data and workflows. Vulnerabilities within these systems can lead to data exposure, operational disruption, or manipulation of automated decisions.
What is AI red teaming?
AI red teaming involves testing AI systems by simulating attacks and adversarial behaviour to identify weaknesses before malicious actors can exploit them.

