
AI Can't Outrun the Basics, Cyber Officials Warn
Senior officials from the FBI, NSA and allied cyber agencies warned Tuesday that simple cybersecurity failures remain the most consequential threat to organizations, even as artificial intelligence speeds up attacks. The comments came during panels at the Billington Cybersecurity Summit in Washington on September 8, 2026. cybersecuritydive
Key facts
Who said it: Officials from the FBI, NSA, and the national cyber agencies of the UK, Canada and New Zealand
Core message: the same fundamentals that would have stopped yesterday's attacks will stop the next 18 months of attacks cybersecuritydive
The fundamentals: identity management, multifactor authentication, patching, asset inventory, retiring legacy technology
The AI angle: AI is increasing attacker speed and capability, but not changing how attackers get in cybersecuritydive
What to do: Prioritize basic controls before investing in new AI security tooling
What did officials say about AI and cyberattacks?
Jason Bilnoski, a deputy assistant director in the FBI's Cyber Division, told the summit that AI is increasing attacker speed and capability, but the way criminal and nation-state actors compromise organizations has stayed the same. The FBI recently urged organizations to fix basic security failures as part of its Operation Winter Shield campaign, arguing that hardening a core set of top controls would reduce the risk from both criminal and nation-state targeting. cybersecuritydivecybersecuritydive
David Imbordino, director of the NSA's Cybersecurity Directorate, put it bluntly: "The basics are no longer boring." cybersecuritydive
Which security basics matter most?
The officials pointed to a consistent list. Catriona Robinson, head of New Zealand's National Cyber Security Centre, named knowing your assets, getting rid of legacy technology, and speeding up patching cycles as measures that help regardless of the adversary. Multifactor authentication is the practice of requiring a second proof of identity, such as a code or hardware key, beyond a password. The FBI listed it alongside identity management, perimeter monitoring and general cyber hygiene as essential. cybersecuritydivecybersecuritydive
Richard Horne, chief executive of the UK's National Cyber Security Centre, argued AI is effectively exposing organizations that never focused on those fundamentals. cybersecuritydive
Is AI helping attackers at all?
Yes, in specific ways. David Liebenberg, head of nation-state threat tracking at Cisco's Talos Labs, said state-backed groups are using AI to dramatically improve long-running social-engineering attacks — including using AI-generated video to pass job interviews at Fortune 500 companies and defense contractors and actually secure positions. Social engineering is the practice of manipulating people, rather than technology, to gain access. cybersecuritydive
Defenders are gaining too. Rajiv Gupta, head of the Canadian Centre for Cyber Security, said AI has augmented human cybersecurity work by a factor he described in multiples of ten. Imbordino predicted AI would become a game changer for defense, helping analysts cut through volume and noise to find actionable signals faster. cybersecuritydivecybersecuritydive
What should businesses do?
Speakers advised businesses not to let the AI hype cycle distract from cyber hygiene, with Robinson urging organizations to be swift but not hasty in adopting new tools. The practical order of operations: inventory what's on the network, enforce MFA, patch fast, retire what can't be secured — then evaluate AI tooling. cybersecuritydive
Source: Cybersecurity Dive, reporting from the Billington Cybersecurity Summit. See also the FBI's Operation Winter Shield guidance.