A new front line star in the AI cybersecurity war


Mustafau | Istock | Getty Images

The stakes have never been higher for senior cybersecurity leaders at top companies.

“It feels like my job has doubled or quadrupled,” said Wally Dalrymple, chief security officer at global education and talent solutions firm ETS.

“It’s coming at us so fast and at such large volumes,” he said.

Artificial intelligence has catapulted the chief information security officer out of the server room and into the boardroom, forcing leaders to address a rapidly changing threat landscape while navigating shifting budgets and business needs.

The July hack by rogue OpenAI autonomous agents on open-source developer platform Hugging Face accelerated the shift and proved that the era of advanced AI hacks had arrived. It also demonstrated the lengths agents will go to accomplish a goal.

In the weeks since, the list of agent-led attacks has swelled, with Reuters reporting Friday that another swarm of OpenAI agents broke containment in May and commandeered a German website.

The startup paused some of its AI research and training after the Hugging Face attack, but the security incidents haven’t stopped OpenAI from releasing new products. The company announced the rollout of its latest GPT-6 Astra model this week despite previously warning of ‘Critical’ cyber capabilities.

And the pace of model releases with specialized cyber features hasn’t slowed, with Google debuting Gemini 3.8 Flash Cyber and Anthropic rolling out Fable 5.1 and Mythos 5.1 this week as well.

“The ground under our feet is shifting,” said Dell security chief John Scimone. “It’s completely changing the variables, the safe assumptions that we’ve been able to rest on for decades.”

“Worth their weight in gold”

There’s one major silver lining to all the added stress: The hiring market is blazing for CISOs with the chops and technical skills to tackle the AI world.

Qualified candidates who check the boxes are easily landing pay packages exceeding seven figures, but recruiters have to move fast, said Michael Piacente, managing partner and cofounder of executive cybersecurity search firm Hitch Partners.

Piacente said his team is often working 18-to-20-hour days, but still losing a candidate a week per search to other offers. He hasn’t seen dynamics comparable to this since the introduction of the cloud.

“It was more of a slow drift,” Piacente said. “It wasn’t everything, all at once together like AI is.”

Barclays' Saket Kalia reacts to Palo Alto Q4 results

“Spidey senses”

The pressure is squarely on CISOs to quickly deploy AI defenses, but urgent demand doesn’t necessarily mean the budgets or tools have caught up.

Cybersecurity budgets are expected to jump 6% in 2026, driven largely by new tools to secure and implement AI, according to Gartner data. In some parts of the world, the spend is higher, with the Middle East and Africa on pace to increase 16% year over year, said IDC analyst Craig Robinson.

Mission-critical sectors like financials, pharmaceuticals, energy and healthcare are scrambling to reinforce cyber defenses before attackers deploy the latest AI tools.

“Some security teams are just so overwhelmed they don’t know where to start, and when it comes to security products, they’re not ready for prime time,” because the technology is so new, said Joe Sullivan, former CISO at Uber and Facebook, who runs a cyber consulting business.

Top cybersecurity vendors have emerged as major winners, with recent earnings from CrowdStrike and Okta showing a surge in demand for AI defense. After languishing in the early part of the year amid broader fears of AI disruption, the stocks have roared back. CrowdStrike and Palo Alto Networks are up about 80% this year, while Okta shares have roughly doubled.

While longstanding all-in-one incumbents are appealing to customers through bundling, there has been an explosion in startups promising to tackle the AI problem.

That’s forcing many CISOs to put their “Spidey senses” to the test to scope out the winners or back several solutions until a clear standout emerges, said Jeremiah Kung, global head of information security at AppLovin.

Dalrymple said the scope of decisions and the pressure to perform have never been more daunting.

“I feel the weight of the world of figuring out how to do it myself,” he said.

AI is compressing the cyberattacker's timeline to be effective: Fortalice Solutions' Theresa Payton
Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *