accelerating established techniques rather than creating entirely new forms of attack.
Chib said:“ We’ re seeing threat actors lean on AI and automation to move faster, speeding up reconnaissance, churning out convincing phishing content, and streamlining their operational workflows. The techniques themselves are still mostly familiar; what’ s changed is how little time and skill it now takes to pull them off.
“ The good news is defenders aren’ t standing still either. At Sophos, we’ re building what we call an agentic SOC, where AI and human expertise work as one, not AI replacing analysts, but accelerating them. It’ s a human-on-the-loop, human-in-the-loop model: AI handles the high-volume, well-bounded work where speed is everything, while experienced analysts step in for the moments that actually need judgment novel attack patterns, high-stakes calls, the cases where business context matters. That combination, AI doing the heavy lifting on speed, humans owning the accountability is what real cyber resilience looks like going forward.”
Shaju sees signs of AI moving further into the ransomware lifecycle.
“ Artificial Intelligence is acting as both a scale multiplier and an enabler of threat vectors, Trellix Advanced Research Center tracks ransomware actors actively using generative AI for automated code translation, malware debugging, and scaling targeted phishing across localised languages. Beyond social engineering, the emergence of fully AIgenerated ransomware strains and LLM-driven infostealers has drastically compressed defender timelines, allowing threat actors to generate functional exploits for newly disclosed vulnerabilities in as little as 10 to 15 minutes.”
Resilience becomes the CISO priority
As attacker timelines shrink, prevention alone is becoming an increasingly fragile security strategy. CISOs must assume that some controls will eventually fail and concentrate on limiting how far attackers can move and how quickly the organisation can recover.
Haber said:“ Protect privileged identities and eliminate unnecessary privileges assigned to all identities( human, machine, and AI) throughout an organisation. Ransomware becomes exponentially more damaging once threat actors obtain administrative credentials. Organisations should reduce standing privilege, adopt just in time access, protect privileged sessions, and continuously identify excessive or toxic privilege combinations that could allow lateral movement.”
Chib said:“ Prevention alone is no longer a viable strategy. CISOs need to plan for resilience instead: the ability to absorb a hit and keep operating. Sophos’ s State of Ransomware 2026 report backs this shift: 56 % of attacks still succeeded in encrypting data this past year, and average recovery costs climbed to $ 1.7 million per incident.”
For Chib, identity must become a core security control, encompassing human and non-human credentials, phishing-resistant MFA and stronger protection for VPNs and administration portals. Internet-facing systems also require rigorous patching, while firewall, endpoint and identity telemetry must feed into XDR or MDR
Identity requires the same urgency, with phishing-resistant MFA extending to staff and third parties, alongside token binding, continuous access evaluation and tested session revocation. Organisations also need complete inventories of Internetfacing appliances and emergency change processes capable of operating in hours rather than days. environments capable of detecting lateral movement before encryption begins.
Milenkovic similarly argues that enterprises need to rethink the speed of remediation. Automated patching should become the default wherever possible, supported by staged rollouts and canary groups. Where infrastructure cannot absorb a patch quickly enough, mitigations such as virtual patching, segmentation and restricted administration paths should be deployed instead.
Identity requires the same urgency, with phishingresistant MFA extending
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 39