If we have selected the wrong experience for you, please change it above.
The importance of artificial intelligence in cyber attacks
Dr. Frank Desiere is CEO of CorTec, where he is also a non-executive director. This dual role shapes his view of governance: he is familiar with operational managerial responsibility but also with the supervisory and monitoring role of a Board of Directors – the interface where effective management is forged. His newsletter and podcast, WE TALK BOARD, are aimed at serving and incoming Board members, Presidents of Boards and senior managers. His focus takes both a Swiss and a European perspective to the effectiveness of Boards, responsible company management, and ongoing training and development of non-executive directors. Alongside his managerial and governance roles, Dr. Desiere gives keynote addresses and delivers executive sessions on governance issues, including as part of Deloitte’s Board Programme. His priority is practical and evidence-based guidance for all those who take on a Board of Directors mandate.
Opens in new window
swissVR Monitor: The uses of artificial intelligence (AI) are expanding, now including the launch of cyber attacks. How has AI changed the nature and frequency of cyber attacks over recent years?
Frank Desiere: I’d describe the role of AI as shifting the economy of a cyber attack. AI reduces the marginal cost of such an attack to almost zero, as it means the brief, research into targets and creation of convincing content can all be automated and scaled up as much as needed. In the past, a cyber attack required a specialised team; now, the skills threshold is much lower.
In terms of the nature of attacks, the shift is probably even more serious. IBM’s “Cost of a Data Breach Report 2025” finds that around 16% of data breaches investigated that year involved attackers using AI, in most cases AI-generated phishing and deepfakes for impersonation purposes. Linguistic errors are no longer a reliable way of detecting attacks, which are now individualised and highly contextualised, and use deepfakes to reproduce CEOs’ voices and appearance convincingly for the purposes of fraud.
The key concern for Boards of Directors is the ever-shorter window between detection of a vulnerability and its exploitation by cyber attackers. This shifts the company’s position from ‘defending its perimeter’ to ‘rapid detection and containment’. Cyber defence is therefore no longer a question simply of having good IT but of resilience – something that is firmly part of the Board’s agenda.
swissVR Monitor: We’re currently at a point of transition from agentic AI to multi-agent AI. What does this technological advance signify for the risk of cyber attack in the future?
Frank Desiere: The distinction is qualitative, not a matter of degree. Generative AI has provided attackers with better tools but left human managers without a defence. And this is exactly where agentic AI is pushing at the boundaries: the AI agent plans, acts, observes and adapts – in most cases without any human intervention at all.
In November 2025, Anthropic demonstrated the new reality when it published details of the first documented – and largely AI-orchestrated – espionage campaign on around 30 targets worldwide. The company estimates this was the work of an actor close to government but that the AI carried out between 80% and 90% of the operation autonomously, with human intervention at only a small number of key points. And this attack took place at machine speed.
Multi-agent systems are now taking this to the next level, using specialist agents to carry out a chain of attacks collaboratively and react to defence in real time. We are moving towards a machine versus machine dynamic in which purely human defences are structurally too slow.
The implications for Boards are that the company’s defences must also be automated and that the agents we currently use, with their rationales, storage capacity and access to tools, are themselves becoming independent targets of attack. This is the downside of any AI-based efficiency measures a Board approves.
swissVR Monitor: Our survey of Swiss Board members demonstrates that only a small minority of companies have a detailed strategy to tackle AI-based cyber attacks. How do you asses the risk to companies that fail to take account of cyber attacks using AI?
Frank Desiere: That risk is considerable – but I want to be clear exactly where it lies. There are two areas of vulnerability. First, if companies do not take account of AI-supported attacks, they are using yesterday’s tools to defend themselves against today’s threats. Signature-based detection is powerless against adaptive malware, and attackers have already industrialised their methods.
The second vulnerability arises within the company itself and is underestimated: companies’ own uncontrolled use of artificial intelligence. The 2025 IBM report found that around one data security breach in five was related to ‘shadow AI’ and that incidents of this kind cost an average of USD 670,000 more to tackle than other kinds of breaches. And 63% of the companies falling victim to this kind of attack had no guidelines on AI governance in place. Here, the risk is not from the criminals behind an attack but from company employees feeding customer data or intellectual property into external AI models.
But I would also like to warn against purely performative action. Not every company needs a free-standing AI cyber strategy document. What is important is that cyber issues are integrated into the company’s existing risk framework and that managing these risks is seen as an issue for the whole company, not just as an IT issue, and is oriented to recognised standards, such as NIST CSF 2.0 or ISO 27001. SMEs are particularly vulnerable: they have fewer resources but are also increasingly at risk through their supply chains, such as in the wake of the European Union’s NIS2 Directive. Companies that delay taking action here risk becoming a case study for the next incident.
swissVR Monitor: So what specific measures should companies take to protect themselves against AI-based cyber attacks?
Frank Desiere: I’d identify five priorities – and I’ll list them in order. First, fight AI with AI. Companies need behaviour- and anomaly-based detection and automatic responses if they are to be able to react at machine speed. IBM reports that organisations already using AI and automation as part of their defence save around USD 1.9 million a year on each incident – and can limit attacks much more quickly.
Second, zero trust and rigorous identity and permissions management, specifically for machine identities and AI agents that increasingly have their own access credentials, is vital. Third, introduce phishing-resistant authentication, such as passkeys, combined with mandatory four-eyes scrutiny and the ability to recall payments and authorisations. Simply having a ‘bad feeling’ is no use when you are up against deepfake CEO fraud: what’s needed is a proper process.
Fourth – and this is often underestimated – human sensitivity needs to be recalibrated. The rule of thumb that typos and linguistic errors are a giveaway of a cyber attack simply won’t work now that notifications are linguistically impeccable. And fifth, basic hygiene remains crucial: patch management, backups that cannot be changed or amended, network segmentation, and an incident response plan that is regularly tested rather than remaining a paper document.
I’d also add two further things at company level: hedging the supply chain and governance of the company’s own AI applications against data leaks and injection of prompts. The order is important here: build resilience first and then add in other measures. Finally, the Board needs to be briefed on the maturity of each one of these aspects, not just on activity.
swissVR Monitor: And what is the role of the Board in ensuring that a company is always up to date with technological trends and that it is prepared for the risks they pose, such as AI-based cyber attacks?
Frank Desiere: Cyber risks and AI risks are matters for the Board, both in law and in practical terms. These risks relate to the non-transferable responsibility of the Board for overall management of the company and to its duty to act with due diligence under Articles 716a and 717 of the Swiss Code of Obligations. Operational implementation can be delegated to management or a CISO; oversight cannot and if the Board fails to fulfil its duties, it is personally liable for any losses under Article 754 of the Code of Obligations. Having D&O insurance does not replace this duty; it makes it a prerequisite.
The Board of Directors does not require extensive technological expertise, but it does need to know enough to ask the right questions and to make well-founded requests of management. It must also ensure that the necessary expertise is available either within the Board or from expert advisers. Specifically, this means: a clear line of responsibility via a Risk Committee or Audit Committee, structured reporting rather than simply listing details of incidents, a tried and tested crisis plan that sets out the specific role of the Board, resources that reflect the company’s appetite for risk, and a keen eye on the regulatory horizon, including revisions to the Swiss Federal Data Protection Act, the impact of NIS2, and the EU’s AI Act.
This is where the vulnerability actually lies. Surveys, including swissVR Monitor, show that a considerable proportion of Boards of Directors are not being briefed regularly on the use and risks of AI. But without such reporting, the Board simply cannot fulfil its duty of oversight.
My principle, both as a CEO and as a Board member, is that our job is not to provide security ourselves but to ensure that the right questions are being asked consistently and that the company tackles cyber resilience as part of its overall resilience plan and not simply as an IT issue. These are exactly the kinds of governance issues I discuss regularly and in detail in my LinkedIn newsletter WE TALK BOARD.