Identity is the new perimeter: AI-powered cyber threats force CISOs into the boardroom

The gist
Identity has replaced the firewall as the front line against a tidal wave of AI-powered cyber threats, pushing CISOs out of the server room and into the boardroom spotlight.
What to know
- By mid-2026, identity-centric security and advanced behavior analytics are essential for detecting sophisticated threats like impossible travel logins and insider abuse across entire ecosystems.
- AI-driven attacks, including a 17-fold spike in deepfakes and zero-day exploits like React Native’s CVE-2025-11953, have driven a 27% surge in North American cargo theft and forced companies to adopt multi-layered, zero-trust defenses.
- CISOs must now translate cyber risk into boardroom language, balancing ‘acceptable insecurity’ with business strategy as cyber resilience shifts from reactive defense to proactive, organization-wide risk management.
Identity Attacks Go Global
Cybercriminals are exploiting identity at every layer, with sophisticated, regionally specialized attacks—from deepfake scams in Asia to OAuth phishing campaigns in the West—forcing a shift to integrated, behavior-driven defenses.
By late 2025, cybersecurity leaders recognized that defending against sophisticated identity-based threats like those from Scattered Spider demanded a fundamental shift from traditional perimeter defenses to integrated identity frameworks. This approach emphasizes comprehensive identity visibility—discovering and classifying all human, machine, API, AI, and vendor identities across environments—and continuous posture hardening through configuration audits and privilege minimization. Tools leveraging advanced analytics and behavior-based detection, such as Permiso’s P0 Labs with its 1,500+ detection rules, enable organizations to detect anomalies like impossible travel logins and insider abuse by correlating telemetry across endpoint, cloud, SaaS, and identity systems, thus effectively shrinking attack surfaces and thwarting credential compromise.
Financially motivated cyberattacks dominate the threat landscape, accounting for over 90% of daily business attacks by early 2026, with identity-centric methods such as business email compromise (BEC) and social engineering at the forefront. Geographic specialization is evident: Eastern European and Russian actors conduct highly structured ransomware and credential theft campaigns, while West African groups, notably from Nigeria, focus on social engineering scams like BEC. Meanwhile, Southeast Asia faces industrialized long-form scams like 'pig butchering,' which exploit investment fraud through sophisticated identity manipulation, underscoring the evolving complexity and global diversity of identity-based threats.
As 2026 unfolds, identity has emerged as the primary vector for lateral movement within cyberattacks, making trust the new vulnerability in cybersecurity. Attackers increasingly exploit advanced identity-based techniques such as OAuth token phishing—exemplified by ShinyHunters’ campaign impacting over 100 organizations—and zero-day exploits like VMware’s hypervisor breach to bypass perimeter defenses. The blurring of cyber, physical, and geopolitical boundaries, highlighted by incidents like China’s infiltration of UK Prime Ministers’ phones and Russia’s Sandworm attacks on Polish energy facilities, further necessitates integrated identity frameworks that transcend traditional security models.
By mid-2026, the manufacturing sector exemplifies the shift toward identity-driven cyber threats, with credential leaks and sophisticated social engineering tactics such as vishing and executive impersonation surging as primary attack vectors. These identity-based intrusions facilitate business email compromise, invoice redirection, and unauthorized access to supplier portals, amplified by the sector’s complex third-party ecosystems where a single compromised vendor can cascade risk to thousands downstream, as reported by Black Kite. This has driven a strategic pivot from infrastructure-first defenses to integrated identity-centric frameworks that protect not only IT and OT systems but also the human and communication layers critical to supply chain security, while attackers increasingly deploy multi-channel, multi-stage campaigns leveraging leaked credentials, trusted hosting, social media, and dark web marketplaces to maximize infiltration success.
Logistics: Where Digital Meets Physical Risk
AI-powered cargo theft and advanced fraud tactics are exposing systemic gaps in supply chain security, making robust identity verification and multi-layered monitoring essential to safeguard both goods and data.
As supply chains have rapidly digitized, the logistics sector faces escalating cyber risks that blend physical and digital vulnerabilities, demanding multi-layered security strategies. Experts like Mihir Thakar of All Cargo Group emphasize cybersecurity as a critical enabler in technology-driven logistics, where threats now extend beyond financial loss to potentially catastrophic physical outcomes, such as hijacking an oil supertanker’s autopilot system. This complexity necessitates integrated monitoring across container freight stations, warehouses, and global operations to safeguard both assets and data in an increasingly interconnected environment.
The surge in AI-powered cargo theft and fraud has rewritten the rules of supply chain crime, exposing glaring gaps in visibility and law enforcement collaboration. With cargo theft rising 27% in North America in 2024, causing up to $35 billion in losses, companies like Geotab advocate for multi-layered technologies—real-time tracking, AI-driven cameras, and driver verification tools—to detect suspicious activities. However, as Akil Naim and Andre Drotenko highlight, sophisticated criminals now employ hacking, phishing, and strategic intelligence gathering to target vulnerable operators, especially smaller owner-operators lacking cybersecurity resources, underscoring the urgent need for a zero-trust security revolution and smarter AI defenses.
Identity verification emerges as a cornerstone in combating supply chain fraud and cargo theft, with logistics experts stressing the critical importance of authenticating truck drivers and carriers to prevent incidents before law enforcement involvement. Yet, legislation alone falls short; ongoing investments in robust identity verification processes and establishing minimum standards for carrier onboarding—covering identity, equipment, and insurance—are essential to level the playing field and reduce vulnerabilities. This approach combats the prevalent use of unregistered valet tags and credential leaks that enable attackers to infiltrate trusted communication channels, reroute shipments, and propagate breaches across vendor networks.
Human factors and training remain pivotal in securing supply chains amid fast-paced logistics operations where urgency can undermine verification protocols, making social engineering attacks more effective. Frontline staff across procurement, sales, and accounts receivable require continuous education on emerging cyber threats and participation in tabletop exercises that bridge cybersecurity and logistics teams. Additionally, regular penetration testing, vendor cybersecurity assessments, and cultivating relationships with agencies like CISA and the FBI are vital to prepare for and respond to cyber incidents, especially given the trucking industry's often outdated technology stacks and the long-term financial and reputational impacts of cyberattacks.
CISOs Step Into Strategy
CISOs now balance business risk and cyber resilience at the board level, translating complex threats into business language while demanding greater authority and cross-functional collaboration.
By early 2026, the role of the CISO has dramatically evolved from a technical gatekeeper focused on network defense to a strategic leader responsible for protecting organizational credibility, resilience, and even national stability. This expansion requires CISOs to navigate the complex intersection of cybersecurity with geopolitics and economics, demanding fluency in strategic communication and policy engagement beyond traditional IT boundaries. As one source aptly put it, CISOs now safeguard reputation and resilience 'one patch, one policy, one coffee at a time,' underscoring the multifaceted nature of their mission in an AI-driven cyber era.
CISOs are increasingly expected to align cybersecurity initiatives with business risk management by calibrating acceptable levels of insecurity rather than pursuing maximal security, a nuanced approach that requires speaking the language of business—risk tolerance, ROI, and financial impact. However, communicating concepts like 'acceptable insecurity' to boards and legal teams remains challenging, necessitating collaboration with marketing or PR professionals to translate technical risks into business-appropriate narratives. This shift also demands CISOs gain authority comparable to CFOs or CHROs to make decisive risk management decisions, moving beyond being scapegoats in crises to becoming empowered strategic leaders.
The escalating pressures from emerging AI and quantum threats have pushed CISOs toward a collaborative leadership model that engages cross-functional teams, data owners, and executive leadership. This team-based approach emphasizes long-term strategic planning and crypto agility to protect data with enduring value—such as health and financial records—while avoiding knee-jerk investments that could lock organizations into inflexible vendor solutions. As noted, the burden 'cannot solely fall on the CISO,' highlighting the necessity for integrated enterprise resilience rather than isolated cybersecurity efforts.
Boardroom engagement has become a critical arena where CISOs must earn their seat by communicating cybersecurity risks in business terms and aligning with organizational strategy. Building trust with CEOs and CFOs is essential to focus limited board time on pressing risks like AI and supply chain security, with 85% of CEOs recognizing cybersecurity as vital not only for protection but also for growth. Leaders like Robert Herjavec emphasize framing cybersecurity investments as drivers of competitive advantage and customer trust, while Pravin Kumar of NPCI highlights the shift toward impact-focused discussions driven by AI-enabled fraud threats. Ultimately, CISOs are transitioning into strategic business enablers tasked with creating confidence across AI, data, identity, regulation, and business continuity, moving beyond resilience to foundational trust.
AI Arms Race Redefines Security
AI is both escalating attacks and transforming defenses, but the real challenge lies in early detection, crypto agility, and building resilient teams that can adapt to threats faster than adversaries.
By late 2025, AI had become a double-edged sword in cybersecurity, enhancing both defense and offense. Companies like Cisco deployed AI-powered identity intelligence at scale using an 8 billion parameter foundation model serving over 2,000 customers, while startups such as Adaptive Security raised $81 million to combat a 17-fold surge in deepfake attacks. Despite these advances, as David Seidman of Plaid highlighted, the primary bottleneck remained in pre-alert processes, underscoring that AI’s promise in SecOps hinges on improving early detection and triage rather than just alert generation.
The evolving AI-driven threat landscape increasingly exploits supply chains and human trust, complicating defense strategies. The 2026 exploitation of the React Native zero-day (CVE-2025-11953) with a critical CVSS score of 9.8 demonstrated how malicious components infiltrate widely used frameworks, while the $40 million crypto theft from Step Finance revealed that attackers often bypass blockchain security by compromising executives’ devices. This shift from password theft to session and token hijacking demands new mitigations like multi-sig hardware wallets and enhanced email filters to counter sophisticated social engineering and token-based attacks.
As AI threats intertwine with emerging quantum computing risks, cybersecurity demands agile, collaborative, and forward-looking approaches. By early 2026, experts emphasized the urgency of crypto agility—designing cryptographic systems flexible enough to adapt to rapid algorithmic obsolescence—and stressed that the burden of defense cannot rest solely on CISOs but must be a 'team sport' involving executive buy-in and cross-organizational cooperation. Protecting long-lived sensitive data such as health records and financial information is paramount, requiring sustained advocacy to secure budgets for future-proofing defenses against both AI and post-quantum threats.
By mid-2026, AI’s role in cyber offense had become indisputable, with attackers leveraging AI to enhance social engineering and supply chain attacks, prompting the rise of AI-native defense platforms like Doppel that dismantle impersonation and manipulation across channels. However, the complexity of AI-driven risks extends beyond technology to data governance, as Dimitri Sirota pointed out that 'AI risk lives in the data,' not just models or identities, highlighting the critical need for visibility into sensitive data to prevent cascading breaches through third and fourth-party vendors. This evolving threat environment demands integrated risk management strategies that align security, business, policy, and financial considerations, with executive engagement and cyber insurance data playing pivotal roles in driving effective AI security investments.
Resilience: From Defense to Team Sport
Cyber resilience now demands proactive, organization-wide strategies—combining strict tool control, executive buy-in, and adaptive systems—to withstand and recover from inevitable AI-driven and quantum threats.
By late 2025, organizations recognized that building cyber resilience in complex supply chains demands more than reactive defense; it requires strict control over critical tools like Remote Monitoring and Management (RMM) software, enforcing multi-factor authentication, and empowering frontline staff through cross-functional training and tabletop exercises. This human-centric approach addresses vulnerabilities born from urgency and greed in fast-moving logistics environments, emphasizing independent verification channels to thwart social engineering attacks and prevent costly disruptions that ultimately burden consumers.
The $40 million crypto theft at Step Finance in early 2026 underscored the imperative shift from reactive defense to proactive risk management, particularly securing executive endpoints and adopting multi-signature hardware wallets to eliminate single points of failure. Concurrently, even minor breaches like Iron Mountain’s data exposure highlighted the necessity of continuous risk assessments and incident response preparedness, including brand impersonation monitoring. U.S. National Cyber Director Sean Crankcross’s policy push for public-private collaboration and function-focused regulations further cemented resilience as a collective, real-time endeavor.
As AI and quantum threats intensified by early 2026, CISOs like those interviewed emphasized that cyber resilience must evolve into a team sport involving cross-organizational collaboration and executive buy-in from data owners, CFOs, and legal teams. Building adaptive, crypto-agile systems capable of evolving with emerging technologies became critical to safeguarding long-lived sensitive data such as health and financial records. This strategic alignment between cybersecurity and business objectives, framed in financial risk terms, fosters mission-driven cultures prepared to absorb shocks and recover swiftly from inevitable incidents.
By mid-2026, boardrooms shifted focus from endless prevention spending to resilience and incident response readiness, as Christy Wyatt of Absolute Security noted, emphasizing that 'it just takes one thing to get through.' This pragmatic stance aligns with insights from logistics leaders like Mihir Thakar of All Cargo Group, who stress continuous monitoring, compliance, and leadership bridging strategy with execution to transform cybersecurity into a mission-driven enabler of business continuity. Moreover, cyber attacks are increasingly viewed as capital events with profound financial and reputational impacts, demanding transparent communication, cross-organizational collaboration, and board-level engagement to sustain trust and mitigate long-term risks.










