Logo
FrontierNews.ai

Why Your Incident Response Plan Isn't Ready for AI-Powered Attacks

When AI-powered attacks strike, they move at the speed of public opinion, not the speed of security teams. A deepfake of a CEO, a synthetic identity scam, or an AI-automated ransomware campaign can spread across the internet and damage a company's reputation before security experts even understand what happened. The problem is that most organizations still treat AI-enabled incidents as purely technical problems, when they're actually business crises that demand coordinated responses from cybersecurity, legal, communications, risk management, and executive leadership working together.

The threat landscape has shifted dramatically. In July 2026, a security researcher documented the first case of fully agentic ransomware, an end-to-end extortion attack driven entirely by a large language model (LLM), a type of AI trained on vast amounts of text data to generate human-like responses. Nation-state actors and other threat groups have been observed using LLMs to automate entire attack sequences: scouting targets, identifying vulnerabilities, breaking into networks, stealing credentials, moving deeper into systems, and exfiltrating sensitive data. This represents a fundamental change in how attacks unfold.

What Makes AI-Enabled Attacks Different From Traditional Threats?

Traditional cyberattacks follow predictable patterns that security teams have learned to detect and respond to over decades. AI-enabled attacks compress detection and response windows in ways that existing playbooks cannot handle. Attackers can now study a target's public presence, writing style, and communication patterns, then generate messages that sound authentic enough to fool employees. They can respond in real time, maintain the momentum of a scam, and make impersonation far more convincing than ever before.

Deepfakes add another layer of complexity. Fake audio or video can appear legitimate enough to deceive employees, customers, partners, journalists, or investors. A fraudulent voice authorization or a viral misinformation campaign can trigger media attention and stakeholder confusion before the organization has a full picture of what happened. These incidents create a common business problem: they make it harder to determine what is real, who can be trusted, and how quickly an organization can respond.

The threat extends beyond external attacks. Enterprise AI tools, development platforms, and workflows can expand the attack surface. Threat actors may use prompt injection (feeding malicious instructions into an AI system), malicious files, or compromised AI services to manipulate a system's behavior, leak sensitive information, or misuse connected tools. This creates new questions for security teams, as well as for legal, compliance, procurement, and business leaders responsible for how AI is deployed.

How Should Organizations Prepare for AI-Driven Crises?

The solution is not to add more technology. Instead, organizations need to shift the conversation from how AI attacks work to what they mean for the business. From a reputational perspective, AI-enabled incidents can move at the speed of public opinion. From a legal and regulatory perspective, leaders need to demonstrate active oversight of AI risk as part of enterprise risk management. From an operational perspective, AI can compress detection and response windows, allowing attacks to move faster, reach more targets, and overwhelm traditional controls.

This is why AI crisis readiness cannot live within the cybersecurity function alone. The response must connect technical validation, legal decision-making, and communications strategy from the start. Organizations should update incident response plans and crisis playbooks around realistic AI scenarios, including deepfakes, voice cloning, synthetic content, prompt injection, and misinformation campaigns.

Steps to Build an AI-Ready Incident Response Plan

  • Cross-Functional Tabletop Exercises: Bring cybersecurity, legal, communications, risk, compliance, and executive leadership into the same room to pressure-test how quickly teams can verify an incident, preserve evidence, and decide what to say publicly. These exercises should use realistic AI scenarios and measure response times.
  • Pre-Identified External Resources: Identify the outside experts your organization may need on short notice, including legal counsel, digital forensics teams, communications advisors, and platform escalation contacts. AI-driven attacks make incident response and forensic investigations significantly harder because they increase the speed, scale, adaptability, and stealth of malicious activity.
  • Pre-Prepared Legal and Communications Templates: Prepare legal templates, takedown workflows, holding statements, escalation paths, and monitoring systems before an incident begins. Minutes matter when fake or stolen content starts spreading, so these materials need to be ready to deploy immediately.
  • Employee Training on AI-Enabled Social Engineering: Require regular training on AI-enhanced phishing and social engineering tactics. Apply secure-by-design principles to internal AI tools, third-party generative AI platforms, and embedded models. Provide robust operational guidance on appropriate AI usage.
  • Measurable Resilience Testing: Test preparedness through multiple methods, including full-scale crisis simulations and disaster recovery exercises with measurable data points, such as recovery time objective (RTO) and recovery point objective (RPO), which measure how quickly systems can be restored and how much data loss is acceptable.

The goal is to avoid building the response during the crisis. When AI-enabled incidents move quickly, companies need the people, processes, and decision paths already in place. Organizations that prepare now will have a significant advantage. They will know who needs to be in the room, what evidence needs to be preserved, how decisions will be made, and how stakeholders will be informed. That preparation can help them respond faster, reduce confusion, and protect trust when an AI-driven crisis unfolds.

Why Government Measurement of AI Threats Remains Incomplete

While organizations scramble to prepare, the federal government faces its own challenge: it cannot reliably measure how much real-world damage AI is actually causing in cyberattacks. In June 2026, the Commerce Department ordered Anthropic to cut off foreign access to its two most capable AI models, Fable 5 and Mythos 5, citing concerns about a jailbreak that could unlock offensive cyber capabilities. Within 18 days, the government reversed itself in stages, first restoring Mythos to approved partners, then lifting controls entirely.

The reversal exposed a fundamental problem: the federal government can measure what AI models do in laboratory tests, but it cannot reliably measure what role AI actually plays in real-world cyberattacks. Lab benchmarks, telemetry data, law-enforcement complaint data, and victim incident reports are treated as a single measurement, when they are actually four separate evidence streams that tell different stories. The FBI's first-ever AI breakout in its Internet Crime Report was $893 million of 2025 losses, but that is an AI-related tally counted only where victims recognized AI and a mix of fraud and intrusion, an incomplete indicator rather than a measurement of AI cyberattacks.

A May 2026 randomized trial by RAND for the UK's AI Security Institute found "generally statistically insignificant" gains when people used frontier models to run end-to-end attacks. Yet the capability side is moving rapidly: in April 2026, an AI model completed a 32-step simulated corporate intrusion on its own for the first time, and within weeks GPT-5.5 solved that range in three of 10 attempts while Mythos solved it in six. The distance between inflated vendor claims and confirmed independent testing will not be closed with better rhetoric.

The solution is straightforward but requires action from federal agencies. CISA is finalizing the reporting rule required by CIRCIA, the law that compels critical-infrastructure operators to report serious cyber incidents. Before that rule is finalized, it should include four simple questions for any reported intrusion: Did AI find the vulnerability? Did AI write the exploit? Did AI stand in for skilled human labor? Did AI in this attack operate without human direction? Allowing "unknown" as a permitted answer would create the first standing federal record of AI's role in real attacks, so future policy decisions can rest on evidence instead of guesswork.

What Is the Current State of AI-Powered Attacks in the Wild?

The threat is not theoretical. A 14-day cyber threat forecast for U.S. organizations issued on July 20, 2026, assessed that the U.S. cyber threat posture is elevated and escalating. Three characteristics define the current cycle: sustained, mass exploitation of internet-facing Microsoft SharePoint on-premises servers by China-nexus actors, now fused with ransomware deployment rather than pure espionage; convergence of nation-state operations against U.S. critical infrastructure across all four principal adversaries; and a ransomware ecosystem operating at a structurally higher baseline than any prior period.

What makes this cycle distinct is the collapse of the historical wall between espionage-grade access and criminal monetization. The same SharePoint flaws being used for state intelligence collection are being weaponized within days for Warlock ransomware. Adversaries are increasingly automating reconnaissance and exploitation with agentic AI tooling. China-nexus actors Linen Typhoon and Violet Typhoon are exploiting on-premises SharePoint vulnerabilities against internet-facing servers for intelligence collection, while Storm-2603, tracked as GOLD SALEM, uses the same access to steal cryptographic keys and deploy Warlock ransomware.

Iranian IRGC actors have moved from access to impact against U.S. operational technology. Joint advisory AA26-097A confirmed CyberAv3ngers-linked actors exploiting exposed Rockwell and Allen-Bradley programmable logic controllers via a vulnerability for which no vendor patch exists, causing confirmed operational disruption and financial loss at water, energy, and government facilities.

Russia is systematically pre-positioning inside critical infrastructure networking devices. A 19-agency advisory led by NSA attributes router-focused targeting of communications, energy, government, defense, financial, and healthcare networks to FSB Center 16, following the disruption of APT28's "Frost Armada" router botnet that had infected roughly 18,000 devices across 120 countries.

The bottom line is clear: AI has changed the speed and scale of cyber risk. It is up to business leaders to change the response model with it. Organizations that prepare early will move faster when it matters. They will know who needs to be in the room, what evidence needs to be preserved, how decisions will be made, and how stakeholders will be informed. That preparation can help them respond faster, reduce confusion, and protect trust when an AI-driven crisis unfolds.