How AI-driven cyberthreats will reshape security strategies

How AI-driven cyberthreats will reshape security strategies

As cyberthreats grow more autonomous and sophisticated, organisations face an escalating battle against AI-driven attacks, deepfakes and evolving fraud tactics. Paul Tucker, Chief Information Security and Privacy Officer at BOK Financial, a top 25 U.S.-based bank, tells us how businesses can prepare for 2026 by adopting Zero Trust strategies, leveraging defensive AI and strengthening cyber resilience across people, processes and technology.

What emerging cyberthreats do you think will define 2026, and how might they differ from those we’re seeing today?

In 2026, AI-augmented threats will dominate the landscape. These threats feature unprecedented autonomy, scale and adaptability. This marks a clear distinction from today’s more manual or scripted attacks. Key emergents include AI agent swarms capable of self-coordinating reconnaissance and exploitation, such as multi-stage attacks without human oversight.

Polymorphic ransomware will evade signature-based detection through real-time code mutation. Supply-chain compromises will target large language models via LLM poisoning with adversarial prompts in third-party services.

Quantum-enabled cryptanalysis will also begin transitioning from theoretical to operational risks, particularly against asymmetric algorithms. According to ENISA’s Threat Landscape 2025, AI-driven attacks already account for over 40% of advanced persistent threats. By 2026, their velocity will increase by orders of magnitude due to accessible open-source agent frameworks.

Traditional vectors like ransomware persist but evolve with triple-extortion tactics incorporating AI-generated harassment. Defenders must shift from reactive postures to proactive, AI-orchestrated resilience aligned with NIST Cybersecurity Framework 2.0.

How do you expect the use of Artificial Intelligence by both attackers and defenders to evolve in the coming year?

The AI arms race will intensify in 2026. Attackers will achieve greater autonomy through agentic systems, which are self-improving entities that chain tools for end-to-end campaigns.

Examples include Mirai-like botnets augmented with Generative AI for operational security. Adversarial Machine Learning will target defensive models by injecting poisoned data to create blind spots in anomaly detection. Gartner predicts that by 2026, 30% of enterprises will face AI-specific attacks, up from single digits today.

Defenders will mature AI from augmentation to orchestration. This involves integrating generative AI co-pilots into Security Orchestration, Automation, and Response platforms for real-time hypothesis testing. User and Entity Behaviour Analytics enhanced with explainable AI will reduce false positives. Tools like automated purple-teaming under the MITRE ENGAGE framework will simulate adversary AI tactics.

Challenges include model drift and ethical risks. Mitigations require robust governance per NIST AI Risk Management Framework 1.0, including red-teaming and bias audits. Mid-sized firms lag. Verizon DBIR 2025 notes only about 35% leverage advanced Machine Learning for threat hunting. This gap presents a strategic opportunity. Ultimately, AI defence must emphasise resilience over parity through continuous validation, human-AI hybrid loops, and adversarial robustness testing to counter the asymmetric advantage attackers gain from low-barrier AI tools.

Do you think deepfakes and AI-generated content will become one of the biggest cybersecurity challenges in 2026?

Oh, 100%. Deepfakes and synthetic media represent a profound escalation in 2026. They erode trust in digital evidence and enable hyper-targeted social engineering. Multimodal models support real-time voice cloning combined with video synthesis. These capabilities will facilitate executive impersonation at scale and evolve business email compromise into ‘CEO video calls’ demanding urgent transfers.

Notable precedents include the 2024 Hong Kong deepfake videoconference scam that caused a US$25 million loss and rising incidents tracked by the FBI’s IC3, with over 300% increase in synthetic media complaints from 2023 to 2025. By 2026, ENISA forecasts deepfakes will feature in 20% of fraud attempts.

Technical challenges stem from diffusion model advancements that lower creation barriers. Mitigations demand layered controls. These include content authenticity standards like C2PA from the Coalition for Content Provenance and Authenticity, biometric liveness detection per ISO/IEC 30107-3, out-of-band verification protocols, and AI-based detectors trained on adversarial examples. Organisations should enforce zero-trust communications policies. Never act on material requests via audio or video alone. Integrate provenance checking into endpoint detection tools. Without these measures, deepfakes risk amplifying disinformation and extortion, particularly in regulated sectors.

How can organisations prepare for the growing sophistication of phishing, ransomware, and identity-based attacks?

For business leaders, especially in financial services, 2026 brings new urgency to treat cyber and fraud risk as a core business issue. Security is now integral to business operations and customer trust, not just a back office IT issue. With threats mounting and regulators raising the bar, companies must double down on defences across the board. That means embracing strategies like ‘zero trust’ identity security, deploying AI driven threat detection, tightening incident response plans, and nurturing a vigilant security culture.

What cybersecurity strategies or frameworks do you believe will be most critical for financial institutions in 2026?

Business leaders face the challenge of protecting their organisations and customers amid evolving threats. Cybersecurity and fraud risk management are not just IT issues, but strategic business imperatives. ‘Zero Trust’ identity security is a critical strategy that prevents attackers from accessing sensitive information even if they manage to steal credentials or penetrate the network. It centres around doubling down on Identity and Access Management and enforcing strong authentication for all users.

Embracing AI as a defence strategy is also critical in keeping up with the rate at which threat actors evolve. Implementing an incident response plan and practising it regularly will ensure that when the inevitable does occur, it won’t permanently cripple the business. It’s important to remember that fraud management needs investment and innovation, such as creating a cross-functional fraud task force because regulators may enforce broader reimbursement for scam victims. Which brings me to my next tip: keep a pulse on compliance and regulatory changes and align your security improvements with the direction regulators are pushing.

How do you see regulatory expectations and compliance standards evolving in response to next year’s threat landscape?

Especially for financial industry players, 2026 will bring a heavier compliance load in cyber and fraud domains. Business owners must keep an eye on evolving regulations. For example, banks may face new rules on how quickly they must report cyberincidents (in some regions, it’s 72 hours or less) and how they handle customer fraud claims.

Data protection laws (like GDPR, state privacy laws) dictate how to manage and report data breaches. Ensure your company has the processes and technology to meet these requirements – this could mean investing in better log retention and forensics tools (to investigate incidents and provide reports), implementing stricter data encryption and access controls (to comply with privacy-by-design), and conducting regular compliance audits or tabletop exercises with legal/compliance teams. It’s wise to designate a point person or team for cyber compliance tracking, who can disseminate new requirements internally.

Non-compliance can result in fines, legal damages, and loss of customer trust, so treating these regulations as a baseline for security efforts (rather than a ceiling) is prudent. Essentially, align your security improvements with the direction regulators are pushing – those areas (resilience, reporting, consumer protection) are a good bet for where to focus resources.

What technologies or innovations give you the most confidence in defending against next generation cyberthreats?

I know you’ve heard it before, but AI truly is a double-edged sword. What do they say? If you can’t beat ‘em then join ‘em. Threat actors are leveraging AI to advance their tactics at alarming rates, and the only way to keep up with them is to leverage AI in defence strategies.

What gives me confidence in the ability to defend against next generation cyberthreats is that no business has to go it alone, it’s a group effort. 2026 will likely see continued emphasis on public-private and industry partnerships for cyberdefence. Financial institutions, for example, benefit from participating in information-sharing groups like FS-ISAC. Closer to home, build relationships with local law enforcement or cybercrime units. Within industry groups, don’t shy away from collaborating on best practices. Cyberthreats are a common enemy, and collaboration is a force multiplier to counter them.

How important will workforce awareness and culture be in maintaining cyber-resilience as threats become more automated?

People are at the core of both causing and preventing breaches. In 2026, businesses should expand the scope of cybersecurity training for employees. Don’t limit it to phishing email drills for office staff – include everyone who handles sensitive info or payments, which might mean frontline workers, call centre reps, executives, contractors, etc.

Update training content to cover new threats like social media scams, deepfake calls, and fraud tactics that target staff, because attackers may now single out HR or finance personnel with convincing ploys, not just the C-suite.

It’s also worth conducting specialised workshops or tabletop exercises; for instance, running a simulation of an AI-generated voice call scam on your finance team to see if protocols are followed. These exercises can reveal policy gaps like does your company have a rule for confirming any fund transfer requests made over audio/video? Reward and reinforce good security behaviour to build a positive culture – celebrate teams that report phishing attempts or point out security improvements.

Ultimately, an alert and educated workforce is one of the best defences against both cyber-attacks and fraud. Given that human error or misjudgement is still a leading cause of breaches, this is an area where business owners should personally champion and invest.

Browse our latest issue

Intelligent CISO

View Magazine Archive