Artificial intelligence is accelerating cybercrime but Jon Abbott, CEO and Co-Founder, ThreatAware, says attackers still rely on familiar weaknesses such as poor security hygiene and lack of visibility to breach organisations.
Artificial intelligence is transforming cybercrime, from automating reconnaissance to generating convincing phishing content in seconds. Powered by AI tools, threat groups can not only scale up their campaigns but also target individuals with unprecedented precision.
But for all the noise about this new era of more sophisticated threats, the reality is that attackers can still use age-old tactics, such as overlooked security vulnerabilities and lapses in human error, to launch an attack. The security fundamentals are still as important as ever, if not more, yet too many organisations are chasing innovations while neglecting these basics that actually prevent breaches. Patching, configuration and visibility are not yesterday’s problems; they are the foundation of modern defence.
The speed and efficiency of today’s cyberattacks make that painfully clear. Once an attacker gains access, they can move faster than most organisations can detect or contain them. You can have the best detection technology in the world, but in many cases, all it will tell you is that you were one second too late.
In this environment, prevention and visibility are what count. If we want to defend against AI-enhanced attackers, we must stop thinking of the basics as routine maintenance and start treating them as our most strategic priority.
Why ‘analogue’ attack tactics are an enduring threat
For all the industry’s focus on technical exploits, we still see the devastating impact of attacks that rely on psychological tactics such as manipulation and deceit.
This was the case with the serious breach suffered by Marks & Spencer, reported to have started with a convincing social engineering attack against a contractor, carried out over the phone. This kind of attack endures because it works, and even as defences grow smarter, people can be tricked into clicking on links or approving requests that look legitimate.
Attackers understand that it’s faster and cheaper to exploit a person than to break a system. These don’t rely on a sophisticated zero-day exploit or complex malware involved in initiating the breach, just persuasion, pressure and process failure.
What has changed as a result of AI is the scale and speed with which attacks can be created and launched. It’s also lowered the barrier to entry for threat actors, giving wider access to tools so that almost anyone with minimal technical proficiency can craft highly believable messages, mimic trusted voices and clone entire websites that are perfect replicas of the real thing. The result is a flood of convincing content that even experienced users struggle to spot.
Social engineering was always about trust and timing. Now, AI allows attackers to execute those same tactics at machine speed. The uncomfortable truth is that while defenders focus on the latest security innovations, attackers are simply refining the oldest tricks in the book.
Why the fundamentals still fail
Alongside old-school social engineering tactics, most breaches are the result of poor security hygiene. The same weaknesses that attackers exploited ten years ago are still there today: unpatched systems, poor passwords, misconfigured devices and weak authentication.
The additional challenge is that, despite huge investments in cybersecurity, many organisations don’t know these problems exist as they lack visibility across their IT environment. This means that they have no reliable way to check if fundamental measures like endpoint protection are in place and operating correctly.
Too often, the basics are treated as background tasks rather than measurable objectives. Patching gets delayed because there’s “another priority.” Multi-factor authentication isn’t enforced everywhere because someone senior pushes back. Endpoint agents silently fail but remain marked as “active” in dashboards.
The result is a dangerous illusion of security – a network that looks protected on paper but is riddled with gaps in reality.
When carrying out discovery for a company, we often find that as much as 30% of their devices are effectively outside of management and monitoring processes. Something like one in ten endpoints lack essential controls altogether and another 20% are misconfigured. These blind spots are precisely what modern attackers exploit once they gain an initial foothold.
Visibility is the missing pillar of cyber resilience
You can’t secure what you can’t see, but many organisations don’t have a complete picture of what’s connected to their environment. The complexity of modern IT – cloud workloads, SaaS, hybrid work and personal devices – has outpaced traditional approaches to asset management.
It’s created a sprawl of devices and identities that security teams can’t always track and those blind spots have become the attacker’s easiest route in.
There’s little use in having the latest analytics platform or threat-hunting tool without knowing what’s actually running inside the estate. Unknown or unmanaged devices offer huge gaps for attackers looking for a way in, and it’s no use investing in cutting-edge detection if a third of your assets are invisible to it.
These routes in could be a home laptop that connects via a forgotten VPN profile, the virtual machine left online months after a project ended or a cloud account with stale credentials. Common scenarios like these are the ‘unknown unknowns’ that quietly erode a company’s cyber resilience.
Each one extends the attack surface without anyone noticing. Traditional audits can’t keep up – they give a snapshot of confidence in a landscape that changes daily. Compliance frameworks are valuable, but they only prove that you were secure at a single point in time. Continuous discovery and validation are what really matter.
Real visibility isn’t a dashboard metric; it must be a discipline. It means having a living inventory of every device, every account and every access path and knowing, in real time, whether they’re protected. When security leaders start treating the visibility of assets and their security controls as the foundation, critical gaps can be identified and remediated, leaving attackers with nowhere to hide.
Building true resilience – where tech meets culture
Real cyber resilience isn’t only about who has the most advanced tools; it’s also about who applies consistent discipline. Buying in new solutions is only worthwhile if those security fundamentals are maintained.
That starts with measurement. If security performance isn’t being tracked, it isn’t being managed. Every organisation should be able to answer basic questions with certainty: which devices are protected, which aren’t and how quickly gaps are closed.
Culture matters just as much. Too many teams still make exceptions to cyber rules, be it an executive using a personal device, a “temporary” exemption from multi-factor authentication or a skipped patch to avoid downtime. These shortcuts are small acts of convenience that quietly accumulate into systemic risk.
Real resilience means no shortcuts, no blind spots and no assumptions. AI may be changing the threat landscape, but it hasn’t changed the rules of defence. Get the basics right, close the visibility gap and you close the door on most attacks.


