How should organizations prepare for AI-powered cyberattacks?
In July 2026, Atif Zaim, Deputy Chair and Managing Principal, KPMG LLP, answers the question many executives are now asking: how should organizations prepare for AI-powered cyberattacks? KPMG’s position is that organizations should assume AI will strengthen both attackers and defenders, making cyber resilience, foundational security controls, and AI-enabled defense capabilities essential to managing risk in the years ahead.
How should organizations prepare for AI-powered cyberattacks?
This question has become increasingly urgent as artificial intelligence advances from chatbots and copilots to agentic systems capable of performing complex tasks. During the session Cybersecurity in the Age of AI: The Arms Race Has Already Started at the 2026 KPMG Tech & Innovation Symposium, the discussion focused on a growing concern: the same technological progress creating new opportunities for organizations is also lowering barriers for cyber attackers.
The challenge is not just about access to better tools, it’s that AI may accelerate the speed, scale, and sophistication of attacks. The conversation emphasized that organizations should view this as an approaching reality rather than a distant possibility. For leaders, the question is how quickly organizations can adapt their defenses to keep pace.
Why It’s Harder Than It Looks
Preparing for AI-powered cyberattacks is difficult because organizations face uncertainty on multiple fronts. Leaders do not know exactly when breakthrough capabilities will become widely available, which threats will emerge first, or how quickly attackers will adopt increasingly sophisticated tools. During the session, speakers compared this moment to preparing for a known risk without having a clearly defined deadline. While the timing remains uncertain, organizations should be developing concrete response strategies now rather than waiting for complete clarity on how the threat landscape evolves.
At the same time, many organizations continue to struggle with cybersecurity fundamentals that have existed for years. Vulnerability management, identity protection, and other foundational security practices remain persistent challenges. As AI expands attacker capabilities, unresolved weaknesses may become more consequential rather than less. The result is a dual challenge: organizations must address existing security gaps while simultaneously preparing for a new threat environment shaped by AI.
The Evidence
1
2
3
4
KPMG’s Answer
Organizations should prepare for AI-powered cyberattacks by strengthening fundamentals while simultaneously embracing AI as a defensive capability.
The discussion repeatedly returned to a simple premise: if attackers are likely to use increasingly capable AI systems, defenders must be prepared to do the same.
The most immediate priority is not necessarily a new technology investment. Strong authentication controls, disciplined security operations, and the reduction of preventable vulnerabilities remain among the most effective ways to improve resilience. These measures may not be new, but they become more important as AI increases the speed at which adversaries can identify and exploit weaknesses.
Organizations should also consider how AI can improve defensive economics. One of the most promising opportunities discussed was using AI to reduce the time between a breach occurring and its detection. If defenders can identify threats in minutes or hours rather than weeks or months, they can materially alter the balance between attackers and defenders. AI's long-term value may lie not only in helping organizations respond to cyber incidents, but in helping them anticipate and detect those incidents sooner.
Organizations that wait for complete certainty before taking action risk finding themselves behind the pace of change. As AI capabilities continue to advance, cyber resilience will increasingly depend on an organization's ability to combine strong security fundamentals with AI-enhanced defenses.
Reinvest in cybersecurity fundamentals. Review identity controls, authentication practices, vulnerability management programs, and other foundational security capabilities to ensure they can withstand a more demanding threat environment.
Evaluate where AI can improve cyber defense. Focus on opportunities to accelerate detection, monitoring, and response capabilities so defensive teams can identify and address threats more quickly.
Explore more
Get in touch
Start the conversation
Connect with our team today to learn how we can help you realize the full potential of GenAI.