
Recent reports about autonomous AI gaining unauthorised access to external systems during cyber-security evaluations have been described as a wake-up call for our entire industry.
But while people are right to focus on the threat posed by AI, I have a different perspective on the story. I prefer to think of these events as having exposed a visibility problem that already exists.
After all, most IT estates are a mix of legacy infrastructure, on-premise systems, cloud platforms and modern applications.
All too often, the attack surface becomes less like a perimeter that can be defended and more like a moving map that is not always complete.
As a result, while teams may be able to see a network issue, an application alert or a cloud resource in isolation, connecting the dots is not always obvious.
What’s more, this fragmented picture is unfolding at a time when AI is compressing the time between vulnerability discovery and exploitation, leaving organisations with less time than ever to understand what they’re actually defending.
Unsurprisingly, many said their organisations have attempted to close the gap by adding more tools. It’s a familiar story. But rather than resolving blind spots, this approach can add additional complexity and delay, forcing teams to switch between dashboards in an attempt to piece together the root cause of an incident.
For security leaders, the consequences are plain to see. The longer it takes to determine the root cause, contain and limit the blast radius, and establish comms to impacted customers, the worse the impact will be for the business.
As a result, teams become reactive, spending their time chasing alerts and restoring services rather than improving resilience or reducing risk.
Visibility, on the other hand, gives you the foundation to make better decisions. But understanding what’s happening across your environment is only half the challenge.
To build genuine cyber-resilience, you also need to understand how an attacker would view the same environment. And this is something that forms a fundamental part of my thinking.
Throughout my career – including my time working in full-scope offensive cyber-security operations – I’ve found that one of the most effective ways to improve security is to think like an adversary.
After all, attackers don’t look at organisations the way defenders often do. They aren’t interested in organisational charts or departmental boundaries. They’re looking for the easiest and most direct path to their objective. That could be a vulnerable system, a poorly configured process or simply someone who clicks on the wrong email.
That’s why, whenever I assess a network, I don’t just look at the technology. I look for weaknesses across people, controls and internal processes – because that’s exactly what an attacker does.
It’s an approach I’ve brought with me to the new team, and one I believe every security leader should adopt. But it does mean constantly asking difficult questions.
For instance, if I were trying to compromise this organisation, where would I start? Which systems would I target first? How would I move through the environment? And, just as importantly, what controls would slow me down or stop me altogether?
Of course, while thinking like an attacker helps to expose gaps, you also need to embed a security-first mindset across your organisation. For example, carrying out targeted spear-phishing exercises designed to test how people respond to real-world threats.
The whole objective of the exercise isn’t to catch people out. Instead, we want to help them hone their own instincts and inoculate them from common themes so they can recognise when something doesn’t look right and what action to take.
Ultimately, this way of thinking comes back to a simple reality that no organisation is immune from these threats. What matters is how prepared you are when it happens.
For me, thinking like an attacker helps you understand your own environment well enough to reduce risk, build resilience and limit the blast radius when the inevitable occurs.
It’s also why visibility and observability can no longer be treated as purely technical functions. What’s more, the clock is always ticking. If the events of this summer are anything to go by, organisations need to be prepared.
Autonomous AI may not have created the visibility problem, but it has made its consequences harder to ignore.
As threats move faster and traverse an organisation’s technology, people and processes, security leaders need more than isolated alerts and partial inventories. They need a clear, connected understanding of their environment: what they have, how it is exposed, and where an attacker is most likely to find a way in.
Justin Henkel is CISO at SolarWinds
Main image courtesy of iStockPhoto.com and MTStock Studio
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543