
Artificial intelligence has shifted the balance between attackers and defenders in cyber-security, yet the strongest defences are still built on fundamentals.
That was the message at a TEISS dinner briefing at the House of Lords, hosted by Illumio. Attendees, all CISOs and senior security leaders from multiple sectors, discussed how to prepare for AI-driven attacks, manage third-party risk and limit the damage when an attacker gets in.
Since Anthropic announced its Mythos model, guidance on how organisations should prepare has been strikingly consistent, said Raghu Nandakumara, VP Industry Strategy at Illumio: improve resilience; limit the blast radius of any breach; focus on basic controls. Japanese banking leaders told him the previous week that their equivalent of Britain’s financial services regulators (FCA / PRA) had issued nine requirements and asked to see progress.
The question he put to the room: is the AI threat hype or reality?
A threat that may already be inside
Attendees saw plenty of evidence for the reality of the threat. Microsoft’s monthly patch update for July 2026 was 10 times its usual size, one attendee noted, the start of a Mythos-driven “patch wave”. Mythos itself, another attendee said, is a powerful tool that deserves attention.
China dominated the discussion of state threats. Chinese actors have been on Western networks for decades, one participant said; the worry is that AI makes that presence harder to detect or enables China to act faster. For critical national infrastructure the fear is of being shut down, perhaps during a conflict. What if these technologies are already in your systems, one attendee asked. Are we prepared for that?
You cannot defend what you cannot identify, another participant answered, and many organisations still lack a clear picture of what their IT estates consist of. For years patching and upgrades lost out to business-as-usual priorities, and the funding to put that right is hard to secure. The AI hype has had one welcome effect, several agreed: boards are paying more attention to security, an opening to get basic cyber-hygiene in place everywhere.
Regulators offered little help. They come to us for information, one attendee said, describing them as not one step behind but 10. Useful intelligence came instead from the NCSC and industry contacts.
The third-party problem
Even securing your own systems might not be enough, attendees agreed, because attackers can enter via third parties. Securing those can be complicated: niche suppliers are often not IT specialists; may be the only source of something the business needs; and pass the cost of any mitigation back to the customer. With tens of thousands of suppliers of all sizes, enforcement is close to impossible.
Companies can issue questionnaires, but these are only ever a snapshot. Liability clauses in contracts offer some protection, though these require negotiation and usually will land on some form of mutual liability. Onerous clauses raise the barrier to entry too high for smaller suppliers, and nobody could sign up to unlimited liability for an incident on the scale of Jaguar Land Rover’s.
Nandakumara said Illumio’s customers now consistently ask them 3 questions: how are you leveraing frontier AI to ensure you deliver more secure products; how are you helping your customers address the risks of fronter AI; how are the developments in frontier AI shaping your roadmap?
Assume breach, limit the blast radius
Beneath much of the evening ran a mindset shift, begun by cloud adoption and hurried along by AI: senior leaders now accept that not every attack can be prevented, and that cloud has multiplied the attack vectors. The practical questions become how to keep the business running, whatever the cause of the impact – and how to recover fast. Jade Puffer, ransomware designed and deployed by AI, has made disruption trivially easy, one participant warned.
Attendees discussed defining a maximum acceptable blast radius. That starts with understanding every asset and access point on the estate, then working out how to contain an intrusion within tolerable limits. The exercise must be revisited as the environment changes, and dependencies need particular care: disruption to one system can unexpectedly extend the blast radius to others. Insider threat gets the same treatment: assume there is one, and rely on segmentation and controls on lateral movement to limit what it can reach.
Keeping senior stakeholders engaged means putting all of this in business terms. One attendee said that whenever they spot a threat that could change how the company does business, they propose a tabletop exercise so stakeholders can watch the consequences unfold.
AI’s new risk surface
Attendees wanted to use AI to defend against AI, similar to how DevSecOps has embedded security in development. But confidence is elusive. If AI is protecting you, how do you know it is working? Many organisations cannot even map what AI is in their systems.
New risks are stacking up, attendees said. Some organisations are too comfortable with the assumed security of on-premises AI – as agents multiply, assuring their identity becomes a problem and staff are urged to use AI without training or instruction, so well-intentioned use exposes the business to greater risk.
AI companies should do more to help organisations manage all of this, attendees argued. Governance must be real, too: are you doing what your paperwork says you are, and do the people making decisions understand the risk appetite?
Closing the discussion, Nandakumara set the AI question aside. Assume attackers will find a way in, he said, emphasising that businesses should focus on foundational security controls, and ensure you can contain the spread and impact of the breach.
To learn more, please visit: www.illumio.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543