
Exploit times have dropped under a minute, leaving defenders who once had days or weeks to react with almost none. That shift framed a TEISS dinner briefing at the House of Lords, hosted by Check Point, where CISOs and senior security leaders discussed how AI is reshaping both attack and defence. The question running through the evening: can organisations manage their exposure when the same technology helping them is also arming the people trying to break in?
Opening the discussion, Jack Godfrey, who works on exposure management at Check Point, set out the tension. AI has brought benefits, he said, and Check Point uses it across research and development, defence and its own products, including agentic tools that help find vulnerabilities. But the same frontier models give attackers new capabilities. With models such as Anthropic’s Mythos in play, the window to respond keeps shrinking, and fixing something within days or weeks is no longer enough.
Attacking at machine speed
Much of the early conversation centred on how AI has tilted the field toward attackers. “Badness as a service” is now available to buy, one attendee noted, lowering the barrier for people who once lacked the skill to attack. Capable tools sit openly on the dark web, and the time it takes to detect a vulnerability keeps falling.
It used to be good enough to be faster than the next organisation, a participant said. That no longer holds. Account takeover is a serious problem right now, attendees agreed, and it’s very likely being accelerated by AI. Attackers can combine AI with social engineering to harvest staff credentials and reach user accounts, working around controls that had held up before. Deepfakes and impersonation came up repeatedly, convincing and very hard to defend against.
The human element cuts both ways. AI lacks the intuition people have, the instinct that tells you something is off, one attendee said. But people are also vulnerable, and hard to wrap protocols around, which is why several put insider threat near the top of their worries.
Embracing AI without losing control
Encouraging adoption while keeping it safe is hard. One attendee framed the task as three pillars: protecting the organisation from AI, protecting its own AI, and protecting the business with AI. The trouble, the group agreed, is that adoption runs ahead of governance.
Organisations are rolling out AI without training people to use it, one attendee said, and most reach for it like a search engine. Shadow AI is rife, with one attendee giving the example of staff photographing their screens and feeding the images into consumer AI tools. That raises obvious questions about what data ends up inside large language models, and how readily users trust the answers without checking them.
The pull is understandable. Leaders want their people to experiment, but proof of value matters more than a headline return-on-investment figure. One attendee asked: do people know what they want AI to do, and whether it is safe? At one law firm, for example, everything an AI produces must be reviewed by a qualified lawyer.
Defending without skipping the basics
For all the concern, the room was clear that AI belongs on the defensive side too. It gives defenders visibility, one attendee said, and the way to avoid being left behind is to adopt it. It suits initial triage and can churn through volumes of data no person could process in the time.
Incident response increasingly depends on automation, and current AI tools are not an ideal fit for that work because they don’t yet behave predictably. There is no single fix to emerging threats, but existing controls can be adapted for threats like deepfakes, such as by using call-backs to verify the call was genuine.
The discussion kept returning to basics that remain undone. For all the talk of AI on both sides, organisations are still getting simple things wrong, attendees said, from patching to identity management. You cannot protect what you do not know you have, one noted, which makes a clear view of your assets the starting point, not an afterthought.
Risk appetite shifts quickly as people come and go, and businesses often end up with several disjoined AI strategies, leaving the overall risk hard to assess. The fix the group favoured was structural: push risk decisions up to board level so someone owns them, and report to the board directly rather than relying on the CIO or CTO to relay the message upward.
When you cannot outrun the attack
Underlying much of the evening was a pragmatic acceptance that some attacks will land. Their speed means there is not always time to respond, and one attendee admitted to raising their cyber insurance premiums in acceptance of that fact. The focus shifts to recovery and to limiting the blast radius when something gets through. If the organisation has accepted the risk, one put it, you get on with the work.
Closing the discussion, Godfrey returned to the fundamentals. Different sectors bring different motivations, he said, with protecting life the priority in some, but it comes down to getting the basics right and building the resilience to bounce back. Managing exposure, in the end, means knowing what you are exposed to and shortening the time it takes to respond, so that when an attack lands, the business can absorb it and recover.
To learn more, please visit: www.checkpoint.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543