Skip to content
Cardan-AI
Back to resources
Cybersecurity8 min1 August 2026

Cybersecurity & AI: new threats and how to defend against them

AI is a powerful attack vector in the hands of cybercriminals. Overview of risks and adapted defence strategies.

AI has changed both sides of cybersecurity. On offense: hyper-personalised phishing generated at scale, voice deepfakes for CEO fraud, automated vulnerability discovery. On defense: behavioural detection, automated incident response, log analysis at a scale human teams cannot reach. A panorama of the real risks and the defenses that work.

The most concrete threat for SMEs and mid-caps is not the most sophisticated: it is the industrialisation of social engineering. An attacker can now generate contextualised phishing emails — mentioning your real projects, imitating a colleague's style — at zero marginal cost. Classic awareness training, based on spotting crude mistakes, is obsolete.

Your company's AI systems are themselves a new attack surface: prompt injection on your public-facing assistants, training-data poisoning, information exfiltration through model outputs. The AI Act and ANSSI frameworks are starting to regulate these risks; addressing them at design time costs ten times less than after an incident.

On defense, gains are real and measurable: AI-augmented SOCs cut detection and response times by 50 to 80% on common scenarios. For a company without an internal SOC, AI-augmented managed offerings make a level of protection once reserved for large groups accessible.

Our recommendation: treat cybersecurity and AI as one subject, not two separate programmes. Every new AI use case should pass a security review; every security investment should assess AI's contribution. That double lens structures our cybersecurity-AI practice.

Key takeaways

  • The most concrete threat for SMEs/mid-caps is industrialised phishing, not the sophisticated attack.
  • Your own AI systems are a new attack surface to secure by design.
  • Treat cybersecurity and AI as one subject: every AI use case passes a security review.

Your cyber-AI roadmap

  1. 1

    Revise awareness

    Replace 'crude-mistake' training with contextualised phishing simulations, matching AI-generated attacks.

  2. 2

    Secure your AI

    Address prompt injection, data poisoning and exfiltration from the design of every exposed AI system.

  3. 3

    Augment detection

    An AI-augmented SOC (internal or managed) to cut detection and response times by 50 to 80%.

  4. 4

    Unify reviews

    Every AI use case passes a security review; every security investment assesses AI's contribution.

How Cardan-AI helps you

Let's secure your systems — and your AI

Audits, penetration tests and specific hardening of your AI systems: we treat cybersecurity and AI as one subject, from analysis to compliance.

Schedule a security audit

About the author

Cardan-AI Intelligence

Our research and analysis unit, dedicated to applied AI for business, industry and regulatory compliance.

Let's talk about your next competitive edge

Thirty minutes to identify the two or three use cases in your operations that pay for themselves within the first year.