Skip to content
Cardan-AI
Back to resources
Cybersecurity8 min1 August 2026

Cybersecurity & AI: new threats and how to defend against them

AI is a powerful attack vector in the hands of cybercriminals. Overview of risks and adapted defence strategies.

AI has changed both sides of cybersecurity. On offense: hyper-personalised phishing generated at scale, voice deepfakes for CEO fraud, automated vulnerability discovery. On defense: behavioural detection, automated incident response, log analysis at a scale human teams cannot reach. A panorama of the real risks and the defenses that work.

The most concrete threat for SMEs and mid-caps is not the most sophisticated: it is the industrialisation of social engineering. An attacker can now generate contextualised phishing emails — mentioning your real projects, imitating a colleague's style — at zero marginal cost. Classic awareness training, based on spotting crude mistakes, is obsolete.

Your company's AI systems are themselves a new attack surface: prompt injection on your public-facing assistants, training-data poisoning, information exfiltration through model outputs. The AI Act and ANSSI frameworks are starting to regulate these risks; addressing them at design time costs ten times less than after an incident.

On defense, gains are real and measurable: AI-augmented SOCs cut detection and response times by 50 to 80% on common scenarios. For a company without an internal SOC, AI-augmented managed offerings make a level of protection once reserved for large groups accessible.

Our recommendation: treat cybersecurity and AI as one subject, not two separate programmes. Every new AI use case should pass a security review; every security investment should assess AI's contribution. That double lens structures our cybersecurity-AI practice.

Key takeaways

  • The most concrete threat for SMEs/mid-caps is industrialised phishing, not the sophisticated attack.
  • Your own AI systems are a new attack surface to secure by design.
  • Treat cybersecurity and AI as one subject: every AI use case passes a security review.

Your cyber-AI roadmap

  1. 1

    Revise awareness

    Replace 'crude-mistake' training with contextualised phishing simulations, matching AI-generated attacks.

  2. 2

    Secure your AI

    Address prompt injection, data poisoning and exfiltration from the design of every exposed AI system.

  3. 3

    Augment detection

    An AI-augmented SOC (internal or managed) to cut detection and response times by 50 to 80%.

  4. 4

    Unify reviews

    Every AI use case passes a security review; every security investment assesses AI's contribution.

How Cardan-AI helps you

Let's secure your systems — and your AI

Audits, penetration tests and specific hardening of your AI systems: we treat cybersecurity and AI as one subject, from analysis to compliance.

Schedule a security audit

About the author

Cardan-AI Intelligence

Our research and analysis unit, dedicated to applied AI for business, industry and regulatory compliance.

Let's talk about your next competitive edge

A 30-minute conversation to identify your most profitable AI use cases.