The democratization of cyber warfare — and what it means for CISOs

Tags:

For most of modern history, sophisticated and costly warfare had a high barrier to entry. In order to maintain a significant tactical advantage, you needed money, infrastructure and highly trained human resources. In the physical realm, you needed trained and capable warfighters along with relatively expensive and specialized weaponry, made by skilled tradesmen. In cyber, you needed operators who understood networks, vulnerabilities, exploitation and how to move through an environment without getting caught.

Warfare was typically a whole-of-society contest that came down to who had the best and most vast resources at their disposal. Those barriers are coming down. They have always been, but now it is accelerating more rapidly than ever before in human history. This is called the democratization of warfare, and it is terrifying. Its ramifications in cyber are being felt throughout both the public and private sectors, on battlefields and in boardrooms.

Warfare has been democratizing for centuries

I’ve seen the democratization of warfare firsthand. In Ukraine, relatively inexpensive, commercially available technology has put capabilities into the hands of individuals that would have been unimaginable not long ago. Look at Moscow. In 2023, drones reached the Kremlin itself, marking the first attack on the Kremlin since Nazi Germany bombed it during Operation Barbarossa in World War II. A target that had gone untouched by an enemy for more than 80 years was suddenly within reach.

Democratization of war is not a new trend. The firearm was itself a democratizing technology, dramatically reducing the skill and physical barriers required to inflict lethal force on an adversary — so was the crossbow before that, and others before that. Those technologies enabled new techniques and expanded existing ones, including forms of irregular warfare that allowed smaller forces to exploit the asymmetry they created. European armies arriving in North America brought a tradition built around disciplined formations and massed firepower, but quickly encountered Indigenous forces that emphasized mobility, concealment, surprise and intimate knowledge of terrain. Colonial forces began adapting to those tactics. Benjamin Church incorporated Native American tactics into his ranger force during King Philip’s War in the 1670s. Nearly a century later, Robert Rogers took those lessons further during the French and Indian War, building Rogers’ Rangers into a force designed to scout, raid and operate deep in terrain where conventional formations struggled.

The technology mattered and so did the underlying lesson: you didn’t have to match a superior adversary soldier for soldier if you could change the conditions of the fight with the technology at your disposal. That lesson carried into the American Revolution, where commanders like Francis Marion and Daniel Morgan employed irregular approaches against the British, using mobility, surprise and targeted attacks to work around traditional advantages in equipment, training and manpower.

Democratization has continued to iterate throughout human history. Today, a $1,000 drone bought online, altered with 3D-printed components and operated with relatively little training can destroy personnel or a weapons system that costs millions of dollars. That changes the economics of warfare. More importantly, it changes who is capable of creating a significant tactical effect on the battlefield.

AI is collapsing the barriers to cyber warfare

We are watching the same thing happen in cyber warfare — and it matters because the downstream effects are already reaching the private sector. Cyber has always offered an asymmetric return on investment compared with conventional warfare: a relatively small number of skilled operators can impose enormous costs on a much larger adversary. Thus, cyber has always been an especially favored weapon of choice for nation-states with constrained resources. AI pushes that asymmetry even further by driving down the cost of sophisticated cyber operations while simultaneously collapsing the skill gap required to conduct them.

We’ve seen glimpses of this before. In 2015, a 15-year-old named Kane Gamble operated from his family home in England and compromised accounts belonging to some of the most senior intelligence officials in the United States, including then-CIA Director John Brennan and Director of National Intelligence James Clapper. He did it largely through social engineering, not some enormous state-sponsored cyber apparatus. AI is pouring gasoline on something that was already possible. It is putting increasingly sophisticated offensive capabilities in the hands of people who previously wouldn’t have had the skills, money or resources to use them. That is the democratization of cyber warfare.

That brings us to what happened in Taiwan. In August, researchers disclosed what they described as the first largely autonomous AI-enabled cyberattack against government infrastructure. The attackers used publicly available AI tools and open-source agent frameworks to build what was effectively an autonomous hacking team. Up to eight agents operated simultaneously, mapping government systems, researching vulnerabilities and changing tactics when something didn’t work. At least 85 government accounts were compromised, and more than 2,500 personnel records were taken before the operation expanded to Taiwan’s nuclear safety agency and energy companies. This wasn’t AI helping someone write a better phishing email. It was AI performing parts of the attack itself.

That level of autonomy changes the equation again. A human operator has a hard limit on how many targets they can research, attack paths they can test and decisions they can make at once. Autonomous agents start to remove that constraint. One person can effectively become a team, with multiple agents working in parallel, testing different paths and adjusting when something fails. In military terms, AI creates a new kind of mass. The attacker hasn’t gotten more people or more resources. Each resource has simply become exponentially more capable.

None of this will stay confined to nation-state conflict. Cyber capabilities have always migrated downstream. Techniques spread, tools become commoditized and knowledge that was once held by sophisticated operators eventually becomes accessible to everyone else. The difference with AI is the speed at which that can happen. There is also an obvious financial incentive. A capability used today to compromise government infrastructure can be pointed at a bank, hospital or technology company tomorrow. The attacker may change and the motivation may change, but the capability doesn’t care who the target is.

We don’t have to speculate about whether these capabilities will reach companies because they already have. In 2025, a likely China-linked espionage actor used Claude Code against roughly 30 organizations across the technology, financial, chemical and government sectors. The AI wasn’t just writing phishing emails or helping with research. According to MITRE ATT&CK, Claude Code agents were used for reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis and exfiltration with minimal human involvement. The line between the capabilities used in cyber warfare and those used against the private sector is already disappearing.

This creates an ugly problem for defenders. Companies still largely defend themselves with expensive human expertise, and there are only so many hours in the day for an analyst to investigate alerts, understand an attack path and decide what to do next. The attacker is beginning to shed those same constraints. They can run more operations against more targets, at lower cost and with less expertise than they could before. We cannot assume our existing model of defense will continue to work when the offensive side of the equation is changing this quickly.

The economics of defense have to change

Security teams cannot answer this by simply adding more people. You cannot hire analysts at the same rate an attacker can spin up agents, and you certainly cannot expect humans working through queues of alerts to keep pace with autonomous systems operating continuously and in parallel. Defenders need the same force multiplier. That means giving AI more responsibility for investigating activity, understanding attack paths, connecting evidence and eventually acting. If AI allows one attacker to operate like a team, we need to give one defender that same advantage.

That also means rethinking what we expect security technology to do. For years, we’ve built tools designed to find problems and put them in front of a human who ultimately decides what happens next. That model doesn’t work when the attacker is operating autonomously at machine speed. Security has to be able to understand what is happening, make a decision and defend the environment in real time. If the attacker can act autonomously, the defender must eventually be able to do the same.

While that may seem risky at first, it is also necessary. There is an analogy to be made here. As a leadership principle, decentralized command exists because sometimes the speed of the fight makes centralized decision-making impossible. Throughout history, forces have crumbled when centralized command structures were overwhelmed with more problems than they could process — we saw this play out in Ukraine, as its armed forces moved away from the centralized Soviet command model they inherited and toward a Western-style model of mission command, where decision-making authority is pushed closer to the fight.

In fact, that is how wars are won: overload the enemy with more problems than they can handle, faster than they can make decisions. A commander counters that by establishing intent, defining the boundaries and giving subordinate leaders the authority to act within them. They don’t stop in the middle of a fight and wait for someone several levels above the subordinate to approve every decision — doing so accelerates a downward spiral of overload that will eventually end in failure.

Security has to start thinking the same way. Give autonomous systems clear intent and guardrails, define what decisions they are authorized to make and let them act when speed matters. In leadership terms, this is the commander’s intent applied to autonomous defense: humans determine the objective and the boundaries while systems make decisions inside them at the speed of the fight. Human control remains critical, but human approval cannot be a prerequisite for every defensive action.

Final thoughts

The democratization of cyber warfare is not coming — it is already underway. We have seen this pattern before: when the cost of a capability falls, the skill required to use it decreases and access expands, that capability does not remain in the hands of a small number of sophisticated actors for long. The same thing is happening in cyber, and the same capabilities being used against governments are already beginning to show up against companies.

For most of history, the advantage belonged to whoever could bring the most resources to the fight. AI changes that equation. A single person can increasingly wield capabilities that once required an organization behind them. Defenders have access to that same leverage. The question is who learns how to use it first.

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *