{"id":9550,"date":"2026-09-22T08:25:00","date_gmt":"2026-09-22T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9550"},"modified":"2026-09-22T08:25:00","modified_gmt":"2026-09-22T08:25:00","slug":"cisos-can-no-longer-ignore-the-nation-state-threat","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9550","title":{"rendered":"CISOs can no longer ignore the nation-state threat"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Flare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity landscape, with the balance swinging between deep collaboration and friction.<\/p>\n<p class=\"wp-block-paragraph\">The goal of CISOs has typically been to get adversaries out of networks as quickly as possible to contain liabilities, while government responders want to remain longer in compromised systems to watch the adversary and gather intelligence.<\/p>\n<p class=\"wp-block-paragraph\">\u201cA CISO will say, \u2018Get them out of my network right now,\u2019\u201d <a href=\"https:\/\/www.csoonline.com\/linkedin.com\/in\/vikram-thakur-b201802\">Vikram Thakur<\/a>, technical director at Symantec by Broadcom Software, tells CSO. \u201cThe government will say, \u2018No, we know they\u2019re there. Leave them there. We want to be able to see what they do.\u2019 So there is no CISO who\u2019s going to say, \u2018Yeah, I think we should continue observing them.\u2019\u201d<\/p>\n<p class=\"wp-block-paragraph\">The accelerating use of AI by nation-state threat actors is compounding this tension by blurring the distinction between national-security threats and ordinary enterprise threats. These blurred lines don\u2019t mean that CISOs need to embrace more of the functions currently assigned to the NSA or FBI. But they do mean that CISOs must incorporate more geopolitical threats into ordinary risk management and increasingly treat nation-state activity as part of their threat models.<\/p>\n<p class=\"wp-block-paragraph\">Moreover, according to government officials, they must also work more closely with the federal government as the cyber front becomes faster and more complex.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe big thing from my perspective and from the president\u2019s perspective is engaging with private industry in a new way,\u201d Sean Cairncross, US National Cyber Director, told attendees at the Billington Cybersecurity Summit earlier this month. \u201cIn order to move forward, protect critical infrastructure, and make sure the systems that our citizens rely on for daily life are protected and secure, we need a relationship that is hand-in-glove.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Why companies may be targets without knowing it<\/h2>\n<p class=\"wp-block-paragraph\">One blind spot when it comes to managing nation-state threats is that many organizations do not consider themselves strategic targets of adversarial nations. <a href=\"https:\/\/www.linkedin.com\/in\/john-fokker-95b614107\/\">John Fokker<\/a>, vice president of threat intelligence strategy at Trellix, tells CSO he frequently encounters this mindset.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe number of times that I\u2019ve been to organizations \u2026 and it\u2019s like, \u2018Yeah, but why would we be a target of nation-states?\u2019\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Fokker points to the Netherlands, which has become the No. 2 produce exporter in the world due to its expertise in optimizing greenhouse technology. As a consequence, Chinese threat actors target greenhouse operations and their suppliers to steal their technology secrets.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSo that whole industry was like, \u2018Hey, I just grow tomatoes,\u2019\u201d Fokker says. \u201c\u2018I have Windows 95, and I don\u2019t have it patched. I don\u2019t care about IT or whatever.\u2019\u201d<\/p>\n<p class=\"wp-block-paragraph\">The challenge for most CISOs is to identify whether and to what degree their research, contracts, customers, suppliers, infrastructure, or access make it strategically relevant to foreign threat actors, because nation-states are continuously trying to figure that out, too.<\/p>\n<p class=\"wp-block-paragraph\">Identifying nation-state intrusions can be a challenge given that threat actors are not as noisy as cybercriminal actors. They operate in stealth mode to give them as much cover as possible, <a href=\"https:\/\/www.linkedin.com\/in\/john-hultquist-76226478\/\">John Hultquist<\/a>, chief analyst of Google Threat Intelligence Group, tells CSO.<\/p>\n<p class=\"wp-block-paragraph\">\u201cJust because you haven\u2019t necessarily seen these incidents, [doesn\u2019t mean] you won\u2019t be affected by them,\u201d Hultquist says.<\/p>\n<p class=\"wp-block-paragraph\">AI is going to make threat actors even more effective, raising their ability to quietly pre-position themselves within organizational assets. \u201cGiven the ability of AI to sort of help them troubleshoot technical problems, they\u2019re simply going to be better at it than they were in the past,\u201d Hultquist says.<\/p>\n<h2 class=\"wp-block-heading\">Pre-positioning converts geopolitics into enterprise risk<\/h2>\n<p class=\"wp-block-paragraph\">Government leaders at the Billington Summit cited potential threats from China in particular as a prominent concern driving why they were exhorting the private sector to up its defense game against nation-states.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat are we going to do [in a] situation [where] we see the Chinese moving to take significant action in cyberspace to degrade our civilian critical infrastructure?\u201d Nick Andersen, acting director and deputy director for the Cybersecurity and Infrastructure Security Agency (CISA), said at the event.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/charlescarmakal\/\">Charles Carmakal<\/a>, CTO of Mandiant Consulting, connects the concern to uncertainty about how the United States would respond to a Chinese attack on Taiwan. \u201cWe see a lot of intrusion activity by Chinese actors into organizations where we know they can disrupt critical infrastructure and do a lot of bad things, but we don\u2019t see them doing it,\u201d Carmakal tells CSO. \u201cThe question is, does something change from a geopolitical perspective that makes them want to change?\u201d<\/p>\n<p class=\"wp-block-paragraph\">AI hasn\u2019t changed the geopolitical objectives behind nation-state intrusions, but it has changed how quickly and broadly adversaries can act.<\/p>\n<h2 class=\"wp-block-heading\">What AI actually changes \u2014 and what it does not<\/h2>\n<p class=\"wp-block-paragraph\">Although some experts fear that AI technology could usher in an autonomous war in cyberspace, a more realistic impact is that it could lower the threshold for malicious activity.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhile we\u2019re talking about the defensive side, we\u2019ve seen evidence that attackers have also been adopting AI into their own workflow, which ultimately could be seen as the bar for a nation-state-level sophistication of an attack has gone down,\u201d Symantec\u2019s Thakur says.<\/p>\n<p class=\"wp-block-paragraph\">Making the challenge greater, AI can enable lots of threat actors \u2014 even relatively amateurish cybercriminals \u2014 to launch what might appear to be a sophisticated nation-state attack. \u201cIf that bar has gone down, all CISOs across the board should be looking and saying, \u2018Wow, now even the credit card thieves look like nation-state attackers; I need to be able to up my game,\u201d Thakur says.<\/p>\n<p class=\"wp-block-paragraph\">Aiding the sophistication upgrade of both nation-states and cybercriminals is the widespread availability of top-level, open-weight AI models out of China. David Wong, a director at Mandiant, Google Cloud, said on a panel at Google\u2019s Cyber Defense summit last week, \u201cImagine a world where you have a nation-state that\u2019s using an open-source or an open-weight model and it\u2019s pointing it at critical infrastructure.\u201d<\/p>\n<h2 class=\"wp-block-heading\">AI compresses the response window<\/h2>\n<p class=\"wp-block-paragraph\">AI is compressing the interval between vulnerability disclosure and exploitation to minutes or seconds, potentially outrunning conventional patching processes.<\/p>\n<p class=\"wp-block-paragraph\">\u201cA friend of mine once told me, in talking about this North Korean actor, \u2018This guy, every day he wakes up and sees if there\u2019s a zero-day or whatever in these appliances, and he just starts running on it,\u201d Google\u2019s Hultquist says. \u201cThe future is, he won\u2019t have to wake up because the agent will have already run all that. He can pull himself out of the cycle and speed it way up.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The compressed time frame makes patching alone inadequate to fight off nation-state threats, given that the few seconds between discovery and exploitation leave organizations with no realistic ability to patch in time. \u201cYou only have to open the window a couple of seconds, and somebody is in,\u201d Trellix\u2019s Fokker says.<\/p>\n<h2 class=\"wp-block-heading\">What CISOs should do now<\/h2>\n<p class=\"wp-block-paragraph\">Although preparing for nation-state attacks in the AI era is no simple task, experts offer four immediate actions CISOs should consider.<\/p>\n<p class=\"wp-block-paragraph\">The first is to calibrate the threat without waiting for truly autonomous AI attacks to occur. In fewer than 10% of Mandiant\u2019s current incident-response cases, roughly 90% or more of the intrusion activity was agentic or AI-enabled, Mandiant\u2019s Carmakal says.<\/p>\n<p class=\"wp-block-paragraph\">AI is already present in many attacks, but predominantly autonomous intrusions remain uncommon, as Carmakal\u2019s estimate suggests. CISOs should prepare for far greater speed and scale as the percentage of fully agentic attacks rises.<\/p>\n<p class=\"wp-block-paragraph\">The second task for CISOs is to plan to operate through a compromise. CISOs should determine whether critical operations can continue if corporate IT must be isolated, credentials revoked, cloud services interrupted, or outside infrastructure unavailable.<\/p>\n<p class=\"wp-block-paragraph\">Cybersecurity leaders should rerun exercises without declaring prolonged power, telecommunications, water, cloud, or supplier disruptions out of scope. \u201cWe probably sat through business continuity exercises and tabletop exercises where we would very conveniently hand-wave away a lot of the difficult problems,\u201d CISA\u2019s Andersen said. \u201cThat\u2019s no longer sufficient.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The third task is to reduce exposure and compress decision time wherever possible. \u201cA lot of the core security controls that you have in the non-AI world help with AI attacks \u2014 things like zero trust, things like MFA, things like limiting the amount of data that you have online,\u201d Mandiant\u2019s Wong said.<\/p>\n<p class=\"wp-block-paragraph\">Finally, as is true for almost everything a CISO does, it\u2019s critical to seek C-suite and board-level direction. Experts say that nation-state resilience cannot be an unfunded mandate placed on Boards, and CEOs must authorize the investment, operational interruptions, and cross-enterprise planning required to make resilience real.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThere are a lot of CISOs who know exactly what they need to do,\u201d Trellix\u2019s Fokker says. \u201cThey just need to be empowered to do so.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Flare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity landscape, with the balance swinging between deep collaboration and friction. The goal of CISOs has typically been to get adversaries out of networks as quickly as possible to contain liabilities, while government responders want to remain longer in compromised [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9551,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9550","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9550"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9550"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9550\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9551"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9550"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9550"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}