A senior security chief at a major international police body put it plainly on the sidelines of a technology gathering in Singapore this week. Artificial intelligence is not inventing crime so much as stretching the crimes we already know. Scams, fraud, impersonation, social engineering. Same bones. More reach. Less time to notice the seam. If you run a company, that distinction matters more than the headline panic. Panic buys tools. Clarity buys priorities.
Speed And Scale Are The Real Shift
Call it an evolution if you want a calmer word. I do. Revolutions get keynote slides. Evolutions get into payroll files. The useful claim, from people who watch cross-border cases rather than product demos, is that AI cyber threats mostly amplify tactics that already worked. Operators can talk to many targets at once. Translation is cleaner. Synthetic identities hold up longer under a casual glance. The awkward phrasing that used to give a scam away is fading, and with it a cheap detection trick a lot of teams still rely on.
Speed changes the economics. A fraud crew that once needed a room of people to tailor messages can now draft, translate, and iterate while a human is still making coffee. Scale changes the odds. If you only needed one tired approver in a hundred, you can now knock on a thousand doors before lunch. Neither of those facts requires a science-fiction villain. They require a workflow.
Perhaps the most interesting aspect is how ordinary the failure still looks. A vendor email. A password reset. A voice that sounds right. An invoice with the logo in the correct place. The machine did not replace the con. It removed the friction that used to limit how many cons could run in parallel.
What “Harder To Detect” Actually Means On A Tuesday
Detection used to lean on clumsiness. Odd grammar. A domain one letter off, spotted by someone who still reads the full address. A call from a number that did not match the country. Those tells are thinner now. Improved translation does not just fix spelling. It copies tone. Digital identities borrow photos, job histories, and relationship graphs that look lived-in.
I have found that teams over-index on the exotic and under-index on the boring confirmation step. A second channel. A known callback number. A delay that feels rude and is actually the control. When the fake interaction is smoother than the real one, culture starts working against you. People do not want to insult a client who writes well.
The dangerous message is no longer the one that sounds wrong. It is the one that sounds like a person you already trust, arriving at the exact hour you are busy.
That is not a reason to treat every email as hostile. It is a reason to stop using “it felt normal” as a control. Normal is now cheap to manufacture.
Fraud Did Not Need A New Idea
Business email compromise, investment lures, fake support desks, romance-adjacent payment traps that spill into corporate expense flows. The catalog is familiar. What changed is throughput. A crew can test subject lines, voices, and landing pages the way a marketing team tests ads. The winners get scaled. The losers get dropped before a defender even writes the advisory.
According to specialists who track these cases across borders, the pattern is enhancement, not replacement. Criminals still want money, access, or disruption. They still study who approves payments and who panics under a deadline. The tools simply let them rehearse more versions of the same pressure.
- One operator can now sustain many conversations without the old copy-paste smell.
- Language barriers that once protected smaller markets are thinner.
- Synthetic profiles survive a quick profile check that would have failed two years ago.
- Campaigns can pivot the same afternoon a company publishes a warning.
If that list feels unglamorous, good. Unglamorous is where the losses actually sit.
Why “Protect Everything” Is A Quiet Failure
Here is the line I wish more leadership teams would tape above the budget meeting. There is no need for everyone to defend against everything at once when they are not the target of everything. That is not complacency. It is triage. A hospital does not staff a trauma bay for every cough, and a company should not staff a war room for every theoretical exploit.
The practical move, repeated by people who have sat on both the policing side and the corporate side, is almost old-fashioned. Name the crown jewels. The assets that, if stolen or halted, stop the business from being the business. Then ask who would actually want them, and how those people tend to work. Only after that do you shop for controls.
I have watched firms buy a beautiful detection platform while the wire-transfer process still lived in a shared inbox and a verbal “looks fine.” The platform was not the mistake. The order of operations was.
Crown Jewels Are Not Your Whole Network
Crown jewels sound like a vault. Sometimes they are. More often they are a process. The ability to move money. The recipe, the patient record, the bidding model, the identity system that unlocks everything else. A factory’s safety controller. A retailer ’s loyalty database. A law firm’s matter files. If you cannot point at five things whose loss would dominate the next board pack, you are not prioritizing. You are collecting.
Start with operations, not with tools. What must keep running on a bad day? Who can change that thing? What would an outsider need to impersonate that person? Those three questions expose more risk than a generic maturity score.
A plain crown-jewel check: 1. Name the asset that stops revenue or safety. 2. Name the role that can alter it. 3. Name the channel that role trusts too quickly. 4. Put a second check on that channel before you buy anything new.
It looks almost too simple. Simple is the point. Attackers are not grading you on elegance. They are grading you on whether the second check exists when they are in a hurry.
Opportunists And Patient Actors Are Not The Same Job
Defenses drift when companies pretend every adversary is a nation-state, or pretend none of them are. Opportunistic criminals want fast money. They spray lures, ride current events, and leave when the account locks. Advanced persistent actors want position. They wait, blend into suppliers, and care more about quiet access than a single invoice.
The controls are cousins, not twins. Opportunistic fraud dies on callback rules, payment delays, and staff who are allowed to be suspicious without looking difficult. Patient intrusion dies on segmentation, identity hygiene, and someone who actually reviews the odd login from a trusted vendor account. Buying one pile of tools for both jobs is how budgets evaporate.
| Adversary type | What they want | Where AI helps them | What actually slows them |
| Opportunistic fraud crews | Fast payment or credentials | Volume, translation, voice clones | Out-of-band checks, payment friction |
| Targeted criminal groups | Access to a specific process | Better pretext research, fake staff | Role limits, vendor verification |
| Patient intrusion actors | Long quiet access | Faster exploit tuning, lure quality | Segmentation, identity review |
| Disruption-minded actors | Halt or embarrass operations | Scaled scanning, tailored pressure | Crown-jewel isolation, rehearsed response |
Read that table as a budgeting argument, not a taxonomy exercise. If your loss history is invoices and gift-card requests, do not lead with a program designed for silent espionage. If your sector is routinely probed for long-dwell access, do not pretend a phishing quiz is the strategy.
Threat Intelligence Is A Filter, Not A Feed
Once you know who would care about your crown jewels, intelligence gets a job. Not a dashboard of every malware name on earth. A short list of tactics those adversaries actually use against companies like yours. Payment diversion. Help-desk resets. Fake recruiters. Compromised software updates. Pick the ones that touch your critical path.
In my experience, the useful brief fits on a page. Who. What they try. Which team feels it first. What “good” looks like this quarter. Everything else is reading material for people who already finished the page.
Intelligence that does not change a control, a drill, or a decision is just a newsletter with a darker font.
Field note from a security lead who got tired of unread reports
Tailor the defense to the adversary you can name. That sentence is less exciting than a new model release. It is also how smaller teams beat larger ones.
The Boardroom Gap Is Still The Quiet Risk
Cyber risk has climbed the register. You can see it in the agenda headings. What has not fully climbed, in a lot of industries, is the conversation itself. There is still a gap between senior management and the security strategy that supposedly protects them. The register says “high.” The capital plan still treats resilience as a cost center that can wait for a cleaner quarter.
A blunt observation from the policing side keeps sticking with me. Plenty of industries have not accepted that everyone is an IT company now. A shipper. A clinic. A mill. A school group. If your product moves, heals, or gets paid through software, you are in the dependency business whether or not you hire engineers.
That does not mean every director needs to parse logs. It means someone in the room should be able to answer, without a slide, what would stop the company for a week and what was tested last quarter. If the answer is a vendor name, you do not have a strategy. You have a contract.
- Put the crown jewels in the risk paper in plain language, not tool names.
- Separate fraud loss from intrusion risk so the budget stops arguing with itself.
- Ask which control failed in the last near miss, not which product was renewed.
- Give managers permission to delay a payment that “feels urgent.”
- Review one supplier path that can reach a critical system.
None of that requires a new committee title. It requires a meeting that ends with an owner.
Management And Security Still Talk Past Each Other
I have sat in rooms where the security lead described identity risk and the operator heard “another project.” The disconnect is rarely malice. It is vocabulary. One side speaks in actors and techniques. The other side speaks in downtime, fines, and customers who leave. Until those dialects share a sentence, the strategy stays in the appendix.
Try this translation. Not “we need better email security.” Instead, “a forged approval can move a week of margin before lunch, and the current check is a single inbox.” Not “agentic risk.” Instead, “a system we allowed to act can now book, pay, or steer without a person in the loop, and we have not decided what it may never do.”
When the sentence includes money or bodily safety, the room changes. That is not manipulation. It is the actual subject.
Agentic Systems Turn Mistakes Into Actions
The part that should keep operators awake is not a chatbot being confidently wrong. Wrong text is embarrassing. Wrong action is a claim, a crash, a payment, a door. Agentic systems are the tools we are starting to trust with steps, not just sentences. They book, file, route, approve, and in some designs they reach into machines that move.
A security chief who spends his time on international cases put the distinction cleanly. One problem is an assistant feeding you bad information. Another problem is a system performing the wrong action, especially in the physical world, where the consequence can be harm to a person. Cars and other self-driving machines sit in that second category. So do factory controls, medical workflows, and building systems if we hand them initiative.
I am not arguing for a freeze. I am arguing for a narrower permission than the demo suggests. An agent that drafts is not the same creature as an agent that sends. An agent that recommends a route is not the same creature as an agent that takes the wheel. Companies blur those lines because the interface looks identical. The liability does not.
The Physical Domain Is A Different Kind Of Error
Software bugs annoy. Physical bugs injure. That sounds obvious until you watch a pilot program where the same team that ships a web feature is asked to govern a vehicle stack or a robot arm. The release cadence, the rollback story, and the “we will patch Tuesday” habit do not travel well into metal.
Watch three things if your roadmap includes machines that act. Who can override. How fast the override works when the network is sulking. What the machine is forbidden to do even if the model is sure. Forbidden is the word vendors dislike and insurers understand.
Action boundary: draft freely, recommend with a log, execute only inside a named limit, never cross into safety-critical motion without a human stop.
Write the boundary before the integration workshop, not after the first incident report. Afterward, everyone is suddenly a philosopher.
We Trust Gadgets More Than We Trust Banks
Here is a comparison that landed harder than I expected. People treat money with a kind of practiced suspicion. Pins. Alerts. A flinch at a skimming device on a familiar machine. The same people will tap through a permission screen on a new app because the icon is friendly and the queue behind them is not.
Trust in technology, the observation goes, is through the roof. We grant access. We accept prompts. We let a device speak for us. That habit was manageable when the device mostly displayed things. It is a poorer habit when the device, or the agent behind it, can act.
Companies copy their customers. Staff click because the prompt looks official. Executives install the assistant because the board asked for productivity. Nobody is foolish in the moment. The moment is designed to be small. The permission is not.
Borrow the financial reflex. If a transfer needs a second factor, an agent action that moves money, data, or machinery needs one too. Not a banner. A stop.
What Companies Should Actually Watch This Quarter
Watchlists fail when they become wish lists. Keep yours rude and short. These are the places I would put a name next to, not a task force.
- Payment changes that arrive with urgency and a polished backstory.
- Help-desk resets for anyone who can approve or deploy.
- Vendor accounts that can reach a crown jewel and have not been reviewed since the contract party.
- New agents with send, pay, or control rights granted “for the pilot.”
- Voice and video requests that skip the callback number already on file.
- Translation-perfect lures aimed at offices that used to be ignored.
- Physical systems whose override depends on a cloud login.
If you can only fund two, fund the payment path and the agent permission path. Everything else can queue behind a real owner.
Identity Is The New Letterhead
Letterhead used to be the costume. Now the costume is a face, a cadence, a Linked-style history, a calendar invite that nests inside a real thread. Digital identity is not a side topic for the fraud team. It is the front door for both opportunists and patient actors.
Ask how a stranger becomes a trusted requester in your company. If the answer is “they sounded right and the domain looked close,” you have a costume problem. Close the path with known channels. Publish internally, not on the open web, the only numbers that can change a bank detail. Then test whether anyone follows them when the voice is excellent.
A small drill beats a long policy. Call the duty manager with a perfect fake and see where the script breaks. Fix the break. Run it again next month with a different accent and a tighter deadline. Attackers iterate. So should the drill.
Staff Are Not The Weakest Link If The Process Is
I am tired of the slogan that humans are the weakest link. Humans are the link you gave a bad tool and a worse deadline. If the only way to hit a shipping cutoff is to approve from a phone in a corridor, people will approve from a phone in a corridor. Training does not fix a process that punishes caution.
Change the incentive. Praise the delay that caught a fake. Put the second check inside the happy path so it does not feel like rebellion. Measure near misses the way you measure defects, without a hunt for someone to blame. Blame cultures hide the next costume.
Specialists who see the case files keep returning to the same modest point. Tailor the defense to the threat you face. A retail floor and a chip designer do not need the same Tuesday. They do both need a Tuesday that someone owns.
A Working Model You Can Steal
If you want a shape rather than a slogan, use this. It is not a framework with a trademark. It is the order that keeps showing up when a program actually reduces loss.
- Name five crown jewels in language a director can repeat.
- Map who can change each one, including suppliers.
- Mark which of those paths an opportunist could hit this month.
- Add one friction step that does not depend on “feeling.”
- Limit any new agent to draft or recommend until the friction exists.
- Brief the board on one near miss, not on a product tour.
- Retire a control that nobody uses so the real ones stay visible.
Step seven is the one teams skip. Unused controls create noise, and noise is where the polished fake hides. Subtraction is a security strategy. It just does not photograph well.
Suppliers Sit Inside The Crown Jewels Now
Your vendor’s rushed assistant is your risk if that assistant can open a ticket on your behalf. Supply chains used to mean parts and code. They now mean identities and agents that act with your customer’s patience. A small software firm with a shiny copilot and a shared admin login can become the costume.
Do not ask suppliers for a novel. Ask three things. Who at their shop can reach your environment. Whether an automated agent can act without a person. How you revoke that reach on a Friday night. If the answers arrive as a marketing PDF, ask again.
I have found the revocation test more honest than the questionnaire. Questionnaires describe intent. A timed revoke describes the system you actually have.
Scams At Scale Still End In A Human Moment
For all the talk of automation, the loss still clears through a person or a process a person owns. Someone releases the wire. Someone resets the token. Someone accepts the calendar change. Scale increases the number of those moments. It does not remove them. That is good news if you are willing to redesign the moment instead of lecturing the person.
Make the safe path the fast path for legitimate work, and the unsafe path visibly slower. Attackers hate visible slowness when their whole advantage is tempo. You do not need to be perfect. You need to be slower than their patience on the one path that pays them.
Speed is their product. Friction, placed only where money or safety moves, is yours.
Put friction everywhere and staff will route around you. Put it nowhere and the crew will not need to.
What Not To Waste The Quarter On
A personal bias, stated plainly. Do not spend the quarter rewriting the acceptable-use policy to mention every model name. Do not buy a platform because a peer mentioned it at dinner. Do not run a company-wide simulation of an exotic intrusion if your last three losses were fake invoices. Do not give an agent production rights to “see what happens.”
Also skip the fantasy that a single detection layer will recognize every synthetic voice. Detection helps. It will miss the careful ones, and the careful ones are the ones aimed at your treasurer. Pair detection with a process that still works when detection shrugs.
The international view is consistent on this. Tools rise and fall. The actors keep using whatever shortens the distance between a lure and a payout. Design for that distance.
A Note On Fear And Proportion
Fear is a poor operating system. It buys shelfware and burns the people you need calm. Proportion is harder to sell and easier to live with. Most companies are not the primary target of the most sophisticated actor on earth. Many companies are a perfectly acceptable target for a crew that has automated the boring parts of fraud.
Hold both ideas. You can be ordinary and still be exposed, because ordinary processes are exactly what scale looks for. You can also refuse the costume of constant crisis. The work is specific. Name the asset. Name the actor. Name the step that stops the money or the motion. Then go home at a reasonable hour so the next near miss gets a clear head.
If that sounds less like a manifesto and more like facilities management, you are reading it correctly. Cyber risk became dramatic. The fixes that hold are often clerical.
Questions Worth Asking Before The Next Pilot
Before another assistant gets a badge, I would want answers in writing. What can it do without a person? What can it never do? Whose name is on the log when it acts? How do we kill it if it starts looping? Which crown jewel can it see, even read-only? Read-only is how reconnaissance likes to begin.
Ask the same questions of the human process the pilot is supposed to replace. If the human process was already a single click, the agent did not create the risk. It inherited it and removed the hesitation. Hesitation, in payment and safety paths, is a feature.
And ask the trust question out loud. Are we treating this rollout like a bank transfer or like a new phone app? If the room laughs, you have your answer. Then change the rollout until the laugh stops.
Bringing The Thread Back To The Desk
Go back to that voice note. The tell was not the audio quality. The tell was that we had no rule stronger than familiarity. Familiarity is now a product feature. International investigators are watching the same pattern in scam operations that can address many victims at once, with cleaner language and identities that survive a glance. Companies that respond by trying to guard every surface will exhaust themselves. Companies that name what must not fail, and who is actually coming for it, still have a chance to be bored. Bored is the goal.
Evolution, not revolution. Speed and scale, not a brand-new crime. A board conversation that still lags the risk register. Agents that can do, not just say. A public habit of trusting technology more quickly than money. None of that is abstract if a payment, a patient, or a vehicle sits downstream of the prompt.
Pick the crown jewels this week. Put one ugly, reliable check on the path that pays an attacker. Keep the new agent on a short leash until that check is real. Then tell the board the near miss in a sentence they can repeat. That is not the whole of security. It is the part that matches the threat as it actually arrives.
The rest can wait until someone tries the voice note again. They will. The only open question is whether the second channel answers before the money moves.
]]>