Skip to content

AI Is Changing Cybersecurity. The Basics Still Matter.

Adam M. Casgar
Adam M. Casgar

AI is changing cybersecurity in some genuinely interesting ways.

We hear plenty about criminals using it to write more convincing scams, automate attacks, and find weaknesses faster. But it's also becoming a serious tool for the people defending systems.

Microsoft recently gave us a good example. They've built a system called MDASH that uses more than a hundred specialized AI agents to hunt for vulnerabilities in software. Different agents focus on different kinds of weakness, then work against each other to validate findings and weed out false alarms. That's considerably more sophisticated than asking a chatbot whether some code looks suspicious.

The results have been real. Microsoft says it helped researchers find 16 previously unknown vulnerabilities in Windows, four of them critical flaws that could have let attackers run malicious code remotely.

Think about what that means. Instead of waiting for a criminal to find a weakness and start exploiting it, AI is increasingly helping security teams find it first.

I'm genuinely excited about that direction. But there's a reality check underneath it that matters more for most businesses.

The future may be AI. Your biggest risk is probably something boring.

It's easy to read about a hundred AI agents hunting vulnerabilities and conclude that cybersecurity has become so advanced that an ordinary business needs some futuristic defense system to keep up.

Meanwhile, most successful attacks still start with something much simpler.

Someone reused a password. Multi-factor authentication was never turned on. A system didn't get patched. Someone clicked a convincing phishing email. An old account was never disabled after an employee left. Access permissions were broader than anyone intended. Backups existed, but nobody had ever tested whether they'd actually restore.

None of those sound as impressive as AI agents finding hidden flaws in Windows. They cause an enormous amount of the damage anyway.

Which is why I wouldn't judge a company's security by how many advanced tools it owns. I'd start by asking whether the fundamentals are being handled consistently.

Are updates actually getting installed? Is multi-factor authentication enforced, not just available? Are accounts removed when people leave? Does anyone know who currently has access to sensitive information? Are backups tested, or just running? Is unusual activity being monitored by someone? Do your employees know what to do when something suspicious lands in their inbox?

Those aren't exciting questions. They're the ones that decide outcomes.

And if you're not sure of the answers, that's worth knowing. Plenty of business owners assume these things are handled because someone is handling their IT. Sometimes that's true. Sometimes nobody has actually checked in three years.

One consequence that's already here

Those 16 vulnerabilities weren't a lab exercise. They were fixed in Microsoft's May 2026 Patch Tuesday, and MDASH has since moved into active use across Windows, Azure, and identity systems.

The practical effect is that the number of vulnerabilities being found and patched is going up, and will keep going up.

If your patching happens promptly, that's straightforwardly good news. Flaws that might have gone undiscovered for years are being found and fixed.

If patching at your business happens whenever someone gets to it, this makes that gap more dangerous rather than less. Every published patch is also a public announcement of where a weakness was, and attackers read those notes carefully. More patches means more announcements, and a shorter window between a fix existing and being exploited on the machines that never took it.

Advanced tools can't compensate for weak foundations

You could own some of the most sophisticated security technology available and still leave the front door open through one compromised account with no MFA on it.

That's what I don't want businesses to lose sight of. The goal isn't to chase every new tool that appears. It's to reduce the number of opportunities an attacker has, and to make sure you'd recognize and contain a problem quickly if someone did get through.

AI is going to be an increasingly important part of how that happens. It'll help find vulnerabilities earlier, prioritize risk, investigate suspicious activity, and automate more of the fixing. Attackers will use the same advances to move faster.

That doesn't make the basics less important. It makes getting them right more urgent.

Strong passwords, multi-factor authentication, properly managed access, patched systems, tested backups, monitoring, and employees who understand what they're looking at aren't becoming obsolete. They're the foundation everything else sits on.

If you're not sure where you stand

If you can't confidently answer the questions above for your own business, that's worth an hour of somebody's attention.

Book 15 minutes with Adam. He'll learn how you're currently handling IT and security, where your concerns are, and whether it makes sense to keep the conversation going.

Share this post