An abstract, grainy blue-violet scene with a bright white, vertical glow amid flowing curved forms, creating a dreamy, serene atmosphere.

Cutting through the noise: Cyber resilience in an AI-powered world

As AI changes cybersecurity, boards need to understand the risk without losing sight of the basics.

author
Glen White, Executive General Manager – Cyber, Cloud and Connectivity Solutions, Kordia
date
6 Oct 2026

Last month was a noisy one in the world of AI. 

A global debate was sparked, almost overnight, about the existential crisis posed by AI and how the technology could “kill us all” within a decade. That claim was made by an ex-Anthropic researcher, and it wasn’t long before the company’s CEO – along with other AI and tech leaders – came out publicly to urge a “slowdown” in AI development. 

World leaders soon entered the debate. Such was the perceived gravity of the situation that King Charles called a summit of AI executives from around the world, warning them of the need for the technology to be reined in.

A lot has been said about the motives of different camps in the debate, and how much of it is grounded in reality versus hype. Amid the speculation, AI is clearly here to stay – and its impact on cybersecurity is very real.

With Cyber Smart Week 2026 under way, it is a good time to take stock of exactly what is happening with AI, how it is changing the face of cybersecurity, and what directors can do to protect their organisations and stay cyber resilient. 

AI’s influence on cybersecurity has been a concern for some time now, including in New Zealand. Kordia’s 2026 New Zealand Business Cyber Security Report, released near the start of the year, found:

    • The number of cyberattacks carried out through AI vulnerabilities in New Zealand has more than doubled, from 6% in 2024 to 14% in 2025.
    • Nearly a quarter (24%) of businesses say staff using AI improperly is one of their biggest cybersecurity challenges.

Those are alarming figures. While there is a lot of talk about how quickly cyber threats will evolve along with AI, there is one important thing to remember: most cybercriminals are still relying on familiar attack methods – such as phishing and social engineering – that have been around long before the advent of AI.

For example, our research found email phishing was the most common way businesses in New Zealand were compromised, and by some margin. Nearly half (45%) of businesses that suffered a cyberattack were breached through email phishing.

AI isn’t necessarily inventing new attack methods at pace. Rather, it is simply helping cybercriminals accelerate their attacks, narrowing the window for defenders to respond.

A sobering example is “breakout time” – how quickly attackers move from an initial foothold to another system within an organisation. This used to take a matter of months; now it is only around 29 minutes on average.

In a world where the timeframe for cyberattacks is becoming exponentially shorter, what should directors do? 

1. Don’t panic. While AI is certainly growing as a tool for threat actors, it is also helping cybersecurity professionals work smarter and faster to combat those threats. A good cybersecurity advisor will stay on top of the latest developments and break down what they mean for your organisation and how to stay protected. 

2. Remember that the fundamentals still matter. Much of good cybersecurity practice is simply about doing the basics and doing them really well. Many cyber incidents stem from basic controls not being implemented or maintained, not novel threats created by AI. This includes things such as multi-factor authentication, patching, identity controls, having an incident response plan and good security hygiene.  

3. Take a balanced approach. Don’t let the latest headlines scare you away from AI. It is important to understand how AI is being used in your organisation so you can quantify the risk. Organisations should also encourage and enable responsible adoption, while strengthening their existing security fundamentals and ensuring appropriate governance is in place. 

4. Think in terms of cyber resilience, not just prevention. One of the best ways to prepare is to assume an incident may occur and ask the right questions, such as how quickly can we detect and contain an incident? How quickly can we recover? Is our incident response plan practical, tailored to our organisation and regularly tested? These questions should be asked at the highest levels of the organisation. 

Cyber Smart Week is New Zealand’s annual health check on our cyber resilience as a nation. It is particularly timely this year, as the world grapples with the future of AI and the opportunities and threats that come with it.

Staying on top of AI-related cyber threats – this year and beyond – begins with getting the basics right and ensuring cyber resilience is a priority topic in the boardroom.

Special offer

Kordia Secure AI Services helps you understand how AI is being used, identify the risks and put the right controls in place. We help you adopt AI securely, so you can unlock productivity and innovation benefits while protecting your data and maintaining oversight. 
 
IoD members and their organisations receive 10% off a Kordia Secure AI Assessment if they book before 31 December 2026.  Enquire today here.