Seeing AI Cyber Threats Coming

How a UK cybersecurity company helped CISOs from seven major UK companies get ahead of AI-enabled cyber risk, understand what widespread adoption would change and build internal support for action.
Service
Horizon Scanning
Client
UK cybersecurity company
Focus
AI-enabled Cyber Risk
Year
2023

Do you face
similar challenges?

[THE PROBLEM]

In autumn 2023, generative AI was developing faster than most corporate guidance. Cybersecurity leaders could see it would matter, but the implications were scattered across academic research, model releases, policy debates and early experiments.

A UK cybersecurity company wanted to help CISOs move beyond general warnings and understand how AI could change the threats, choices and controls facing their organisations. They needed to understand what widespread AI use would change - inside their organisations and in the hands of suppliers, customers and hostile actors - and have credible material they could use to explain those implications internally, build consensus and act.

From technical advances to [forecasted business impacts]
Managing Director
UK cybersecurity company
Using his up to date technical insight and ability to translate capability advances into forecasted business impacts, James helped to design the content and structure of the programme.
[ our approach ]

How we solved the problem

CLICK ME
Read Ahead
We tracked new research, model releases, company announcements and informed debate to understand where AI capability was moving.
This was autumn 2023, so relevant evidence often sat in academic papers or specialist writing rather than corporate guidance. We filtered it for what would matter to large organisations. The resulting threat assessment was robust for the time, but it should not be read as a current view of the threat landscape.
CLICK ME
Model What Changes Next
We modelled how employees, suppliers, customers and attackers could use AI, and what widespread adoption would change.
That connected technical advances to practical questions about data, new attack routes, supplier exposure, adoption pressure and AI-enabled defence. For each scenario, we identified the signs that would show it becoming more likely.
CLICK ME
Make It Usable
We designed a four-part programme that helped participants explain the implications internally and develop a shared view of what mattered.
Expert input from Oxford, MIT and the Alan Turing Institute was combined with structured discussion, current evidence and reports participants could take back into their organisations.
CLICK ME
Work Back From the Future
We placed participants inside a detailed future scenario, then asked what would have to become true and which decisions would be needed beforehand.
Taking the role of the CISO made second-order effects tangible and helped the group identify decisions about data, suppliers, skills, investment, safe adoption and defence.
DISCUSS YOUR WORK
[ CLIENT RESULTS ]
Our work in numbers
The final report brought together the conclusions participants agreed across the four-workshop programme.
12
Agreed conclusions
Participants identified concrete steps for safe adoption, organisational preparedness and defence.
8
Preparedness actions identified
The programme brought security leaders together across sectors to compare experience and build a shared view.
7
Major UK companies