Intelligent CISO Issue 95 | Page 15

COVER story

As cyberthreats grow more autonomous and sophisticated, organisations face an escalating battle against AI-driven attacks, deepfakes and evolving fraud tactics. Paul Tucker, Chief Information Security and Privacy Officer at BOK Financial, a top 25 U. S.-based bank, tells us how businesses can prepare for 2026 by adopting Zero Trust strategies, leveraging defensive AI and strengthening cyber resilience across people, processes and technology.

HOW AI-DRIVEN CYBERTHREATS WILL RESHAPE SECURITY STRATEGIES

What emerging cyberthreats do you think will define 2026, and how might they differ from those we’ re seeing today?
In 2026, AI-augmented threats will dominate the landscape. These threats feature unprecedented autonomy, scale and adaptability. This marks a clear distinction from today’ s more manual or scripted attacks. Key emergents include AI agent swarms capable of self-coordinating reconnaissance and exploitation, such as multi-stage attacks without human oversight.
Polymorphic ransomware will evade signaturebased detection through real-time code mutation. Supply-chain compromises will target large language models via LLM poisoning with adversarial prompts in third-party services.
Quantum-enabled cryptanalysis will also begin transitioning from theoretical to operational risks, particularly against asymmetric algorithms.
According to ENISA’ s Threat Landscape 2025, AI-driven attacks already account for over 40 % of advanced persistent threats. By 2026, their velocity will increase by orders of magnitude due to accessible open-source agent frameworks.
Traditional vectors like ransomware persist but evolve with triple-extortion tactics incorporating AI-generated harassment. Defenders must shift from reactive postures to proactive, AIorchestrated resilience aligned with NIST Cybersecurity Framework 2.0.
How do you expect the use of Artificial Intelligence by both attackers and defenders to evolve in the coming year?
The AI arms race will intensify in 2026. Attackers will achieve greater autonomy through agentic systems, which are self-improving entities that chain tools for end-to-end campaigns.
WWW. INTELLIGENTCISO. COM 15