Skip to Content
OPINION

Thought for the week: AI-enhanced nation state cyber threats may be systemic

As AI-enhanced threats grow, organizations should continue shifting the balance toward stronger security and monitoring controls.

Published
Subscribe to IAPP newsletters

Contributors:

Brian Hengesbaugh

CIPP/US

Global Chair, Data and Cyber

Baker McKenzie

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

This article is part of an ongoing series that will explore issues or recent developments in data, cybersecurity and artificial intelligence governance.

To begin your week, I recommend reading this recent Cybersecurity and Infrastructure Security Agency advisory detailing malicious cyber activity targeting more than 100 internet-exposed systems in the Water and Wastewater Systems sector in July 2026. The advisory points to various steps for organizations in the WWS sector to reduce internet exposure, and secure remote access to operational technology environments. 

A TechCrunch article reporting on the advisory further explains that U.S. intelligence agencies believe Iran is likely behind the attacks in response to the U.S. and Israel-led strikes against Iran, noting more broadly that: "U.S. officials have warned in recent years that hackers working for China have been planting destructive malware on critical infrastructure ready to activate as a distraction in the event of an anticipated Chinese invasion of Taiwan. Russia has also been linked to several cyberattacks on water providers, and power and energy grids, across Europe as part of a growing campaign seen as aimed at testing the NATO alliance."

Several observations on these developments

AI-enhanced nation state cyber threats may be systemic

We have long been concerned that cyber risks due to nation-state actors are probably more pervasive than organizations realize. In fact, with the availability of AI-enhanced cyber tactics, techniques and procedures, nation states may have accumulated footholds on a systemic basis across key industry verticals. The reality has always been asymmetry in the cyber world, meaning that the company always needs to be right 100% of the time to be secure, whereas the threat actors only need to be right once to succeed with network access. When a nation-state threat actor with its resources — now with enhanced AI capabilities — wishes to gain a foothold in a private sector or other organization, it may be virtually impossible for the organization to resist or even know that they have been compromised.

Kinetic war is a green light for nation state cyberattacks

With the kinetic strikes against Iran, it is logical that Iran would have unleashed its offensive cyber capabilities to attack U.S. and Israeli companies and other interests. We are seeing at the surface some of the results of those attacks and more may be bubbling under the surface. These and other developments have been drivers for recently announced policy changes the U.S. government will use its cyber capabilities for both offensive and defensive missions.

Increased geopolitical risk can be a soft trigger

The broader concerns are that larger nation states with more resources than Iran, such as Russia or China, could be more effective in leveraging existing footholds, or creating new ones, to carry out AI-enhanced cyberattacks. Such attacks certainly would be initiated if we ever reached a kinetic war with such nations but could also conceivably be activated in a quieter manner as a result of increased geopolitical tension. Such increased tension could come in various shapes and sizes, and nation states would be unlikely to provide any warning before carrying out such attacks.

How should organizations respond from an overall enterprise risk standpoint?

Re-evaluate cost/benefit analysis of strengthened security and monitoring controls

At the enterprise level, companies typically need to balance various factors in relation to security and monitoring controls. Factors supporting enhanced security and monitoring controls include compliance with affirmative legal obligations, such as federal, state, and non-U.S. privacy, cyber, and other laws, contractual duties, business needs to assurance of confidentiality, availability, and integrity of company assets, and the like. 

On the flip side, factors against investment can include cost, operational burden, such as ease of customer use, privacy and data issues with monitoring employees and other users' access to systems. The reality with the overall AI-enhanced nation state and other cyber threats is that organizations should generally dial-up more security and monitoring controls, and "sharpen the pencils" to figure out how to manage the associated cost, operational burden and privacy/data monitoring risk.

Assure alignment between legal and compliance and information security

Legal and compliance leaders within the organization should assure alignment with information security leaders when making proposals to senior leadership wherever possible. Working together, these different functions can help address potential business concerns with investments in increased security and monitoring controls and assure better protection overall for the company. Stated differently, if legal and compliance is at odds from an internal rivalry or other interpersonal perspective, this can make it difficult for senior leadership to acquire a clear understanding of risks and allocation of resources.

Shift the organizational mindset even more toward security

The reality is that many organizations, particularly those that have experienced significant cyber incidents, have already shifted their mindset toward security. Given today's AI-enhanced cyber risks, however, all organizations should be evaluating how to press even more toward security. 

It is sometimes difficult to measure return on investment with enhanced security controls, because the security team needs to prove the negative. For example, "Because we've implemented phishing-resistant MFA using FIDO2 security keys, we have not become victim to credential harvesting." This may not be easy for senior leadership to understand, but it is real and increasingly a mission-critical task.

Contributors:

Brian Hengesbaugh

CIPP/US

Global Chair, Data and Cyber

Baker McKenzie

Tags:

Cybersecurity law

Related Stories