Safety

AI Accelerates Cyber Risk; Firms Have About 12–18 Months to Prepare

A new global EY study warns that rapid advances in artificial intelligence are increasing the sophistication and reach of cyberattacks, while many corporate assets remain exposed.

AI Accelerates Cyber Risk; Firms Have About 12–18 Months to Prepare

A new global study from EY (Ernst & Young) finds that rapid advances in artificial intelligence (AI) are making cyber threats more dangerous, while a substantial share of corporate digital assets remains exposed to intrusion. The report warns that online criminals can readily exploit organizational vulnerabilities, and decision‑makers have at most 1.5 years (12–18 months) to prepare for next‑generation attacks.

How attacks are evolving

According to the EY analysis, AI‑based cyberattacks are becoming increasingly sophisticated. Attackers using advanced technology no longer focus solely on the most valuable systems; instead they often gain entry via weaker, less protected points and move laterally across connected networks.

Where the risks concentrate

The study identifies the technologies that support day‑to‑day operations and internet‑accessible physical devices as particularly vulnerable. Shared digital environments with external partners, AI‑driven applications, and network infrastructure also pose significant risk.

More than two‑thirds of surveyed cybersecurity leaders said the greatest threat comes from internal blind spots — areas where security teams lack sufficient visibility. EY labels these areas "vulnerability zones": assets that do not receive adequate security monitoring and protection. On average, 36 percent of organizations' digital resources fall into this vulnerable category.

Recommended actions for companies

EY cautions that traditional approaches focused mainly on post‑incident recovery are no longer adequate. Executives must identify which business processes must be maintained under any circumstances in the event of a major cyber incident so they can continue serving customers.

"The arrival of artificial intelligence in cyberattacks has created a new situation that most companies are not fully prepared for. It is no longer enough to protect only the most critical systems: the security of the entire digital operation must be guaranteed. That will be possible if they can assess what threat an AI‑driven hacker attack could pose to their organization," said Erik Slooten, partner for EY AI Confidence.

Zala Mihály, partner at EY, said that over the next 12–18 months companies should prioritize:

  • improving visibility across their entire asset inventory;
  • addressing the most significant security gaps;
  • deploying AI‑based defensive solutions;
  • strengthening protection for external partners and network infrastructure.

He added that organizations that treat security as an integral part of overall operations rather than merely a technical task will be better prepared for the coming years' challenges.

Timing and implications

EY's analysis makes clear that organizations face a limited window to strengthen defenses. The report's figures and expert recommendations indicate the 12–18 month period is critical: during that time firms should improve visibility, reduce blind spots, and integrate modern AI‑driven security measures to lower the risk posed by the new generation of cyberattacks.