An Ernst & Young (EY) study warns that cyberattacks powered by artificial intelligence (AI) are becoming more sophisticated. Attackers using advanced tools are often not targeting only the highest-value systems directly; instead they exploit weaker entry points and then move laterally across interconnected networks.
Which areas are most vulnerable?
The analysis finds that companies are particularly exposed through technologies that support daily operations and through physical devices accessible online. The digital environments shared with external partners, AI-based solutions, and network infrastructure also carry significant risk.
According to the study, an average of 36% of corporate digital assets fall into a vulnerable category — devices and resources lacking sufficient security monitoring and protection. EY describes these areas as vulnerability zones or "blind spots."
Blind spots: concerns from security leaders
More than two-thirds of the surveyed cybersecurity leaders said that blind spots within their organizations represent the greatest danger, because these are areas where security teams lack adequate visibility. Such blind spots encourage attackers to enter through less-secured points and then propagate through corporate networks.
How AI changes the threat landscape
"The emergence of artificial intelligence in cyberattacks has created a new situation that most companies are not fully prepared for. It is no longer enough to protect only the most important systems: the security of the entire digital operation must be guaranteed. Companies can do that only if they can assess what threat an AI-driven hacking attack might pose to their organization," said Erik Slooten, EY AI Confidence partner.
EY argues that the traditional approach—focused mainly on recovery after breach attempts—is no longer sufficient. Decision-makers must also determine which business processes must remain operational under any circumstances in the event of a major cyber incident to ensure continued service to customers.
Recommendations: priorities for the next months
Zala Mihály, partner at EY, recommends that over the next 12–18 months companies concentrate on:
- improving visibility across the full asset estate;
- addressing the most critical security gaps;
- deploying AI-based defensive solutions;
- strengthening protection of external partners and network infrastructure.
Zala says firms that integrate security into the organization’s day-to-day operations, rather than treating it solely as a technical task, will be better prepared for the challenges ahead.
Implications
The EY analysis highlights that the spread of AI technologies brings new defensive capabilities but also advances attackers’ methods. For companies, mapping blind spots and reducing risks—especially those propagated via network connections and third-party relationships—are strategic priorities.



