LAS VEGAS — Policymakers and business executives need to focus on basic cybersecurity resilience instead of getting distracted by flashy claims about AI-fueled hacking nightmares, a group of senior U.S. and allied government officials said on Wednesday.
“The immediate challenge is not runaway AI,” Jonathon Ellison, director for national resilience at the UK’s National Cyber Security Centre, said during a panel at the Black Hat 2026 cybersecurity conference here. “The immediate challenge is being resilient enough for the faster-paced environment that we are entering into, given the legacy issues that we are carrying.”
Michael Duffy, the acting U.S. federal chief information security officer, said organizations needed to shift from a prevention-focused mindset to one that prioritizes continuity of services.
“Things will go down,” he said, and organizations need to prioritize their most important systems so they can continue delivering on their mission.
The cybersecurity community, he added, needs “a new risk calculus for what it means to operate in a contested environment.”
Artificial intelligence is making hacking easier and could make it more destructive in the near future, the government leaders acknowledged. Even so, hackers don’t need AI to exploit the serious technical and process vulnerabilities that exist inside many businesses and government agencies.
That danger became clear last week after Iran-linked hackers launched cyberattacks against water utilities in at least 12 states. Water systems are some of the most vulnerable infrastructure operators in the U.S. because of their overworked staffs, small budgets, low tolerance for downtime and heavy reliance on aging operational technology.
In recognition of the increasing likelihood that hackers will disrupt critical infrastructure, the U.S. government has recently begun emphasizing resilience as part of its cybersecurity messaging. The Cybersecurity and Infrastructure Security Agency recently launched a program, dubbed CI Fortify, designed to get critical infrastructure operators to prepare for downtime and offline operations.
“Part of this … is intentionally spending resources on harm reduction, not just risk reduction,” said Joseph Alm, the assistant secretary for cyber, infrastructure, risk and resilience policy at the Department of Homeland Security. “Assume that you’re compromised. How do you make sure critical services continue? How do you minimize the time and the challenge from that?”
Other countries have provided a template that the U.S. is seeking to emulate. CI Fortify originated in Australia, and Canada has also begun meeting with critical infrastructure providers to discuss the barest minimum number of systems they would need to continue operating. Rajiv Gupta, the head of the Canadian Centre for Cyber Security, said this “Minimum Vital Canada” initiative was “incredibly important in terms of understanding how to prioritize these systems.”
CISOs need to be talking to other business leaders about how to maintain essential services in the event of a cybersecurity incident, Duffy said. He stressed that effective resilience will require collaboration across business roles and buy-in from senior leaders outside of the cybersecurity organization.
“This is the time,” Duffy said, “for CISOs to be having that level of conversation, to say, ‘This system may go down. What is plan B? How do we ensure that the critical function of the organization can maintain its delivering on the mission regardless of what’s happening to it?’”
No rush to regulate
Even as AI increases security defenders’ anxieties about the dangers of operating vulnerable infrastructure, the Trump administration is not interested in regulating what frontier models can do.
Instead, Alm said, the administration’s goal is “trying to maintain AI dominance and trying to make sure that we don't, in an effort to minimize risk, actually maximize the greatest risk, which is that we lose leadership in AI and that other people define the future for us and we inhabit the world that they create.”
At the same time, he said, it is important that “we put in place sufficient guardrails that we don’t end up creating immense danger.”
Panelists agreed that while AI had not yet caused a devastating cyber crisis, the speed of technological change presented an unprecedented challenge to security leaders and policymakers.
“The stakes,” Ellison said, “are way, way higher than they were before.”