Cyber Resilience

Cutting through the noise: Cyber resilience in an AI-powered world

By
4 October 2026

Last month was a noisy one in the world of AI.

A global debate was sparked, almost overnight, about the existential crisis posed by AI and how the technology could “kill us all” within a decade. That claim was made by an ex-Anthropic researcher, and it wasn’t long before the company’s CEO – along with other AI and tech leaders – came out publicly to urge a “slowdown” in AI development.

World leaders soon entered the debate. Such was the perceived gravity of the situation that King Charles called an urgent summit of AI executives from around the world, warning them of the need for the technology to be reined in.

A lot has been said about the motives of different camps in the debate, and how much of it is grounded in reality versus hype. Amid the speculation, AI is clearly here to stay – and its impact on cybersecurity is very real.

With Cyber Smart Week 2026 this week (5-11 October), it is a good time to take stock of exactly what is happening with AI, how it is changing the face of cybersecurity, and what directors can do to protect their organisations and stay cyber resilient.

AI’s influence on cyber security has been a concern for some time now, including in New Zealand. Kordia’s 2026 New Zealand Business Cyber Security Report, released near the start of the year, found:

  • The number of cyberattacks carried out through AI vulnerabilities in New Zealand has more than doubled, from 6% in 2024 to 14% in 2025.
  • Nearly a quarter (24%) of businesses say staff using AI improperly is one of their biggest cybersecurity challenges.

Those are alarming figures. While there is a lot of talk about how quickly cyber threats will evolve along with AI, there is one important thing to remember: most cybercriminals are still relying on familiar attack methods – such as phishing and social engineering – that have been around long before the advent of AI.

For example, our research found email phishing was the most common way businesses in New Zealand were compromised, and by some margin. Nearly half (45%) of businesses that suffered a cyberattack were breached through email phishing.

AI isn’t necessarily inventing new attack methods at pace. Rather, it is simply increasing the speed and scale at which criminals carry out these tried-and-tested attacks.

A sobering example is time-to-exploit – the duration between when a software vulnerability is publicly disclosed and when attackers first weaponise it in the wild – has shrunk dramatically. This used to take a matter of months; now it is only around 29 minutes on average.

In a world where the timeframe for cyberattacks is becoming exponentially shorter, what should directors do?

  1. Don’t panic. While AI is certainly growing as a tool for threat actors, it is also helping cybersecurity professionals work smarter and faster to combat those threats. A good cybersecurity advisor will stay on top of the latest developments and break down what they mean for your organisation and how to stay protected.
  2. Remember that the fundamentals still matter. Much of good cybersecurity practice is simply about doing the basics and doing them really well. Many cyber incidents stem from basic controls not being implemented or maintained, not novel threats created by AI. This includes things such as multi-factor authentication, patching, identity controls, having an incident response plan, and good security hygiene.
  3. Take a balanced approach. Don’t let the latest headlines scare you away. It is important to understand how it is being used in your organisation so you can quantify the risk. Organisations should also encourage and enable responsible adoption, while strengthening their existing security fundamentals and ensuring appropriate governance is in place.
  4. Think in terms of cyber resilience, not just prevention. One of the best ways to prepare is to assume an incident may occur and ask the right questions, such as how quickly can we detect and contain an incident? How quickly can we recover? Is our incident response plan practical, tailored to our organisation and regularly tested? These sorts of questions should be asked at the highest levels of the organisation.

Cyber Smart Week is New Zealand’s annual health check on our cyber resilience as a nation. It’s particularly timely this year, as the world grapples with the future of AI and the opportunities and threats that come with it.

Staying on top of AI-related cyber threats – this year and beyond – begins with getting the basics right and ensuring cyber resilience is a priority topic in the boardroom.

This article originally appeared on the Institute of Directors (IoD) website. Kordia is proud to be the National Cyber Security Partner for the IoD.

kordia-feat_Secure AI Services-min