Menu Customer section

Uncategorized 4 min

September 2026: Business cyber resilience — how AI is changing cybersecurity


Cyberattacks have changed in recent months not only in volume, but above all in how they are carried out. Attackers increasingly target identities, access tokens, cloud permissions and the supply chain itself. AI is also playing a growing role — for defenders and attackers alike. Czech organisations face another important shift: following the introduction of the new Cybersecurity Act, attention is gradually moving from compliance to genuine resilience.

A few years ago, a typical cyberattack was relatively easy to explain: a phishing email, a stolen password, malware and an attempt to move deeper into the infrastructure. That model has not disappeared. It simply no longer captures everything that is happening today.

Recent incidents and analyses point to several changes that Czech businesses should pay attention to. Attackers are looking for ways to bypass multifactor authentication, exploit legitimate cloud identities, infiltrate software development pipelines and use AI across more stages of an attack.

MFA alone can no longer stop an attack

This shift is illustrated by the EvilTokens phishing platform, which Microsoft analysed in detail in September. According to its analysis, more than 12,000 email accounts across over 10,000 organisations were compromised. Yet the method is more revealing than the scale.

The attackers exploit the device-code authentication flow. They do not necessarily need to obtain a user’s password or technically “break” MFA. Instead, they can persuade the victim to authorise access that the attackers then exploit. A stolen access token can open the door to email and other services. AI also helps personalise phishing messages and analyse compromised mailboxes.

The security question therefore changes from “Do we have MFA?” to “Can we detect the misuse of legitimate identities and permissions?”

When an identity does not belong to a person

An even more significant shift is illustrated by Storm-3168, an actor Microsoft described in connection with attacks on Azure cloud environments. The attackers used compromised service principals — identities used by applications and services rather than people.

This was followed by extensive operations against cloud resources, from databases and virtual machines to Key Vault and mechanisms designed to protect recovery capabilities.

For businesses, the implication is clear: identities are no longer just employees and their accounts. Corporate infrastructure contains thousands of other identities — applications, APIs, automated processes, cloud services and, increasingly, AI agents. Each can hold permissions, and each can become a route into an organisation. As agentic AI develops, managing these permissions will become even more important.

Attackers also target how software is built

The supply chain is another major area of concern. Google Threat Intelligence Group has highlighted attacks targeting development environments, CI/CD infrastructure, security tools and software libraries. Targets can include access tokens, build processes and the very mechanisms intended to establish trust in the resulting software.

Supply-chain security is therefore no longer only about asking, “Is our supplier secure?” Increasingly, organisations need to ask, “Do we know how the software we use is built, who can influence that process, and what happens if any part of it is compromised?”

This is where supply-chain management, vulnerability management, software bills of materials (SBOMs), threat intelligence and continuous infrastructure monitoring come together.

The Czech picture: less visible does not mean less dangerous

Czech data also show an interesting shift. In its August statistics, the Czech National Cyber and Information Security Agency (NÚKIB) recorded 28 cybersecurity incidents, more than two-thirds of which were classified as intrusions. Nine incidents were rated significant. By contrast, no DDoS incident affecting availability was recorded.

This does not mean that DDoS has ceased to be a threat. It does, however, highlight an important distinction between a visible attack and an unnoticed compromise. A website outage is immediately apparent. An attacker moving inside infrastructure can remain undetected for much longer.

That is why network visibility, network detection and response (NDR), identity management and threat intelligence are becoming more important: they help organisations see not only an incident itself, but also the signals that precede it.

From legal compliance to genuine resilience

Regulation is gradually moving in the same direction. In the Czech Republic, the main question is no longer whether NIS2 and the new Cybersecurity Act are coming. Affected organisations are entering the practical phase: what exactly must change in their infrastructure, processes and risk management?

NÚKIB’s September Cyber Security Boost call illustrates this shift. Among other areas, it supports projects focused on compliance and risk management, supply-chain security, SBOMs, vulnerability management, incident response and recovery.

The common denominator is resilience. Documentation, a firewall or a completed checklist are not enough. Organisations need to understand what is happening in their infrastructure, recognise unusual behaviour, manage access and be ready to respond when protective measures fail.

And now autonomous networks are arriving

AI is not only changing attacks. Enterprise networking is also undergoing a significant transformation. After years of AIOps, automation and scripting, platforms are emerging that can continuously analyse networks, identify the causes of problems, propose changes and increasingly carry out certain operations independently.

This raises another security question: what should AI be allowed merely to recommend within enterprise infrastructure, and what should it be allowed to do on its own?

More autonomous networks bring more than greater efficiency. They also increase the importance of governance, identity, permissions and oversight of automated decisions.

Cybersecurity in 2027 will not depend on a single product

Current developments point to a fairly clear picture. The perimeter has not disappeared. Firewalls remain important. MFA is still an essential security measure. But individual layers are not sufficient on their own.

Organisations need to combine infrastructure protection, network visibility, identity management, threat intelligence, data security and incident response capabilities.

Above all, they need to know what they are protecting, why they are protecting it, what is happening in their environment and how they will respond if one of those protective layers fails. This is where the difference between compliance alone and genuine cyber resilience is becoming most apparent.


Loading…