How? Use automated detection, enforce AI usage policies, segment networks, verify requests via separate channels, monitor anomalies, strengthen access controls…
Recent trends indicate that large-scale DDoS attacks can reach tens of terabits per second, and many incidents are short-lived, sometimes lasting only minutes. This reduces the effectiveness of purely manual response models, and increases the importance of preconfigured and automated controls.
At the same time, organizations face a growing internal risk surface. The use of unsanctioned AI tools — often called “shadow AI” — introduces potential data leakage pathways, particularly when employees input sensitive information into external systems without oversight.
Social engineering has also evolved, with attackers using synthetic media to impersonate trusted individuals.
While attack techniques evolve, defensive fundamentals remain relevant, but must be adapted to higher speed, scale, and complexity.
Practical security measures
To address this landscape, here are some cybersecurity best practices to review and implement:
(Editor’s note: The security measures below reflect a general industry view of current threats and should be assessed alongside independent guidance and local operational needs.)
- Deploy automated detection and response controls for high-volume threats, ensuring predefined rules can trigger mitigation (e.g., rate limiting, traffic filtering) without waiting for manual intervention.
- Maintain human oversight of automated systems, including audit trails and rollback mechanisms, to reduce the risk of false positives or unintended disruptions
- Segment networks and isolate critical systems to limit the blast radius of DDoS attacks or lateral movement following initial compromise
- Continuously monitor for anomalous traffic patterns using baselining, rather than relying solely on static thresholds
- Establish visibility across all cloud and SaaS applications in use, including unsanctioned tools, to reduce blind spots in data flows
- Implement data loss prevention or equivalent controls that can detect and block sensitive data being shared with external AI services
- Define and enforce an AI usage policy, including approved tools, acceptable data inputs, and logging requirements for auditability
- Train employees to verify high-risk requests (e.g., financial transfers, credential sharing) using out-of-band communication channels such as separate messaging platforms or phone verification
- Introduce shared verification protocols for executives and finance teams, such as pre-agreed authentication phrases or transaction approval workflows
- Harden identity and access management with multi-factor authentication and least-privilege access, especially for accounts with financial or administrative authority
- Regularly test incident response procedures against short-duration, high-impact scenarios to ensure teams can act within compressed timeframes
- Encrypt sensitive data both at rest and in transit, while minimizing unnecessary data retention to reduce exposure in case of exfiltration
- Monitor for data exfiltration attempts, not just encryption activity, as modern attacks focus on theft rather than disruption
- Evaluate backup strategies alongside data access controls, ensuring backups cannot be easily accessed or exfiltrated by attackers
- Track developments in post-quantum cryptography and begin inventorying cryptographic assets to prepare for future migration needs
Evolving operational approach
Automation can improve response speed, but it is most effective when paired with governance, visibility, and well-defined escalation paths. Security teams should treat AI and automation as force multipliers rather than replacements, ensuring that critical decisions remain reviewable and accountable.
The current threat landscape is defined less by any single technique and more by the convergence of scale, speed, and deception.
Organisations that adapt their processes to operate within those constraints — particularly by reducing decision latency and tightening data controls — will be better placed to manage both external attacks and internal risk exposure.
