Why cyber resilience can’t wait in the age of AI

by Nathan Britton - Security Architecture Lead
| minute read

In summary:

  • AI is accelerating cyber risk by making attacks faster, more convincing and easier to execute, increasing the urgency for organisations to strengthen their cyber resilience.

  • The UK Government’s Cyber Resilience Pledge and the Five Eyes warning reinforce that cyber resilience is no longer just an IT issue. It is a board-level responsibility requiring strong governance, leadership and preparedness.

  • Organisations that focus on cyber security fundamentals, strengthen supply chain resilience and embed cyber risk into business decision-making will be better positioned to protect operations, build trust and adopt AI with confidence.

Recently the UK Government has launched practical initiatives to improve cyber resilience across the economy, while the UK’s closest cyber security allies warn that AI is dramatically accelerating cyber risk. Together, these developments send a clear message: cyber resilience is now a leadership priority, not just an IT concern. With 43% of UK businesses reporting a cyber security breach or attack in the last year, according to the UK Government’s Cyber Security Breaches Survey, the need for stronger resilience has never been clearer. This is reflected in Sopra Steria’s own operational data. In 2024, phishing accounted for 59.9% of the security incidents observed across our customers’ networks, underlining how established attack methods remain highly effective even as AI makes them more convincing and scalable.  

Introduction 

The Five Eyes statement highlights how AI is changing the threat landscape. Threat actors can use AI to automate the discovery, weaponisation and exploitation of vulnerabilities, while AI-generated social engineering and deepfakes make attacks more convincing. Most concerningly, AI lowers the barrier to entry, putting capabilities that were once limited to highly skilled attackers and researchers into the hands of a much broader group. 

By increasing the speed, scale and sophistication of cyber attacks, AI is changing the economics of cyber risk. The message for organisations is clear: cyber resilience must be strengthened now. 

We’re seeing cyber resilience discussions move beyond traditional prevention and recovery towards how organisations can defend against AI-enabled attacks. These discussions are no longer taking place amongst security teams but are becoming a focus for executive committees, with leaders seeking greater assurance that their organisations can identify, withstand and respond to emerging threats. 

 At the same time, the UK Government launched the Cyber Resilience Pledge, which Sopra Steria signed as a founding signatory at 10 Downing Street. The pledge provides a practical framework for strengthening resilience and recognises that cyber resilience is a shared responsibility across organisations, supply chains and impacts the wider economy. 

Together, these developments send a clear message to the boardroom: cyber resilience is not simply a technical discipline; it is an organisational and leadership imperative. Those organisations that act now will be better placed to protect their critical operations, earn the trust of their customers and build reputational advantage. 

The changing pace of cyber risk 

Our cyber teams are seeing criminals use generative AI to strengthen existing attack techniques rather than replace them. It's helping attackers create more convincing phishing emails that are increasingly difficult to spot. In the near term, human expertise will remain important, but AI is already lowering the barrier to entry and increasing the speed and scale at which techniques can be used.  

Frontier AI models will serve to accelerate this shift even further, with the impact likely to be measured in months rather than years. 

The Department for Digital, Culture, Media and Sport (DCMS), providing context to the Cyber Resilience Pledge, noted that hostile cyber activity in the UK is becoming more intense, frequent and sophisticated, with direct harm to businesses and the wider economy. 

Their shared advice is not to reinvent cyber security, but to strengthen the fundamentals with greater urgency. Reducing attack surfaces, improving patching, prioritising risk, reducing reliance on legacy systems, strengthening identity controls and preparing response plans remain essential.  

In our experience, customers are asking more questions about how to identify AI-generated threats, what evidence exists that their controls can detect AI-driven activity, and whether traditional security monitoring remains effective against rapidly evolving attack techniques.  

The Cyber Resilience Pledge extends this focus to supply chains too, encouraging organisations to assess and assure suppliers based on risk and alignment to their own appetite. This is something we’re also seeing across our clients. In several business email compromise cases managed by us in 2024, attackers used compromised accounts belonging to trusted suppliers and partners to send phishing emails. 

The urgency is already visible in vulnerability management. The average time between the disclosure and exploitation of a vulnerability has fallen to just five days. This leaves organisations with a much smaller window in which to identify, prioritise and patch weaknesses. 

The key difference today with the rise of AI is the need for urgency and the message was clear, the time to act is now. 

The need for cyber resilience at boardroom level 

Both the Five Eyes warning and the Cyber Resilience Pledge stress that resilience must be on the boardroom agenda, not just confined to IT. Organisations need to move from a mindset of “if” a breach happens to “when” and broaden their focus beyond protection and detection to include response and recovery. NCSC’s Cyber Assessment Framework describes this as minimising the adverse impact of a cyber security incident and restoring essential functions where necessary. 

The Government's Cyber Resilience Pledge gives organisations practical direction: strengthen governance, improve exec-level cyber awareness, participate in threat intelligence initiatives and enhance assurance across supply chains. These are tangible actions that improve resilience today while preparing organisations for tomorrow’s challenges. 

In order to enable this urgent change accountability must sit with leadership. Boards and senior leaders need to understand cyber risk, challenge current practices, support investment decisions and empower teams to act. The most resilient organisations will be those where cyber risk is part of normal business decision-making, not a specialist topic discussed only in post incident reviews. 

Signing the Cyber Resilience Pledge is therefore an important signal. For organisations such as Sopra Steria, it demonstrates commitment to making cyber a board responsibility, aligning with the Cyber Governance Code of Practice, engaging with NCSC initiatives and strengthening assurance. 

As organisations such as Sopra Steria explore the opportunities of AI while managing the risks it presents, executive leadership is critical.  

Closing 

The combined message from the UK Government and the Five Eyes cyber security agencies is simple and urgent: AI is accelerating cyber risk, and organisations must respond with equal urgency. Technology will play an important role, but resilience ultimately depends on leadership, effective governance and a renewed commitment to security fundamentals. The organisations that succeed will not be those that simply adopt AI the fastest, but those that build the resilience needed to use it with confidence. By signing the Cyber Resilience Pledge, Sopra Steria has reinforced its commitment to that approach, helping to create a more secure, resilient and trusted digital future. 

Search

cyber-security-and-resilience

Related content

Zero Trust Architecture: Building resilient services for today's threats

In this blog, we explore Zero Trust Architecture (ZTA) and its role in strengthening an organisation against modern cyber threats, to improve resilience and increase the flexibility and ability to respond to changes in both threat and risk profile.  

Safeguarding your supply chain in today's dynamic landscape

In a time where supply chain threats are on the rise, the need for robust safeguarding has never been more critical. Read more to find out how to ensure security within your supply chain through four important steps.

Inspiring the next generation of scientists, engineers and tech experts at the Cheltenham Science Festival 2022

Our team enjoyed the opportunity to engage with the next generation of scientists and engineers, experimenting with tech and exploring careers within the exciting worlds of cyber, digital and tech.