{"slug": "cisos-can-no-longer-ignore-the-nation-state-threat", "title": "CISOs can no longer ignore the nation-state threat", "summary": "CISOs must fold nation-state threats into ordinary risk management and work more closely with the federal government as AI accelerates nation-state threat actor activity, according to Symantec by Broadcom Software technical director Vikram Thakur, Trellix vice president of threat intelligence strategy John Fokker, and Google Threat Intelligence Group chief analyst John Hultquist. US National Cyber Director Sean Cairncross told the Billington Cybersecurity Summit that protecting critical infrastructure requires a \"hand-in-glove\" relationship with private industry. Fokker cited the Netherlands, the world's No. 2 produce exporter, where Chinese threat actors target greenhouse operations and their suppliers to steal technology secrets.", "body_md": "Flare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity landscape, with the balance swinging between deep collaboration and friction.\n\nThe goal of CISOs has typically been to get adversaries out of networks as quickly as possible to contain liabilities, while government responders want to remain longer in compromised systems to watch the adversary and gather intelligence.\n\n“A CISO will say, ‘Get them out of my network right now,’” [Vikram Thakur](linkedin.com/in/vikram-thakur-b201802), technical director at Symantec by Broadcom Software, tells CSO. “The government will say, ‘No, we know they’re there. Leave them there. We want to be able to see what they do.’ So there is no CISO who’s going to say, ‘Yeah, I think we should continue observing them.’”\n\nThe accelerating use of AI by nation-state threat actors is compounding this tension by blurring the distinction between national-security threats and ordinary enterprise threats. These blurred lines don’t mean that CISOs need to embrace more of the functions currently assigned to the NSA or FBI. But they do mean that CISOs must incorporate more geopolitical threats into ordinary risk management and increasingly treat nation-state activity as part of their threat models.\n\nMoreover, according to government officials, they must also work more closely with the federal government as the cyber front becomes faster and more complex.\n\n“The big thing from my perspective and from the president’s perspective is engaging with private industry in a new way,” Sean Cairncross, US National Cyber Director, told attendees at the Billington Cybersecurity Summit earlier this month. “In order to move forward, protect critical infrastructure, and make sure the systems that our citizens rely on for daily life are protected and secure, we need a relationship that is hand-in-glove.”\n\nOne blind spot when it comes to managing nation-state threats is that many organizations do not consider themselves strategic targets of adversarial nations. [John Fokker](https://www.linkedin.com/in/john-fokker-95b614107/), vice president of threat intelligence strategy at Trellix, tells CSO he frequently encounters this mindset.\n\n“The number of times that I’ve been to organizations … and it’s like, ‘Yeah, but why would we be a target of nation-states?’” he says.\n\nFokker points to the Netherlands, which has become the No. 2 produce exporter in the world due to its expertise in optimizing greenhouse technology. As a consequence, Chinese threat actors target greenhouse operations and their suppliers to steal their technology secrets.\n\n“So that whole industry was like, ‘Hey, I just grow tomatoes,’” Fokker says. “‘I have Windows 95, and I don’t have it patched. I don’t care about IT or whatever.’”\n\nThe challenge for most CISOs is to identify whether and to what degree their research, contracts, customers, suppliers, infrastructure, or access make it strategically relevant to foreign threat actors, because nation-states are continuously trying to figure that out, too.\n\nIdentifying nation-state intrusions can be a challenge given that threat actors are not as noisy as cybercriminal actors. They operate in stealth mode to give them as much cover as possible, [John Hultquist](https://www.linkedin.com/in/john-hultquist-76226478/), chief analyst of Google Threat Intelligence Group, tells CSO.\n\n“Just because you haven’t necessarily seen these incidents, [doesn’t mean] you won’t be affected by them,” Hultquist says.\n\nAI is going to make threat actors even more effective, raising their ability to quietly pre-position themselves within organizational assets. “Given the ability of AI to sort of help them troubleshoot technical problems, they’re simply going to be better at it than they were in the past,” Hultquist says.\n\nGovernment leaders at the Billington Summit cited potential threats from China in particular as a prominent concern driving why they were exhorting the private sector to up its defense game against nation-states.\n\n“What are we going to do [in a] situation [where] we see the Chinese moving to take significant action in cyberspace to degrade our civilian critical infrastructure?” Nick Andersen, acting director and deputy director for the Cybersecurity and Infrastructure Security Agency (CISA), said at the event.\n\n[Charles Carmakal](https://www.linkedin.com/in/charlescarmakal/), CTO of Mandiant Consulting, connects the concern to uncertainty about how the United States would respond to a Chinese attack on Taiwan. “We see a lot of intrusion activity by Chinese actors into organizations where we know they can disrupt critical infrastructure and do a lot of bad things, but we don’t see them doing it,” Carmakal tells CSO. “The question is, does something change from a geopolitical perspective that makes them want to change?”\n\nAI hasn’t changed the geopolitical objectives behind nation-state intrusions, but it has changed how quickly and broadly adversaries can act.\n\nAlthough some experts fear that AI technology could usher in an autonomous war in cyberspace, a more realistic impact is that it could lower the threshold for malicious activity.\n\n“While we’re talking about the defensive side, we’ve seen evidence that attackers have also been adopting AI into their own workflow, which ultimately could be seen as the bar for a nation-state-level sophistication of an attack has gone down,” Symantec’s Thakur says.\n\nMaking the challenge greater, AI can enable lots of threat actors — even relatively amateurish cybercriminals — to launch what might appear to be a sophisticated nation-state attack. “If that bar has gone down, all CISOs across the board should be looking and saying, ‘Wow, now even the credit card thieves look like nation-state attackers; I need to be able to up my game,” Thakur says.\n\nAiding the sophistication upgrade of both nation-states and cybercriminals is the widespread availability of top-level, open-weight AI models out of China. David Wong, a director at Mandiant, Google Cloud, said on a panel at Google’s Cyber Defense summit last week, “Imagine a world where you have a nation-state that’s using an open-source or an open-weight model and it’s pointing it at critical infrastructure.”\n\nAI is compressing the interval between vulnerability disclosure and exploitation to minutes or seconds, potentially outrunning conventional patching processes.\n\n“A friend of mine once told me, in talking about this North Korean actor, ‘This guy, every day he wakes up and sees if there’s a zero-day or whatever in these appliances, and he just starts running on it,” Google’s Hultquist says. “The future is, he won’t have to wake up because the agent will have already run all that. He can pull himself out of the cycle and speed it way up.”\n\nThe compressed time frame makes patching alone inadequate to fight off nation-state threats, given that the few seconds between discovery and exploitation leave organizations with no realistic ability to patch in time. “You only have to open the window a couple of seconds, and somebody is in,” Trellix’s Fokker says.\n\nAlthough preparing for nation-state attacks in the AI era is no simple task, experts offer four immediate actions CISOs should consider.\n\nThe first is to calibrate the threat without waiting for truly autonomous AI attacks to occur. In fewer than 10% of Mandiant’s current incident-response cases, roughly 90% or more of the intrusion activity was agentic or AI-enabled, Mandiant’s Carmakal says.\n\nAI is already present in many attacks, but predominantly autonomous intrusions remain uncommon, as Carmakal’s estimate suggests. CISOs should prepare for far greater speed and scale as the percentage of fully agentic attacks rises.\n\nThe second task for CISOs is to plan to operate through a compromise. CISOs should determine whether critical operations can continue if corporate IT must be isolated, credentials revoked, cloud services interrupted, or outside infrastructure unavailable.\n\nCybersecurity leaders should rerun exercises without declaring prolonged power, telecommunications, water, cloud, or supplier disruptions out of scope. “We probably sat through business continuity exercises and tabletop exercises where we would very conveniently hand-wave away a lot of the difficult problems,” CISA’s Andersen said. “That’s no longer sufficient.”\n\nThe third task is to reduce exposure and compress decision time wherever possible. “A lot of the core security controls that you have in the non-AI world help with AI attacks — things like zero trust, things like MFA, things like limiting the amount of data that you have online,” Mandiant’s Wong said.\n\nFinally, as is true for almost everything a CISO does, it’s critical to seek C-suite and board-level direction. Experts say that nation-state resilience cannot be an unfunded mandate placed on Boards, and CEOs must authorize the investment, operational interruptions, and cross-enterprise planning required to make resilience real.\n\n“There are a lot of CISOs who know exactly what they need to do,” Trellix’s Fokker says. “They just need to be empowered to do so.”", "url": "https://wpnews.pro/news/cisos-can-no-longer-ignore-the-nation-state-threat", "canonical_source": "https://www.csoonline.com/article/4224629/ai-reshapes-the-nation-state-threat-landscape-for-cisos.html", "published_at": "2026-09-22 08:25:00+00:00", "updated_at": "2026-09-22 08:55:05.711222+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "artificial-intelligence"], "entities": ["Vikram Thakur", "Symantec by Broadcom Software", "John Fokker", "Trellix", "John Hultquist", "Google Threat Intelligence Group", "Sean Cairncross", "Billington Cybersecurity Summit"], "alternates": {"html": "https://wpnews.pro/news/cisos-can-no-longer-ignore-the-nation-state-threat", "markdown": "https://wpnews.pro/news/cisos-can-no-longer-ignore-the-nation-state-threat.md", "text": "https://wpnews.pro/news/cisos-can-no-longer-ignore-the-nation-state-threat.txt", "jsonld": "https://wpnews.pro/news/cisos-can-no-longer-ignore-the-nation-state-threat.jsonld"}}