AI amplifies and automates cyberattacks, forcing organizations to adopt cyber resilience that integrates prevention, advanced detection and rapid recovery.
According to the National Information Systems Security Agency (Anssi), the cyber threat continues to intensify in France. In his last Overview of the cyber threatAnssi indicates having processed 4,386 security events during the year, confirming high pressure on French organizations, in particular via ransomware and remote access compromises.
This dynamic is worrying. While a large proportion of these attacks still rely on social engineering or phishing campaigns targeting individuals, the worrying prospect for the future is that advances in AI will allow cybercriminals to fully automate cyberattacks, without any human intervention, at unprecedented speed and scale.
AI as a weapon and “vibe hacking”
In the summer of 2025, Anthropicthe company behind the Claude family of large language models (LLMs), said agentic AI has become “weaponized” to carry out cyberattacks and is now integrating into cybercrime practices. Called “vibe hacking,” this approach involves attackers using LLMs and other AI tools to automate and deploy cyberattacks on a large scale. Automated phishing, adaptive malware, and AI-generated ransomware are becoming common.
These alerts echo the analyzes published in France. ANSSI emphasizes that artificial intelligence constitutes both a defensive lever and a threat amplification factor, in particular by facilitating the automation, personalization and optimization of attacks. The French authorities also warn of a risk of a growing gap between organizations capable of adapting their systems to evolving threats and those whose security systems remain insufficiently mature, particularly among SMEs and local authorities.
Faced with the emergence of an AI threat landscape that is now inevitable, what can organizations do? AI is accelerating the sophistication, scale and automation of cyberattacks. In this context, traditional cybersecurity tools, focused solely on prevention and detection, are no longer enough. This means that organizations must not only plan how to prevent an attack, but also how to recover from it, quickly and securely. This is the whole challenge of cyber-resilience.
Cyber resilience emerges as a critical strategy
The concept of cyber resilience integrates traditional attack prevention and detection with extremely rapid recovery capability. It is based on a holistic approach that includes integrated data storage security, connected threat detection, and dynamic response and recovery. Given the breadth of capabilities required to deliver holistic cyber resilience, this is ideally delivered by a “best of breed” vendor ecosystem, supported by integrated products and proven architectures.
A secure data platform
Ensuring that the foundations of the data environment have a high level of security is essential to preventing an attack or reducing the attack surface. Rapid remediation of vulnerabilities, multi-factor authentication, as well as the implementation of simple and effective data snapshots, benefiting from comprehensive protection, which are both immutable and indelible, contribute to a secure foundation offering the assurance that a recovery point is available. The ability to operate the platform with automated, policy-managed configuration and effective compliance controls to prevent human errors that compromise data integrity.
Connected threat detection
Understanding the entire technology landscape is essential. The ability to distinguish signal from noise and quickly identify malicious activity relies on extended detection and response (XDR), security information and event management (SIEM), and security orchestration, automation, and response (SOAR) solutions. Ensuring that the storage platform integrates with these platforms is critical to providing visibility and correlation with the rest of the connected environment. Integrating telemetry data from storage allows these solutions to automatically trigger and label snapshots when anomalies occur.
Dynamic Response and Recovery
If the worst happens and an attack manages to disrupt the IT environment, a Secure Isolated Recovery Environment (SIRE) is an essential part of the recovery process. Having a set of data out of reach of attackers, disconnected from the rest of the information system, provides an environment dedicated to forensic investigation, cleanup and restoration of the affected environment for the most critical services of the company. Time is of the essence in this process, the ability to quickly restore and analyze with a high-performance storage platform is critical to successful business recovery. The recovery environment will typically support multiple capability levels aligned with the criticality of different business services in order to achieve recovery objectives.
Don’t find yourself on the wrong side of the digital divide
The accelerating speed of cyber threats greatly reduces response times. Organizations must be able to recover in hours rather than days or weeks if the worst happens.
We face a digital divide between organizations that have effective cyber resilience as a strategic differentiator and those that do not. As recent attacks have shown, the consequences of an ineffective strategy include significant financial losses, reputational damage, and business disruption.
Don’t find yourself on the wrong side of the digital divide. A relevant first step towards developing cyber resilience is to focus on deploying an interconnected ecosystem to provide a secure data platform, connected threat detection, and dynamic response and recovery.