AI is fundamentally changing the cyber threat landscape. 

While organisations are rapidly adopting artificial intelligence to improve productivity and accelerate transformation, cyber criminals are using the same technologies to launch faster, more sophisticated attacks.

In this webinar, RSM Australia's Kaustubh Vazalwar (Director, Cyber Security, Data Privacy & Operational Resilience) and Michael Clark (Director, Business Transformation) explore how AI is reshaping cyber risk, why traditional incident response plans are no longer enough, and what organisations can do to strengthen governance, resilience and decision-making. 

Through practical examples, real-world case studies and actionable recommendations, they explain how leaders can close the gap between understanding AI risks and responding effectively when an incident occurs.

Remote video URL

 Webinar Transcript 

Introduction

 

Kaustubh Vazalwar:

Good morning everyone, and welcome to today's webinar on AI-accelerated cyber incidents and closing the response gap.

My name is Kaustubh Vazalwar, Director of Cyber Security, Data Privacy and Operational Resilience at RSM Australia. Joining me today is my colleague Michael Clark, Director in Business Transformation.

Over the next 40 minutes, we'll explore how artificial intelligence is changing the cyber security landscape, what organisations should be doing differently, and how leaders can prepare for the increasing speed and sophistication of cyber threats.

By way of introduction, I've spent more than 23 years helping organisations manage cyber security, privacy and operational resilience risks. I work closely with executives and operational leaders to strengthen governance and align cyber security with broader business strategy.

Michael Clark:

Thanks, Kaustubh.

I'm a Director within RSM's Business Transformation practice, where I help organisations improve performance through changes across people, process and technology.

Our work focuses on helping organisations become more efficient, productive and competitive by aligning technology strategy with business strategy and delivering large-scale transformation programs across government, private sector and not-for-profit organisations.

Kaustubh:

Today's discussion brings together two important perspectives.

On one hand, organisations are rapidly adopting AI to transform how they operate. On the other, cyber threats are evolving just as quickly.

Most organisations understand that AI has changed cyber risk. Boards are discussing it, executives recognise it, and cyber security appears on organisational risk registers.

However, understanding the risk is only part of the challenge.

The real question is:

Can your organisation respond quickly and effectively when an AI-enabled cyber incident occurs?

Understanding risk and responding under pressure are two very different organisational capabilities.

Today's webinar focuses on building that response capability.

We'll cover:

  • The changing cyber threat landscape
  • The AI response gap
  • Practical governance and resilience strategies
  • Industry case studies
  • Key actions organisations can take immediately

We'll also leave time for questions at the end.

One of the key questions organisations should be asking is:

Are we actually ready?

Not simply whether we've passed an audit or have documented controls—but whether we could successfully respond if an AI-enabled cyber attack occurred at 4:00 pm on a Friday afternoon.

Would we have:

  • the right people,
  • the right processes,
  • the right technology,

working together quickly enough to make a difference?

Today's threat landscape includes:

  • AI-augmented attacks
  • Prompt injection
  • Supply chain compromise
  • Advanced ransomware
  • Denial of Service attacks

These threats require organisations to think beyond traditional cyber security.

AI should not be viewed as simply another technology initiative.

It affects every aspect of organisational risk, including:

  • Strategic risk
  • Financial risk
  • Operational risk
  • Legal and compliance risk
  • People and culture
  • Supply chain
  • Privacy
  • Cyber security

Rather than creating an entirely new category of risk, AI acts as a risk multiplier across existing enterprise risks.

This has significant governance implications.

If AI governance sits solely within IT or innovation teams, organisations risk overlooking broader legal, financial, operational and cultural impacts.

AI offers enormous benefits for cyber defence.

It improves:

  • Threat detection
  • Behavioural analytics
  • Vulnerability prioritisation
  • Security reporting
  • Operational efficiency

However, the same technology benefits attackers.

We're seeing:

  • AI-generated phishing
  • Deepfakes
  • Adaptive malware
  • Prompt injection
  • Model inversion
  • Data poisoning

In RSM's offensive security testing, more than 73% of AI-integrated systems tested were susceptible to AI-related attacks.

This creates an asymmetry.

Defenders require governance, approvals and investment.

Attackers simply need access to AI tools.

Organisations are currently using AI across three broad categories:

  1. Personal productivity
    • summarisation
    • drafting
    • document comparison
  2. Enterprise intelligence
    • forecasting
    • analytics
    • decision support
  3. Agentic AI
    • systems capable of taking actions automatically

The third category fundamentally changes organisational risk because poor AI outputs become automated business actions rather than simple recommendations.

AI has not fundamentally changed cyber attack techniques.

Phishing...

Credential theft...

Social engineering...

Application exploitation...

These all existed before AI.

What has changed is:

  • speed
  • scale
  • sophistication

Attacks that once required skilled teams over weeks can now be launched in hours—or even minutes.

The challenge isn't entirely new threats.

It's familiar threats moving much faster than organisational response capabilities.

Organisations need to rethink incident response across six key areas:

  • Secure by Design
  • AI lifecycle controls
  • AI threat modelling
  • Explainability
  • Continuous monitoring
  • Cross-functional governance

Importantly, only two of these are purely technical.

Most involve governance, leadership and organisational processes.

Technical readiness does not equal organisational readiness.

Strong security tooling can detect incidents.

It cannot make business decisions.

Effective response requires multiple business functions working together, including:

  • IT & Cyber
  • Risk
  • Legal
  • Communications
  • Service Owners
  • Executive leadership

Organisations should clearly define:

  • decision rights
  • escalation triggers
  • trusted reporting
  • recovery playbooks

These capabilities should be tested regularly under realistic conditions.

Throughout the webinar, several themes emerged:

  • AI is accelerating cyber threats.
  • Governance is just as important as technology.
  • Traditional response plans require updating.
  • Organisations should embed security and privacy by design.
  • Executive decision-making must be practised—not assumed.
  • Confidence is not the same as capability.

The goal is not perfect security.

The goal is organisational resilience.

As AI continues to evolve, organisations must ensure governance evolves alongside it.

Strong frameworks, tested response plans, executive preparedness and cross-functional collaboration will determine how effectively organisations respond when incidents occur.

If your organisation is reviewing its AI governance, cyber resilience or incident response capabilities, RSM can help through governance reviews, risk assessments, maturity assessments and strategic roadmaps.

Thank you for joining today's webinar. We appreciate your time and hope you found the session valuable.

 

You may also be interested in RSM’s 2026 Cyber Security Report which has just been released:

 

Have a question? Get in touch

Please provide your company name.

How can we help?
Digital Solutions

Please note: no careers queries or applications are accepted via this form. 
Visit our Careers site for more information.