Government cybersecurity officials from the United States, the United Kingdom, Canada, New Zealand, and their intelligence-sharing partners gathered in Washington this week with a message that cuts against the current AI sales pitch: the thing that stops most cyberattacks has nothing to do with artificial intelligence.
At the Billington Cybersecurity Summit, an FBI cyber official put it plainly. The same basic steps that stopped attacks last year will stop most of them over the next year and a half, regardless of how much AI attackers throw at the problem. That means keeping track of who has access to what, watching the edges of your network, following good password and login habits, and requiring multi factor authentication, which just means a second step to prove it is really you logging in, not only a password.
This is not a hunch. The FBI just ran a public campaign called Operation Winter Shield, built from real investigations, that lists ten specific actions organizations should take. Near the top of that list: use login methods that cannot be phished, fix known software weaknesses before attackers find them, cut down on employees who have administrator level access to systems, and have a tested plan ready for the day something goes wrong.
The data backs this up. IBM's 2025 breach report found that just over half of breaches came from an actual attack, while human error and IT failures caused most of the rest. Only a small slice, sixteen percent, involved AI at all, and even then it was mostly used to make phishing emails and fake videos more convincing, not to break through defenses that were already solid.
That distinction matters for how businesses spend their security budget. Buying an AI detection tool while skipping basic password hygiene is like installing a smart doorbell on a house that leaves its back door standing open. Officials at the summit were blunt about this temptation, warning companies against chasing flashy new AI security products while neglecting maintenance work that is less exciting but far more effective.
Where AI is genuinely changing things is on the attacker's side, and one example should worry any company that hires remote workers. State backed hacking groups, including ones linked to North Korea, have used AI generated video to pass live job interviews and land real positions inside Western companies, including defense contractors. This is not a new scam; it is a years old fraud scheme that AI has simply made much harder to catch, since a well made deepfake can now respond in real time to interview questions.
For businesses, the message is not to ignore AI. It is to stop treating it as a shortcut around fundamentals. Officials also noted that AI genuinely speeds up defenders too, helping security teams sort through massive volumes of alerts to find the handful that matter, a task that used to take a person far longer to do by hand.
The practical takeaway is simple even if unglamorous. Know what devices and software sit on your network, know who has access to sensitive systems, turn on strong login verification everywhere it is available, and verify who you are actually hiring before you hand them a laptop and a password. None of that requires an AI budget. It requires discipline that most breaches show is still missing.