An AI-related lawsuit will force the ouster of leadership at a large organization; over one billion dollars will be spent on AI tokens; an AI-generated software flaw will cause a global outage; Mother Nature will cause outages and regulatory violations; and an attempt to control AI costs by changing models will lead to a data breach. Such are market research firm Forresterโs predictions for cybersecurity and risk in 2027.
Besides the implications of tech and geopolitics, security and risk leaders face the (relatively) mundane but important tasks of managing their own AI consumption and maintaining their regulatory reporting obligations in the face of unexpected events, a report by the analysis firm states. The report speaks also of ‘the hamster wheel of AI-assisted vulnerability discovery’. It says: “Patch releases have reached truly staggering proportions, with major vendors sometimes delivering hundreds of โ and in the most extreme case, over a thousand โ updates across dozens of products at one time.” The pressure to develop and distribute patches quickly will overwhelm software engineers; hence, a need to rely more on AI, the report predicts. The firm is holding a security and risk forum in Washington DC on November 9 and 10.
‘Reshaped by AI’
Meanwhile in a ‘Relentless Defence‘ report, the tech firm Cisco has surveyed ‘a threat landscape being reshaped by AI’, given that AI becomes ‘critical to defence and a powerful weapon for attackers’. Near all of those the firm surveyed experienced at least one material disruptive cyber incident in the past year. More than a third (35pc) involved an AI-related attack. At the same time, about a quarter (26pc) of respondents state that AI is already significantly reducing operational burden in terms of security.
Chintan Patel, Cisco Chief Technology Officer, EMEAย says: โBoards have stopped asking whether AI will deliver. They are asking whether their organization is secure enough to use it. Regulation accelerated that shift, but it will not finish it. The organizations treating security as a compliance exercise will struggle. Those building it into how they operate are already ahead.โ
The company’s report argues that security has ‘become a shared concern across infrastructure, finance, and the C-suite; no longer a line item confined to the Security Operations Center (SOC)’. Its survey found a small group of businesses significantly outperform the rest by breaking down silos and working as a single unit on security.





