Jason W. Richards
Principal at JWR Strategies and former FBI assistant director
As we think about securing America for the next 250 years, we have to prepare not only to prevent cyber attacks, but to keep critical missions operating when disruption occurs. For law enforcement, intelligence, and national security, that means maintaining trusted communications even when the networks and infrastructure we normally rely on are degraded, compromised, or unavailable.
But continuity alone is not enough. We also need to consider what our communications reveal. An adversary may never break the encryption protecting a message, but knowing who communicated, when, from where and with whom can expose an investigation, identify a sensitive government operation, or reveal relationships and patterns that put people and missions at risk.
AI makes it possible to collect and correlate those seemingly insignificant signals at unprecedented speed and scale.
Cyber resilience, therefore, needs to include both the ability to keep communicating through disruption and the ability to reduce what those communications reveal. That is where Presence Security becomes important: protecting not just the message, but the people, relationships and missions around it.
Justin Daniels
Faculty member at IANS and partner at Baker Donelson
One of the next big fights in enterprise AI will not be about whether the technology works. It will be about who tells the business that using the cheapest LLM model may be a bad idea.
As AI usage scales, token costs are about to matter a lot. Business teams will inevitably ask why they are paying premium prices for proprietary models when cheaper open-weight alternatives can do the job. Then somebody will suggest a Chinese model that performs remarkably well for a fraction of the cost.
Congratulations, security teams: you inherit the mantle of yes, but there are serious cyber security concerns with that decision.
The problem is that cheaper tokens do not magically erase questions about model provenance, training data, intellectual property, privacy, or supply chain risk.
I call this the “fruit of the poisonous LLM”. If you do not understand what sits inside the model, everything built on top of it may inherit risks you never priced into that bargain. Moreover, the US government may decide to ban Chinese models based on national security or other concerns.
Tokenomics will increasingly drive AI architecture. Security teams need to understand that economic pressure now, because waiting until the CFO champions the cheaper model makes for a tough AI governance strategy.
Karl Holmqvist
Founder and CEO of Lastwall
Cyber Security Awareness Month is a reminder that the stakes are getting higher on both sides of the security landscape. Technology is giving defenders more powerful tools, but it is also giving attackers more leverage. The cost of getting it wrong is rising: according to Sophos, the average cost to recover from a ransomware attack reached US$1.7 million in 2026, excluding the ransom itself – an increase of about 11 per cent year over year.
At the same time, we are entering a more agentic world, where increasingly digital and interconnected systems underpin everything from energy and communications to transportation and supply chains.
In that environment, identity becomes more important, not less. Strong identity is a rising tide for the broader security stack because, at its core, cyber security comes back to trust: who or what is requesting access, what authority do they have, and what are they allowed to do?
Agentic systems make that question even more urgent. As AI agents begin acting autonomously on behalf of people and organisations, authenticating the human alone will no longer be enough. We also need to authenticate the agent, understand the authority delegated to it, and define the boundaries it is expected to operate within.
Quantum adds another layer of urgency. “Store now, decrypt later” means sensitive data being collected today can remain a security liability years into the future. That makes post-quantum preparation a current security issue, not a distant one.
For governments, the opportunity is to build resilience from first principles: modernise identity, begin the transition to post-quantum cryptography, and continue investing in sovereign capabilities that strengthen both national security and the domestic technology ecosystem.
Rick Howard
Cyber security executive
I’ve been in the cyber security industry for over 30 years. I’ve spent gazillions of dollars deploying prevention strategies across four different CISO jobs. Here at the end of my career, I’ve come to realise that these prevention strategies, like zero trust and intrusion kill chain prevention, are great ideas, but they are expensive and hard to deploy fully.
The only strategy that makes sense for most organisations is resilience. I just need to survive the attack, not prevent it.
That means being able to continue operating when the systems, networks, and communications you normally depend on are degraded, compromised, or unavailable. And if keeping the mission running means shifting to different networks, providers, or communications paths, security has to move with it.
Resilience has to become more than recovery. We need systems that can adapt during an attack, maintain trusted communications, and protect presence as conditions change. If an attack succeeds but the mission continues securely, resilience has done its job.
Kevin Gosschalk
Founder and CEO of Arkose Labs
The internet is no longer just humans and traditional bots. Consumer AI agents like Meta’s Muse, Instinct, and Grok Bot are now browsing, logging in and taking actions on behalf of real users, often without clearly identifying themselves. At Arkose Labs, that’s what we call Population Two: a new class of legitimate agents acting for real customers, but showing up in ways most security systems were never designed to understand.
That makes the old “human or bot?” question much less useful. A customer’s AI agent and a malicious agent can look surprisingly similar from the outside. The real question is: What is this agent trying to do, and should it be allowed to do it?
That is where cyber security has to evolve. Detection still matters, but visibility and intent matter more. Businesses need to know when an agent is interacting with them, understand what it is trying to accomplish, and decide what level of access makes sense. These agents are already becoming part of everyday online activity. The organisations that adapt fastest will be the ones that can distinguish legitimate agent activity from abuse without simply blocking both.
John Keefe
Chief strategy officer at Texas Cyber Command
Cyber Security Awareness Month is an important reminder of just how much of our daily lives, our economy, and our national security now depend on secure and reliable digital infrastructure. And the cyber challenges in the world we find ourselves in today are daunting.
Society and the global economy are highly dependent on the internet. Adversary nation-state cyber units from China, Russia, and Iran are intruding into US and allied critical infrastructure, and that activity is not limited to espionage. There is a pervasive problem with ransomware criminals victimising healthcare systems, schools, and businesses. At the same time, we are witnessing a technical transformation with the rise of artificial intelligence and its impact on cyber security, and perhaps not too far off, the advent of quantum computing.
In that kind of world, cyber security has to be about more than preventing an intrusion. It also has to be about ensuring that the systems and communications we depend on can continue to operate when something goes wrong.
Secure, reliable, and resilient communications through cyber space are an absolute necessity. I’m talking about the ability to transmit and receive communications across multiple paths, with failover modes that maintain connectivity while also thwarting malicious actors’ ability to intercept those communications. Governments, defence organisations, healthcare systems, financial systems, critical infrastructure owners and operators, and international businesses need that kind of capability.
That is an important part of the Cyber Security Awareness Month conversation. We should absolutely continue focusing on how to prevent attacks, but we also need to be thinking about how organisations remain secure and operational when disruption inevitably occurs.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.