Latest articles

If You Bet On AI, Bet On Cybersecurity Too

Written by John Chambers

If you’ve been following the news lately, you likely have seen stories about serious cyber attacks.

Just a few weeks ago, a criminal group said it stole sensitive personal data on as many as tens of thousands of current and former FBI employees.  If hackers can penetrate the FBI, no CEO or government leader should assume they’re secure.

Such cases are proliferating at an exponential pace, and the challenge is only going to grow because now such attacks can happen without a human at the keyboard.

There’s been a few particularly concerning instances in recent months. An Open AI agent found its way around controls on an Australian government portal after being told “no.” A swarm of roughly 700 AI agents bypassed safeguards, reaching the open internet, and hacked into systems belonging to the open-source AI platform Hugging Face.

Seven hundred agents may sound like a lot, but it isn’t. Pindrop, a cybersecurity company backed by my portfolio company JC2 Ventures, looked at 100 of its customers over a two-month period to see how many AI agents had entered their systems. The answer was 750,000.

Most of those agents were legitimate. Some weren’t. But that is exactly the challenge: how do leaders know who – or what – is entering their cyberspace? What is its intent? What is it authorized to do? And are its actions consistent with that authorization?

Enterprises have accumulated layers of infrastructure, applications, and vendors. Attackers don’t have to defeat every layer. They only need to find the weakest point in the chain. As AI accelerates the discovery and exploitation of vulnerabilities, the question isn’t whether AI agents will knock on your company’s door. It’s how you’ll know which ones to let in.

The other problem is speed. An attacker can penetrate an environment, access data, or plant malicious code in approximately 10 minutes. An organization may not realize it has been compromised for months. You cannot defend machine-speed attacks with human-speed responses. AI must be part of the defense.

For nearly a decade, I’ve said that AI and cybersecurity would become two of the biggest growth opportunities in technology and increasingly converge. AI has already entered its acceleration phase. I believe cybersecurity is now entering its own.

Similar to the AI-driven transition we saw in software, I believe a new generation of cybersecurity leaders will emerge, while traditional players that fail to adapt will fall behind – and there will be far more losers than winners. If you want to bet on AI, you also need to bet on cybersecurity.

The market is beginning to recognize this transition. Cybersecurity leaders such as CrowdStrike and Palo Alto Networks have significantly outperformed the broader Nasdaq over the past six months. Across the JC2 Ventures portfolio, there are six cybersecurity companies total, but all 15 of the AI companies incorporate elements of cybersecurity, because the two need to go together. You can’t bolt cybersecurity onto AI after the fact.

But companies can’t realistically rip out every existing system. Organizations must improve what they already have while moving toward architectures designed for AI, autonomous systems, and cybersecurity together. And AI itself needs to be part of the defense. Human intervention alone cannot operate at the speed required.

While CEOs have been saying that cybersecurity is at the top of their agendas, they are only starting to invest in it. My advice? Chief security officers and CIOs tend to focus on the vertical stack. I would argue that AI is most effective when it goes horizontal. The same goes for cybersecurity. Leaders need to invest across all supply chains and functions.

Every organization – whether a tech company, a traditional business, or a government –  should be well into implementing its AI strategy by now. CEOs should drive AI implementation and cybersecurity in parallel, using productivity gains from AI to free resources for the next generation of growth while investing in the security architecture required to protect it.

This isn’t just the CIO’s or CISO’s responsibility. All operating leaders need to be aligned.

And don’t think of cybersecurity as a product you buy and then move on from. This is an ongoing cat-and-mouse game. The architecture, people, and defenses need to continually evolve as AI gets smarter and faster.

I remain an optimist about AI. The opportunity is enormous. But that doesn’t mean AI will lift all boats in cybersecurity – there will be winners and losers in this transition. Organizations that treat AI and cybersecurity as a single bet will be well positioned. Those that don’t risk becoming tomorrow’s cautionary tales.

Former Cisco Executive Chairman and CEO John Chambers was widely considered one of the best performing U.S. CEOs during his 25+ year tenure at Cisco. As Executive Chairman, a position Chambers held until December 2017, he led the Board of Directors and provided counsel to the CEO and leadership team on strategy, digital transformation and strategic partnerships, Chambers oversaw 180 mergers and acquisitions during his tenure at Cisco and managed the company through multiple economic downturns  He currently runs JC2 Ventures as CEO and serves as an advisor to heads of state, including France’s Emmanuel Macron and India’s Narendra Modi. This is the 44th in a planned series of exclusive columns Chambers is producing for The Innovator.  

About the author

John Chambers