The Three AI Questions

table of contents

AI risks were top of mind for the security leaders we spoke with at Fal.Con 2026, the CrowdStrike user conference. We were busy demonstrating our integration with the CrowdStrike Falcon platform in our booth. The presentation I gave in the Hub Theater on Defending Against AI-driven Threats was well-attended, and, reminiscent of Cerberus, the multi-headed hound of Greek mythology, the incisive questions and concerns about AI we heard from CISOs fell into three distinct yet connected categories:

Question 1. How Can I Protect My Organization From Attackers That Are Leveraging AI Automation?

This question came up most often in our discussions. Awareness is growing that AI can quickly reverse-engineer services, processes, and applications to discover multiple vulnerabilities and use automation to chain them together at machine speed. As I discussed in my recent blog, the breadth and speed of these AI-accelerated attacks mean that an initial compromise is virtually assured. The sentiment is growing that resilience, not just prevention, must drive cyber defense strategy because breaches are inevitable in this new threat landscape.

Some attendees we spoke with were preparing to brief their boards of directors on how they plan to mitigate risk and bolster operational resilience amid emerging AI-powered threats. So, it was very timely that we demonstrated to the attendees at Fal.Con how our Xshield platform can prevent AI-driven reconnaissance and lateral movement, making their critical systems invisible to attackers—agentic or human.

Serendipitously, Anthropic recently released a research report entitled Mapping AI-Enabled Cyber Threats. In it, they related real-world attacks to the MITRE ATT&CK® framework and gave each a risk score using their ARiES scale. They concluded that no other technique came close to lateral movement’s predictive power for a successful attack. The report found that:

  • Lateral movement was the strongest indicator of a high-risk AI-enabled attacker.
  • Actors using AI for lateral movement scored twice the average risk score.
  • “No other technique came close to lateral movement’s predictive power for a successful attack.”

As the chart below shows, lateral movement was more than double the effect of all other tactics in AI-driven attacks, so strong lateral movement controls like those in our Xshield platform are needed to increase enterprise resilience to AI-driven attacks.

Lateral movement as a predictor in AI-driven attack risk

From Mapping AI-Enabled Cyber Threats: Insights from the LLM ATT&CK Navigator, June 2026, by Anthropic: https://www.anthropic.com/research/attack-navigator

Question 2. How Can I Implement Agentic AI to Increase Efficiency and Effectiveness in My Organization Without Increasing Risk?

Organizational leaders are under pressure to deploy agentic automation to increase productivity and reduce headcount. Because of this imperative, internal AI agents are often deployed with broader access to enterprise systems than rigorous least-privilege policies would otherwise mandate. This is clearly a security risk, and organizations are floundering in addressing it. Many are implementing new startup solutions that enforce prompt guardrails or controls on the endpoint or data layer.

A foundational method to keep an internal AI agent from ever doing what it must never do is to strictly control access to network resources through identity-based microsegmentation. This ensures that no AI agent has access privileges greater than the human identity employing it.

On this topic, our ColorTokens Federal CTO, Lou Eichenbaum, former CISO of the United States Dept. of the Interior, said, “Agents can authenticate, invoke tools, query data, modify records, trigger workflows, and interact with enterprise applications in data center and cloud environments. That makes an AI agent more than an application feature: it is a non-human identity with potentially high-speed, high-scale access.”

Folks who attended the demo at our booth at Fal.Con left with a clear understanding that network-level controls must be in place to prevent internal AI agents from becoming a kind of non-human insider threat.

Access the eBook: Enable AI Without Expanding the Blast Radius

Question 3. How Can Our Cyber Defense Strategy Leverage AI To Better Protect the Enterprise From Attacks?

Several security leaders asked us how we use AI to combat AI-enabled attackers. We demonstrated how our Xshield AI gives them two levels of functionality to increase their resilience against AI-driven threats.

  • Increased situational awareness of up-to-date MITRE ATT&CK lateral movement tactics, techniques & procedures (TTPs), and CISA Known Exploitable Vulnerabilities (KEVs)– and understanding how they specifically apply to your environment using plain-English LLM queries.
  • Xshield AI provides automatic policy recommendations, which reduce the skill and effort needed to configure strong controls to stop potential attacks and enable real-time breach response.

This capability solves a pressing problem: because AI-driven vulnerability discovery is so fast, patching every exposed asset in a large enterprise environment in time to stop a new exploit has become virtually impossible. The recent CISA Binding Operational Directive 26-04, issued on June 10, requires patching within three days of discovering a critical vulnerability, but this is often an unachievable goal in large-scale enterprises, and even if achieved, it would not stop AI-accelerated attacks in time. Our AI-enabled policy recommendation lets security teams immediately isolate vulnerable assets with controls tuned to the MITRE TTPs and CISA KEVs, buying them time to implement patches.

Access the Best Practices Guide: AI Threat Resilience in the Age of Mythos

The three questions sparked interesting discussions with security leaders at the conference. Whether you attended Fal.Con or not, if you would like to follow up with us on the new AI-driven threat landscape and how you can be like the hero Hercules and conquer the three-headed hound of the AI underworld, we’re at your service.

To continue the conversation about AI-driven threats and limiting lateral movement risk, contact the ColorTokens team.