The Great Cybersecurity Collision

Rory Yates

Managing Director, Insurance,Synechron

Cybersecurity

Summary:
Shifting IT threat landscapes and cybersecurity management are colliding.

The cybersecurity challenge is at a tipping point: AI is advancing, IT landscapes are changing dramatically, third-party models are expanding and new frontier AI models are emerging. It's all changing everywhere at once.

This changing IT landscape has now completely transformed the modern cybersecurity threat landscape. Security teams are no longer just fighting human adversaries; they are engaged in an asymmetric, machine-speed battle against autonomous exploitation.

In this paper, we try to decompose this into four key areas of change for the cybersecurity-first BFSI organization of the future.

Highlights

  • Weaponizing against frontier models: Elite cyber-offense, now democratized.
  • A fragmented IT landscape, unifying again: Perimeter defense is obsolete.
  • TPRM as a strategic asset: Third-party risk becomes a competitive edge.
  • The response crisis: Human speed can't keep pace with machine speed.

Foreword:

“I spend my time moving between two rooms: one where insurers and banks are rolling out agentic AI as fast as they can build it, and one where their security teams are racing to defend against it just as fast. These aren’t paradoxical, but it’s often clear that the latter room is in catch up mode. And it’s now starting to change at an unprecedented pace.

The honest answer to frontier AI isn't more "security as-is" — it's security fused with AI. And that means rethinking our IT landscapes, treating third-party risk far more strategically, and admitting the machines are now faster than the humans watching them. But together they are a force to be reckoned with.

I'll be talking through this on stage at Money 20/20 this October, and I hope this paper gives you a head start on that conversation.”

Rory Yates, Managing Director, Synechron

Contents:

Section One - Weaponizing Against the Frontier Models

Section Two - The Fragmented IT Landscape Is Unifying Again

Section Three - TPRM Is a Strategic Asset

Section Four - The Response Crisis: Human vs. Machine Speed

Conclusion

Weaponizing Against the Frontier Models

Security teams used to fight human adversaries. Increasingly, they're fighting an asymmetric, machine-speed battle against autonomous exploitation, and the same frontier AI systems reshaping every other part of the business are reshaping the attacker's toolkit first.

The emergence of highly capable frontier AI systems (like the latest iterations of Claude, GPT and the Mythos phenomenon) has democratized access to elite cyber-offensive capabilities.

Next-generation models have shifted from passive code assistants to agentic tools capable of scanning massive operating networks, uncovering hidden zero-day vulnerabilities and stringing them together into targeted exploits: autonomous vulnerability chaining that once demanded a skilled human operator now runs largely on its own.

Threat actors can use bypassed frontier models to build completely unique, evasion-resistant ransomware strains without writing any base code, effectively bringing advanced malware creation to a low-skilled marketplace, no-code cybercrime, open to anyone willing to look for it (or prompt it). And because advanced models easily bypass traditional language and cultural bottlenecks, bad actors can spin up thousands of convincing, automated phishing campaigns and real-time deepfake media platforms in seconds: hyper-personalized social engineering at a scale no human team could match unaided.

None of this is hypothetical, and it is happening all the time. We now need to use AI models as security assessment tools, as monitoring tools and as intelligent defense tools, which means AI maturity in cyber security has to accelerate at pace. Not just model use, but in security terms: in the way we design systems, assess risk and threat potential and set our acceptance criteria.

The Fragmented IT Landscape Is Unifying Again

As enterprises adopt hybrid cloud environments, edge computing and distributed work models, the traditional perimeter defense model is entirely obsolete. Defense now needs to proliferate across all connected enterprise assets. IoT and data model services once seen as low-risk are now attack layers in a connected system.

“The traditional perimeter defense model is entirely obsolete.”

The proliferation of distribution and the widening of ecosystems have all created fantastic value-generative capability. At the same time, these have formed more complex risk models than ever before. And now we have handed incredible advanced intelligence to bad actors, fully democratized, and the threat becomes unknowable almost as fast as it appears.

The systems meant to protect us against this are still very rudimentary. Three gaps stand out:

  1. The “Asset Change” Lag: Security controls cannot keep up with rapid cloud provisioning. A vast majority of organizations require days or even weeks to fully apply cybersecurity protocols to newly deployed cloud or IoT assets.

  2. OT–IT Convergence: Critical Operational Technology (OT) networks, historically isolated from the internet, are being connected directly to enterprise cloud systems and AI tools, creating high-consequence entry points into real-world physical infrastructure.

  3. Blind Spots at the Edge: Security teams report critically low visibility over smart meters, distributed field communications equipment and cloud edge environments, leading to massive blind spots.

Evidently, approaches to this need to shift toward a cybersecurity-first model. The issue with this tends to be organizational. From experience, when hosting a closed-door roundtable with Chief AI Officers and CISOs, it became clear that frontier models for AI and development security either need the same or a massively scaled and centralized core team and trust layer. Each approach has its pros and cons, and our view is that it needs to be hybrid. The issue now is that having to do this (fixing data models and orchestrating “human at the helm” models) comes at a cost beyond the LLM token usage that no one business-cased for.

We need to move these things in tandem so that one unlocks the other - because we need AI in our security models to protect us against AI.

Third-Party Risk Management (TPRM) Is a Strategic Asset

Third-party risk didn't make the opening list of colliding forces by accident. It isn't a supporting theme to what's happening elsewhere in this paper — it's where those forces actually collide. The same frontier models weaponizing cyber-offense in the first section are pointed at vendor code just as readily as anything built in-house, and the same unifying, connected IT landscape dissolving the traditional perimeter in the second section is dissolving the line between "our systems" and "their systems" just as fast. If an enterprise's defenses stop at its own walls, the vendor relationship is the door left open.

“Better management of expanding third-party and supply-chain models is now vital.”

Better managing expanding third-party and supply-chain models is now vital.

Modern organizations are no longer just building software, there is an expectation to assemble it, using third-party components, open-source libraries and external digital vendors. That assembly model is what makes modern development fast, but it also multiplies the number of doors into the enterprise that never run through an in-house system at all.

Attackers have noticed: data poisoning and corrupted pipelines are becoming a preferred route in, with adversaries increasingly targeting the upstream training data or repositories used by third-party vendor applications, subtly poisoning the models before they ever reach enterprise infrastructure. The damage doesn't stay contained to one vendor, either. Because these tools and Application Programming Interfaces (APIs) are shared across an entire market, a single vulnerability in a widespread vendor tool or API allows automated frontier models to instantly compromise thousands of downstream commercial counterparties, cascading exploits that turn one flaw into a market-wide event before a human review cycle has even started.

That's precisely why TPRM has to move as fast as the risk it's managing. TPRM is evolving rapidly, and we are exploiting systems like ServiceNow to ensure market-leading capability, removing huge amounts of human lag and developing fast-response systems. Treating third-party risk as a strategic asset rather than a compliance checkbox means building it to move at machine speed from the start.

The Response Crisis: Human vs. Machine Speed

Because AI-driven attacks drastically reduce the time between vulnerability discovery and execution, typical defense workflows are struggling to survive. TPRM can be run at machine speed, and the IT landscape can unify around a cybersecurity-first model, but none of that matters if the humans actually responding to a live threat are still working at human speed. This changes how we do three things:

  1. Vulnerability Management: AI-infused security professionals, aided by threat-detection tools operating across every surface, need to find and prioritize vulnerabilities before an autonomous attacker chains them together. Not weeks after once the exploit has already run.

  2. Incident Response: When something does get through, the same orchestration has to compress recovery and resolution time from days down to minutes, catching emerging threats before they're fully realized rather than cleaning up after the fact.

  3. Defense Testing: The controls themselves need constant testing against how attackers are actually behaving right now, not how they behaved when the control was designed. It’s vital for change-management adaptivity to be built into the IT change process from the outset, not audited in after the fact.

“We have frontier AI models; we now need frontier cybersecurity models as well.”

This requires a real change in how we see cybersecurity threats, moving from a world built around human-engineered attacks to one where we use AI itself to find the vulnerabilities and help build the solution, and building that shift into the organizations we design, not adding it on afterward. The entities capable of doing this are ones designed for cybersecurity from the outset and managed with it at the forefront.

We have frontier AI models. We now need frontier cybersecurity models as well.

Intelligent cybersecurity business models need to proliferate to survive this landscape. The organizations who are ahead of the game are leaning on AI-driven defenses paired with strict administrative guardrails.

While attackers move incredibly quickly, internal IT teams possess an asset attackers don't: deep, localized institutional knowledge of their own environments.

When this context is fed into custom defense AI models, security teams can spot highly subtle behavioral anomalies that an external agentic model cannot anticipate.

Conclusion

Four different pressures, all that point to the same answer. Security can't be run as a project anymore. It needs to be run as a service: always on, moving at the same speed as everything it's protecting.

That's not a case for more guardrails, and it's not a case for more consultants standing at the perimeter either. While attackers move incredibly quickly, internal IT teams hold an asset attackers don't have: deep, localized institutional knowledge of their own environments. Fed into the right defense AI models, that context lets security teams spot subtle behavioral anomalies an external, generic model would never catch. Built the right way, cybersecurity-as-a-service isn't something bought in and handed over, it's built into the organization, and the organization keeps running it.

None of this stays theoretical for long. Rory Yates will be on stage at Money 20/20 this October, talking through this exact collision that’s been hiding in plain sight for anyone paying attention, until now.

The Author

Rory Yates
Rory Yates

Managing Director, Insurance

Rory is a seasoned business leader with over 29 years of experience in various domains, including strategy & transformation, marketing, innovation, and sustainability. As a Chief Strategy Officer, Board Advisor and growth expert in the insurance, Insurtech and technology sectors he ensures all parties are aligned with a clear vision, mission, and value based structure.

Rory is passionate about creating safer, smarter, and more self-sufficient ecosystems that benefit people, businesses, and the environment. He leverages his expertise in strategy, sustainability, and humanity to advise and consult with various stakeholders, from start-ups to private equity firms, on how to achieve positive social and environmental impact.