Organizations are investing more in security than ever before, yet many still struggle with a fundamental problem: they are preparing for tomorrow’s crisis with yesterday’s mindset. For decades, companies organized security around neat categories. Cybersecurity protected networks. Physical security protected facilities and people. Human resources managed workforce issues. Legal handled compliance. The model worked because threats largely stayed in their lanes. That is no longer the case. Today, AI-powered impersonation, deepfakes and automated social engineering are creating risks that move quickly across digital, physical and operational environments. A deepfake phone call can enable financial fraud. An online threat against an executive can become a physical security concern. A recent EY survey data of 250 corporate leaders and directors reveals that only 12% of organizations feel most prepared to detect a targeted physical attack. Bridging this gap requires an integrated approach across every step – detection, deterrence, prevention, preparation, response, mitigation, investigation and recovery — long before a situation escalates. Threats are changing faster than organizations One of the most common misconceptions about AI-driven threats is that they represent entirely new forms of risk. In reality, the underlying motives are familiar: fraudsters still want to steal money, and adversaries still seek sensitive information. What has changed is the execution. Throughout my career in forensic accounting and law enforcement, I watched criminal schemes evolve from basic fraud to complex international operations. The execution today is incredibly sophisticated, particularly around remote hiring. Transnational threat groups now deploy deepfakes and stolen identities to bypass virtual HR hiring loops. If your compliance and background diligence operate separately from your IT provisioning, you could end up physically shipping secure corporate hardware and handing network access straight to a thief or worse — a foreign adversary. Organizations can work to counter this by building unified, cross-functional verification pipelines that bridge HR, cyber provisioning and physical asset logistics from day one. Security teams still operate in silos While threats are becoming more interconnected, many security programs remain fragmented. Each function across cybersecurity, physical security, HR and legal may perform its role effectively, but risks arise when information is not shared seamlessly between them. Recently, I asked the leadership at a large organization what formal processes govern the relationship between their physical security teams and cybersecurity teams. The answer was revealing. The teams had “strong relationships” and “communicated regularly” but lacked documented processes, shared escalation procedures and clearly defined responsibilities during a crisis. Relationships are important, but they are not a substitute for a security program. When organizations rely primarily on informal communication, response efforts become dependent on individual personalities and availability at a particular moment — whether you are handling a volatile protest near corporate offices, a shooter in a facility or building a logistics plan to move 500 employees, technology and intellectual property out of a geopolitical conflict zone. If your departments rely on casual check-ins instead of integrated policies and shared tooling, precious time and operational flexibility may be lost when they are needed to mitigate a threat. The next evolution of security involves integration Over the last decade, boards and executive teams have invested heavily in cybersecurity. Organizations built security operations centers, established governance structures and developed incident response plans. This same approach should be applied more broadly across security and crisis management functions. That includes integrating cyber threat intelligence with physical threat monitoring, improving coordination between CISOs and chief security officers, and confirming crisis management plans account for a wider range of risks. Furthermore, human expertise should remain at the center of automated defenses. AI is highly effective at aggregating data, such as overlaying toolsets onto camera feeds to identify physical threats or tracking social media spikes regarding a terminated employee. But AI hallucinates. You need competent, qualified people evaluating that intelligence in real time before making major operational calls. The companies that make the most progress shift from an event-driven mindset to a threat-driven mindset. Rather than waiting for an incident to occur, they continuously assess emerging risks and make operational decisions before a situation escalates. Security is a core operational responsibility The convergence of cyber and physical threats is prompting organizations to rethink how security functions operate. If an organization’s cy
AI is exposing a security structure built for yesterday’s threats
Organizations are investing more in security than ever before, yet many still struggle with a fundamental problem: they are preparing for tomorrow’s crisis with yesterday’s mindset. For decades, companies organized security around neat categories. Cybersecurity protected networks. Physical security
Source: CSO Online