RSS Amplifier

Packt SecPro · Jul 17, 2026

#243: The Entrepreneurial Adversary

0
Sign in to vote or save

Austin Miller · Packt SecPro

Most product teams test components in isolation. Winmill tests the product ecosystem as one connected surface: the device, hardware, and firmware, the OS and communication protocols, the web, mobile, and API applications that connect to it, and the cloud backend and network behind it, in one engagement, so every attack surface is covered.

The timing matters. For companies selling connected products into the EU, the Cyber Resilience Act and the Radio Equipment Directive are active obligations. Winmill testing aligns with EN 18031 (RED), with accredited laboratory engagements available when your compliance path requires them.

No scoping delays. Testing starts within days, with severity ranked findings delivered in a live portal.

To see our approach firsthand, we are offering SecPro readers a complimentary penetration test.

Claim your complimentary pen test

Talk with the Winmill team

In a rush? Take a look at our key takeaways and come back when you have a little more time.

  • The defining change in cybercrime over the coming decade is unlikely to be the emergence of entirely new motivations or threat actors.

  • The rapid decline in the technical barriers that once restricted sophisticated offensive capability to highly experienced individuals and well-resourced organisations.

  • Artificial intelligence is reshaping the economics of expertise, allowing determined attackers to learn faster, coordinate more effectively and execute increasingly complex operations with fewer resources.

  • For defenders, this means traditional assumptions about who poses a credible threat are becoming outdated.

  • Successful organisations will be those that prepare for a world in which offensive capability is more widely distributed, attacks increasingly target trust rather than technology alone, and adversaries are defined less by their background than by their ability to orchestrate increasingly capable autonomous systems.

When two young individuals were sentenced for their roles in the cyber attacks against Transport for London (TfL), much of the public discussion focused on their age. Headlines naturally gravitated towards the idea that teenagers had been responsible for disrupting one of the UK’s largest public transport organisations, reinforcing the familiar narrative of the gifted young hacker capable of outsmarting major institutions. While age makes for compelling news coverage, it is arguably the least important aspect of the story from a cybersecurity perspective: indeed, the more significant lesson is that the characteristics which once defined a capable cyber adversary are changing rapidly, and organisations need to reconsider how they model the threats they face.

For decades, cybersecurity has categorised adversaries according to motivation or affiliation. We distinguish between nation-state actors, organised cybercriminal groups, hacktivists, insiders and opportunistic attackers because these categories traditionally reflected differences in capability, resources and operational maturity. Those distinctions remain useful today, but they are becoming less predictive of what an attacker can actually accomplish. As artificial intelligence becomes integrated into every stage of offensive operations, technical expertise is no longer the primary limiting factor it once was. Instead, access to capable AI systems, combined with determination and creativity, is steadily reducing the barriers that once separated amateur attackers from experienced professionals.

This shift mirrors many of the broader transformations already taking place across the cybersecurity industry. AI-assisted software development has reduced the time required to build applications. Autonomous security platforms have begun reducing the manual effort involved in detection and response. Identity has become the primary mechanism for establishing trust in increasingly distributed environments. It should therefore come as little surprise that the same technological forces are also reshaping the adversary, changing not only how attacks are conducted but also who is capable of conducting them.

Historically, becoming an effective cyber attacker required years of technical development—it was very much a business which expected the practitioners to be experts and demanded their expertise if they wanted to “achieve” anything. Individuals needed to understand operating systems, networking protocols, programming languages, authentication mechanisms and vulnerability research before they could reliably compromise complex environments. Even after acquiring those skills, they often needed experience developing malware, performing reconnaissance, evading detection, and maintaining persistence within enterprise networks. The learning curve was steep enough that sophisticated attacks were largely confined to experienced professionals, well-resourced criminal organisations or “nation state” attackers.

Artificial intelligence is compressing that learning curve. Modern language models can explain unfamiliar protocols, generate scripts, troubleshoot programming errors, summarise technical documentation and help users understand offensive tooling at a pace that would have been unimaginable only a few years ago. They do not eliminate the need for human judgement, nor do they magically produce sophisticated exploits on demand, but they dramatically reduce the amount of time required to acquire practical competence. An individual who previously spent months understanding Active Directory, PowerShell or cloud infrastructure can now receive interactive guidance, explanations and working examples within minutes.

This distinction is important because AI is not replacing expertise; it is accelerating its acquisition. Experienced penetration testers, malware developers and reverse engineers still possess a considerable advantage over inexperienced operators. However, the gap between novice and intermediate capability is narrowing, allowing motivated individuals to reach operational effectiveness far more quickly than previous generations of attackers. Security teams should therefore expect to encounter adversaries whose technical backgrounds are increasingly difficult to infer from the sophistication of their attacks.

Get up to speed with advice from MITRE

The democratisation of offensive capability is not solely about education. It is also about access to specialised expertise that can increasingly be consumed as a service rather than developed internally. Just as cloud computing allowed organisations to rent infrastructure instead of building data centres, AI allows individuals to access technical knowledge without mastering every underlying discipline themselves. Offensive operations are gradually becoming exercises in orchestration rather than the product of deep expertise across every technical domain.

Consider the range of activities involved in a typical intrusion. Reconnaissance, phishing infrastructure, malware development, scripting, privilege escalation, persistence, lateral movement and data exfiltration have traditionally required different skill sets. Criminal groups often distributed these responsibilities among specialists, reflecting the increasing professionalisation of cybercrime over the past decade. AI changes that equation by allowing a single operator to receive assistance across multiple stages of the attack lifecycle, reducing the need for large teams while increasing the effectiveness of individuals.

This does not mean that AI independently conducts sophisticated cyber attacks. Human operators remain responsible for defining objectives, making strategic decisions and adapting to changing circumstances. What changes is the amount of specialist knowledge they need to possess before beginning an operation. Increasingly, attackers can rely on AI to accelerate routine technical work while focu/sing their own efforts on planning, coordination and decision-making.

See NIST for more

The TfL case illustrates another important consequence of this technological shift. Public attention naturally focused on the youth of the individuals involved, yet age itself tells us remarkably little about future cyber risk. If AI reduces the importance of accumulated technical experience, then younger individuals inevitably gain access to capabilities that once required many years of study. Equally, individuals entering cybersecurity from entirely different professions may become capable of launching attacks that previously lay well beyond their technical reach.

This is not a prediction that future cybercrime will be dominated by teenagers. Rather, it is an observation that traditional assumptions about who possesses offensive capability are becoming increasingly unreliable. Organisations have often associated sophisticated attacks with highly trained professionals working within organised criminal groups or government agencies. While those actors remain among the most capable adversaries, they are no longer the only ones capable of executing technically complex operations.

The defining characteristics of future attackers may therefore shift away from formal technical expertise and towards entirely different attributes. Curiosity, persistence, creativity and malicious intent become more important when AI assists with many of the underlying technical tasks. This represents a subtle but significant change in how defenders should think about emerging threats, particularly when considering insider risk, recruitment, fraud and social engineering.

Cybersecurity has traditionally viewed organised groups as inherently more dangerous than individuals because organisations possess greater resources, broader expertise and more resilient infrastructure. While this remains true at the highest levels of cyber conflict, AI is increasing the capabilities available to individual operators. A lone attacker equipped with powerful AI tools can accomplish considerably more than would have been possible only a few years ago, particularly against organisations with limited security maturity.

This change does not suddenly place individuals on equal footing with nation-state intelligence services. Advanced persistent threat groups continue to benefit from dedicated research teams, bespoke tooling, extensive intelligence gathering and significant financial investment. However, the distance between an individual attacker and a moderately organised criminal group is beginning to shrink. Mid-sized organisations, local government, healthcare providers and educational institutions may increasingly find themselves facing attacks that appear unusually sophisticated despite originating from relatively small groups or even single operators.

The implications for defenders are considerable. Risk assessments that assume complex attacks require large criminal enterprises may underestimate the threat posed by determined individuals equipped with modern AI systems. Security programmes will need to account for the fact that operational sophistication is becoming less closely correlated with organisational scale.

Another consequence of AI-assisted offensive capability is the continued evolution of cybercrime as an entrepreneurial ecosystem. Criminal marketplaces have long offered malware, stolen credentials, ransomware affiliates and phishing kits, allowing attackers to purchase capabilities instead of developing them independently. AI extends this trend by making specialist knowledge itself increasingly accessible, reducing dependence on highly skilled collaborators and enabling smaller operations to achieve greater technical sophistication.

Rather than mastering every aspect of offensive security, future attackers may assemble campaigns using a combination of commercial infrastructure, open-source tooling and AI-assisted development. One system may help automate reconnaissance, another may generate convincing phishing content, while a third assists with scripting or infrastructure configuration. None of these systems independently creates a successful attack, but together they reduce the friction involved in planning and executing malicious operations.

This mirrors developments occurring within legitimate software engineering. Developers increasingly coordinate multiple specialised AI agents rather than writing every line of code themselves. Cybercriminals are likely to adopt similar approaches, transforming their role from technical specialist to coordinator of increasingly capable autonomous tools. The overall effect is to increase both the speed and accessibility of offensive operations without necessarily increasing the underlying expertise of individual attackers.

The growing accessibility of offensive capability coincides with another important transformation: attacks are increasingly directed against trust rather than technology alone. As organisations strengthen traditional technical controls, adversaries continue shifting their attention towards identity, communication and human decision-making. AI enhances these attacks by making deception faster, more convincing and easier to scale than ever before.

Check out Microsoft's thoughts

Synthetic voices, AI-generated video, realistic phishing emails and convincingly written business communications are already changing the economics of social engineering. Future attackers may construct entire fraudulent business identities, conduct prolonged conversations with employees and adapt their messaging dynamically according to responses received from victims. These attacks rely less upon exploiting software vulnerabilities and more upon manipulating confidence, authority and organisational processes.

This development reinforces a broader trend within cybersecurity. Identity has already become the foundation of enterprise trust, and AI makes identity-based deception considerably more effective. As organisations become increasingly dependent on digital interactions, distinguishing genuine communications from convincing fabrications will become one of the defining security challenges of the coming decade.

Fortunately, these technological developments are not exclusive to attackers. Security professionals are adopting the same AI capabilities to accelerate investigations, improve threat hunting, automate documentation and assist with incident response. Junior analysts can perform tasks that previously required considerably more experience, while senior practitioners can focus their attention on complex investigative work rather than repetitive operational activities. The overall effect is to increase the productivity of security teams facing persistent skills shortages.

See CISA for more

This creates an unusual competitive dynamic in which both attackers and defenders benefit from the same underlying technology. AI does not inherently favour one side over the other, but it does reward those who integrate it most effectively into their operational workflows. Organisations that merely purchase AI-powered security products without adapting their processes are unlikely to realise substantial benefits. Conversely, security teams that combine AI assistance with mature governance, strong operational discipline and experienced personnel may significantly outperform adversaries relying solely on automation.

The differentiator, therefore, becomes organisational capability rather than access to AI itself. Much as cloud computing eventually ceased to be a competitive advantage in its own right, AI will increasingly become standard infrastructure rather than a differentiating technology. Competitive advantage will instead arise from how effectively organisations govern, supervise and integrate increasingly autonomous systems into their security operations.

The cybersecurity industry has relied upon familiar adversary classifications for many years, but those models may require revision as offensive capability becomes increasingly accessible. Categories such as nation-state actor, organised cybercriminal, hacktivist and insider remain valuable because they describe motivation, resources and strategic objectives. However, they may become less useful for estimating technical capability when AI allows relatively inexperienced individuals to conduct increasingly sophisticated operations.

Future threat intelligence may therefore pay greater attention to operational characteristics than organisational identity. Analysts may distinguish between fully autonomous attack campaigns, AI-assisted human operators, capability-amplified individuals and highly coordinated criminal enterprises that integrate multiple autonomous systems into their operations. These distinctions better reflect how attacks are executed rather than simply who happens to be conducting them.

Such changes would represent a natural evolution of threat modelling rather than a complete replacement of existing frameworks. Understanding motivation will remain essential for prioritising defensive resources, but understanding how adversaries generate capability may become equally important. As AI continues reducing traditional barriers to entry, organisations will need threat models that reflect the changing economics of offensive operations rather than assumptions inherited from previous decades.

The future cyber adversary is unlikely to look dramatically different from today’s attackers in terms of motivation. Financial gain, espionage, ideological activism and personal curiosity will continue driving malicious activity across the internet. What changes is the relationship between motivation and capability. Individuals who previously lacked sufficient technical knowledge to pursue sophisticated attacks may increasingly acquire practical offensive capability through AI-assisted learning and autonomous tooling.

For defenders, this means security strategies can no longer assume that sophisticated attacks originate only from highly organised groups with extensive technical resources. The barrier separating ordinary individuals from capable adversaries is steadily declining, forcing organisations to prepare for a much broader range of credible threats. Technical controls, identity verification, governance frameworks and security awareness programmes will all need to evolve in response to attackers who can operate faster, learn more quickly and coordinate increasingly capable AI systems.

The Transport for London case should therefore be viewed as more than an isolated criminal prosecution. It offers a glimpse into a future in which technical expertise is no longer the defining characteristic of a dangerous cyber adversary. The next generation of attackers will not necessarily be more intelligent than those who came before them, nor will they always belong to large criminal organisations. Instead, they will increasingly be individuals whose capabilities have been amplified by artificial intelligence, fundamentally changing who organisations should expect to face in the years ahead. And, because of that, cybersecurity in the new world will have to amplify the human element in response, not merely act as the first line of defence.

Read the original on secpro.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.