CyberSecurity SEE

Claims Data Reveals Current Impacts of AI Risks

Claims Data Reveals Current Impacts of AI Risks

Artificial Intelligence & Machine Learning,
Cyber Insurance,
Fraud Management & Cybercrime

Resilience Data Shows Social Engineering Dominates Over AI-Native Losses


Jud Dressler, director, Resilience Risk Operations Center

In the evolving landscape of cybersecurity, the integration of artificial intelligence (AI) is significantly reshaping risk parameters. However, recent findings indicate that the immediate ramifications of AI may not encompass the emergence of entirely new attack vectors. Instead, it appears to provide cybercriminals with the means to enhance traditional tactics, particularly social engineering strategies. Jud Dressler, the director of Resilience’s Risk Operations Center, asserts that AI is enabling criminals to execute familiar schemes more convincingly and with greater financial consequences, thus amplifying their impact.

According to Dressler, claims data sheds light on the type of incidents that lead to executed claims, while also offering insights that traditional threat intelligence may overlook. This information is crucial for Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs), allowing them to discern which attacks result in actual financial repercussions including business interruptions, fraud losses, or ransom obligations. While threat intelligence reports articulate potential vulnerabilities and adversarial maneuvers, claims data reveals tangible outcomes, illustrating where security controls either succeed or fail during actual incidents. Organizations can use this empirical evidence to inform their investment allocations, shaping their security budgets based on demonstrated losses rather than merely theoretical risks.

“It is vital not to overlook the current risks while we strive for future preparedness,” Dressler emphasized, highlighting the necessity for a balanced approach.

In the recent 2026 Midyear Cyber Risk Report, Resilience indicated that there were no recorded losses attributed to AI-native attacks, such as prompt injection, model exploitation, and agentic misuse, during the first half of 2026. Rather, AI has predominantly served as a force multiplier in amplifying human-facilitated attacks. Alarmingly, social engineering constituted 85% of incurred losses in Resilience’s portfolio, a considerable increase from 17% two years prior. Furthermore, losses stemming from payment fraud experienced a staggering tripling compared to the previous year. The focus remains on exploiting human vulnerabilities, including credentials and internet-facing devices.

In an insightful video interview with Information Security Media Group (ISMG), Dressler elaborated on several critical points:

  • How claims data effectively distinguishes between actual financial losses and emerging cyber threats.
  • The layered controls, response mechanisms, and governance frameworks that can mitigate exposure to these threats.
  • The pressing need for a resilience-centric strategy in light of ongoing data theft, operational deficiencies, and recurring extortion attempts.

Dressler’s background lends significant weight to his insights. He served as a U.S. Air Force colonel for over two decades, during which he played a pivotal role in cyber operations, including establishing the Air Force’s Advanced Cyber Schoolhouse and commanding incident response teams. He also taught as a permanent professor and led the Department of Computer and Cyber Sciences at the U.S. Air Force Academy. With a Ph.D. in computer science from Rice University, Dressler brings profound expertise to the evolving conversation about cybersecurity and AI.

As businesses grapple with the complexities of today’s cyber environment, understanding the significance of these findings is crucial. Organizations must adapt to the shifting nature of cyber risks, particularly as AI technologies continue to evolve, equipping cybercriminals with tools to exploit vulnerabilities faster and more efficiently. The emphasis should be on fortifying defenses against established risks while gradually preparing for future challenges.

Source link

Exit mobile version