I started last Tuesday’s cyber breakfast briefing with a show of hands. Who in this room has full visibility and control of the AI tools their team is using?
Not many hands went up. That was roughly what I expected, and it turned out to be the honest starting point for everything that followed.
We had brought three very different people together at Fortinet’s offices on Moorgate to talk about the risks of agentic AI. Will Morrish from CovertSwarm, who breaks into organisations for a living. Duncan Bates from Fortinet, who builds the technology meant to stop him. And Richard Morrison-Butcher, T/DCI at City of London Police and Centre Director of the Cyber Resilience Centre for London, who sees the aftermath when nobody stops anyone.
Three perspectives that usually disagree. On the substance, they did not.
Richard was clear that criminal adoption of AI is happening now rather than approaching. National crime recording shows a 395% year on year increase in victims identifying AI use in reconnaissance and phishing. Criminal groups are structured organisations with HR and marketing functions, and AI has lowered the barrier to entry for people who were never technical enough to be a threat before.
He also talked us through JADEPUFFER, a critical exploit in an open-source LLM-building framework that was used in a fully autonomous ransomware attack. Target acquisition, reconnaissance, credential gathering, lateral movement, failure response and exfiltration, all executed end to end with little or no human at the keyboard. That is a genuine milestone, and it deserves the attention it is getting.
But it was not the part of the morning that unsettled the room.
Will took us through three recent cases. What connects them is that in none of them did an attacker defeat a security control.
Add to that Will’s account of a finance engagement where his team spent a fortnight arguing with customer service over a transaction, purely to build enough trust that an agent would eventually send them a screenshot from a real Gmail address. The attached payload walked past a well-regarded EDR platform and opened up the internal network.
No zero day. No unpatched CVE. Permissions and human helpfulness, working exactly as designed.
Duncan put it best. Fixating on the firewall ignores the threats where the phone call is coming from inside the house.
Here is where the panel converged, and I did not steer them there.
Richard confirmed that crime data still points to basic misconfiguration and spoofable domains as the primary attack vectors. He mentioned finding a company still running HTTP rather than HTTPS in 2026. Duncan argued that AI-assisted tooling will make previously complex exploits trivial, which makes rigorous patching more important rather than less. Will made the point that most successful attacks still exploit vulnerabilities that should not exist in the first place.
The British Library is the case study that carries both halves of the argument. The 2023 ransomware attack cost them 440GB of data and 60% of their digital estate, and full recovery has only recently been announced. Multi-factor authentication had been declined on cost grounds. Cyber Essentials Plus was not in place.
And yet the electoral records survived, because they sat behind pre-existing cryptographic protection and better network segregation. Somebody had worked out what mattered most and hardened it properly.
That is the whole lesson in one organisation. Get the basics wrong and you lose most of it. Identify your crown jewels and protect them properly and you keep the part you could not afford to lose.
Will’s advice on that point was to stop blindly patching everything and start prioritising around critical assets. A critical-rated vulnerability on a temporary marketing site is not the same problem as a medium-rated one next to your finance system, and treating them as equivalent burns engineering time you do not have.
Compliance is a floor, not a ceiling
Cyber Essentials came up repeatedly, and all three panellists treated it as table stakes rather than an achievement. The UK government has written to FTSE 100 and FTSE 250 companies asking them to mandate Cyber Essentials or Cyber Essentials Plus across their supply chains for tender eligibility, so the pressure is only going one way.
I used the old line about running from a bear, that you only need to be faster than the slowest person. It got a laugh, but the serious version is that not holding certification does not mean your practices are bad. It means nobody has validated them.
Duncan was refreshingly candid on the limits. Organisations control their own Cyber Essentials scope and can legitimately exclude segments, so scoping can exclude a lot of sins. De-scoped elements are publicised, though, so as he put it, it comes out in the wash.
Which is when Will delivered the line I have already repeated three times this week: "The Titanic was fully compliant when it set sail".
Agentic AI changes the speed, the scale and the number of people capable of running an attack. It has not changed the way most attackers get in.
If you cannot see the AI tools your team is already using, you cannot govern them, and you cannot revoke what they have been permitted to do. That gap is not a future problem. On the evidence Will presented, it is being exploited right now, by attackers who never had to break anything.
Start with visibility. Then multi-factor authentication, patching, backups you have actually tested, and role segregation that assumes any account can be taken over. None of it is new. All of it still decides the outcome.
Thank you to Will and CovertSwarm, to Duncan and the team at Fortinet for hosting us at Moorgate, and to Richard for giving up a morning that policing could easily have claimed instead.
We are already planning the next Mind The Gap breakfast. If there is a topic you want put in front of a panel like that one, tell us and we will look at it!