
Artificial intelligence is reshaping cybersecurity across the defense industrial base, but it does not replace the fundamentals of good cyber hygiene.
As manufacturers explore AI to improve productivity and operations, cybercriminals are using the same technology to automate attacks, generate more convincing phishing campaigns, and identify vulnerabilities at a speed not previously possible.
That is the focus of MxD Cyber’s recent webinar AI vs. AI: The Cyber Arms Race featuring Jake Braun, executive director of the Cyber Policy Initiative at the University of Chicago, and Mike Tanji, director of cybersecurity at MxD.
While the discussion explored emerging AI capabilities, one message is clear: Organizations that struggle with basic cybersecurity practices today will not solve those challenges simply by adopting AI.
AI is lowering the barrier for attackers
Artificial intelligence is making cyberattacks faster, cheaper, and easier to launch.
Braun noted that AI is already performing well in offensive security testing and helping automate tasks that previously required experienced attackers. Tanji added that AI is also enabling less-sophisticated threat actors to carry out more credible attacks by automating vulnerability discovery and creating more convincing phishing campaigns.
The result is an environment where organizations should expect more phishing attempts, more automated reconnaissance, and a higher overall attack volume.
Cyber resilience matters as much as prevention
As offensive capabilities improve, organizations should recognize that preventing every attack is unrealistic.
Both speakers emphasized the importance of cyber resilience, or the ability to detect incidents quickly, recover operations, and continue serving customers even when systems are disrupted.
For manufacturers, this means investing not only in preventive controls but also in response planning, recovery procedures, and operational resilience.
Focus on the fundamentals
Despite rapid advances in AI, the webinar repeatedly returned to a familiar conclusion: Most organizations still need to improve the fundamentals.
Braun encouraged manufacturers to focus on understanding what assets are connected to their networks, knowing what software is running, and ensuring systems are securely configured before worrying about more advanced AI-driven defenses.
He also stressed that multifactor authentication remains one of the most effective security measures organizations can implement.
As Tanji noted, AI amplifies existing cybersecurity challenges, but doesn’t eliminate them.
AI works best when paired with human expertise
The webinar carried a warning: AI is not a replacement for experienced employees.
While AI can accelerate research, automate repetitive tasks, and help organizations tackle projects that previously required significant resources, human expertise remains essential for validating results and identifying mistakes.
Organizations should also train employees to use AI effectively. Without that foundation, employees may treat AI like a search engine or place too much confidence in inaccurate outputs.
The takeaway: For manufacturers, AI should enhance existing expertise rather than replace it.
Small manufacturers don’t have to build everything themselves
Both Tanji and Braun recommended that small and mid-sized manufacturers with limited cybersecurity resources rely on mature cloud platforms rather than attempting to manage every security function internally.
Organizations that use services from established providers should ensure security features such as multifactor authentication and other built-in protections are enabled, allowing internal teams to focus on managing business risk instead of building security capabilities from scratch.
The discussion also reinforced that manufacturers should be cautious about introducing AI tools into their environments without understanding how they handle sensitive information or where organizational data may be stored.
Ultimately, while AI is accelerating both attacks and defenses, success still depends on disciplined cybersecurity practices, well-trained employees, and organizations that continue to strengthen the fundamentals.
Speakers
Jake Braun is Executive Director of the Cyber Policy Initiative at the University of Chicago and co-founder of Cambridge Global Advisors. He is a nationally recognized cybersecurity policy expert whose work focuses on AI, critical infrastructure security, and cyber resilience.
Mike Tanji is Director of Cybersecurity at MxD. A former intelligence officer, he helps manufacturers strengthen cybersecurity and adopt digital technologies securely across the defense industrial base.