LAS VEGAS - Senior cyber officials from the U.S., UK, and Canada said Wednesday that the biggest near-term threat to critical infrastructure is not runaway AI, but a failure to prepare for attacks. At the Black Hat 2026 conference, they urged government and business leaders to focus on keeping essential services running when systems go down.
"The immediate challenge is not runaway AI," Jonathon Ellison, director for national resilience at the UK's National Cyber Security Centre, said during a panel. "The immediate challenge is being resilient enough for the faster-paced environment that we are entering into, given the legacy issues that we are carrying."
Michael Duffy, the acting U.S. federal chief information security officer, said organizations need to shift from a prevention-focused mindset to one that prioritizes continuity of services. "Things will go down," he said, and agencies must identify their most important systems so they can keep delivering their mission. He said the cybersecurity community needs "a new risk calculus for what it means to operate in a contested environment."
An attack already in progress
The officials acknowledged that AI is making hacking easier and could make attacks more destructive in the near future. But hackers don't need AI to exploit the serious technical and process vulnerabilities inside many businesses and government agencies.
That danger became clear last week, after Iran-linked hackers attacked water utilities in at least 12 states. Water systems are among the most vulnerable infrastructure operators in the U.S. because of overworked staffs, small budgets, low tolerance for downtime and heavy reliance on aging operational technology.
A push to plan for downtime
The U.S. government has begun emphasizing resilience in its cybersecurity messaging. CISA recently launched CI Fortify, a program designed to get critical infrastructure operators to prepare for downtime and offline operations.
"Part of this … is intentionally spending resources on harm reduction, not just risk reduction," said Joseph Alm, assistant secretary for cyber, infrastructure, risk and resilience policy at the Department of Homeland Security. "Assume that you're compromised. How do you make sure critical services continue? How do you minimize the time and the challenge from that?"
The U.S. is following templates from other countries. CI Fortify originated in Australia, and Canada has begun meeting with critical infrastructure providers to identify the minimum systems needed to keep operating. Rajiv Gupta, head of the Canadian Centre for Cyber Security, called the "Minimum Vital Canada" initiative "incredibly important in terms of understanding how to prioritize these systems."
Duffy said CISOs need to talk to other business leaders about maintaining essential services during a cybersecurity incident. He stressed that effective resilience requires collaboration across business roles and buy-in from senior leaders outside of the cybersecurity organization.
"This is the time," Duffy said, "for CISOs to be having that level of conversation, to say, 'This system may go down. What is plan B? How do we ensure that the critical function of the organization can maintain its delivering on the mission regardless of what's happening to it?'"
No rush to regulate AI
Even as AI raises security defenders' anxieties about operating vulnerable infrastructure, the Trump administration is not interested in regulating what frontier models can do. Alm said the administration's goal is "trying to maintain AI dominance and trying to make sure that we don't, in an effort to minimize risk, actually maximize the greatest risk, which is that we lose leadership in AI and that other people define the future for us and we inhabit the world that they create."
At the same time, he said it is important that "we put in place sufficient guardrails that we don't end up creating immense danger."
The panelists agreed that AI has not yet caused a devastating cyber crisis, but the speed of technological change presents an unprecedented challenge to security leaders and policymakers. "The stakes," Ellison said, "are way, way higher than they were before."
Why this matters for Government
Federal employees can look to CISA's CI Fortify program, designed to help critical infrastructure operators prepare for downtime and offline operations. The message for state and local agencies, after the water utility attacks, is that under-resourced teams are targets too. The officials' advice: assume compromise, know your plan B, and have those conversations with leadership before the next attack.
Your membership also unlocks: