Cybersecurity: “Who’s in Your Wallet?”

By Michael McAdams, President, Pasadena Private Lending

We often hear from our many borrowers about what they are doing to minimize risks from a variety of computer security and cybercrime exposures. For example, we have seen hackers try to commandeer a borrower’s wire instructions and send emails, allegedly from us, saying that we have changed OUR wire instructions for them to send us our monthly payments. But with simple telephonic confirmation, all has been well, at least so far.

But the world is getting more complex every day. We endeavor to stay current on security trends from industry conferences as well as recommendations from our own tech consultants and accounting and legal professionals.

But recently, our primary CPA firm, RSM USA, produced a special report on the status of cybersecurity for middle market companies in the U.S. Those findings were enlightening, and we thought we would share them with you, our readers, along with relevant observations of our own and from our borrowers’ experiences.

Stunningly, middle market companies are increasingly targeted because they represent high-value environments with uneven security maturity, procedures and protections. Accordingly, nearly 1 in 5 (18%) of middle market company executives polled by RSM said their organizations experienced a data breach of some sort in the previous 12 months.

 

 

That said, ever the optimistic entrepreneurs even with the elevated threat environment, middle market executives almost universally feel confident about their existing control environment. However, “confidence isn’t the same as preparedness,” says Rich Servillas, a director at RSM US LLP. “I see a lot of gaps in incident response engagements with organizations that have good infrastructure but no rehearsed decisions or overall security risk framework.”

AI and cybersecurity: The double-edged sword

The rapid evolution of AI introduces heightened cyber risks across several dimensions. AI’s promise of increased efficiency and insight is enticing, but companies often move too quickly without effective governance in place. In addition, if individual users or teams test or use unapproved or unvetted AI and generative AI solutions, shadow AI can emerge within the organization. Both scenarios can quickly result in the exposure or loss of sensitive data.

The survey went on to say that firms can only manage what can be seen, and companies often don’t realize that they have their own shadow IT. Or they just turn a blind eye to it and do not have the proper controls in place to manage or mitigate the challenges it brings. Meanwhile, many of their employees are using public AI tools to ask questions about how to perform certain tasks and using customer data. But that’s potentially instant data loss by using somebody else’s cloud or somebody else’s computer that you don’t know.

Middle market companies must get their arms around AI deployment, even as the broader market has yet to settle on a clear approach. And middle market companies face that challenge with fewer resources at their disposal.

On the bright side, cybersecurity firms and teams are becoming more adept at leveraging AI, and more functionality is now built into security products to increase protection capabilities. AI enables the middle market to take some security measures that were previously out of reach by leveraging tools with built-in AI, essentially extending their workforce without adding personnel.

The identity challenge increases

In addition to AI deployment risks, the cyberthreat landscape for middle market companies is elevated because AI makes sophisticated attacks easier to launch. Campaigns that previously required an exceptionally gifted threat actor and months to develop can now be orchestrated at scale by a relative novice with AI assistance. The growing use of AI underscores the need for critical security features in the middle market: identity and privileged access, control of sensitive data, and assignment of authorizations.

The RSM survey reported middle market firms focusing their resources mainly on detection and response (39%), securing the cloud (36%), and strategy and risk management (35%). Digital identity, prioritized by only 23% of respondents, represents a significant missed opportunity to focus on what human and non-human users can access rather than where they are connecting from. “Identity is at the center of information compromises,” says RSM US Principal Alden Hutchison. “Most threat actors don’t break in. They log in. When identity controls and permissions are weak, attackers don’t need exploits. As organizations adopt AI, those same gaps scale faster, because AI will act on any access it’s given, intended or not.”

Identity is the focal point of securing AI, establishing rights and defining what it is authorized to do. However, companies often debate how to structure authorizations. Should AI tools have authorizations all the time and their own specific identity? Or should they inherit the identity of the user? Companies have dealt with these questions for human identities in the past, but their importance is elevated because of the rapid growth of non-human identities.

Regardless of the size of internal departments, many middle market companies continue to rely on outsourcing for key cybersecurity functions, especially for specialized tasks. Respondents indicated that the leading cybersecurity functions currently outsourced are cloud security management (50%), security awareness training (44%), security operations center (43%), and cybersecurity risk and compliance management (41%).

 

We understand that experts are seeing early signs of AI in how threat actors communicate, with cleaner language, faster responses and more consistency. And the bigger shift is who’s using it. The ransomware-as-a-service era is fading, and more of what is being reported are lone-wolf operators. AI is what’s making them dangerous. It’s closing the gap between a sophisticated attacker and someone who wouldn’t have been a threat 18 months ago. Few are seeing attacks run entirely by AI, but that’s where this is trending. According to RSM, endpoint detection and response (EDR) maturity has genuinely improved outcomes, and we are seeing more and more incidents getting contained at the initial access or lateral movement phase, prior to encryption.

And not all news is bad from AI. Experts tell us at PPL that AI is enhancing incident response capabilities, but also enabling predictions. In some cases, companies are now better at predicting the likelihood of threats and where they’re most likely to happen due to the support of AI.



Skip to content