AI-Accelerated Cyber Risk Management

Cyber

Kroll Perspectives: AI-Accelerated Cyber Risk Management

Has your organization been exposed? How can you act on the exposures that matter most? What’s the best way to demonstrate measurable risk reduction?

 

Anthropic's release of Claude Fable 5 and Claude Mythos 5, along with its Project Glasswing update, shows how advanced cyber reasoning capabilities are moving from research demonstrations into operational defensive use cases.

– Gayathri Kunapuli, Kroll

Six Shifts Driven by Frontier AI

In our conversations with clients since the Project Glasswing and Project QuiltWorks announcements, the question has moved from “What does this mean?” to “How do we operationalize our response?”

AI accelerates the clock while reinforcing the fundamentals

Security leaders still need inventory, ownership, prioritization, remediation and verification; those capabilities must now operate on compressed timelines.

Discovery is becoming abundant

Remediation velocity is becoming the scarce resource. The ability to prioritize what matters, assign owners, remediate and demonstrate risk reduction will define true resilience.

Threat Exposure Management is shifting from a security workflow to an enterprise risk discipline

CISOs, CFOs, general counsel, CROs and boards need a shared view of exposure, financial impact, legal posture, ownership and evidence.

Regulators are emphasizing evidence and accountability

The expectations center on governance, resilience, disclosure readiness, third-party oversight, documentation and defensible decisions.

The focus for security teams is shrinking the exposure window

Prioritize the paths that can affect the business and reduce those exposures before attackers can operationalize them.

CrowdStrike's Project QuiltWorks, with Kroll among its initial partners, was built for the next step

We help close the exposure gap at machine speed by enabling organizations to assess, prioritize and remediate AI-discovered vulnerabilities in production code.

27 sec

Fastest adversary breakout time

89%

Year-over-year rise in AI-powered attacks

0 sec

Time between discovery and exploit
Source: CrowdStrike 2026 Global Threat Report

 

How to Prepare

 

Frontier AI Risk Assessment

Kroll delivers frontier AI risk assessments that help organizations move from awareness to action through one continuous exposure-closure loop. We enable leaders to determine not only where they are exposed, but also which risks to prioritize, what actions are required, who owns them, and how to fund and verify remediation, accelerating remediation velocity. 

We Help Clients

  • Assess exposure across the organization and validate how individual weaknesses can combine to create real attack paths. 
  • Prioritize exposure using threat intelligence, attack paths, privilege impact and business context. 
  • Operationalize remediation through workflows, SLAs, escalation paths and orchestration. 
  • Validate closure of attack paths and continuously adapt as threats and environments evolve. 

Our Clients Achieve

  • Faster discovery and prioritization
  • Remediation within defined SLAs
  • Reduced attack paths
  • Improved patching cadence
  • Clear, executive-ready reporting

Project QuiltWorks

Project QuiltWorks is an industry coalition including Kroll, built to close the AI vulnerability gap for enterprises. This coalition sets a new standard for vulnerability discovery and collaborative cybersecurity in AI. 

Frontier AI models integrated across the Falcon platform through Project QuiltWorks uncover logic flaws, misconfigurations and novel exploit paths that scanners and human reviews may miss.

As part of Project QuiltWorks, Kroll is working with CrowdStrike to combine technology-enabled discovery, adversary-informed prioritization and guided remediation with Kroll’s expertise in consulting, incident response, regulatory compliance, AI risk management and remediation.

Move exposure management closer to AI speed while preserving the human accountability required to strengthen resilience and make decisions that reduce enterprise risk.

– Gayathri Kunapuli, Director, Cyber and Data Resilience

What Every C-Suite Should Be Asking

C-Suite Role
Key Considerations
Key Threats to Manage and Measure
CISO
Which exposures can an attacker realistically reach, chain and exploit? Where does remediation stall?
Threat-informed prioritization, ownership, mitigation plans, verification evidence and operational metrics.
CFO
What is the potential financial impact, which investments reduce risk most and where are we paying for activity rather than risk reduction?
Financial exposure scenarios, remediation capacity analysis, risk-reduction options and investment trade-offs.
General Counsel / CRO
What is material, what needs disclosure or notification, who accepted the risk and what evidence supports the decision?
Governance and risk management records, disclosure and notification playbooks, third-party obligations and defensible documentation.
Board / Audit or Risk Committee
Are we exposed in ways that affect operations, customers, regulated data, revenue or resilience?
Plain-language reporting on exposure trends, verified closure, accepted risks, residual exposure and investment decisions.

AI-Enhanced Vulnerability Exploitation Pathway

Kroll Perspectives: AI-Accelerated Cyber Risk Management

MITRE ATT&CK Tactics

  • TA0001 – Initial Access

Key Techniques

  • T1566 – Phishing (Spearphishing Link / Attachment / Voice)
  • T1656 – Impersonation
  • T1204 – User Execution

AI Enhancement

  • LLM-generated spearphishing emails at scale
  • AI voice cloning (vishing / executive impersonation)
  • Target profiling using OSINT summarization

Real-World Examples

  • Scattered Spider (2023–2025): Used highly tailored social engineering and helpdesk impersonation; emerging reporting shows the use of AI-written scripts to improve success rates
  • Business Email Compromise (BEC) Campaigns (2024–2026): Increasing use of generative AI to produce fluent, context-aware phishing emails
  • Deepfake Voice Fraud (UK energy firm case, €220k theft): AI-generated CEO voice used to authorize fund transfer

What Executives Can Do Now

Immediate Actions

  • Align security, legal, finance, risk and business leaders on how exposure decisions will be made and escalated.
  • Establish a shared view of critical exposures, accountable owners and business impact.
  • Review how AI-enabled systems, agents, third parties and non-human identities are incorporated into existing risk management processes.
  • Connect exposure management with incident response, crisis management and disclosure planning.
  • Identify where remediation, mitigation or risk acceptance decisions are slowing down.

 

Near-Term Actions

  • Evolve prioritization to include exploitability, attack paths, business impact, resilience impact and mitigation options.
  • Strengthen the operating model for exposure management, including ownership, escalation, governance and executive reporting.
  • Test how quickly the organization can respond to a high-impact exposure across security, IT, legal, finance and the business.
  • Refresh incident response, BCP and DR planning for AI-enabled systems, third-party dependencies and accelerated exploitation scenarios.
  • Develop board-level reporting that shows exposure reduction, decision quality, accepted risk and remediation capacity.

Stay Ahead With Kroll

Kroll supports thousands of clients on the frontier of AI and risk, leveraging global, market-leading expertise in a wide range of risk mitigation disciplines. Learn more about the core areas of expertise that we leverage to build our bespoke solutions. 

Why Choose Kroll?

  • Deep technical and vulnerability management expertise, gained from more than 150k hours of security testing per year
  • Unparalleled incident response experience
  • Frontline intelligence from thousands of investigations every year
  • A broad range of services for security, risk, investigations and compliance

 

Talk to a Kroll Expert

Stay Ahead with Kroll

Cyber Risk Assessments

Kroll's cyber risk assessments and advisory services deliver actionable recommendations to improve security, using industry best practices & the best technology available.

Threat Exposure Management

Kroll’s field-proven cyber security assessment and testing solutions help identify, evaluate and prioritize risks to people, data, operations and technologies worldwide.

Technology Expert Services

Our team has decades of experience serving as independent advisors, and our client-focused approach and deep technical expertise allows us to work across a spectrum of technologies, industries and data issues.

Cyber Transformation

Implement, configure and run scalable cybersecurity programs at the pace of digital transformation

Regulatory Compliance Assessments

Expert support to comply with a wide range of cybersecurity compliance requirements and build long-term cyber resilience.

Cyber Litigation Support

Whether responding to an investigatory matter, forensic discovery demand, or information security incident, Kroll’s forensic engineers have extensive experience providing litigation support and global eDiscovery services to help clients win cases and mitigate losses.