The takeaway from the Billington Cybersecurity Summit: AI didn't create new cyber problems; it exposed old ones

National Cyber Director Sean Cairncross put it bluntly: “You don’t necessarily need the newest tool. You need to clean up the basics in a lot of these enterprises.”

The pattern across every speaker, DOE’s Andrew McClure, DISA’s Lt. Gen. Paul Stanton, Canada’s Rajiv Gupta, Australia’s Stephanie Crowe, New Zealand’s Catriona Robinson, was the same:

→ Most breaches still trace back to unpatched systems, default passwords, and IT/OT that was never properly segmented, not novel AI-driven attacks.

→ AI is accelerating the timeline on old problems (patching, vuln remediation), not inventing new ones.

→ The upside: the same offensive AI tools attackers use can be turned inward to scan your own network and surface the gaps you’ve been ignoring for years.

→ Before deploying agentic AI defensively, understand the fundamentals, the constraint model, the second- and third-order effects, or you’re automating on top of a weak foundation.

Robinson’s line is the one worth sitting with: “Resist the breathless rush to grab the new tools. Resist the thoughtless assumption that inputs equals outcomes.”

For GovCon and cleared-workforce leaders, this tracks with what we see in hiring, too: the fundamentals (people, process, basic hygiene) still decide outcomes more than the shiny layer on top.

[link to article]

1 Like

Couldn’t agree more, especially with Catriona Robinson’s point. In the GovCon space, we see a lot of excitement around adding AI layers to operational stacks, but an automated process built on bad basic hygiene just speeds up failure.

The demand for cleared talent who actually master core systems architecture, patch management, and fundamental network segmentation is higher than ever. Tools amplify your baseline—if the foundation is weak, the output will be too.

1 Like

Great point. Building on a weak foundation just gives you faster failure.

Lt. Gen. Stanton and the panel nailed it. AI didn’t change the game; it just sped up the clock on old tech debt. If you aren’t using these tools internally to scan and fix your own known gaps today, you can bet attackers are using them against you tomorrow. Clean up the foundation first.

1 Like