National Cyber Director Sean Cairncross put it bluntly: “You don’t necessarily need the newest tool. You need to clean up the basics in a lot of these enterprises.”
The pattern across every speaker, DOE’s Andrew McClure, DISA’s Lt. Gen. Paul Stanton, Canada’s Rajiv Gupta, Australia’s Stephanie Crowe, New Zealand’s Catriona Robinson, was the same:
→ Most breaches still trace back to unpatched systems, default passwords, and IT/OT that was never properly segmented, not novel AI-driven attacks.
→ AI is accelerating the timeline on old problems (patching, vuln remediation), not inventing new ones.
→ The upside: the same offensive AI tools attackers use can be turned inward to scan your own network and surface the gaps you’ve been ignoring for years.
→ Before deploying agentic AI defensively, understand the fundamentals, the constraint model, the second- and third-order effects, or you’re automating on top of a weak foundation.
Robinson’s line is the one worth sitting with: “Resist the breathless rush to grab the new tools. Resist the thoughtless assumption that inputs equals outcomes.”
For GovCon and cleared-workforce leaders, this tracks with what we see in hiring, too: the fundamentals (people, process, basic hygiene) still decide outcomes more than the shiny layer on top.
