July 6, 2026
In Partnership With:
For many, the word ‘cybersecurity’ draws up images of a dark room, multiple screens with reams of fluorescent green ones and zeroes passing by the shadowy face of a hacker. It’s become a Hollywood cliché.
But with the rise of AI and future technologies, cyber attacks are no longer something that only happens to the characters in the movies and on TV shows. The Institution of Engineering and Technology conducted a poll in September 2025 which found that more than half (56%) of the public were fearful of being hacked in the future, while 74% believed hackers are becoming increasingly inventive.
These fears were reflected at Intelligence Squared’s recent event in partnership with IBM, The Age of Intelligence. Kamal Ahmed – Executive Editorial Director at Fortune Europe and this series’ host – polled the audience: who currently holds the strategic advantage in cybersecurity – the attackers or the defenders? At the beginning of the event, an astonishing 84% said the attackers had the edge.
But perhaps the even more surprising aspect of the evening was that the experts on stage disagreed with each other on this key point.
Journalist Jon Sopel acknowledged the growing scale and visibility of cyber threats, and both Matt Rowe, Chief Security Officer at Lloyds Banking Group, and Dimple Ahluwalia, Global Offering Leader for IBM CyberDefend, argued that advances in AI and emerging technologies may ultimately strengthen defenders more than attackers.
So why does the public believe attackers are winning? Part of the answer lies in the succession of high-profile attacks that have dominated headlines.
“When the seatbelt was introduced, it allowed cars to go faster. That is what cybersecurity will do for business.”
From well-known retailers, multinational manufacturers or public institutions, more and more enterprises are being targeted for both the sensitive personal data of customers and ransom payouts. At times, these attacks can even have devastating effects on national economies, as complex supply chains can impact small and medium-sized businesses.
Often, these large corporations are targeted because of their brand recognition. Knowing that their attack will appear in the media, attackers instill fear into the general public. That is why, as Jon Sopel – former North America Editor for the BBC and now co-host of the hit podcast The News Agents – put it, it’s in these moments “that you think, ‘Wow, everything’s insecure’.”
Yet those working at the front line of cybersecurity see reasons for practical optimism. While 84% of attendees believed attackers currently hold the strategic advantage, both Rowe and Ahluwalia stated that this picture is changing. AI is undoubtedly creating new opportunities for malicious actors – but it is also giving defenders unprecedented visibility into their own systems and vulnerabilities.
Ahluwalia argued that attackers enjoy an advantage that has little to do with technology. Every successful breach becomes a headline; every attack generates fear, disruption and public scrutiny. The countless attacks that are quietly detected, contained and prevented rarely make the news. The result is a perception that attackers are always advancing and defenders are always reacting. But what if that perception is increasingly outdated?
At the board level, cybersecurity was often seen as a cost of doing business but not something to invest in. But with the continuous innovation of frontier AI, the costs of not investing in cyberdefence are increasing exponentially. IBM’s own 2025 Cost of a Data Breach Report reports that the average cost of a data breach was $4.44 million in that calendar year. In the US, the average cost was at an all-time high of $10.22 million. However, IBM also found that boards which invested in AI-powered security defenses saved an average of $1.9 million per breach and shortened the ‘breach lifecycle’ by 80 days. For reference, the average lifecycle of a breach is 279 days.
Ahluwalia offered a powerful analogy to understand why attitudes around cybersecurity have changed: “When the seatbelt was introduced, it allowed cars to go faster. That is what cybersecurity will do for business.” Done well, it is not a brake on innovation but the condition that allows organisations to scale, experiment and adopt new technologies with confidence.
“The cyber arms race will not be won by technology alone. It will also be won through governance … and better habits around data. ”
To open The Age of Intelligence, Ahmed asked the panellists about what might be called the ‘3AM test’: the moment when an urgent security alert lands in the middle of the night, a sensitive dataset needs to be handled, and the fastest available tools are not necessarily the ones approved by the organisation.
In that moment, cybersecurity stops being abstract. It becomes a test of judgment and training. Does an employee reach for an unauthorised AI tool because it appears to offer a quick answer? Or do they know enough about the risks, and the organisation’s protocols, to hold firm?
This is where defenders can begin to turn home advantage into real advantage. Most organisations still lack formal governance for ‘Shadow AI’: the use of unauthorised AI tools by employees. Companies with high levels of Shadow AI face significantly higher breach costs. In their 2025 Cost of Data Breach Report, IBM reports that 97% of AI-related security breaches involved systems that lacked proper access controls.
The lesson is clear: the cyber arms race will not be won by technology alone. It will also be won through governance, employee awareness and better habits around data. We often talk about human error as though it is inevitable. But in the age of AI, behaviour can be shaped, systems can be clarified, and employees can be given the confidence to make better decisions under pressure.
It is not a glamorous fix, but it may be one of the most powerful. If attackers benefit from speed, confusion and improvisation, defenders benefit from preparation, resilience and trust in their training.
AI’s greatest contribution might not be automation. It might be visibility. For the first time, organisations can analyse vast quantities of security data in real time, identifying patterns, vulnerabilities and anomalies that would previously have remained hidden.
As Rowe argued:
“Cybersecurity is a big data problem. AI and machine learning are really well disposed to solving big data problems. And on the defender side, we’ve got home-field advantage. We know our environment. We can use AI to really illuminate any security flaws and close them”.
Cybersecurity has always been about data. But as data continues to become the cornerstone of enterprise, now, with AI, attackers can target organisations where it matters most: their vast volumes of logs, alerts, user activity and system signals. Human teams cannot realistically defend these systems alone.
“It is important to remember that cyberattacks are still crimes, and they affect not only businesses but their consumers.”
This is where AI meets governance. Despite different economic models, resource profiles or expertise, the entire ecosystem must work together to align defences. Rowe discussed how Lloyds Banking Group are working with everyone from the UK government to the National Cyber Security Centre and the National Centre for Resilience to raise standards across the board. He acknowledged it won’t be an easy task. Large enterprises will naturally have different pressure points to SMEs.
Rowe also challenged the tendency to view every cyberattack as a corporate failure. While organisations must take responsibility for their defences, cyberattacks remain criminal acts. When someone’s home is burgled, the focus is rarely on whether the victim should have purchased a different lock. Yet companies that suffer attacks are often judged far more harshly. It is important to remember that cyberattacks are still crimes, and they affect not only businesses but their consumers.
The full answer to Ahmed’s poll question, then, may be more nuanced than the audience’s initial verdict suggested. Attackers continue to benefit from speed, scale and the constant search for new vulnerabilities. But defenders possess advantages of their own: visibility into their environments, increasingly sophisticated AI tools, and the ability to learn collectively from every attempted breach. The balance of power is not fixed. It is being contested in real time.
Yet even as organisations adapt to today’s threats, another challenge is already appearing on the horizon. Quantum computing promises enormous advances in science, medicine and industry, but it could also render many of today’s encryption standards obsolete. For Ahluwalia, the lesson is not to panic but to prepare. Just as organisations are now building governance frameworks for AI, they must begin planning for a quantum-safe future. The organisations that start that journey today will be better positioned when the technology eventually matures.
At the beginning of the evening, 84% of the audience believed attackers held the strategic advantage. By the end, the room felt rather differently. Ahmed asked for a show of hands and this time the audience was about evenly divided.
The future of cybersecurity will not be defined by a single technology, whether AI or quantum computing. It will be defined by how organisations combine technology with governance, preparation and trust. Attackers will continue to evolve their tactics. They always have. But defenders are evolving their defences too. And as AI gives organisations greater visibility into their systems, stronger resilience across their networks and the confidence to innovate securely, the age of intelligence may ultimately prove to be an age of advantage for the defenders.