Breach prevention gives way to harm reduction, Western cyber chiefs say
Federal compliance regimes were built to prevent breaches; senior cyber officials now say surviving them is the real assignment.
TL;DR
At Black Hat, DHS Assistant Secretary Joseph Alm, federal acting CISO Michael Duffy, and cyber chiefs from the UK and Canada each argued that AI-accelerated attack capabilities have made breach prevention an insufficient strategy. Organizations must assume intrusions will succeed and plan for continuity under pressure. The framing is notable less for its novelty (practitioners have said this for years) than for who's saying it: the officials whose agencies administer compliance regimes built on the premise that the right controls prevent breaches.
The shift from "prevent the breach" to "survive the breach" isn't new to the engineers and CISOs who've been living it. What changed Wednesday is that the people running the policy side of US cyber defense said it plainly, in public, and tied it directly to AI.
Joseph Alm, DHS assistant secretary for cyber, called cyber compromise "just a swan", not a black swan, not an unforeseeable crisis. Federal acting CISO Michael Duffy argued the next decade of policy must focus on anticipating attacks and maintaining operations under pressure, not on preventing the last crisis from repeating. UK NCSC's Jonathon Ellison and Canadian cyber chief Rajiv Gupta offered similar assessments, with Gupta describing a "Minimum Viable Canada" initiative to identify essential functions through a hypothetical three-month internet outage.
The dissonance is hard to miss. CMMC, FedRAMP, NIST SP 800-171, and the rest of the federal compliance apparatus are built on a control-implementation model: identify the requirements, implement the controls, pass the assessment, and (the implicit promise) you've reduced risk to an acceptable level. Nobody says "acceptable" means zero, but the structure rewards prevention. It doesn't reward continuity planning or harm reduction. You don't get a DIBCAC passing score for a well-rehearsed incident containment procedure.
Ellison added an important qualifier: most organizations' immediate problem isn't novel AI attacks. It's the known vulnerabilities already sitting in their networks from years of underinvestment. AI raises the ceiling on what attackers can do, but the floor is still unpatched.
For the compliance director or CISO reading this, the immediate question is whether these statements signal regulatory change or are merely officials thinking out loud. The answer probably sits with how CISA's NCIRP update (closed for public comment in February 2025) actually gets implemented, and whether the AI Cybersecurity Collaboration Playbook published in January 2025 evolves from voluntary guidance into something harder.
The posture shift these officials described doesn't require a new regulation to matter. It changes what "due care" looks like in a post-breach review, what a contracting officer might consider reasonable security practice, and what a court might treat as foreseeable harm. That's enough to put continuity planning on the Monday to-do list.
Published ·Deep Fathom