The Attacker's Capability Just Scaled Without a Hiring Plan
Five federal agencies don't typically drop everything to co-sign a single security advisory. NSA, CISA, FBI, EPA, and DOE just did. The target? AI-generated scripts hitting Siemens industrial controllers in water systems, power grids, and manufacturing plants. When government moves that fast, the threat isn't theoretical anymore.
But here's what everyone's missing: we're not facing smarter attackers. We're facing attackers who can suddenly be everywhere at once.
The Real Shift Nobody's Pricing In
I was reviewing risk assessments with a financial services client last week, and we hit the same pattern I've seen a dozen times this quarter. Every fraud scenario, every vendor-compromise path, every business-process attack — the risk score quietly assumes the bad guy has to be good. Not just motivated. Genuinely skilled. Rare.
That assumption just broke.
Writing a working exploit for an industrial control system still requires the same narrow expertise it always did. Years of hands-on work with equipment most people never touch. Deep knowledge of obscure protocols. Patience to map systems that don't show up in a web browser. That one expert used to hit maybe one site per day. Now they point AI at the problem and hit a hundred sites before lunch.
The talent didn't multiply. The output did.
We've Watched This Movie Before
The pattern isn't new — just the technology. In the early 2000s, phishing required actual skill: social engineering chops, email infrastructure, target research, convincing copy. Then came phishing kits. Pre-packaged templates. One-click deployment. Suddenly every script kiddie could run a campaign that looked like it came from a pro.
Ransomware followed the same arc. It used to require technical operators who could navigate networks, exfiltrate data, negotiate payments, manage infrastructure. Then ransomware-as-a-service turned the whole operation into a rental. The affiliates don't need to know how it works — they just need a target list and a Bitcoin wallet.
Every time the tooling industrializes, the volume goes vertical. The constraint was never motivation. It was always capability. And once capability becomes a commodity you can download or prompt into existence, the economics flip overnight.
Nobody went bankrupt the day phishing kits launched. The fraud losses just started climbing, quarter after quarter, until they were structural. The town didn't empty when the railroad arrived — it just slowly realized the factory wasn't coming back.
Your Threat Model Has an Expiration Date
Here's the uncomfortable part: most enterprise risk assessments are quietly betting that expertise stays scarce. I see it every time I review a risk matrix. The "likelihood" column leans hard on complexity as a natural dampener. This attack requires deep knowledge of our vendor integration. This fraud path needs someone who really understands our settlement process. This exploit requires hands-on access to legacy systems.
All true. All increasingly irrelevant.
Because the question isn't whether the attack is complex. It's whether that complexity still functions as a barrier once one skilled person can use AI to package their expertise into a tool that runs itself. The intricate, fiddly, requires-deep-knowledge attacks? Those are exactly the ones AI is built to scale.
I'm watching clients re-run risk assessments they finalized six months ago, and the math is shifting. Not because new vulnerabilities appeared. Because the "threat capability" variable — the one that was supposed to keep likelihood manageable — just moved. And nobody went back to re-score.
The Water Plant Is a Detail
If you're thinking "I don't run critical infrastructure, this doesn't apply to me," you're missing the pattern. The Siemens controller is the example. The economics are the point.
Anywhere your control environment assumes the attacker needs to be an insider, or deeply technical, or patient enough to hand-craft an approach — that assumption is now a liability. Financial reconciliation abuse. Vendor master manipulation. Complex reimbursement fraud. Process gaps that require "deep knowledge of how we actually work" to exploit.
Those weren't protected by good controls. They were protected by the fact that running the attack was more trouble than it was worth. AI didn't make attackers smarter. It made "more trouble than it's worth" obsolete.
The gap between "theoretically possible" and "economically viable" just collapsed. And that gap was doing a lot of unacknowledged heavy lifting in your risk posture.
What This Looks Like Monday Morning
I sat in a controls review last month where someone pointed at a segregation-of-duties gap and said, "Yeah, but you'd need to really understand our month-end close process to exploit that. It's not like someone's going to figure that out from the outside."
Six months ago, that was a reasonable take. Today, I'm not sure. Because the question isn't whether a random attacker understands your close process. It's whether they can feed your job aids, process documentation, and system screenshots into a tool that generates 50 working attack variants while they're getting coffee. (But what do I know — I've only watched the "expertise becomes a commodity" movie three times already.)
The playbook isn't rocket science:
First, stop treating complexity as a control. If your risk assessment is leaning on "this is too hard for most attackers," re-score it. Complexity buys you less time than it used to.
Second, look for the places you're protected by scarcity, not defenses. Vendor integrations with weak validation. Manual reconciliations that assume mistakes are rare. Approval workflows that trust role context. Anywhere the control is "nobody would bother" instead of "nobody could succeed."
Third, ask the uncomfortable question in your next risk meeting: Where in your current business is an expert + AI going to do the same thing that just happened to water systems? Where does one skilled person, equipped with tooling that scales their output 100x, suddenly make an unlikely risk a weekly occurrence?
Because the federal advisory about industrial controllers isn't a water-sector problem. It's a preview. The attacker's capability just scaled without a hiring plan. And your risk model is still assuming they're working alone.
Here's what to do this week: Pull your last enterprise risk assessment. Find three risks rated "low likelihood" because the attack is complex or requires insider knowledge. Ask your team: if one expert could run this attack at scale using AI assistance, does the rating still hold? If the answer makes you uncomfortable, you're asking the right question.
Frequently asked questions
- What did the five federal agencies warn about in their recent advisory?
- The NSA, CISA, FBI, EPA, and DOE co-signed an advisory warning that attackers are using AI-generated scripts to target Siemens controllers that run water systems, power grids, and manufacturing facilities.
- How does AI change the economics of cyberattacks?
- AI allows a single expert attacker to automate their work and target hundreds of sites in a day instead of one, or build a commercial-grade tool that runs attacks autonomously. This scales output without scaling the talent required, following the same economic pattern as phishing kits and ransomware-as-a-service.
- Why are existing risk models now unreliable?
- Most risk ratings assume low likelihood based on attack complexity and scarcity of skilled attackers. Both assumptions have shifted—AI-powered automation removes the bottleneck of rare expertise—but organizations haven't re-scored their risks to reflect this change.
- What question should leaders bring to their next risk meeting?
- The post recommends asking: 'Where in your current business is the same thing going to happen?'—pushing organizations to identify which of their threat models rely on the now-obsolete assumption that attacks require rare, scarce expertise.
More Ai Posts
The AI Pricing Time Bomb: Your Strategy
You're paying 2% of true AI costs. Learn what happens when OpenAI and Anthropic reprice subscriptions and how to future-...
Why Solo AI Builders Are Your Market Canaries
Solo developers using AI are discovering pricing models and tools enterprises will demand in 2-3 years. Watch them to pr...
Stop Waiting for AI: Your Competition Already Started
AI disruption isn't coming tomorrow—it's happening now. While most companies debate, competitors are shipping. Here's wh...
