IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
Google Cloud urges stronger cyber basics amid AI attacks

Google Cloud urges stronger cyber basics amid AI attacks

Tue, 25th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Google Cloud has urged companies to strengthen basic cybersecurity controls as artificial intelligence changes how attacks are carried out, according to Chris Betz, chief information security officer at Google Cloud.

Betz said the spread of AI has led some to believe that long-established security practices matter less than they once did. He argued the opposite: controls such as multi-factor authentication, Zero Trust frameworks, regular patching, and broad detection and response are becoming more important as attackers use AI to increase the speed and precision of their operations.

His comments reflect a wider debate in the technology sector over whether AI will reshape cyber defence mainly through new tools or through stricter execution of existing practices. For cloud providers and large corporate customers, the question has become more urgent as AI systems are deployed across software development, business processes, and customer-facing services.

"As AI accelerates the capabilities of adversaries, foundational strength becomes the primary differentiator between resilience and vulnerability," Betz said.

Betz described AI as an optimisation tool on both sides of the security contest. Conventional automation had already made it possible to handle repetitive tasks at scale, he said, but AI now allows attackers and defenders to carry out highly specific actions much faster and in far greater volume.

That is changing the threat landscape in real time, he said. Among the developments he highlighted were malware that can generate malicious scripts on demand and alter code during execution to avoid detection, as well as vishing and deepfake techniques used for identity theft and business email compromise. He also pointed to unauthorised AI tools as a source of so-called shadow agents inside organisations.

Vulnerability shift

A central part of the argument concerns vulnerability management, where AI is changing both discovery and response. Betz said identifying and fixing software weaknesses had, within a few years, shifted from a largely manual process to one in which AI tools find flaws at a much higher rate, while the window between discovery and exploitation has narrowed sharply.

He said the increase in volume means organisations cannot focus only on finding vulnerabilities. They also need to prioritise the flaws that pose the greatest risk to systems and networks, then move quickly to reduce exposure.

Organisations are using several models to scan for flaws and propose code fixes that engineers can move into production, Google Cloud said. Betz said AI can be applied across the software development lifecycle, from discovery through testing and deployment, to help defensive work keep pace with threats.

Threat modelling

Betz also pointed to threat modelling as an area where AI can have a practical effect. He said the work depends on pulling together context from source code, cloud architecture, system design, and network paths, which can be difficult for security teams to do consistently at scale.

Teams have been testing multiple AI models to gather system information and identify threats, according to Betz. He said Google Cloud's engineering teams now put product launches through an agent-based security review pipeline, with higher-risk indicators referred for human review and static threat models replaced by continuously updated product dossiers.

The comments also cast the role of the chief information security officer in broader business terms. Betz said security leaders are now expected to operate not only as technologists but as strategic executives who can explain risk clearly to boards, senior management, and security teams.

That shift has been reinforced by board-level attention to AI risk. As companies invest in generative AI tools and agent-based systems, cybersecurity leaders face pressure to show they can adopt the technology without weakening governance or increasing operational exposure.

Google Cloud used the commentary to point to a series of related security efforts across its business and partner ecosystem. These included work with Wiz on AI-related visibility and response, research into supply-chain attacks and cloud threats, and a roadmap to migrate its infrastructure to post-quantum cryptography by 2029.

Other examples included the use of confidential computing in medical AI, defences against abusive browser notifications, and internal work on agentic source code review. Google Cloud also cited recent investigations into extortion campaigns using voice phishing, attacks on developer toolchains, and software supply-chain compromises affecting open-source packages.

The thread linking these issues is that AI expands the number of ways attackers can adapt while increasing the burden on defenders to maintain strong controls across users, software, and infrastructure. In Betz's account, that makes basic security discipline not a legacy approach but a prerequisite for any organisation trying to use AI safely.

"By aligning security fundamentals with business objectives and using AI to enhance defense, we can lead our organizations securely into the future," Betz said.