AI Raised the Cyber Stakes, But Best Practices Still Win

Technology

Every AI security guide published this year opens with the same assumption:

That your organization has the fundamentals in place. Secure configurations. Controlled access. Continuous monitoring. Inventory of what you're actually running.

That assumption is doing a lot of work and for many organizations, it's wrong.

Faster Threats, Same Security Gaps

AI didn't introduce new categories of risk. It changed the speed and volume at which existing vulnerabilities are found and turned into attacks. 

Tony Sager, Senior Vice President and Chief Evangelist at CIS put it plainly in a ai iconblog post about Mythos, the AI-based vulnerability discovery capability that drew significant attention earlier this year. Sager notes that AI doesn't change the existence of vulnerabilities, but how fast and how broadly they are identified and potentially weaponized. The classes of vulnerability remain the same. The ones AI finds will overwhelmingly fall into the same categories security teams already analyze, plan for, and address.

This is reassuring because if you have solid fundamentals already established then your defenses will address most realistic attack paths. It's also clarifying because it means the answer to AI-accelerated threats is not new, it remains consistent execution of the controls that already work. If you don't have a solid security foundation established, AI is making existing gaps more dangerous. Not because the attack surface fundamentally changed, but because the time between vulnerability discovery and exploitation is compressing. The same entry points attackers have always used become harder to defend when the window to close the gaps shrink. 

Foundational Security Best Practices

The security measures that are proven to stop today's most common attacks are already built, independently validated, and prioritized so resource-constrained organizations can start with what moves the needle most. The Center for Internet Security provides two foundational resources that make consistent implementation possible: the CIS Critical Security Controls® (CIS Controls®) and the CIS Benchmarks®.

Data-backed Cyber Defense Framework: CIS Controls

The CIS Controls identify the security practices with the greatest demonstrated impact on reducingoperationalizing logo risk. They are prioritized so organizations of any size can start with what matters most. That starting point is Implementation Group 1 (IG1), what CIS refers to as essential cyber hygiene.

The newly released CIS Community Defense Model v3 (CIS CDM v3) puts numbers behind that claim. Based on 2024-2025 threat data, IG1 defends against 84% or more of the ATT&CK sub-techniques across the five most prevalent attack types: System Intrusion, Social Engineering, Basic Web Application Attacks, Privilege Misuse, and Denial of Service. Implementing all CIS Safeguards defends against 97% or more across every category. CDM v3 goes further than previous versions by introducing the CIS Controls Active Defense Lifecycle, which maps not just whether a Safeguard mitigates a technique, but when in the attack lifecycle it stops an adversary. Knowing a control works is valuable. Knowing it stops an attacker before they reach their objective is a strategic advantage.

Top 5 Attacks

Globally Trusted CIS Benchmarks

Knowing which security measures to implement is one thing. Understanding exactlyCIS Benchmarks icon how to configure the systems you actually run is another. The CIS Benchmarks provide more than 100 vendor-neutral configuration guides that translate CIS Controls guidance into specific, actionable settings for operating systems, cloud platforms, network devices, and applications. They are developed and maintained by a global community of security experts and are updated continuously to reflect the current threat environment.

Together, the CIS Controls and CIS Benchmarks form the measurable foundation that every AI security framework on the market assumes you already have in place.

From Security Gaps to Audit-ready

AI is moving faster than security teams can hire for, train for, or manually respond to. The answer isn't reacting faster after an incident. It's having the right foundations in place before one. Organizations that know what they are responsible for protecting, have their fundamentals applied consistently, and can see problems early retain an advantage. 

CIS SecureSuite® Membership is how organizations build that advantage at operational speed.

Assess Without the Manual Burden

CIS-CAT® Pro Assessor scans systems against the CIS Benchmarks and produces detailed, machine-readable results showing exactly which configuration settings pass, which fail, and by how much. A team doesn't have to manually check hundreds of settings across dozens of systems. 

Remediate Faster

CIS Build Kits automate the configuration changes needed to close gaps identified in an assessment. The cycle becomes assess, remediate, reassess, document. That cycle is what operational readiness actually requires, and it runs faster with automation than without it.

 

Demonstrate Progress Over Time

Auditors, regulators, and leadership don't accept a policy document as evidence. They want assesStrong Security iconsment results, conformance data, and documentation of progress over time. The CIS SecureSuite Platform connects assessment results to conformance tracking across the full timeline. When an auditor asks how your organization has progressed on CIS Benchmark conformance over the past year, the Platform provides an answer with data attached. Those results are a deliverable: specific, sourced, and usable in an audit.

The goal is not to match the speed of the threat. It is to close the gaps before the threat finds them. CIS SecureSuite Membership is built to do that at a pace teams can sustain.

Ready to Close the Gap?

Automated assessment, remediation support, and conformance tracking work together to turn your security program into documented, audit-ready evidence. CIS SecureSuite Membership brings it all together so you can move from gap to audit-ready faster.

The fundamentals haven't changed. The speed at which you apply them now matters more than ever.

As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.