sign up log in
Want to go ad-free? Find out how, here.

CyberCX Executive Director Dimitri Vedeneev on cyber security risk management, - 'understand if your risk models are aligned to the threat picture'

Technology / news
CyberCX Executive Director Dimitri Vedeneev on cyber security risk management, - 'understand if your risk models are aligned to the threat picture'
h

Interest.co.nz is unpacking how AI will change your everyday life - the risks, the opportunities, and what to actually expect. Our series brings you the policymakers, experts and industry leaders from New Zealand and overseas.

By Anna Whyte

‘AI agent hacks gym to get its user a spot in pilates’, ‘Meta becomes latest firm to say its AI hacked another company’, ‘Did Iran hack water systems in at least seven US states?’

All headlines from the last two weeks as cyber security takes a front and centre stage.

Dimitri Vedeneev, Executive Director Secure AI at cyber security company CyberCX, spoke to interest.co.nz about the cyber security trends and threats he’s seeing roll out in New Zealand. He says it's all about being prepared.

CyberCX’s 2026 ‘Hack Report, created with data and insights from 1400 customers over three years, found one in three security assessments carried out uncovered a 'severe finding', which could result in an organisation being hacked.

Half of the penetration tests of AI applications in companies had at least one severe finding, double the rate of web application penetration tests, with industries such as manufacturing, construction, healthcare and logistics faced the highest rates of severe findings.

Dimitri Vedeneev, Executive Director Secure AI at CyberCX. Supplied.

On the scale of the cyber security threat businesses and New Zealanders face, Vedeneev said it will depend.

“These systems are designed to accelerate or automate different processes that human beings are creating. So where you have a nation-state threat actor, they're definitely going to be using AI to accelerate their espionage goals, influencing and shaping government policy.

“And private sector, where you've got more financially motivated threat actors like ransomware, they're going to be using whatever tools are available that are cheap and efficient to achieve their objectives, which is usually stealing money, scamming, etc."

He said while there will be an acceleration of some of the cyber harms and threats experienced before AI was on the scene, threat actors will need to also retool themselves and their ways of working.

“One key difference is that they don't normally have to go through governance committees, they don't have to worry about privacy of citizens.”

He said there needed to be a step change, not just in investing in cyber to keep companies and citizens’ safe, “but really talking about it at a senior strategic level around the fact that… legacy platforms or older forms of technology staying around in environments for longer because they were meant to be fit for purpose, probably isn't quite right in this current threat picture.”

Vedeneev said a simulation or “tabletopping a major cyber incident” is recommended to help companies and governments plan and practice.

“... where maybe speed is a differentiating factor… and what decisions might executives take after that experience to plan for, coordinate, and govern their approach to both the public and private customers or citizens. I think those will be the determining factor whether somebody is more or less secure in this new world.”

He said the notion of assuming your systems are breached and planning accordingly helps with both mental and technical preparation for an eventual incident, “and so reduce the blast radius of anything that could go wrong.”

Vedeneev said LLMs, large language models, are very good at pattern recognition.

“Pattern recognition is very, very good feature for finding vulnerabilities in code. They're not great at every single vulnerability. They're good at certain parts or certain types of vulnerabilities," Vedeneev said.

“However, they can do them at scale, and so one of the features of these models is they don't get bored, they don't get tired, and so the economics have really shifted from previously requiring somebody who was very skilled, quite well paid, whether criminal or otherwise, and they would focus really on the highest value, biggest impact vulnerabilities… shifting the balance into potentially many, many vulnerabilities being found."

“However, they will still need experienced… criminal operators to weaponise and utilise at scale.”

But what’s unknown is what happens when more publicly available models come from non-allied nations “that are available to threat actors at scale”.

That is a risk they are warning people to be prepared for.

“Entities haven't prioritised actually remediating fixes on issues that they know about or should know about… so vulnerabilities that may be potentially known to only a small number of people with no patches [security fixes] available, those are important," sazid Vedeneev.

“The large tail of activity should be around remediating known vulnerable or known old technology that just has been sitting there in the environment for a long period of time."

“I'm not here to peddle panic or fear, but what we are recommending is folks reassess their programmes of work, understand if their risk models are aligned to the threat picture," he said.
 

We welcome your comments below. If you are not already registered, please register to comment

Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.

1 Comments

There was a cybersecurity chap on RNZ yesterday discussing how the Russians are already using AI to sniff out vulnerabilities in hardware routers all over the world, then biding their time.

Typical targets are electric and water utilities, banks and insurance companies, government entities, health organisations, local councils.

Many of these organisations have older, perhaps undocumented networks and systems, likely with multiple vulnerabilities and limited budgets.

I would hope that all of these organisations prioritise the use of AI in penetration testing their own networks and fixing the latent vulnerabilities pdq

Up
0