fb pixel

AI-enabled cyber threats have become a practical planning issue for organizations that rely on sensitive data, uptime, compliance, and trust. Manufacturing, healthcare, insurance, legal services, and financial services all depend on systems that connect employees, vendors, clients, regulated data, payment workflows, and third-party platforms. AI gives attackers a faster way to study those systems and create convincing requests. 

The scale of the issue is clear. The FBI’s 2025 Internet Crime Report recorded 1,008,597 complaints and $20.877 billion in reported losses. AI-related complaints accounted for 22,364 complaints and $893.3 million in reported losses. The FBI also described tactics that include fake social profiles, voice clones, forged identification documents, and believable videos depicting public figures or loved ones [1, 2]. 

For business leaders, the priority is concrete. Cybersecurity plans need to match how work actually moves through the organization. A manufacturer may be protecting production schedules, CAD files, supplier access, and Controlled Unclassified Information. A medical practice may be protecting patient records and scheduling systems. A law firm may be protecting privileged files and trust accounts. A financial or insurance firm may be protecting customer information, claims workflows, and transaction approvals.

 

What are AI-driven cyber threats?

AI-driven cyber threats are attacks that use artificial intelligence to increase speed, scale, targeting, or believability. The final step may look familiar: a phishing email, fake login page, wire request, malicious file, vendor portal compromise, help desk request, or social engineering call. 

The AI advantage appears earlier in the attack. Criminals can use AI to generate polished messages in the voice of a supplier, executive, client, attorney, adjuster, physician, or finance contact. They can summarize public information about a company, translate scams into natural language, mimic a trusted voice, produce fraudulent documents, or sort stolen data for leverage [2, 3]. 

NIST’s Generative AI Profile for the AI Risk Management Framework gives organizations a useful lens for this issue. The profile is designed to help organizations identify risks posed by generative AI and choose risk management actions aligned to their goals and priorities [4]. 

Where AI is changing business risk

More convincing social engineering

AI makes it easier to create messages that fit a specific business process. A fake claim update can reference a real carrier. A patient portal message can sound administrative. A client request can use familiar matter terms. A vendor message can include the language a finance team expects to see. 

HHS Health Sector Cybersecurity Coordination Center reports that ransomware and data breaches are the two most common cyberattacks targeting the health sector and that these attacks often begin with phishing. HHS also warns that AI has made phishing attempts more effective [9]. 

Faster target research

Attackers can quickly gather roles, vendors, email formats, recent announcements, job postings, technologies, and public contracts. That research can feed targeted messages about shipments, purchase orders, engineering files, medical billing, client matters, policy updates, or account changes. 

This matters because regulated industries often rely on fast approvals, trusted relationships, and time-sensitive service. An attacker who understands the workflow can make a request feel routine. 

Sensitive data exposure through AI tools

Employees use AI tools to summarize documents, draft emails, analyze spreadsheets, organize research, write code, and simplify technical information. Approved use can improve productivity. Sensitive data entered into the wrong tool creates exposure. 

For regulated organizations, the risk can involve CUI, PHI, policyholder data, privileged legal files, customer financial information, credentials, incident details, contracts, and internal security documentation. CISA has encouraged defense industrial base organizations, National Security Systems owners, federal agencies, and critical infrastructure owners and operators to apply best practices that protect sensitive, proprietary, and mission-critical data in AI-enabled and machine learning systems [6]. 

Ransomware with sharper pressure tactics

Ransomware remains a board-level issue because it affects operations, cash flow, compliance, and reputation at the same time. CISA’s StopRansomware guidance states that ransomware incidents can severely impact business processes and leave organizations lacking the data required to operate and deliver mission-critical services [7]. 

AI can make the pressure around ransomware more personal. Attackers can sort stolen information quickly, identify sensitive files, map customers or vendors, and tailor extortion messages to the business impact. 

IT and operational technology convergence in manufacturing

Manufacturing risk grows as office systems, production systems, vendor support tools, and cloud platforms connect. CISA’s 2026 guidance on applying zero trust principles to operational technology says IT-OT convergence introduces new cybersecurity risks and makes perimeter-based defenses and implicit trust models inadequate for protecting OT systems and physical processes [8]. 

For manufacturers, cybersecurity is also a production issue. Remote vendor access, engineering workstations, ERP and MRP systems, backups, plant networks, identity controls, and asset visibility all deserve executive attention.

Industry-Specific Response Priorities

Manufacturing and defense contractors 

Manufacturers should prioritize asset visibility, identity controls, IT and OT segmentation, vendor access, tested backups, and evidence tied to customer or CMMC requirements. Mainstay’s manufacturing guidance also highlights production uptime, protection of sensitive data and intellectual property, responsive IT infrastructure, and compliance support as core manufacturing needs [22]. 

For defense contractors, start by mapping where Federal Contract Information and Controlled Unclassified Information are stored, processed, or transmitted. Include email, cloud storage, engineering workstations, file shares, ERP or MRP systems, quoting workflows, supplier portals, and backup environments. Then confirm MFA coverage, privileged access controls, logging, endpoint protection, vulnerability management, incident response evidence, and service provider access. 

CMMC has moved from preparation topic to contract-readiness issue. Official Defense Department resources state that the CMMC program verifies implementation of cybersecurity standards for nonfederal systems that process, store, or transmit FCI or CUI, and that Phase 1 implementation began November 10, 2025, with emphasis on Level 1 and Level 2 self-assessments [18, 19, 20]. 

  • First action: create a system-by-system map of CUI, FCI, CAD files, supplier data, and production-impacting assets. 
  • High-risk workflow to test: an urgent supplier portal request or engineering file transfer from a compromised vendor account. 
  • Leadership metric: percentage of production and CUI systems covered by MFA, logging, endpoint protection, backups, and documented access reviews. 

Healthcare 

Healthcare organizations should treat AI-enabled phishing as a patient-care and operations risk. ASPR describes cybersecurity in health care as a patient protection issue because cyberattacks can disrupt critical services, health systems, and care delivery [10]. 

Priority areas include EHR access, ePHI mapping, MFA, phishing-resistant training, medical billing workflows, patient portal security, backup restore testing, third-party access, and incident response plans that include clinical and administrative leaders. HHS OCR guidance also states that effective risk management is essential for HIPAA Security Rule compliance and broader cybersecurity preparedness [11]. 

  • First action: update the HIPAA Security Rule risk analysis with current EHR, billing, scheduling, portal, remote access, and vendor workflows. 
  • High-risk workflow to test: a caller using AI-assisted voice impersonation to reset a clinician or billing account. 
  • Leadership metric: restore time for EHR, scheduling, and billing systems, plus MFA coverage for workforce and vendor accounts. 

Insurance 

Insurance firms should protect policyholder data, claims workflows, producer portals, payment approvals, adjuster systems, document intake, and third-party service provider access. 

The NAIC Insurance Data Security Model Law requires licensees to develop, implement, and maintain an information security program, investigate cybersecurity events, and notify the state insurance commissioner of qualifying events. NAIC maintains an adoption map because state implementation varies [12, 13]. 

AI risk in insurance often appears in ordinary workflows: manipulated claim documentation, synthetic identities, payment change requests, compromised producer accounts, fraudulent vendor communications, and social engineering aimed at claims or finance teams. 

  • First action: document how claims documents, policyholder records, producer portal credentials, and payment changes are verified. 
  • High-risk workflow to test: an AI-generated claim package with altered supporting documents and a changed payment destination. 
  • Leadership metric: high-risk claim and payment requests that receive secondary verification through a trusted channel. 

Legal services 

Law firms should build protections around client confidentiality, eDiscovery, document management, practice management systems, billing, accounting, email, secure file exchange, and trust accounting. 

The ABA’s survey on legal technology trends reported that 60% of firms have formal cybersecurity policies, while phishing and ransomware remain major threats. It also noted increased use of MFA [14]. 

Generative AI adds another layer to legal risk because client information, matter strategy, privileged documents, billing records, and legal research can move through new tools. ABA Formal Opinion 512 states that lawyers’ existing duties related to competency, informed consent, confidentiality, and fees apply when using generative AI [15]. 

  • First action: create a firm AI use policy that defines approved tools, permitted use cases, matter-level data restrictions, review requirements, and supervision responsibilities. 
  • High-risk workflow to test: a client email requesting a trust account transfer or a changed payment instruction for a closing or settlement. 
  • Leadership metric: percentage of matters using approved file exchange, MFA, documented access permissions, and secure client communication procedures. 

Financial services 

Financial services firms should treat AI-enabled fraud as an identity, transaction, and customer-information protection issue. 

For covered financial institutions, the FTC Safeguards Rule requires a written information security program with administrative, technical, and physical safeguards designed to protect customer information. FTC guidance and 16 CFR Part 314 address risk assessment, access controls, multifactor authentication, monitoring and testing, staff training, incident response, service provider oversight, and governance reporting requirements [16, 17]. 

Financial firms should review wire approvals, account change requests, customer identity verification, advisor communications, vendor payments, and access to systems that store customer information. AI-enabled impersonation raises the value of clear approval thresholds and secondary verification. 

  • First action: set documented verification thresholds for wires, ACH changes, account profile updates, vendor payments, and urgent executive approvals. 
  • High-risk workflow to test: a deepfake or AI-written request that appears to come from a client, advisor, executive, or vendor. 
  • Leadership metric: percentage of financial transactions above threshold that receive secondary verification and audit-ready documentation. 

A practical cybersecurity plan for AI-driven threats 

NIST Cybersecurity Framework 2.0 gives leaders a practical structure: govern, identify, protect, detect, respond, and recover. NIST describes the framework as a resource for industry, government, and organizations to reduce cybersecurity risk [5]. 

1. Map the data and workflows attackers would target

Start with the data that creates business, compliance, or client risk. In manufacturing, that may be CUI, CAD files, production schedules, and supplier data. In healthcare, focus on PHI, EHR data, billing records, and scheduling systems. Insurance firms should include policyholder information, claims files, producer portals, and payment workflows. Law firms should map privileged files, client communications, eDiscovery systems, and trust accounting. Financial services firms should map customer information, account access, transaction approvals, and vendor payment workflows. 

The goal is to know where sensitive information lives, who can access it, how it moves, and which vendors touch it. 

2. Recheck identity controls for high-risk users

AI-enabled attacks often aim at people with authority or access. Review MFA coverage, conditional access, privileged accounts, service accounts, shared mailboxes, vendor accounts, and former employee access. Finance, HR, executives, attorneys, clinicians, engineers, claims staff, and administrators deserve special attention. 

Strong identity habits include regular access reviews, removal of stale accounts, monitoring of administrative activity, and tight control over shared credentials. 

3. Create an AI use policy grounded in data classification

AI use guidance should be simple enough for employees to follow during normal work. Define approved tools, approved use cases, restricted data categories, and review steps for new AI workflows. 

For regulated organizations, restricted data categories should include CUI, PHI, privileged legal information, policyholder records, customer financial information, credentials, security documentation, incident details, contracts, and regulated client data. 

4. Put verification into high-risk requests

AI-generated messages can sound polished and specific. Build verification into workflows that move money, grant access, release files, change records, or reset credentials. 

Use known contact methods for supplier bank changes, client payment instructions, claims payments, payroll changes, password resets, remote access requests, patient record requests, and urgent executive approvals. A short verification step can prevent a high-cost incident. 

5. Make vulnerability management visible to leadership

Vulnerability management needs executive visibility because attackers can move quickly once a widely used system has a known weakness. Leaders should receive a plain-language monthly view of critical systems, high-risk vulnerabilities, patch status, exceptions, and vendor dependencies. 

Prioritize internet-facing systems, VPNs, firewalls, remote monitoring tools, email and collaboration platforms, ERP or practice management systems, file transfer tools, cloud environments, and vendor access platforms. 

6. Test response and recovery in business terms

Incident response should include the people who make operational decisions. Include IT, security, finance, operations, legal, compliance, HR, communications, executive leadership, and industry-specific leaders such as plant managers, practice administrators, claims leaders, or clinical operations. 

Run one tabletop exercise around a realistic scenario: vendor impersonation, ransomware, email compromise, AI-generated wire fraud, compromised legal document exchange, producer portal takeover, or EHR access disruption. Then test one backup restore for a system that directly supports revenue, service, patient care, production, or client delivery. 

7. Bring MSPs, MSSPs, and key vendors into the program

Many regulated organizations rely on outside providers for IT, cloud services, endpoint protection, backups, email security, identity, logging, compliance documentation, or incident response. Those providers affect day-to-day security and assessment readiness. 

Ask each provider for evidence that matters: MFA coverage, privileged access controls, patch reporting, endpoint status, backup test results, incident response roles, logging coverage, vendor risk documentation, and AI tool governance. 

How a cybersecurity partner can help 

AI-era cybersecurity requires more than a one-time control checklist. Regulated organizations need operating habits that connect people, systems, vendors, data, and leadership decisions. 

Mainstay Technologies supports organizations with outsourced IT and information security services, including assessments, risk-focused guidance, cybersecurity support, CMMC preparation, managed services, and ongoing security program support across New Hampshire, Massachusetts, and Greater Boston [21, 22]. 

For manufacturers and defense contractors, that support can connect CMMC preparation with practical cyber resilience. For healthcare, insurance, legal, and financial services organizations, it can turn regulatory obligations, sensitive data, and operational risk into a managed information security program. 

The practical priority for the next 90 days 

AI-driven cyber threats reward speed, weak verification, exposed access, and unclear data handling. Regulated industries can respond with practical discipline: know the data, protect identity, control AI use, verify high-risk requests, keep vendors accountable, and test recovery before an incident forces the issue. 

For leaders, the work starts with one question: which systems and workflows would create the most business pain if an attacker used AI to target them this quarter? 

Frequently Asked Questions

What is the biggest AI-driven cyber threat for regulated industries?
The biggest near-term threat is AI-enhanced social engineering. It affects payment approvals, credential theft, vendor communications, file requests, client interactions, patient communications, claims workflows, and executive impersonation. 
How should manufacturers connect CMMC and AI cyber risk?
Manufacturers with defense work should map FCI and CUI, confirm identity controls, strengthen endpoint and backup protection, document evidence, and review MSP access. These steps support CMMC readiness and reduce exposure to AI-enabled phishing, credential theft, and vendor impersonation. 
What should healthcare organizations do first?
Healthcare organizations should focus on phishing resilience, MFA, EHR access, ePHI mapping, vendor access, backup testing, and incident response. AI-enhanced phishing is especially relevant because HHS identifies phishing as a frequent starting point for health sector ransomware and data breach incidents [9]. 
How should law firms govern AI tool use?
Law firms should create an approved AI use policy that protects client confidentiality, privileged information, matter strategy, and billing records. The policy should define approved tools, approved data categories, review steps, and supervision responsibilities. 
What should an MSP or MSSP provide for AI-era cybersecurity?
An MSP or MSSP should provide clear evidence around MFA, privileged access, patching, endpoint protection, logging, backups, incident response roles, vendor access, security awareness training, and AI tool governance. 

Sources and references 

Sources used for fact-checking and reference. URLs are included for review and publication workflow. 

[1] FBI, 2025 IC3 Annual Report. https://www.fbi.gov/file-repository/2025_ic3report.pdf 

[2] FBI, Cryptocurrency and AI Scams Bilk Americans of Billions. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions 

[3] FBI IC3 Public Service Announcement, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud. https://www.ic3.gov/PSA/2024/PSA241203 

[4] NIST, Artificial Intelligence Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework 

[5] NIST, Cybersecurity Framework. https://www.nist.gov/cyberframework 

[6] CISA, New Best Practices Guide for Securing AI Data Released. https://www.cisa.gov/news-events/alerts/2025/05/22/new-best-practices-guide-securing-ai-data-released 

[7] CISA, StopRansomware. https://www.cisa.gov/stopransomware 

[8] CISA, Adapting Zero Trust Principles to Operational Technology. https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology/ 

[9] HHS HC3, AI-Augmented Phishing and the Threat to the Health Sector. https://www.hhs.gov/sites/default/files/ai-and-phishing-as-a-threat-to-the-hph-white-paper-tlpclear.pdf 

[10] ASPR, Cybersecurity in Health Care: Protecting Patients from Attacks. https://aspr.hhs.gov/cyber/Pages/default.aspx 

[11] HHS OCR, Security Rule Guidance Material. https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html 

[12] NAIC, Insurance Data Security Model Law. https://content.naic.org/sites/default/files/model-law-668.pdf 

[13] NAIC, Model Act 668 Insurance Data Security Model Law Adoption Map. https://content.naic.org/sites/default/files/legal-adoption-map-668-idsm.pdf 

[14] American Bar Association, ABA Releases New Survey on Legal Tech Trends. https://www.americanbar.org/news/abanews/aba-news-archives/2025/03/aba-survey-on-legal-tech-trends/ 

[15] American Bar Association, ABA Issues First Ethics Guidance on a Lawyer’s Use of AI Tools. https://www.americanbar.org/news/abanews/aba-news-archives/2024/07/aba-issues-first-ethics-guidance-ai-tools/ 

[16] FTC, FTC Safeguards Rule: What Your Business Needs to Know. https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know 

[17] eCFR, 16 CFR Part 314, Standards for Safeguarding Customer Information. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314 

[18] Defense Department CIO, About CMMC. https://dodcio.defense.gov/CMMC/About/ 

[19] Defense Department CIO, CMMC Resources and Documentation. https://dodcio.defense.gov/CMMC/Resources-Documentation/ 

[20] eCFR, 32 CFR Part 170, Cybersecurity Maturity Model Certification Program. https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170 

[21] Mainstay Technologies, Cybersecurity and Information Security Services. https://www.mstech.com/cybersecurity/ 

[22] Mainstay Technologies, IT and Cybersecurity Services for Manufacturing. https://www.mstech.com/it-cybersecurity-services-for-manufacturing/