The **National Agency for the Security of Information Systems (ANSSI)** has released its 2025 Cyber Threat Overview, highlighting that the level of cyber threats remains high and affects all types of organizations. The report emphasizes that the rise of generative AI—a type of artificial intelligence capable of creating text, images, or code—has significantly increased the number, variety, and effectiveness of cyberattacks. As companies increasingly adopt AI without proper safeguards, the potential attack surface has expanded. Attackers have already shown the ability to bypass traditional security measures, and the skills needed to conduct complex cyberattacks are becoming easier to acquire, making these threats more accessible to less experienced individuals.
For cybersecurity professionals, this signals that current security strategies are no longer sufficient to keep up with the rapid evolution of cyber threats. Simply defending against attacks is no longer enough; the report suggests that organizations must shift toward a more proactive approach. This means using the same advanced technologies that attackers are leveraging to inspect and secure their own systems. While many security teams initially view the development of powerful AI models with concern, the report argues that focusing on the speed of AI progress is not helpful. Instead, security teams should harness these tools to actively identify and address vulnerabilities before they can be exploited.
The path to becoming an information system security officer (RSSI) varies widely. Some professionals come from backgrounds in governance, risk, and compliance, where risk management is a core responsibility. Others transition from the information technology sector, inheriting security responsibilities along with their technological roles. Still others come from security architecture, where they understand how systems are built. In recent years, more RSSIs are coming from engineering backgrounds, especially in software publishing companies. These engineers tend to adopt an offensive mindset, actively seeking out flaws in systems rather than waiting for problems to arise. This proactive approach is increasingly seen as essential in the current threat landscape.
Teams with this offensive mindset view themselves as creators of dynamic, evolving solutions that continuously identify potential weaknesses in security programs, infrastructure, and the threat environment. This mindset is driven by a deep curiosity about how systems are built and how they might fail. It is the core of security research, which thrives on understanding not just how systems are designed but also how they might be manipulated or misused. As a result, these teams focus on developing automated tools that can detect, prioritize, and address security risks based on specific business goals.
To implement these changes effectively, two key principles are emphasized. First, neutrality with respect to AI models: building workflows that are not dependent on a specific model or supplier, as the best tools today may not be the best in six months. This neutrality also extends to deployment, ensuring that security teams can run AI models in secure, isolated environments when necessary. Second, scope—defining the tasks assigned to AI agents clearly. Assigning vague or overly broad tasks can lead to inconsistent results, while specific, well-defined tasks with clear context ensure consistent performance and accuracy.
Not all security programs will be able to immediately shift their operations to rely on AI agents, and that is normal. For those just starting this journey, the focus should be on examining each area of responsibility, defining the specific outcomes expected, and reviewing existing tools rather than assuming a complete overhaul is needed. The main risk at this stage is getting stuck in analysis. As attackers become more sophisticated and require fewer resources, defenders must raise their standards. Waiting for an incident or a supplier’s fix is no longer an option. In Europe, where agencies like ANSSI and ENISA now require proof of resilience, security programs must adapt or risk falling behind adversaries who are constantly evolving.
European Cybersecurity Agencies Warn of AI-Amplified Threats and Call for Proactive Defense Strategies
AI-rewritten from original reportingHow it works
cybersecurityaiproactive-defenseanssisecurity-strategyautomated-agents



