Claims Pay a bill
Log in

How Organizations Can Prepare for AI-Enabled Cyber Threats

AI symbol surrounded by checkmarks and warning icons

Artificial intelligence (AI) is helping organizations improve efficiency, automate tasks and enhance customer experiences. At the same time, bad actors are using AI to make cyberattacks more convincing and more difficult to detect.

Whether you work for a business, government agency, municipality, school district, nonprofit or other organization, understanding these risks can help strengthen security.

AI Is Making Cyberattacks More Sophisticated

Many cyberattacks rely on deception. Criminals use emails, text messages, phone calls and websites to convince people to take actions that place information or systems at risk.

AI can help attackers create messages that appear professional, personalized and highly credible. As a result, employees may encounter phishing attempts that are harder to recognize than those from the past.

Organizations should encourage employees to verify unusual requests rather than relying solely on appearance or tone.

Be Alert for Impersonation Attempts

Attackers may attempt to impersonate:

  • Executives
  • Employees
  • Vendors
  • Contractors
  • Government officials
  • Trusted business partners

These requests may involve financial transactions, payment changes, sensitive information or account access.

Establishing verification procedures can help reduce the risk of fraud.

Build a Culture of Security Awareness

Employees remain one of the most important lines of defense against cyber threats.

Organizations should encourage personnel to:

  • Verify unexpected requests
  • Report suspicious activity
  • Question unusual instructions
  • Participate in ongoing cybersecurity awareness efforts

Creating an environment where employees feel comfortable speaking up can help identify

potential threats before they become serious incidents.

Strengthen Account Security

Strong security fundamentals remain effective against many AI-enabled threats.

Organizations should consider:

  • Multifactor authentication
  • Strong password practices
  • Timely software updates
  • Limited access based on job responsibilities
  • Regular reviews of user access

These protections help reduce opportunities for cybercriminals to gain access to systems and information.

Use AI Responsibly

Many organizations are exploring AI to improve productivity and service delivery. Before implementing AI tools, organizations should understand their privacy, security and governance requirements.

Employees should understand:

  • What information can be shared with AI tools
  • Which data must remain protected
  • Applicable policies and procedures
  • Security expectations for approved AI solutions

Balancing innovation with responsible use helps organizations realize AI's benefits while managing risk.

Preparing for the Future

AI capabilities continue to advance rapidly, creating new opportunities and challenges for organizations across every industry. Cybercriminals are already using AI to improve scams, automate attacks and make malicious activity more difficult to detect.

As these technologies continue to evolve, organizations should focus on building strong cybersecurity foundations, promoting security awareness and developing processes that can adapt to emerging threats. Organizations that prepare today will be better equipped to manage tomorrow's risks.

Prepare Before an Incident Occurs

Every organization should have a plan for responding to cybersecurity incidents.

Planning ahead can help answer important questions:

  • Who should be contacted?
  • How should incidents be reported?
  • Which systems are most critical?
  • How will stakeholders be informed?

Preparation can help reduce disruption and improve recovery efforts.

What to Remember

AI is changing the cybersecurity landscape, but effective security still depends on awareness, verification and preparation.

Organizations that promote strong security practices and responsible AI use will be better positioned to defend against evolving cyber threats.

Product, coverage, discounts, insurance terms, definitions, and other descriptions are intended for informational purposes only and do not in any way replace or modify the definitions and information contained in your individual insurance contracts, policies, and/or declaration pages from Nationwide-affiliated underwriting companies, which are controlling. Such products, coverages, terms, and discounts may vary by state and exclusions may apply.

The information included here is designed for informational purposes only. It is not legal, tax, financial or any other sort of advice, nor is it a substitute for such advice. The information may not apply to your specific situation. We have tried to make sure the information is accurate, but it could be outdated or even inaccurate in parts. It is the reader’s responsibility to comply with any applicable local, state or federal regulations. Nationwide Mutual Insurance Company, its affiliates and their employees make no warranties about the information nor guarantee of results, and they assume no liability in connection with the information provided.