Attackers need to understand what they are attacking, how to attack it, and how to turn access into whatever they are after. AI is shrinking that learning curve. It helps attackers map infrastructure, find flaws faster, and produce more convincing lures to use against users.
Defenders have the opposite problem. It is not "we don't know what to do." Frameworks like CIS are not exotic ideas; they are approachable, practical paths to securing a company. Asset inventory, MFA, patching, and backups are well understood. Implementation falls short because someone has to fund them, own them, and accept the friction they create for users.
So how do we fix things? Defenders need to explain risk in terms leadership will act on. This is the uneasy political work defenders have to get good at.