Blog September 11, 2026
What AI changed about your attack surface
Assistants inherit whatever permissions the user already has. That is the design, and it is where most new exposure sits. What we check first, and what your insurer has started asking for.
The phishing mail that gets through now is usually well written. That is the change. For years the advice was to watch for broken English and strange formatting, and for years that advice worked well enough. It stopped working.
The assistants you rolled out are part of the surface
Copilot, and every third-party integration hanging off your Microsoft or Google tenant, can read whatever the signed-in user can read. That behaviour is deliberate, and it is the whole point of the product. So when an account still has access to a finance folder that nobody remembered to lock down, the assistant will summarise it on request, politely, in seconds.
We find this constantly. Nobody was careless. Permissions just accumulate. Someone covers a colleague's leave, gets added to a group, and is never removed. Four years later an assistant makes that visible in one line.
Audit the permissions before you switch the assistant on, not after.
Your insurer is going to ask
Cyber carriers and the auditors your parent company sends have both started asking how AI touches regulated data. Some renewal questionnaires now name it directly.
Here is the part that catches people out. They want evidence, not assurances. A policy nobody follows is worth nothing at renewal. Access logs, and a data classification that maps to what is actually in your tenant, are worth a great deal.
Use it on defence as well
Our SOC runs agents that correlate signals across tools before an analyst looks at anything. Triage, log analysis, a first pass at summarising an incident. It shortens the gap between an alert firing and a human making a judgment, and that gap is usually where the damage happens.
Two rules we hold to. Nothing irreversible fires without a person reviewing it. And every workflow gets tested against a case where the model is confidently wrong, because sooner or later it will be.
If you want a second opinion on where your exposure sits, we run security audits your parent company will accept.