AI has changed the cybersecurity calculus for every business. Attackers are using it to automate reconnaissance, personalize phishing at scale, and develop malware that adapts in real time. For defense contractors handling Controlled Unclassified Information, the stakes are higher. The same AI-driven techniques that target commercial enterprises are being aimed at the defense supply chain by nation-state adversaries with far more resources and patience.
Most of the cybersecurity industry knows it. Darktrace reports that 87% of security professionals said they’re seeing more AI-driven threats, and nearly half said they’re not adequately prepared to stop them.
At CMMC CON 2026, Microsoft Chief Security Advisor Kevin Thomas will dig deeper into the new era of cyber threats in a session titled, “How to Prepare for the Next Generation of Security Risks Due to AI,” on Sept. 23 at 12 p.m. ET. Thomas serves as Microsoft’s Chief Security Advisor for the U.S. Defense Industrial Base and Federal, where he works with contractors and government leaders on cybersecurity strategy, resilience, and CMMC readiness. A former multi-time CISO with more than 20 years securing federal and defense environments, he has led organizations through CMMC Level 1 and Level 2 efforts and previously built and led consulting and managed security organizations supporting federal customers.
Thomas’ session will cover four areas, each with actionable steps contractors can take with existing resources:
- How the threat model has changed: What’s genuinely different when both attackers and defenders have capable AI, including how AI compresses the window between vulnerability discovery and exploitation
- Where risk profiles are moving: Six parts of a contractor’s environment, from code repositories to AI agents themselves, where risk is accelerating fastest
- Fighting AI with AI while getting the basics right: Why machine-speed response is now a requirement and why fundamentals like patching, least privilege, and phish-resistant multi-factor authentication still matter as much as ever
- A 90-day start with the team you have: A practical sequence beginning with inventorying every AI tool in use, establishing governance, and tabletop-exercising an AI-assisted intrusion
Register now for CMMC CON 2026 to hear Thomas break down how AI is changing the threat picture for defense contractors and what they should be doing about it now.
