26 Jun Cyber-attacks in the age of AI: Key considerations for General Counsel
In June 2026, Marsden held an interactive cyber security workshop hosted by Fiona Phillips of Marks & Clerk and Gareth Bateman of CrowdStrike. The session was designed specifically for General Counsel and senior in-house lawyers, offering them a practical and accessible look at how to deal with cyber incidents in an AI-driven environment.
CrowdStrike’s 2026 Global Threat Report notes that 89% of AI threats have reached a critical turning point and that over 90 organisations have experienced legitimate AI tools being exploited to generate malicious commands and steal sensitive data. A key theme in the report was the speed at which the hackers can obtain and control a system, with the average time being 29 minutes and the fastest time being 27 seconds. In the practical session, participants worked together in groups and were tasked with manipulating an AI system to achieve unintended outcomes, demonstrating how easily AI can be exploited through carefully crafted prompts.
How are the hackers able to infiltrate a system so easily?
Legitimate AI: this adoption presents its own risks. Business teams are increasingly deploying AI tools to improve productivity. Without appropriate controls and visibility, organisations may not know what sensitive information is being shared with AI platforms, leaving IT and security teams with limited visibility into how these tools are being used and creating potential confidentiality, regulatory and data protection risks.
Deepfakes and voice phishing: voice cloning and social engineering (manipulation of individuals into revealing confidential information) attacks are becoming increasingly sophisticated. Rather than attacking technology directly, threat actors often target employees by impersonating trusted individuals and exploiting human behaviour. AI-generated voices, videos and communications can be used to bypass traditional security controls, making phishing and credential theft more effective. In some cases, threat actors may seek legitimate employment or contractor roles within organisations to gain trusted access to systems. As a result, cyber resilience increasingly depends on employee awareness, identity verification processes and robust internal controls, rather than technical safeguards alone.
Legacy technology: AI makes the ecosystem complex. A lot of industrial manufacturing technology becomes legacy infrastructure over time. These systems are expensive, have long lifespans, and often become outdated and unsupported. This creates pressure on businesses to keep them running, despite the fact that they are often vulnerable to security risks. IT teams are frequently hesitant to patch or upgrade legacy systems, as doing so can be costly and may require shutting down entire operations to rebuild or repair them, resulting in lost revenue and operational disruption.
What is the role of the General Counsel during a cyber-attack?
During a cyber-attack, you are in a race with the criminals. One of the main messages during the session was that you cannot build crisis management processes during a crisis. Increasingly, organisations are looking to their senior legal leaders during periods of uncertainty.
The most effective General Counsel are involved in preparation long before an incident occurs and their role is extremely valuable as they can:
Navigate complex regulatory environments
Influence senior stakeholders and boards
Coordinate cross-functional teams
Bring expertise and awareness
How can General Counsel prepare for a cyber crisis?
When preparing for an attack, these are the key questions General Counsel should ask themselves:
- Have I seen my company’s instant response plan?
- Am I in that plan, and when would I be contacted during an attack?
- Who is available during our quiet periods?
Hackers tend to prefer quiet working periods such as Christmas and Fridays. - Where are our vendor contracts?
Amend these to add in cyber clauses if you don’t already have these in place. - Do our corporate customer contracts have a cyber-attack clause that requires us inform our customers?
- What does our insurance policy state in relation to a cyber-attack?
Increasingly, organisations are conducting cyber crisis workshops that involve executive leadership, legal teams and external advisers. They allow decision-makers to test their responses in a controlled environment and build confidence before a real incident occurs.
How is cyber risk reshaping the role of the General Counsel?
The role of the General Counsel is increasingly extending beyond traditional legal expertise. By advising on cyber risk and helping organisations navigate crisis situations, General Counsel can position themselves as strategic business leaders and trusted advisers to both the executive team and the board.
As the cyber threat landscape is becoming faster, more AI-enabled and more difficult to manage, General Counsel play a critical part in governance, preparation, regulatory compliance and crisis decision-making.
The organisations that respond most effectively are those that prepare before an incident occurs.
Please see Marks & Clerk’s In-house legal guide on preparing for a cyber incident:
If you are a CLO or General Counsel and would interested in attending a follow-up interactive session, please get in touch with Sarita Rai.