
BCG on Compliance · 2026-07-01 · 23 min
Key moments - from our scoring
Substance score
48 / 100
Five dimensions, 20 points each
Matthew Rosenquist, a 36-year cybersecurity veteran, argues that compliance leaders must shift from rigid, backwards-looking defense to forward-looking adaptation. The central threat reshaping the 2026 landscape is AI: attackers are deploying untested AI tools at scale with no consequences, while defenders must balance innovation with stability and mature implementation. Nation states now dominate the threat landscape, targeting critical infrastructure in finance, transportation, power, water, and logistics with tens of billions in funding, creating cascading vulnerabilities that trickle down to common cybercriminals. Rosenquist identifies three specific ways AI amplifies attacks - particularly social engineering, which by end-2025 was enhanced in 80% of attacks and has evolved from basic localization to personalized targeting across LinkedIn and social media. His core message to compliance officers: stop enforcing rigid controls and become enterprise risk partners who predict and adapt faster than regulations change. He outlines a four-domain prediction methodology examining attacker tactics, defender capabilities, technology landscape shifts, and leadership expectations to guide strategic planning through 2026.
Nation states fund massive vulnerability research with tens or hundreds of billions of dollars, creating high-quality exploitations that eventually trickle down for use by common cybercriminals. Unlike traditional criminals who must develop attacks independently, modern cybercriminals leverage nation-state-developed tools and techniques for critical infrastructure attacks, sanctions evasion, intellectual property theft, and economic espionage.
Critical infrastructure sectors including finance, transportation, water, power, shipping, and logistics are being actively targeted by nation states and should raise awareness and incorporate these threats into risk assessments, prevention, detection, and response strategies.
Compliance leaders often become rigid in their thinking and defend outdated processes even as regulations, customer expectations, and risk assessments evolve. Cybersecurity and compliance must be dynamic to adapt to changing regulations, customer expectations, executive priorities, and vendor requirements rather than maintaining fixed controls.
In 2025, AI-enhanced attacks focused on basic tasks like language conversion and grammar correction. By 2026, attackers scan social media profiles including LinkedIn and Facebook to craft highly personalized, convincing messages based on work history and connections, enabling targeted attacks at massive scale simultaneously - a fundamental game change from the previous binary choice between targeted or mass attacks.
Rather than waiting for mature tools or maintaining rigid controls, leaders should predict what attackers will do with new AI capabilities, tweak current defenses to detect these methods, and proactively seek innovative AI solutions by working with both existing vendors and new startups rather than waiting passively for feature releases.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a few genuinely useful observations - particularly the asymmetry between attacker and defender AI adoption timelines and the dual-mode social engineering point - but a significant portion is high-level framing and generalist commentary that offers little a well-read compliance professional wouldn't already know.
AI has enabled both of those things to happen. It can now craft a highly customized, very resourceful type of social engineering attack, and yet do it to millions of people simultaneously.
By the end of 2025, it was estimated that over 80% of social engineering attacks were somehow enhanced by AI.
The insight that attackers' freedom to use immature AI tools creates a structural adoption gap for defenders is a fresher framing, but most of the episode recycles well-worn cybersecurity themes (nation-state threats, CISO role evolution) without genuinely contrarian or first-principles argument.
Our job is to make sure everything is stable. We have to wait until the tools are well developed and tested, properly implemented. And so we have to wait until they get to that level of maturity before we get to use them.
for the very first time ever, a single driver dominated all four of those domains, and that was AI.
Thirty-six years of hands-on cybersecurity experience and a structured annual prediction methodology signal genuine practitioner depth, but Matthew presents more as an independent strategist and commentator than as a named CISO or executive who has demonstrably operated a security function at enterprise scale.
You've been in cybersecurity for 36 years.
I do have a very methodical process in developing these things, I look at four distinct areas.
There are a handful of concrete data points (the 80% AI-enhancement figure, named sectors, a specific model reference) but no sourcing, no named company case studies, and several claims rest on vague quantifiers like 'tens or sometimes hundreds of billions,' limiting the evidentiary weight considerably.
By the end of 2025, it was estimated that over 80% of social engineering attacks were somehow enhanced by AI.
critical infrastructures are absolutely being targeted by aggressive nation states. So if you're part of the finance, transportation, water, power, shipping and logistics, you're being targeted.
The host surfaces one genuinely creative second-order question about whether fraudulent AI use inadvertently hardens defensive tools, but most questions are leading, soft, and allow the guest to deliver pre-packaged talking points without meaningful pushback or deeper probing of unsourced claims.
are ah, they indirectly also helping making AI solutions more robust, more predictable in that sense, and therefore also uh, more contained for the good usage eventually.
Is it just a game where you have to lose or be patient?
Computed from the transcript - who did the talking, and the words that came up most.
With more than three decades at the forefront of cybersecurity strategy, Matthew Rosenquist has helped organizations navigate some of the most significant technological shifts of our time. As part of our ongoing Cyber Crime Series, he joins us to discuss the evolving cyber threat landscape and what compliance leaders need to be preparing for in 2026. In this episode, Matthew explains why yesterday’s playbook may not be enough to tackle tomorrow’s cyber risks. He shares his perspective on the trends and threats that are likely to shape the year ahead, why attackers continue to hold a structural advantage over defenders, and how the growing influence of nation-state actors is changing the nature of cyber risk. From emerging technologies to shifting threat dynamics, this conversation offers valuable insights into what organizations should be watching closely, and what compliance leaders can do now to stay ahead. About the Show: BCG on Compliance is a podcast from Boston Consulting Group that explores today's most pressing criminal trends and how compliance experts are adapting to counter those threats.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Uh, imagine you're on a big freeway and you're standing there and cars are blowing by you and you can see them near miss and driving off into the horizon, and you're thinking, wow, that was a big truck, or wow, that car came really close. That is valuable. But what you really need to do is to turn around and see the vehicles that are coming at you.
Speaker B: That's Matthew Rosenquist. He's a cybersecurity strategist and someone who spent more than three decades helping organizations develop ways to fight back against the rising tide of cybercrime. As part of our ongoing cybercrime series, I wanted to know what compliance leaders can do to protect their organizations against cybercriminals. He explains why nation states are a rising threat, what leaders get wrong when talking to cybersecurity professionals, and also what he predicts to be the main trends in cybersecurity in 2026. This is BCG on compliance, a podcast that explores today's most pressing financial crime trends and how compliance professionals are adapting to stay ahead of that curve. I'm Han Joibelt. So, Matthew, hi and welcome to the show. It's great to have you.
Speaker A: My pleasure.
Speaker B: You've been in cybersecurity for 36 years. What would you say over the decades have been the biggest change or changes in how cyber attacks look today versus how they looked at the beginning of your career?
Speaker A: Yeah. The real big change over the last three or even four decades has been the introduction and the involvement of nation states. There have always been attackers, fraudsters and criminals and so forth that have been interested in cyber and been involved. But the game fundamentally changed when nation states came on the scene, brought in tens or sometimes hundreds of billions of dollars to really drive the research within the industry, to bring together the technical, behavioral and process in an organized fashion to pursue their national agendas. And there is a cascade effect in them funding massive vulnerability research or creating very high quality exploitations that get released out into the wild. Eventually all that trickles down. And those cyber criminals, instead of having to try and figure out themselves, they're simply able to go out and leverage what's being used and developed professionally by these nation states.
Speaker B: And can you elaborate a little bit on nation states? What is that exactly? And, uh, obviously, ideally, without naming concrete
Speaker A: names, okay, I'll be nice that I won't name the primary countries, but these are governments out there that are using offensive cyber capability as a force multiplier. They typically go after a couple of different areas. Either they're trying to Undermine the critical infrastructure of an adversary, be a neighbor, it might be a country across the planet that they don't share a border with. They use it to get around sanctions, to generate hard currency because of being sanctioned or embargoed, things of that sort. They use it as a force multiplier, as part of their foreign policy. So if they're at war with another country, they will use that as well. And then also to steal intellectual property. It's economic espionage where they will steal the knowledge and bring it back into their country so that their state owned and state operated industries can get a radical advantage, so that they don't have to spend the time doing their own research, just steal it from another country. And economically that brings tremendous prosperity in an unfair way.
Speaker B: Nation states engaging in cybercrime can sound like a vague geopolitical issue or even more likely the plot of a bad action thriller. However, Matthew suggests that isn't the case. If you work in certain key industries, it's already a problem for you.
Speaker A: When we categorize the different threat agent archetypes, you may look at cybercriminal or a disgruntled employee. All of those are different archetypes and with it it comes with a certain level of resources, a, uh, certain motivation, a certain capability. Nation states have the highest absolute capability to do harm, to gain access and to undermine organizations. As an example, critical infrastructures are absolutely being targeted by aggressive nation states. So if you're part of the finance, transportation, water, power, shipping and logistics, you're being targeted. So you need to raise your awareness and your defenses to understand that that needs to be incorporated in your risk assessments. It needs to be part of your prevention and detection and response and as well as that prediction. And you need to get better in understanding. Now if you're not one of those, if you're a small mom and pop shop or you know, you're manufacturing bolts, you're probably not directly being targeted. However, if the regional, you know, electrical grid goes down because of it, you're probably going to be impacted.
Speaker B: I want to know what kind of friction Matthew encounters when working with compliance teams.
Speaker A: The biggest frustration is when I sit down with compliance leaders and they're rigid, right? They've always done something a certain way, they've always measured it a certain way, and that's the way they're going to do it. And that's the barriers that they're going to establish and defend in the business, even against the other business units, the profit centers. And they don't understand that cybersecurity and compliance is dynamic. It has to change as regulations change. It has to change as risks change. It has to change as expectations for from the executives, from partners and vendors, from government regulations, from all these different aspects, from customers, expectations from customers change. So it's important that compliance leaders aren't rigid in their thinking. And it's very easy to fall into that trap, especially if a, uh, regulation hasn't changed. But the interpretation might, the customer expectations might, the level of compliance and risk acceptance from the board or the CEO or the other C suites may have changed. Right. We need to look at that. And many of the frameworks have to be interpreted in amongst themselves. Right. They were designed to be general. They have some guidelines. There may be some hard points there that have to be hit, but there still is a lot of interpretation. And that takes teamwork across the leadership scope of an organization.
Speaker B: Every year, Matthew releases his top 10 predictions for cybersecurity. We'll share the full list in the show notes below. But Matthew was kind enough to share some of them here.
Speaker A: When I go through my process, and I do have a very methodical process in developing these things, I, I look at four distinct areas. I look at what these cyber attackers are doing. That's area number one. I look at what the defenders are doing, what technologies and processes and policies. What are the defenders doing? That's area two. The third area is the technology landscape. This is the battlefield that we play on. What are the new technologies that everybody's adopting or misusing? And that'd be the third area. And the last area is around that cybersecurity leadership. How are the expectations changing? How is the liability changing? The funding patterns. Right. Communication and collaboration among the industry, all of those things. So in those four areas, I generate predictions now for 2026, for the very first time ever, a single driver dominated all four of those domains, and that was AI. The attackers, they've already rushed to use AI and they are using the newest tools every single day to their benefit to pursue their goals. So they're all in on AI because it is tremendously powerful and they can use it definitely to their advantage. So AI dominates the attackers and what they're doing and what they are currently doing. In 2026, we look at the defenders. Well, the defenders have to keep up and in many cases we have to use the same tools as the attackers, just configured differently for security and defenses. We also have to adopt AI to counter what the attackers are doing.
Speaker B: From your perspective, attackers have an advantage over defenders. Why, in your opinion Is that.
Speaker A: Oh yes, so they absolutely do have an advantage. They have several advantages. First and foremost, they get to maintain the initiative because the attacker always gets to decide what to attack, how they're going to attack, when they get the advantage of preparation, things like that. And especially in this case, attackers get the advantage of using the new tools, which, uh, are AI, right? They're AI powered tools. And these new tools and new tools are emerging daily that they can leverage, but they aren't necessarily vetted or tested or robust. The attackers don't care. They're going to use them in whatever state. And if they break or if they cause harm, oh well, they'll just try again. That's not their concern. In fact, they're looking to do harm, so they are fine with using untested tools for their advantage. Now, defenders, we can't do that, right? Our job is to make sure everything is stable. We have to wait until the tools are well developed and tested, properly implemented. And so we have to wait until they get to that level of maturity before we get to use them. Otherwise we may introduce and use a tool that causes harm, that brings the organization down and that's what the attackers are doing. And, uh, we're getting paid to defend against that. So we cannot do that. We have to wait. And that gives a window for the attackers that they get to use these tools and benefit from all those advantages until the defenders get more mature tools to counter. Because this is an arms race.
Speaker B: And so what can cybersecurity officers and crime fighters do about it? Because obviously you want to be faster, but as you said, right, you don't want to be rushing things with immature technology. So is it just a game where you have to lose or be patient? And think about it more from a long run perspective, what are your options?
Speaker A: When we look at the structure of we need to be able to predict and prevent and detect and respond. If we know attackers are going to be using the latest AI tools, and we know what those tools can do, we can start to predict this is what we should expect from the methods that they're using. And with that in mind, we can now tweak our current defenses to help either protect against that or at least detect when those things are occurring so that we can respond to them. And so the second thing we need to do is we need to proactively seek AI solutions. And that means working with innovative vendors, both the vendors that you have because they are developing AI features, but also new vendors, new startups that have technologies that may be able to help you. We can't just wait until, oh yeah, they've come up with a new feature in six months and then we'll adopt it. You will have already felt the pain. Right. And then you still have to go through the process of your own configuration and adoption and integration to your processes that takes even longer.
Speaker B: One thought, and maybe that's a crazy thought, uh, that I had when I was listening to you, is as fraudsters are using AI in a much earlier state of maturity and at quite a scale, are ah, they indirectly also helping making AI solutions more robust, more predictable in that sense, and therefore also uh, more contained for the good usage eventually. So is there a second order impact where the fraudulent use can actually help evolve the AI solutions we see today as being more unstable?
Speaker A: Yeah, to a certain extent. Right. As attackers use different tools that generates information or data that we can then use to train our tools. The problem is the tools are changing so fast and the capabilities are elevating so quickly that that data becomes stale very fast. So yes, we can use the data that an attacker was using. Anthropics four point model. Right. Which is a little dated. But the fact that attackers are switching, or will soon be switching over to Mythos, a lot of the legacy data isn't going to matter. It's just too outdated. We need to see what they're going to be doing with the new models. Looking ahead, whenever we look behind, that can provide some, um, historical viewpoint, some strategic understanding for direction, for vector acceleration, things of that sort. But it's really about looking forward. That's where the primary value of cybersecurity really kind of sits. And the example I use with audiences, imagine you're on a big freeway and you're standing there and cars are blowing by you and you can see them near miss and driving off into the horizon and you're thinking, wow, that was a big truck, or wow, that car came really close. That is valuable. But what you really need to do is to turn around and see the vehicles that are coming at you. That's where the most value is. If we're only looking into the past of what went by, there is some value, but not really where we need to go.
Speaker B: And on another note, I mean, global markets are adopting new AI technologies at a, uh, really great speed, as you also been alluding to. And a lot of this adoption is accompanied by unknown risks. And I'm wondering what's your view on known areas of vulnerability right now that bad actors can easily exploit and follow on question to that how should or how would you advise leaders of companies to go about these known vulnerabilities, but still kind of being able to adopt some of the new technology?
Speaker A: Okay, so let's break this down. AI right now is really opening up three big areas. And we see it now. The engines are available now. The technology is available now, and it's only getting better. So three areas. The first one is amplifying existing attacks. Think social engineering, for example. And we saw LLMs really contribute to attackers being able to craft beautiful, highly convincing social engineering attacks at scale. And so this changed the game from social engineering perspective. So it used to be that attackers could either focus their effort on a particular target and do a social engineering attack. Focus that was high quality. Right. So their chances of being successful were high. But it was targeted at a unique organization. Right. A specific company. They could either do that, or they could scale and create a generic attack and just blast it out to tens or hundreds of millions of people, hoping for 1/10 of a percent to click on it. AI has enabled both of those things to happen. It can now craft a highly customized, very resourceful type of social engineering attack, and yet do it to millions of people simultaneously. By the end of 2025, it was estimated that over 80% of social engineering attacks were somehow enhanced by AI. And back in 2025, it was basic. It was converting it to local language, making sure grammar was correct. In 2026, it is completely blown out of the water. And now it's scanning individuals, LinkedIn and Facebook and social media accounts, crafting messages based on their work history and their presence and who they know. So fundamentally, it's an entirely different game.
Speaker B: So, Matthew, fully understood there's a lot of challenges, and especially in the short term, it seems like a lot of the innovation is favoring the fraudsters potentially more than the defenders. What are some positive trends that make you excited about the innovation and the month and quarters to come?
Speaker A: Yeah, so again, the attackers, right now, they have an advantage. But the core of cybersecurity is about adaptation. And because the attackers are pushing here, it forces cybersecurity, our entire industry, to adapt. And we are seeing adaptation. We're seeing how CISOs are now transforming from being the technical guardian that always says no to businesses to actually becoming an enterprise risk expert that says, yes, AI is very valuable to the business. Let's go fast. I will help with security. And that transformation is incredibly powerful. That sets us up to be able to provide more value, that establishes greater partnership with cybersecurity, and all the other business units. And it helps build trust. That is the key to being invited in early to establish the principles of security so that we can be in that forefront and we can be more proactive to establish privacy and safety and security and trust. So when we look towards the future us understanding the scope and the changing landscape of cybersecurity, those technology, the expectations, the business trade offs that we can be a partner to, we will be in a stronger position if we push through that transformation, if we drive adaptation, which is again, the core of what we have to be. We have to constantly be adapting. So we need the leadership, cybersecurity leadership, to really drive towards that optimization of risk. Not this mindset of I'm going to have rigid controls, I'm just going to eliminate it. No, I need to be a business partner. I need to help the organization adapt to these changes. I need to be the expert to understand how the attackers are evolving and how we're going to adapt to them and then drive to that now and fast. We can adapt. We just need to step forward. And I think there will be many, many organizations who will lead that charge, who will show to the world and to the peers, yes, we can adapt. The attackers will have the advantage. They always will. This is nothing new. It's nothing to fret over. We are going to then elevate what we do, how we do it to keep pace with those attackers because we are just as professional, if not more. And even though they have an advantage, we can rise to the occasion and we will.
Speaker B: Is your organization's cybersecurity plan up to date? Join the conversation by connecting with, uh, us on your podcast app, writing a review of the the show, or emailing us@bcgoncompliancecg.com I'm Han Joibert. Thanks for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.