The future did not kick down the firewall. It arrived in the inbox, wearing a better sentence and fewer typos, because apparently even scams have discovered productivity software. CDW's latest security research, as reported by ZDNET, gives defenders a useful checkpoint instead of another fog machine labeled emerging risk. If your plan still treats AI-enabled attacks as a problem for later, later has already opened a ticket. ## What CDW found, according to ZDNET According to Charlie Osborne at ZDNET, 43% of organizations surveyed have experienced AI-enhanced or AI-generated phishing attacks. ZDNET also reported that 37% of organizations have encountered AI-augmented malware, while 41% of companies plan to use AI in their cyber defenses. CDW's own newsroom identifies the research as its 2026 Cybersecurity Report, which is a polite way of saying the annual security weather report now includes a chance of automated deception. The breach-breakdown version is simple: the scope is not universal, but it is far too large to file under future concerns. The exposed surface is familiar, phishing and malware, which is exactly why this matters. Security teams do not get to dismiss AI-driven activity as exotic when it is being bolted onto the same old delivery mechanisms that already ruin everyone's Tuesday. ## How the threat changes, according to ZDNET and Cybersecurity Today ZDNET's summary says AI is driving new phishing and malware-based threats, and that is the operational detail hiding behind the headline. Phishing has always depended on trust, timing, and believable context, and AI-generated language lowers the friction for producing lures that look less obviously stitched together in a basement during a power outage. If your awareness training still leans heavily on spotting bad grammar, congratulations, your control has been promoted to decorative wall art. Cybersecurity Today, in its interview with CDW Canada's Ivo Wiens, framed AI as part of both the attack problem and the defense problem, alongside pressure from organized crime and nation-states. That matters because defenders are not dealing with one cartoon villain in a hoodie, they are dealing with different threat actors adopting tools where those tools help. The useful response is not panic, it is updating assumptions: email filters, malware detection, and incident response workflows need to be tested against AI-enhanced inputs, not just last year's templates. ## Why defensive AI needs adult supervision, according to NSF research Research by Sheyla Gyles and Chutima Boonthum-Denecke, available through the National Science Foundation's public access repository, describes AI-driven security systems as able to analyze vast amounts of data in real time, recognize subtle patterns, and adapt to new attack strategies more efficiently than conventional approaches. That is the good news, and yes, security could use some good news before the coffee machine becomes an unmanaged endpoint. The same research also highlights concerns about effectiveness, ethical implications, and adversarial manipulation. Translation: do not buy a dashboard deity and call it strategy. AI can help with detection, prevention, and response, but it should be evaluated like any other security control, with measurable performance, clear failure modes, and human review where mistakes carry privacy or business consequences. The goal is not to replace judgment, it is to reduce noise fast enough that analysts can spend more time on the alerts that deserve a pulse check. ## What it actually means for you, according to CDW and ZDNET For security leaders, CDW's research should trigger a practical review, not a ceremonial panic slide. Start by asking whether your phishing training reflects AI-generated messages, whether malware detection looks for behavior rather than just known artifacts, and whether your incident response process can handle a higher volume of plausible junk without turning analysts into keyboard-shaped ash. If your company is part of the 41% that ZDNET says plans to use AI in defenses, make that plan concrete and testable. For everyone else, the takeaway is less dramatic but still useful: be slower with inbox trust and faster with verification. A polished message is no longer evidence that a human with good intentions wrote it. Watch for defensive AI moving from plan to practice, and watch whether companies can explain how they validate these tools without turning your data into yet another offering on the privacy bonfire. ## Sources - Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
- CDW Releases 2026 Cybersecurity Report
- AI-Driven Cybersecurity: Opportunities, Challenges, and ...
- Cybersecurity Today: Cyber Security Research from CDW: Interview with Ivo Wiens, Field CTO Cybersecurity: Cyber Security Today Weekend for October 26, 2024
Sources
- Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
- CDW Releases 2026 Cybersecurity Report
- AI Threats and Opportunities in Cybersecurity | Cat Daniels posted on the topic | LinkedIn
- ZDNET - New CDW research finds that AI is driving new...
- AI-Driven Cybersecurity: Opportunities, Challenges, and ...
- Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
- New CDW research finds that AI is driving new phishing and malware ...
- CDW Releases 2026 Cybersecurity Report
- Cybersecurity Today: Cyber Security Research from CDW: Interview with Ivo Wiens, Field CTO Cybersecurity: Cyber Security Today Weekend for October 26, 2024
- AI Outpaces Security: Rethinking Cybersecurity Approach | Identity Jedi posted on the topic | LinkedIn