Summary
The core message of the session is that AI is already changing cyber operations as a force multiplier, but the speakers deliberately reject a simplistic “everything will be autonomously hacked next year” doom scenario. Juriaan opens with a fictional ONE Conference 2027 setting in which rogue agents, breached chatbots, autonomous AI bot intrusions, exposed personal data, and minute-scale exploitation dominate the agenda. He then asks the audience whether they think this will be next year’s reality; only a minority raise their hands, and the speakers say they do not think this is the likely reality. Their value proposition is a grounded look at the current, observable threat landscape rather than speculative fear, followed by practical guidance on what organizations should do.
Juriaan and Bram introduce themselves as NCSC researchers and advisers working on AI and cybersecurity. Bram notes that his master’s thesis examined the impact AI systems will have on cybersecurity, while Juriaan explains that he has followed AI since the release of ChatGPT at the end of 2022 and especially since the announcement of Project Glasswing. Juriaan then frames the analysis with the Unified Kill Chain, a 17-step model divided into “in,” “through,” and “out” phases, incorporating elements from MITRE ATT&CK. The model is used to explain how an attacker moves from reconnaissance through persistence, privilege escalation, lateral movement, data exfiltration, ransomware, and final objectives such as extortion.
In the “in” phase, Juriaan says AI is most visibly useful today: mapping attack surfaces, finding exposed secrets and misconfigurations, supporting vulnerability research, patch diffing, writing exploits, generating malware, and automating parts of phishing infrastructure. He emphasizes that AI lowers barriers and accelerates work, but it does not magically turn an unskilled actor into an advanced APT: “garbage in is garbage out.” He cites falling time-to-exploit figures, including a reported 1.6-day mean time to exploit and some vendor claims that averages are already “in the minus digits,” meaning more zero-days than n-days on average.
In the “through” phase, the talk shifts to more specific and advanced uses: post-compromise discovery, network mapping, finding lateral movement paths, context-based malware that changes inside a victim environment, and privilege escalation through misconfiguration discovery. Juriaan stresses speed as both a defender challenge and a detection opportunity, because actions that would normally take minutes, hours, or days may occur in seconds or minutes and should trigger anomaly detection. In the “out” phase, AI is described as helping collect, prioritize, and prepare sensitive data for exfiltration, but Juriaan offers an important caveat: he has not seen cases of fully autonomous ransomware, sabotage, disruption, or wiper malware. At this stage, AI still appears to function as an intelligent operational assistant, though that could change in the future.
Key Topics
5 key topics from Juriaan Spierenburg and Bram van Aggelen at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Map your attack surface before AI-assisted attackers do.
- Tune alerts for actions happening at machine-speed anomalies.
- Prioritize patching because time to exploit is shrinking sharply.
- Treat AI as a force multiplier, not an autonomous apocalypse.
- Verify AI-generated malware claims against observed real-world evidence.
“garbage in is garbage out, and it also applies to this category”
Up Next

Next in agenda
Human resilience when truth is hackable
Inge Wetzer
Also on threat intelligence
A Pragmatic Path to Continuous Purple Teaming
Cas van Cooten


Also on threat intelligence
