AI Is Changing Cyberattacks. Companies Are Not Prepared, Says Filip Štolle
Prague, March 24, 2026
Cyber threats are growing and accelerating, driven in part by the rise of artificial intelligence. Companies across Europe are facing an increasing number of cyber risks, which are also evolving more rapidly due to AI. At the same time, organizations are preparing for new regulatory requirements that, on their own, do not guarantee true resilience. In this interview, Filip Štolle, Managing Director of axelum, builds on the key topics of this year’s Axelum Security Day conference and explains how the nature of cyberattacks is changing, why the line between individuals and organizations is becoming blurred, and what ultimately determines whether a company can withstand an attack.
At the Axelum Security Day conference, you spoke about the current state of cybersecurity. How would you describe today’s global security situation and its impact on companies in Europe?
In my view, the world is significantly more dangerous than it used to be, and cyberspace has become just another dimension of ongoing conflicts. Companies in Europe can no longer assume they are standing aside. Attacks are increasingly long-term, stealthy, and focused on infiltration as well as preparation for future impact.
Do you think the nature of cyberattacks has changed in recent years? How are they different from a few years ago?
Cybercrime has become highly professionalized and, in many cases, operates like a well-managed business. At the same time, everything is accelerating—mainly due to AI, which simplifies attack preparation, malware mutation, and campaign scaling. What used to take days can now often be done in hours.
It is often said that the line between attacks on individuals and companies is becoming blurred. How does this manifest in practice?
Today, attacks on companies often start with an individual—their mobile device, personal equipment, or identity. The techniques are essentially the same; only the entry point differs. Automation also enables attackers to target individuals and organizations simultaneously, without the need for careful target selection.
New regulatory requirements, especially NIS2 and DORA, are a major topic. What do these changes mean in practice?
Security is no longer optional. Regulations bring not only obligations and penalties but also personal accountability for management. This means leadership must treat security as an integral part of business management—not as a peripheral IT issue that can be fully delegated to specialists.
Experts point out that compliance does not automatically mean real security. Do you see this in practice as well?
Yes. Compliance and real security are related, but they are not the same. A company may have all the right documentation and still not be well protected if measures are not monitored, tested, and continuously improved in practice. What matters is reality—not just formal compliance or well-written policies. Unfortunately, attackers do not follow regulations.
How big is the gap between theoretical security measures and reality, as revealed by Red Team simulations?
In our experience, often very significant. Measures may look good on paper, but a real attack reveals whether they work as a whole and whether people know how to respond under pressure. That is why realistic testing, such as Red Teaming, is so important—not only for security teams but also for management and crisis response.
How does AI change cyber threats and the way organizations defend against them?
AI increases the capacity of both sides. With its help, a single individual can now perform work that previously required multiple people. In the short term, however, it tends to benefit attackers more, as they face lower risks of making poor decisions and can experiment much faster.
Looking across different sectors, what cybersecurity challenges do companies face most often today?
Companies often invest in technology, but lack people, processes, and clear responsibilities. The result is fragmentation, isolated solutions, and weak response capabilities. In many cases, the problem is not the absence of tools, but the inability to manage, integrate, and use them effectively.
What steps should organizations take to be better prepared for future threats?
Organizations should use regulatory pressure as an opportunity to genuinely improve security—not just to produce documentation. They need clear accountability, greater focus on third parties, and an overall strategy. Security must be managed as a whole, not as isolated parts or standalone projects.
Filip Štolle, CISA, CISSP, is an information security expert with more than 20 years of experience. He has worked on key projects across banking, energy, retail, and the public sector. He helps international clients design and implement information security management systems, optimize processes, and deploy concrete security measures. He is also the CEO of Axelum s.r.o., where he leads a team of more than 20 security specialists, and he lectures on information security at a university. In his work, he draws on deep technical expertise in penetration testing, technical audits, and forensic analysis, which he actively focused on earlier in his career.