Malik Haidar has spent over a decade navigating the high-stakes world of multinational cybersecurity, bridging the gap between raw technical intelligence and corporate strategic planning. As an expert who has witnessed the evolution of threats from simple scripts to sophisticated autonomous systems, he brings a unique perspective on how modern businesses must adapt to survive. In our conversation today, we delve into the shifting landscape of 2026, where artificial intelligence has moved from a defensive aid to an aggressive, automated adversary that exploits vulnerabilities faster than any human team could hope to patch.
We explore the erosion of traditional risk-cost calculations in the private sector, the alarming vulnerability of public infrastructure such as regional water facilities, and the looming shadow of quantum decryption. Haidar outlines why current diplomatic efforts often fail against hostile state actors and argues that the only path forward is a comprehensive blend of policy, tax incentives, and a “distrust and verify” approach to international AI safety.
With AI tools like Mythos now capable of automating the discovery of vulnerabilities and the immediate creation of exploit code, how is this shift in speed fundamentally altering the way you advise corporations on their defensive posture?
The emergence of tools like Mythos has turned what used to be a tactical skirmish into a high-speed war of attrition where humans are increasingly sidelined. In the past, a vulnerability might be discovered and then linger for weeks while a hacker manually crafted an exploit, but today, AI compresses that timeline into mere seconds. When I speak with corporate boards, I emphasize that we are no longer defending against a person, but against a tireless machine that scans configuration errors and software flaws 24/7 without fatigue. This automation doesn’t just increase the frequency of attacks; it heightens the risk of massive collateral damage because these tools often strike targets they weren’t even intended for, creating a chaotic ripple effect across the digital economy. We have to move away from reactive patching and toward a mindset where the “means” of exploitation are treated as an ever-present, autonomous force that requires an equally automated and robust response.
You’ve often mentioned that cybersecurity is essentially a business decision, but how has the ubiquity of ransomware and AI-driven threats changed the internal “risk versus cost” equations for modern firms?
For decades, firms treated cybersecurity like a line-item expense that could be trimmed, often deciding to accept the risk of a breach rather than footing the bill for top-tier defense or expensive insurance premiums. They operated under the assumption that the probability of an “unacceptable loss” was low, but the modern digital economy has created an immense, opaque attack surface that makes those old calculations obsolete. Ransomware has been a wake-up call, yet many companies still suffer from a sort of cognitive dissonance where they underestimate the sheer scale of the threat because they cannot “see” the AI bots probing their perimeters. My job is to show them that the cost of defense is now significantly lower than the cost of a total operational shutdown, especially when AI can find a single overlooked error and exploit it to paralyze an entire multinational’s logistics. It is a sensory shift for leadership; they have to start feeling the digital heat of the threat environment before the fire actually starts.
While major financial institutions have the capital to build fortresses, we’ve seen smaller entities and public sector utilities, like those water facilities in Michigan, fall victim to attacks—what specific hurdles prevent these essential services from achieving basic security?
The situation with the water facilities in Michigan is a perfect, albeit tragic, example of the “resource gap” that AI is currently widening. These smaller public sector entities are often working with legacy systems and skeletal IT staffs who are already overwhelmed just keeping the lights on, let alone defending against autonomous hacking tools. They simply lack the financial gravity to attract the kind of talent or acquire the advanced AI-driven defensive mechanisms that a major bank uses every day. It creates a terrifying reality where the most critical services to human life—our water, our local power, our emergency response—are the most exposed because the incentives for high-level investment aren’t there. We are essentially asking a local volunteer fire department to fight a wildfire started by a laser-guided drone; the mismatch in capabilities is staggering and requires immediate intervention.
Looking toward the near future, how do you see the arrival of quantum decryption in the next 3 to 5 years impacting the already fragile digital infrastructure we rely on?
The prospect of quantum decryption arriving between 2029 and 2031 is the “looming shadow” that keeps most of us in the intelligence community awake at night. We are currently running our entire global economy on digital infrastructure that is riddled with unintended vulnerabilities, and quantum computing will essentially provide hackers with a skeleton key to every locked door. While we hope to use AI to address these software holes before the quantum era fully arrives, the reality is that the transition will be slow and messy. If we don’t start implementing quantum-resistant protocols today, the autonomous tools of 2026 will look like child’s play compared to the decryption capabilities that will exist by the end of the decade. It’s a race against time to rebuild the foundation of our digital house while the storm is already beginning to howl outside.
Given that traditional cybersecurity norms are often ignored by hostile foreign actors in sanctuaries like Russia or China, what role should a new national cybersecurity strategy play in enforcing accountability?
We have to face the hard truth that international negotiations on AI safety and cybersecurity often run into a brick wall because there is no penalty for breaking the rules. For decades, the consequences for state-sponsored hacking have been negligible, which gives countries like China or criminal syndicates in Russia zero incentive to stop their activities. A truly effective national strategy cannot just be a technical manual; it must be a blend of aggressive tax incentives, strict regulation, and procurement policies that force accountability down the supply chain. We should follow a “distrust and verify” model—a 2026 update to the old Cold War mantra—where any multilateral agreement includes rigorous, transparent procedures to ensure compliance. Without the political will to impose real, painful consequences on those who use AI as a weapon, the cycle of attacks will only continue to accelerate.
As we prepare for the high-level bilateral discussions on AI safety scheduled for this September, what is your forecast for the evolution of international cooperation in this space?
My forecast is that we are entering a period of deep skepticism where bilateral talks between the US and China will serve as a necessary but slow-moving theater for stability. Much like the arms control negotiations of the past century, it will likely take years of posturing and UN discussion processes before we arrive at a meaningful agreement that actually changes behavior on the ground. We will see a world where almost every nation uses AI for governance and economic growth, but only a handful will fully militarize it, leading to a new kind of “AI-cold war.” Ultimately, I believe the sheer danger of autonomous hacking will eventually force a level of cooperation that diplomacy alone couldn’t achieve—not out of a sense of global goodwill, but out of a shared fear of losing control over the very tools we’ve created. The next few years will be defined by whether we can build these “AI guardrails” before a major, AI-driven systemic collapse forces our hand.

