Imagine a world where, as Alexandra Forsyth put it, hackers “just play around.” No fixed target and no geopolitical motive, just curiosity, chaos, and increasingly powerful AI tools. That’s the direction enterprise cybersecurity is heading, she warned, and the stakes are high.
Forsyth, a cybersecurity expert, consultant, and podcast host, suggests to UC Today that the next era of enterprise cybersecurity may not be about “who attacked you,” but rather “what they discovered while poking around.”
In our interview, Forsyth outlined how AI is accelerating opportunistic cybercrime, why identity and human processes are increasingly the battlegrounds, and how quantum computing is quietly becoming a looming menace in board-level strategy. Real-world provocations illuminate her views; Jaguar Land Rover’s recent shutdown, Cl0p’s extortion campaigns, and the accelerating race to quantum-safe cryptography.
Together, they map the high-stakes challenge for IT and C-Suite leadership in 2026 and beyond.
The Rise of Opportunistic Attackers
Forsyth warned that cybercriminals are increasingly opportunistic, exploiting human error, misconfiguration, and moments of chaos rather than orchestrating long-term, state-backed campaigns.
She highlighted:
A lot of the cyber threats we see now aren’t the big, sophisticated operations people imagine. They’re opportunistic, quick, and often driven by younger actors who are just probing for weaknesses.”
This was clear in the Marks & Spencer breach earlier this year, when a social-engineering campaign targeting a third-party vendor brought one of the UK’s biggest retailers to a halt. The attack forced temporary store closures and cost an estimated £300 million in profit losses, with over £500 million wiped from its market valuation.
Investigations suggest the hackers didn’t begin with a clear goal; they exploited an exposed human link, gained access, and escalated from there. The breach disrupted payments, logistics, and customer service systems, marking a vivid example of how a single vendor misstep can cascade across an enterprise network.
For Forsyth, that typifies the new reality: “It’s no longer just about defending the perimeter. It’s about continuous vigilance, real-time awareness, and a culture where everyone, from the CEO to the intern, recognises they have a role in security.”
“A lot of the cyber attacks that have taken place this year have been carried out by young individuals,” Forsyth noted. “We’ve been seeing young hackers come to the forefront.”
For CISOs, that trend means traditional defences, such as firewalls, patching, and MFA (multi-factor authentication), are no longer enough. The new battleground is lateral movement and early detection: spotting intrusions before they know what they’ve found.
Identity and Human Risk: The Perimeter Has Shifted
With attackers exploiting the messy intersections of people and processes, identity has become the frontline of defence.
It’s the kind of aspirational control that could prevent countless internal breaches, from fake password resets to rogue access requests. Yet, Forsyth warned that organisations often overlook the basics. “The more information you’re sharing… it can increase the risks.”
CISOs face a double challenge of balancing identity governance with employee productivity and efficiency. Offboarding is a prime example. Dormant credentials, orphaned accounts, and unmanaged API tokens continue to be a consistent vector. “Identities that aren’t revoked quickly enough become attack vectors,” she said.
A 2025 IBM study found that compromised credentials were the initial attack vector in nearly 19 percent of breaches, costing firms an average of $4.3 million per incident.
Innovation vs. Resilience: Slowing Down to Speed Up
Forsyth’s offers some sage advice when it comes to discussing the pace of AI and cloud adoption:




