The 1Kosmos team recently returned from the Billington Cybersecurity Summit, where the clearest message was about pace. Attackers are using AI to run familiar playbooks faster and more often, which puts new weight on fundamentals like identity.
For 17 years, Billington has gathered public-sector cybersecurity leaders in Washington, DC, including CIOs and CISOs from most cabinet departments, alongside vendors and practitioners from the private sector. The discussions there influence how the people who defend critical systems set priorities and spend their resources, which makes it one of the more consequential events on the security calendar.
Reducing risk in the age of AI-enabled attacks
This year's theme, "Reducing risk in the age of AI-enabled attacks," fit the moment. Speaker after speaker described AI risk as substantial today and growing quickly, while also stressing how complicated the picture is. AI helps defenders as well as attackers, and older attack methods and traditional defenses still deserve attention even as AI dominates the conversation.
Several themes from the conference matter well beyond the public sector. For anyone who couldn't attend, or who was too busy at Billington to take it all in, here is our recap.
Attackers are scaling familiar tactics, not inventing new ones
Although AI-enabled attacks were the focus, many speakers emphasized traditional defenses and basic cyber hygiene. It's tempting to assume an advanced technology can only be countered with equally advanced strategies. Defenders on the front lines report something different: attackers mostly use AI to run attacks we've seen before, at a speed and scale that weren't possible in the past.
This cuts both ways. Security teams that already feel stretched now face a higher volume of attacks from adversaries who can operate continuously at machine speed. On the other hand, defenders can rely on approaches they already know, provided they raise the bar in areas where adequate performance used to be enough. Gaps in the basics become openings that AI can exploit at scale.
For identity and access teams, this makes strong verification and authentication more important. As attackers find new ways to scale familiar tactics, a hardened identity layer is what stops those tactics from turning into unauthorized access.
Public-private collaboration is more critical than ever
The public and private sectors have long depended on each other for cybersecurity. Government agencies protect critical targets and produce valuable threat intelligence, and private companies build security tools and support government partners. Speakers described that relationship deepening as each side relies on the other in new ways.
Private companies are increasingly targeted by nation-state actors pursuing geopolitical goals. An attack on a business can cause economic damage or disrupt supply chains, sometimes more effectively than an attack on a government or military target. Companies can no longer treat international affairs as someone else's problem, and they need to work closely with the public sector on strategy and security.
Public agencies, for their part, are watching AI-enabled attacks weaken existing policies and protections. That applies to agencies with national security missions and also to state and local governments, universities, and agencies that seem far removed from security work. Updated standards only go so far without tools to enforce them, so agencies are looking to the private sector for stronger technology built for government use.
Speakers from both sectors agreed that collaboration needs to become more consistent and better coordinated for either side to succeed.
AI is reshaping attack and defense
Many of the anecdotes about AI's effect on cyber risk came back to trust. If documents and voices can be convincingly faked, the usual ways of confirming them stop working.
One cybersecurity executive described a scenario in which an attacker uses AI to produce a fraudulent invoice that looks authentic in every detail. When someone calls to confirm it, SIM swapping or a similar technique reroutes the call to a synthetic voice that sounds completely real. The employee did the right thing by double-checking, and the safeguard still failed because AI handles fraud and impersonation that well.
That scenario is a direct challenge for identity. When familiar signals can be manipulated, organizations need stronger ways to confirm that a person is who they claim to be.
Defenders also described real gains from AI in speed and productivity. Many were optimistic while acknowledging an imbalance; defenders are bound to use AI responsibly, and attackers face no such limits. A common view was that AI calls for rethinking nearly everything from regulatory requirements to risk mitigation, with continual adaptation from here on.
Cyber warfare is expanding the threat landscape
This year's summit took place against the backdrop of major conflicts, including those involving Ukraine and Iran, and several speakers had direct or indirect ties to those fronts. All of them described cyber operations as central to how each party gathers intelligence and disrupts strategic targets, including weapons systems. Cyber warfare has been around for years, though it has never been this prominent.
Those speakers returned to a point made earlier in the conference: effective defense depends on collaboration across the whole public sector, including civilian agencies, and with the private sector, which is both a target and a major source of intelligence and defensive tools.
Together, the growth of cyber warfare and AI-enabled attacks make for a more volatile threat landscape. Nation states have vast resources for hacking and strong motivation to be aggressive and persistent, so any organization that could be a target should treat cybersecurity as a top priority.
Final thoughts
The mood at the summit was upbeat despite broad agreement that the work is getting harder. More than 3,000 cyber defenders attended. These are people who spend their days stopping attacks and responding to incidents, and they are used to working under pressure. Even as they watch AI being weaponized and geopolitical tensions play out online, they're confident the community can meet the challenge.
For our team, Billington reinforced that establishing trust in digital interactions will matter more as threats evolve. Strong identity controls and closer public-private collaboration will be central to that work, along with the ability to adapt as AI changes both attack and defense.
The 1Kosmos team recently returned from the Billington Cybersecurity Summit, where the clearest message was about pace. Attackers are using AI to run familiar playbooks faster and more often, which puts new weight on fundamentals like identity.
For 17 years, Billington has gathered public-sector cybersecurity leaders in Washington, DC, including CIOs and CISOs from most cabinet departments, alongside vendors and practitioners from the private sector. The discussions there influence how the people who defend critical systems set priorities and spend their resources, which makes it one of the more consequential events on the security calendar.
Reducing risk in the age of AI-enabled attacks
This year's theme, "Reducing risk in the age of AI-enabled attacks," fit the moment. Speaker after speaker described AI risk as substantial today and growing quickly, while also stressing how complicated the picture is. AI helps defenders as well as attackers, and older attack methods and traditional defenses still deserve attention even as AI dominates the conversation.
Several themes from the conference matter well beyond the public sector. For anyone who couldn't attend, or who was too busy at Billington to take it all in, here is our recap.
Attackers are scaling familiar tactics, not inventing new ones
Although AI-enabled attacks were the focus, many speakers emphasized traditional defenses and basic cyber hygiene. It's tempting to assume an advanced technology can only be countered with equally advanced strategies. Defenders on the front lines report something different: attackers mostly use AI to run attacks we've seen before, at a speed and scale that weren't possible in the past.
This cuts both ways. Security teams that already feel stretched now face a higher volume of attacks from adversaries who can operate continuously at machine speed. On the other hand, defenders can rely on approaches they already know, provided they raise the bar in areas where adequate performance used to be enough. Gaps in the basics become openings that AI can exploit at scale.
For identity and access teams, this makes strong verification and authentication more important. As attackers find new ways to scale familiar tactics, a hardened identity layer is what stops those tactics from turning into unauthorized access.
Public-private collaboration is more critical than ever
The public and private sectors have long depended on each other for cybersecurity. Government agencies protect critical targets and produce valuable threat intelligence, and private companies build security tools and support government partners. Speakers described that relationship deepening as each side relies on the other in new ways.
Private companies are increasingly targeted by nation-state actors pursuing geopolitical goals. An attack on a business can cause economic damage or disrupt supply chains, sometimes more effectively than an attack on a government or military target. Companies can no longer treat international affairs as someone else's problem, and they need to work closely with the public sector on strategy and security.
Public agencies, for their part, are watching AI-enabled attacks weaken existing policies and protections. That applies to agencies with national security missions and also to state and local governments, universities, and agencies that seem far removed from security work. Updated standards only go so far without tools to enforce them, so agencies are looking to the private sector for stronger technology built for government use.
Speakers from both sectors agreed that collaboration needs to become more consistent and better coordinated for either side to succeed.
AI is reshaping attack and defense
Many of the anecdotes about AI's effect on cyber risk came back to trust. If documents and voices can be convincingly faked, the usual ways of confirming them stop working.
One cybersecurity executive described a scenario in which an attacker uses AI to produce a fraudulent invoice that looks authentic in every detail. When someone calls to confirm it, SIM swapping or a similar technique reroutes the call to a synthetic voice that sounds completely real. The employee did the right thing by double-checking, and the safeguard still failed because AI handles fraud and impersonation that well.
That scenario is a direct challenge for identity. When familiar signals can be manipulated, organizations need stronger ways to confirm that a person is who they claim to be.
Defenders also described real gains from AI in speed and productivity. Many were optimistic while acknowledging an imbalance; defenders are bound to use AI responsibly, and attackers face no such limits. A common view was that AI calls for rethinking nearly everything from regulatory requirements to risk mitigation, with continual adaptation from here on.
Cyber warfare is expanding the threat landscape
This year's summit took place against the backdrop of major conflicts, including those involving Ukraine and Iran, and several speakers had direct or indirect ties to those fronts. All of them described cyber operations as central to how each party gathers intelligence and disrupts strategic targets, including weapons systems. Cyber warfare has been around for years, though it has never been this prominent.
Those speakers returned to a point made earlier in the conference: effective defense depends on collaboration across the whole public sector, including civilian agencies, and with the private sector, which is both a target and a major source of intelligence and defensive tools.
Together, the growth of cyber warfare and AI-enabled attacks make for a more volatile threat landscape. Nation states have vast resources for hacking and strong motivation to be aggressive and persistent, so any organization that could be a target should treat cybersecurity as a top priority.
Final thoughts
The mood at the summit was upbeat despite broad agreement that the work is getting harder. More than 3,000 cyber defenders attended. These are people who spend their days stopping attacks and responding to incidents, and they are used to working under pressure. Even as they watch AI being weaponized and geopolitical tensions play out online, they're confident the community can meet the challenge.
For our team, Billington reinforced that establishing trust in digital interactions will matter more as threats evolve. Strong identity controls and closer public-private collaboration will be central to that work, along with the ability to adapt as AI changes both attack and defense.
The latest in identity security.
Enter our orbit.
The latest in identity security.
Enter our orbit.
The latest in identity security.






