Every year I leave Hacker Summer Camp in Las Vegas with a head full of ideas, questionable stickers and at least a dozen new things I want to try when I get back home. Between DEF CON 34 and BSides Las Vegas, this year was no different.

The tone around AI has changed

The conversations around AI were especially interesting because the tone has noticeably changed. A year or two ago, many discussions centered around caution. Would AI replace analysts? Would attackers gain an insurmountable advantage? Were we opening Pandora’s box, and could we secure it?

This year felt different.

The overwhelming sentiment I encountered was that AI is becoming another tool in the security toolbox. It’s not magic. It’s not Skynet. It’s not replacing defenders. It’s simply becoming part of how modern security teams operate.

That shift in mindset has some interesting implications for the future.

Honeypots are about to get a lot more convincing

One of the concepts that stuck with me was the idea that we need to think more offensively about our own AI usage. For years we’ve relied on honeypots to attract attackers and collect intelligence. The next evolution may be far more sophisticated.

Imagine creating entire “honey companies” with:

  • AI-generated employee profiles
  • Realistic business histories
  • Believable web presences
  • Intentionally exposed services designed to attract adversaries.

Sprinkle in public disclosures about recently remediated vulnerabilities and suddenly you’ve built a much richer environment for collecting attacker behavior.

The goal isn’t deception for the sake of deception. The goal is gaining visibility into how attackers operate when they believe they’ve found a legitimate target. AI makes creating and maintaining those environments dramatically more achievable than it would have been just a few years ago.

Build for the model you’ll be using next year

Another recurring theme was AI agents and how organizations should approach building them. The shiny new model released this week won’t be the shiny new model six months from now. If we’re building systems that are tightly coupled to a single vendor or model, we’re probably creating technical debt from day one.

Instead, the future seems to belong to organizations that build flexible frameworks around AI. A simple approach I kept coming back to has four steps:

  1. Discover what models, tools, skills and plugins the task actually needs
  2. Plan around the outcome you want, not the technology you’re using
  3. Act, letting AI do the work where it makes sense
  4. Validate, with a human reviewing the results

That last step matters. Despite all the excitement around autonomous agents, I don’t think we’re headed toward a future where security professionals disappear from the process. If anything, their role becomes more important. Humans move from manually doing every task to overseeing systems that can execute at much greater speed and scale.

AI is lowering the barrier to entry for attackers

One myth that continued to get challenged throughout the conference was the idea that AI is suddenly enabling highly sophisticated attacks that were previously impossible. In reality, what we’re seeing is that AI is lowering the barrier to entry for common attacks. It helps bad actors move faster. It helps them find low-hanging fruit more efficiently. It helps them scale activities that already worked.

That’s not a reason to panic. It’s a reason to get the basics right.

Organizations that continuously manage their attack surface, reduce unnecessary exposure and focus on risk reduction from an external perspective will be far better positioned than those chasing every new AI-generated threat headline. Attackers don’t need an advanced zero-day if they can still find an exposed service, forgotten asset, or weak configuration.

OT and critical infrastructure deserve more attention

One area that deserves much more attention is operational technology and critical infrastructure. The knowledge gap that once existed around many OT environments is shrinking quickly. AI can help individuals understand unfamiliar protocols, systems and architectures much faster than before. As that barrier drops, the likelihood of these environments being targeted and compromised goes up.

The security conversation around these systems can’t stop at prevention. We also need to spend more time talking about business continuity and disaster recovery.

  • What does a small or medium-sized business do if power is unavailable for days?
  • What happens when water systems, building controls, communications, or other critical services experience prolonged disruption?

Those aren’t theoretical questions anymore. They’re business questions that need answers.

Where MSPs fit in the AI ecosystem

Perhaps the most exciting discussion for me was around what the future AI ecosystem might actually look like.

I don’t think every MSP is going to become an AI research company. I don’t think every customer is going to hire teams of machine learning engineers. Instead, I can see a future where large cloud providers and security vendors provide the underlying infrastructure: secure hosting, AI services, container platforms, serverless functions, identity controls, monitoring and application security.

On top of that foundation, MSPs become builders and guides. They use AI-assisted development to rapidly create custom applications, automate workflows and solve very specific customer problems. They maintain the code, improve the business logic and help clients continuously evolve their applications as requirements change.

In that world, companies get software tailored to their business without needing a massive development team. MSPs create more value. Infrastructure providers focus on security, scalability and reliability. Everyone works higher up the technology stack.

From experimentation to implementation

Walking away from DEF CON and BSides Las Vegas this year, my biggest takeaway is that we’re moving from experimentation to implementation. The conversation is no longer about whether AI will impact cybersecurity. It already has. The real question is how we build systems, processes and businesses that take advantage of it while managing the risks that come along for the ride.

And if history has taught us anything, the organizations that embrace new technology thoughtfully and systematically, instead of fearing it, tend to be the ones shaping the future rather than reacting to it.

Keep the conversation going with other MSPs

The most useful part of a week like this is getting to compare notes with other security practitioners on what’s actually working. That’s the thinking behind the CyberMSP Community, a space where MSPs can swap threat intel, compare workflows and get answers from experts without a sales pitch attached. If you’re interested, you can join the CyberMSP Community today.

Written by Roddy Bergeron Technical Fellow, Cybersecurity @ Sherweb

Roddy Bergeron's career has taken various paths including government auditing, nonprofit work, public/private partnerships with the State of Louisiana, helping build an MSP by building their managed service, managed security, vCISO and compliance programs, and now as the Cybersecurity Technical Fellow with Sherweb. Roddy has obtained many certifications over the years including his MCSE, CCNA:Security, CEH, CCSP, CISSP and CSAP. Our MSP community is extremely important to Roddy and he loves giving back to the community that has helped him out so much over the years. Roddy hopes to continue to help other MSPs succeed and raise the cybersecurity tide for our industry.