Skip to main content

Securing Communications in an AI-Assisted World

Christine Gadsby spoke with Decipher's Dennis Fischer about cybersecurity’s evolution, mobile communications risks, AI-driven threats, and secure government communications.

Sep 17, 2026

·

Blog

·

Christine Gadsby, Vice President and Chief Security Advisor, BlackBerry

I recently appeared on the podcast Decipher to talk about how AI is changing the threat environment for organizations that depend on trusted communications. What came through clearly is that the shift is already operational, not theoretical.

AI-assisted tools are changing how people work, communicate, and make decisions. They are also changing how attackers operate, enabling adversaries to impersonate users, automate deception, and move faster across digital environments. A central theme of our conversation was that these developments make secure communications more important, not less. Organizations need trusted channels where identity, message integrity, operational continuity, and confidentiality can be protected, especially when the surrounding threat environment becomes harder to read.

AI Raises the Stakes for Trust

One of the first things we talked about was how AI changes the human side of security. Security has always been a human challenge as much as a technical one. People have to decide which messages to trust, which instructions to follow, and which requests deserve urgent action. AI increases the pressure on those decisions by helping attackers create more convincing messages at greater scale.

AI-assisted social engineering can make phishing, fraud, impersonation, and disinformation harder to detect. The underlying tactics are familiar. The pace and polish are different. Attackers can now draft credible messages, adapt tone, translate content, summarize stolen context, and target individuals with fewer barriers than before.

This is especially consequential, we agreed, for government agencies, critical infrastructure operators, regulated enterprises, and executive teams. In those environments, communications carry operational decisions, sensitive data, emergency instructions, and crisis response coordination. If those communications are compromised, delayed, or manipulated, the impact extends beyond information loss. Relying on ordinary channels for sensitive communications is a risk that AI-assisted attacks make more consequential.

Secure Communications Must Be Built into Operations

We spent time on what it actually takes to build security into communications rather than treating it as an emergency measure. A pattern came up that will be familiar to anyone who has followed the software industry: early on, vulnerabilities were treated as external problems to manage after discovery. Over time, security became part of engineering, release management, and product governance. Communications security needs the same treatment.

That means it cannot be reserved for occasional incidents, executive travel, or emergency exceptions. It has to be planned before a crisis, tested before it is needed, and integrated into daily workflows for the people who will depend on it.

Several practical questions surfaced: Which channels are approved for sensitive discussions? How are participants authenticated? What happens if primary networks are unavailable? How do leaders communicate when speed and accuracy both matter? The point was that organizations need to work through those questions before an attack, outage, or crisis creates pressure to improvise.

Encryption is one part of the problem. Organizations also need identity assurance, access control, auditability, policy governance, message integrity, and resilience when standard collaboration platforms are unavailable or untrusted.

AI Changes the Speed of Risk

One point came up repeatedly: AI-assisted threats accelerate familiar attack categories rather than introducing entirely new ones. Phishing, credential theft, executive impersonation, data leakage, and misinformation all remain recognizable risks. What changes is how quickly they can be generated, personalized, and distributed.

That speed matters in a specific way. A convincing message sent during a high-pressure event can lead to the wrong decision before a security team has time to intervene. A forged instruction can spread through informal channels before it is verified. A deepfake voice or AI-polished message can exploit trust relationships that were built over years.

The response to that cannot be controls that create so much friction that people work around them. Secure communications platforms should reduce the friction of trusted behavior rather than adding to it. Users should be able to verify identity, protect sensitive exchanges, and maintain operational continuity when normal systems are disrupted.

Resilience Depends on People and Process

Secure communications depend on people knowing what to use, when to use it, and how to verify unusual requests. Policies must be clear enough to follow under pressure. Training must reflect realistic scenarios, not generic guidance. Crisis plans must account for attackers attempting to inject false instructions into communication channels.

Something that stood out in our conversation: strong security programs are often built by people who adapt before the playbook is complete. Organizations should not wait for every AI-assisted risk to be fully defined before improving how they protect sensitive communications.

Practical preparation starts with identifying the communications that matter most: leadership coordination, incident response, public safety instructions, operational alerts, legal and regulatory discussions, and exchanges involving sensitive data. Once those workflows are clear, organizations can define which channels are acceptable, which controls are required, and which fallback methods will be used if normal tools fail.

The Path Forward

AI will continue to reshape how organizations work and how attackers operate. What came through in our conversation is that the right response is to strengthen the foundations that make communication trustworthy.

That means treating secure communications as a core part of cyber resilience: protecting sensitive conversations before they are targeted, validating identity before action is taken, and ensuring critical teams can keep operating when trust in ordinary channels is uncertain.

If attackers can manipulate what people believe, who they trust, or which instructions they follow, they can influence outcomes without breaching every system. Communications sit within the security perimeter, and protecting them requires the same deliberate planning applied to any other security control. For organizations that handle sensitive decisions, emergency coordination, or regulated information, that planning should already be underway.

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now