Back from Barcelona: AI, crisis and leadership
I spent a few days in Barcelona running a workshop on AI and crisis management in cybersecurity. A packed room, very different profiles, and one shared observation: the fog. Too much information, too many tools, not enough bearings.

I spent a few days in Barcelona running a workshop on AI and crisis management in cybersecurity. A packed room, very different profiles, and one shared observation: the fog. Too much information, too many tools, not enough bearings.
I opened with a simple question: who here feels like a hacker? A few hands went up. Not the ones you would expect.
Behind that word, people often picture a masked pirate. I see it more as a way of thinking. A hacker is someone who observes, questions, repurposes. A kind of artistic mindset, not a criminal one.
And that is exactly the attitude we will have to cultivate, because crises no longer look like the ones we learned to handle.
AI no longer answers, it acts
We have moved from ChatGPT answering questions to AI agents making decisions. Not on their own, not without you, but fast enough that you lose your footing if you are not prepared.
It is no longer a spectacular technology. It is a silent infrastructure. Like electricity. And it forces one thing: being clear about what you expect from it. Because it has no intention. No intuition. It does what it is asked, sometimes too well.
I said it plainly in Barcelona: AI does not need meaning, you are the one who has to give it.
This shift is anything but theoretical. In August 2025, Anthropic documented an extortion operation in which a cybercriminal used a coding agent to hit at least seventeen organisations, across healthcare, emergency services, public institutions and religious bodies, with ransom demands sometimes exceeding 500,000 dollars. The AI was not just executing orders: it decided which data to steal and drafted extortion messages calibrated to frighten.
Three months later, in November 2025, the same company revealed the first cyber espionage campaign run very largely by an AI. A group it attributes with high confidence to a Chinese state actor conducted 80 to 90% of the operations near-autonomously, with humans stepping in only at a few critical decision points. At its peak, the machine was firing several requests per second, a pace no human team can hold.
That is what "it acts" means. Not a science fiction future: agents that recognise, decide and strike, at a speed that outruns our reflexes. The good news is that the same shift applies to defence. The bad news is that a tool without intention does the attacker's work just as well as yours, depending on what it is asked to do.
Why do 95% of cyber incidents have a human origin?
There is one figure we forget far too often: 95% of cybersecurity incidents have a human origin. A mistake. Fatigue. A cognitive bias.

You might think automation changes the equation. It moves the cursor, it does not erase it. Verizon's Data Breach Investigations Report shows that nearly half of breaches now involve ransomware, and that around a third begin with the exploitation of a software vulnerability. In France, ANSSI notes that more than half of its most critical incident-response operations in 2024 started with flaws in exposed security appliances. Behind every unpatched hole, every reused password, every attachment opened too quickly, there is a human decision.
AI industrialises the attack; it does not remove the way in. And most of the time, that way in is us.
What exactly is cyberpsychology?
That is why I talk about cyberpsychology. It is not a fancy word, it is simply the reality of our daily life: it is people who click, who reply, who ignore or who panic. And these are the same people we expect to react correctly when everything spins out of control.
Understanding the human factor should be the foundation of any cyber strategy. Not a bonus chapter.
Leadership is not a role, it is a skill
In moments of tension, people do not look at someone's title. They look at who keeps a cool head. Who asks a clear question. Who speaks up without adding to the chaos.
Leadership, for me, is not about running a team. It is about knowing how to be useful to others, in the moment. Clarifying, reassuring, unblocking, proposing.
These are human skills. Junior or senior, technical or not, it does not matter. What counts is the stance. And the readiness to act.
In the middle of a crisis, what exactly do you expect from AI?
A crisis is the moment when everything that was blurry becomes urgent.
- Who decides?
- What to prioritize?
- Who communicates?
AI can help. It can cut detection time, provide scenarios, analyze event logs faster than you can read them. But it will not replace what you fail to set out clearly: your logic, your priorities, your limits.
That is where leadership comes in. Not the leadership of grand theories. The everyday kind. The kind that, when everything is shaking, keeps a steady mind. The kind that can say "I don't know yet" and still moves forward.
That composure is not a luxury. ENISA, the European cybersecurity agency, reviewed several thousand incidents for its 2024 landscape: attacks against the availability of services come first, ahead of ransomware and data breaches. In other words, crisis is no longer the exception, it is the permanent regime. You do not prepare for it by buying one more tool, but by knowing who decides when the tool does not decide for you.
What I saw in the room
It was not a room full of hackers. Nor pure decision-makers. It was a patchwork. And that was exactly right.
What I saw was people realizing that AI was not some distant future. It is here. And that the real stake is not understanding the models, it is knowing how you are going to fold it into your daily life without becoming a spectator of your own tools.
I also saw a lot of discomfort. Fatigue. A lot of "we don't know where to start." And that is normal.
Where do you start to take back control?
I offered them a simple starting point:
- Read, to feed yourself with something other than streams of notifications.
- Write, to clarify what you really think.
- Debate, so you don't go in circles inside your own certainties.
It is not a miracle method. It is a rhythm. And in a world that keeps accelerating, rhythm is worth its weight in gold.
AI will keep moving forward, whether you like it or not. The only real choice is how you approach it: as one more gadget, or as a lever to become clearer, quicker to react, more human.
What I take away from this workshop is that many people are ready. But they are waiting for permission.
The good news: it will not come from above.
It comes from you.
Learn more about My resources and my book "Être en cybersécurité"
Sources
- AI agents used in real attacks: Anthropic, "Detecting and countering misuse of AI", August 2025, and "Disrupting the first reported AI-orchestrated cyber espionage campaign", 13 November 2025.
- Human factor, 95% of incidents with a human origin: World Economic Forum, Global Risks Report 2022, chapter 3.
- Ransomware and exploitation of vulnerabilities: Verizon, Data Breach Investigations Report.
- Exposed security appliances and critical incidents in 2024: ANSSI, Panorama de la cybermenace 2024, 1 March 2025.
- Threat hierarchy (availability, ransomware, data): ENISA, Threat Landscape 2024, 19 September 2024.
Frequently asked questions
What is agentic AI and why does it change cybersecurity?
Agentic AI refers to systems that no longer simply answer but act: they recognise, decide and execute. In late 2025, Anthropic documented an espionage campaign in which 80 to 90% of the operation was carried out by an AI, with only a handful of human decision points. On defence as much as on offence, speed changes scale.
Are AI-driven cyberattacks already a reality?
Yes. In August 2025, Anthropic described a vibe hacking extortion operation targeting at least seventeen organisations, with ransom demands sometimes exceeding 500,000 dollars, where the AI chose which data to steal and drafted the threatening messages. These are no longer lab demonstrations.
Why do people say 95% of cyber incidents have a human origin?
The figure comes from the World Economic Forum's Global Risks Report 2022: the vast majority of incidents trace back to a human error, a moment of fatigue or a bias. Even when the attack is automated, the way in (an unpatched flaw, one click too many) is most often a human decision.
What is cyberpsychology according to the author?
It is the realistic recognition of the human factor in cybersecurity: it is people who click, reply, ignore or panic. Understanding these behaviors should be the foundation of any cyber strategy, not a bonus chapter.
What role does AI play in crisis management?
AI can cut detection time, suggest scenarios and analyze event logs faster than a human. But it does not replace the logic, priorities and limits that the decision-maker has to set clearly.
Why does the author define leadership as a human skill?
Because under pressure, people do not look at someone's title but at who keeps a cool head, asks a clear question and acts without adding to the chaos. Leadership is a stance that is useful to others in the moment, open to juniors and seniors alike.
Where should you start to adapt to AI?
The author suggests a simple three-part starting point: read to feed yourself differently, write to clarify your thinking, debate to avoid going in circles. It is a rhythm to hold, not a miracle recipe.
Sources & methodology
- World Economic Forum, Global Risks Report 2022 (chap. 3, Digital Dependencies and Cyber Vulnerabilities),
- Anthropic, Detecting and countering misuse of AI (August 2025),
- Anthropic, Disrupting the first reported AI-orchestrated cyber espionage campaign (13 November 2025),
- Verizon, Data Breach Investigations Report,
- ANSSI, Panorama de la cybermenace 2024 (1 March 2025),
- ENISA, Threat Landscape 2024 (19 September 2024),

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
