Summary
- Nation-state threats often unfold as long-running campaigns, making it critical to connect isolated signals and identify patterns sooner.
- Legacy infrastructure, internet-facing systems, and weak segmentation give advanced attackers more opportunities to gain access and move laterally.
- Security programs must operate at the speed of changing risk, rather than relying solely on fixed assessment and remediation cycles.
- Visibility, secure network architecture, and connected security platforms can improve detection confidence while limiting attacker freedom.
- Resilience requires preparing for controls to fail, empowering teams to contain threats quickly, and restoring critical operations while investigations continue.
These days, advanced attackers don’t need to invent a sophisticated new technique every time they target an organization. They simply need to find something that works.
This could take the form of an unpatched router, an internet-facing legacy system, or a poorly segmented network. AI frontier models further accelerate this process by absorbing large amounts of information, identifying weaknesses, and finding the most effective avenue into an environment. The vulnerability may be complex, but the path used to exploit it is often surprisingly simple.
That is what connects AI-driven threats with nation-state threats such as Salt Typhoon: Both can move quickly, operate persistently, and take advantage of weaknesses that have been left unresolved.
The issue for security leaders is not simply that there are more threats. It’s that there is less time to recognize and respond to them. Organizations need a security program that can see risk sooner, reduce an attacker’s freedom to operate, and take action with less friction.
What Salt Typhoon teaches enterprise security leaders
Salt Typhoon demonstrates how nation-state threat actors operate with a clear objective, combining different attack behaviors over an extended period while remaining difficult to detect. Each stage may produce signs of activity, but those signals can appear minor or unrelated when viewed in isolation.
That is where organizations can miss the larger campaign. By connecting unusual activity and even unsuccessful probing over time, security teams have a better chance of recognizing an attack in progress and intervening before the adversary reaches its most damaging stage.

Nation-state threats are infrastructure threats
Infrastructure is particularly attractive to patient, well-resourced attackers because it connects the entire organization.
Routers, internet-facing systems, and other network components often sit at the boundary between internal and external environments. If those systems are compromised, they can give an attacker a foothold from which to observe traffic, maintain access, or move deeper into the organization.
Legacy infrastructure compounds this problem. Older equipment can contain vulnerabilities that are no longer being fixed. It may not support current security capabilities or interoperate cleanly with newer technologies. This creates complexity, and complexity creates more opportunities for exposure.
Weak segmentation then gives an attacker room to move. Even when some separation exists, it may not be sufficiently controlled or observable to prevent lateral movement. An attacker can establish a presence and patiently look for the next opening.
This lesson extends beyond telecom
Salt Typhoon has been closely associated with telecommunications providers, but the architectural lesson applies to any enterprise. If an environment is complex, under-instrumented, and slow to modernize, an attacker has more room to operate. And limited visibility makes business impact even worse.
The longer an attacker remains in an environment, the more questions the organization must answer, including:
- What data was exposed?
- What additional access was gained?
- Where did the attacker move, and can the environment be trusted again?
Without the visibility to answer these questions confidently, organizations may have to assume broader compromise. In complex environments, that uncertainty drives up both recovery cost and downtime. That can mean taking more systems offline, rebuilding more of the environment, and accepting greater business disruption.
Security must function as an operating model
One of the most important shifts an organization can make is how it operates around risk. Traditionally, security teams have worked through scheduled cycles. Vulnerabilities are assessed, prioritized, and addressed according to established patching and governance processes.
Attackers do not operate on that schedule.
They move faster than most enterprise governance models. A vulnerability that looked manageable in one patch cycle can become urgent within hours if it becomes part of active exploitation. In many environments, the structure for decision-making and remediation still assumes there is time to wait. That assumption breaks down quickly when risk conditions are changing in near real time.
Moving at the speed of risk requires a different operating mindset. When a serious flaw is identified, the default should be to fix it. Deferral should be the exception, supported by a clear business and risk rationale — not the routine outcome of a slow process.
This is bigger than vulnerability management. It requires visibility, architecture, governance, and response capabilities that work together.
Start with a trustworthy view of your environment
Keeping pace with nation-state threats requires more than reacting faster when an attack occurs, though. Organizations also need to rethink how they view, structure, and protect their environments and how they prepare to respond when preventive controls fail. This starts with visibility.
The first step is to map the landscape: what you have, where it is exposed, which protections are in place, and whether those protections are effective. This internal analysis should then be compared with what the environment looks like to a threat actor.
Only after this process is complete can teams establish a baseline for normal activity and begin distinguishing routine traffic from malicious or anomalous behavior.
Reduce attacker freedom through secure architecture
Every architectural security measure has its place, but for most organizations, the most defensible end state will look a lot like Zero Trust. Instead of extending trust after an initial connection, Zero Trust continually evaluates the user, device, network, application, and transaction to determine what access should be allowed.
Most organizations must move toward that end state incrementally, starting with genuine segmentation. Simply placing telephony, user devices, and servers on separate virtual networks is not enough if nothing controls or inspects the traffic between them. Effective segmentation creates enforceable boundaries, while microsegmentation applies controls at the individual system or workload level to further restrict lateral movement.
Network modernization makes more advanced controls possible. Modern infrastructure can evaluate context such as a user’s identity, device location, patch status, and security posture — not just the port and protocol carrying traffic. A device that falls short of requirements might be permitted to download updates, for example, but blocked from accessing business applications until it is secure.
There are many steps on the journey to Zero Trust, and few organizations can implement them all at once. The priority is to keep progressing toward more continuous, contextual decisions that steadily reduce the trust extended — and the freedom available to an attacker.
Bring AI into the security operating model
AI introduces new technology, but many of the underlying security responsibilities are familiar. The same questions need to be answered:
- What data can an AI application access?
- Who is allowed to use it?
- What can that person do with the information?
- How will the organization evaluate the trustworthiness of AI-generated output?
To answer these questions, organizations must begin with governance. They need to define the intended use of AI, establish the rules governing that use, and decide how those rules will be enforced.
An administrative policy may tell employees what they are allowed to do. Technical controls help ensure the intended outcome occurs — and help detect when it does not. Both are necessary.
AI security, therefore, cannot be separated from identity, access, and data security. These capabilities need to operate together, with clear ownership of what happens when AI is misused or produces an untrustworthy result.
Connected platforms improve confidence and speed
One of the most practical uses of AI in enterprise security is inside the tools teams already rely on, especially security information and event management (SIEM) and security operations platforms. AI can lower the expertise barrier by letting analysts interact with data in more natural language, iterate on questions more quickly, and move faster from investigation to action.
That matters because most environments pull security data from dozens of different tools. Security leaders need platforms that can connect those tools, bring the data together, and make it easier to understand what is happening, what should be prioritized, and what actions can be automated over time.
The best path is to identify a platform that already has these AI capabilities, whether that is a next-generation SIEM or another security enablement platform, and then connect the existing environment into it. Some of those capabilities may be native to the platform. Others may come from tools feeding into it. The objective is to improve visibility, increase confidence, and create a safer path from human-in-the-loop decisions to faster, more effective response.
Resilience is what happens when protections fail
A mature security program assumes controls can fail. Resilience begins with that assumption and then defines what happens next: detection, incident response, containment, and recovery.
One sign of maturity is the ability to take specific containment actions when defined, severe conditions are detected, without waiting for a large governance process to assemble. Another sign is being able to contain only what needs to be contained instead of resorting to a broad shutdown that creates unnecessary business disruption.
Maturity also shows up in how organizations test themselves. Tabletop exercises still matter, but higher-performing programs go further. They validate detection and response actions more actively and use lessons from both real incidents and structured exercises to improve how they operate.
Finally, resilience requires recovery to move on a parallel path. Businesses cannot always wait for every forensic and remediation step to finish before operations are restored. A more resilient environment is compartmentalized enough to support business recovery while other response work continues.
Move at the speed of risk
Nation-state threats expose weaknesses many organizations already know they have: limited visibility, aging architecture, inconsistent segmentation, fragmented tools, and governance that moves too slowly when risk changes. Salt Typhoon is one reminder of that. AI-enabled acceleration is another.
The challenge is knowing which weaknesses create the greatest risk and where improvement should begin. To understand this requires an accurate view of your current environment, a clear definition of what your security program needs to accomplish, and an understanding of the gap between the two. A security assessment can provide that clarity while helping prioritize improvements that can realistically be executed and sustained.
Security leaders do not need to solve everything at once. They do need to know where exposure exists, how an attacker could move through the environment, and whether the organization can make and execute the right decisions fast enough.
The best place to start is with a clear view of the current environment, the gaps that matter most, and a prioritized plan for addressing them in a way the organization can actually sustain.
If you’re looking for support in this area, we can help. GDT meets you wherever you are in this process, beginning with a complimentary workshop—which you can learn more about here. It’s a great starting point for identifying what you want to achieve and the best next steps to take.
