La menace n'a jamais été aussi élevée

La menace n'a jamais été aussi élevée

🎙 RISKINTEL MEDIA 👥 204K 📅 February 8, 2026 ⏱ 36 min 👁 30K 📄 interview 🧭 2026-08-16
Available in: English (current) Français

Keywords

cyber riskransomwareagentic AIvulnerability managementboard communication

Summary

In this interview, Ivan Milenkovic, VP Cyber Risk Technology at Qualys, discusses the escalating cyber threat landscape, particularly in the UK, which he describes as the worst year on record. He emphasizes that cyber incidents are not just technical failures but business impact planning failures, using the analogy of crumple zones in cars to illustrate the need for resilience. He notes a shift in attacker behavior from pure ransomware extortion to disruption and data theft, driven by return on investment and geopolitical factors. Milenkovic argues that organizations must prioritize risks based on business impact, not just technical vulnerabilities, and communicate in financial terms to boards. He highlights the emergence of agentic AI in both attacks and defense, citing an Anthropic report on an autonomous attack as a ‘Sputnik moment’. He advocates for using AI to fight AI, focusing on the 1% of vulnerabilities that are actively exploited. He criticizes the proliferation of security tools (averaging 76 in large enterprises) and proposes a ‘Risk Operations Center’ to translate technical signals into business risk. The interview underscores the need for cybersecurity to align with business objectives and for security professionals to move from a ‘Department of No’ to a strategic partner.

199 words

Critical Evaluation

Value of the Information & Strength of the Argument

The interview provides valuable insights into current cyber risk management challenges and the strategic shift needed. Milenkovic’s arguments are well-structured, using analogies (crumple zones, locks, Sun Tzu) to make complex concepts accessible. He effectively argues that cybersecurity must be business-driven, not purely technical, and that risk prioritization should be based on potential business impact. The discussion on agentic AI is timely, referencing a real report (Anthropic) and advocating for AI-driven defense. The argumentation is coherent and persuasive, though it occasionally veers into promotional territory for Qualys’ solutions. The value lies in the practical advice for CISOs and the emphasis on translating cyber risk into financial language for boards.

Scientific Rigor, Source Quality, Title Accuracy

The interview demonstrates reasonable scientific rigor, referencing the UK NCSC annual report and specific incidents (Toyota, UK logistics) to support claims. However, specific sources are not cited in detail, and some statements (e.g., the 1% exploitation rate) lack direct references. The title is somewhat sensationalist but aligns with the content’s urgency. The discussion is expert opinion rather than peer-reviewed research, but it is grounded in industry experience. The adequacy between title and content is acceptable, though the title could be more precise. No public comments were provided for analysis.

212 words

Title / Content Match

The title 'La menace n'a jamais été aussi élevée' (The threat has never been so high) is somewhat sensationalist but broadly matches the content's emphasis on rising cyber threats and the need for urgent action.

Quality & Reliability

7/10

Interview with a cybersecurity expert (Ivan Milenkovic, VP Cyber Risk Technology at Qualys) providing informed opinions and references to industry reports (NCSC) and incidents (Toyota, UK logistics). The discussion is expert-based but lacks detailed citations or verifiable data. The content is coherent and aligns with known cybersecurity trends.

Key Moments

Cited Sources

Concurring Sources

  • NCSC Annual Review 2024 — Referenced in the interview as the source of the 'It's time to act' headline.

Contribution & Novelties

The interview provides a clear, expert perspective on the need to align cybersecurity with business objectives, emphasizing risk-based prioritization and communication with boards. It introduces the concept of a ‘Risk Operations Center’ as a translation layer between technical signals and business risk. The discussion on agentic AI in both attack and defense is timely, highlighting the urgency of adopting AI-driven security measures.

Pour aller plus loin :

  • Agentic AI in cybersecurity — Overview of AI applications in cybersecurity, including agentic approaches.
  • NCSC Annual Review — The UK’s National Cyber Security Centre annual report, referenced in the interview.
  • Ransomware trends — CISA’s guidance on ransomware, relevant to the shift in attacker behavior.

111 words

Radar Profile

The radar profile shows high scores in information quantity and quality, reflecting the expert's depth of knowledge. The technical level is moderate, suitable for a general audience. The reliability is good but not perfect, as the interview relies on expert opinion rather than peer-reviewed data. The overall profile suggests a valuable, informative discussion with minor limitations in source citation.

Reliability 7/10