The stark reality of modern compliance was laid bare at the SCCE Compliance & Ethics Institute, where federal investigators issued a critical ultimatum to leaders responsible for upholding organizational integrity: a company faltering in its cybersecurity defenses is fundamentally failing to comply with the very policies it endeavors to enforce. Jennifer L. Gaskin of CCI reported on the pivotal discussions that underscored a growing consensus: cybersecurity is no longer a peripheral IT concern but a core ethical and compliance imperative.

Josh Goldfoot, a Deputy Assistant Attorney General within the Department of Justice’s Criminal Division, challenged the traditional perception of compliance officers as mere internal enforcers. Instead, he posited them as "advisers and architects that are creating systems that help your organizations follow the law, behave ethically and head off problems." This redefinition places a significant onus on these professionals to actively champion cybersecurity as a central component of their strategic oversight. Goldfoot’s pointed question to attendees at the 25th annual SCCE Compliance & Ethics Institute in Orlando resonated deeply: "If your organization is bad at cybersecurity, then ultimately, is it really complying with any of the policies you sought to enforce?"

This urgent call to action is amplified by the escalating sophistication and prevalence of cyber threats, particularly those augmented by Artificial Intelligence. The FBI’s Internet Crime Complaint Center (IC3) reported a watershed moment in 2025, logging over one million complaints for the first time, a substantial increase from approximately 860,000 in the preceding year. The financial toll was equally staggering, with reported losses nearing $21 billion. This surge signifies a dramatic shift in the threat landscape, rendering traditional cybersecurity measures, such as basic antivirus protection, insufficient even for organizations that may not perceive themselves as prime targets. Goldfoot emphasized this point, stating, "If you have money, and you’re connected to the internet, you are of interest to sophisticated hacking groups."

The AI Accelerant: Eroding Traditional Defenses

The exponential growth in cybercrime statistics highlighted by the FBI is, in large part, attributable to the disruptive capabilities of AI, according to Jason Cromartie, Special Agent in Charge of the FBI’s Cincinnati field office. Cromartie, who opened the general session, identified phishing as a persistent gateway for attackers, but noted that generative AI has elevated the deceptive power of these communications. The tell-tale signs of poorly crafted emails, such as grammatical errors and spelling mistakes, are rapidly diminishing, making malicious messages far more convincing. "These tools reduce the traditional warning signs and allow attackers to exploit trust at a whole new level," Cromartie explained.

The menace extends beyond text-based deception. Deepfake technology is achieving unprecedented levels of realism, and voice-cloning capabilities are becoming increasingly accessible. Cromartie recounted a concerning FBI investigation involving a Fortune 500 company that suffered a $1 million loss when an employee, acting on what they believed was a legitimate voicemail from their CFO, authorized a fraudulent transaction. The CFO in question was reportedly overseeing a critical merger at the time, a detail that likely added a layer of urgency and plausibility to the impersonation.

Looking ahead, Cromartie identified "agentic AI" as the next significant frontier in cyber threats. These AI agents possess the capacity to autonomously search for information, identify targets, construct believable personas, and continuously attempt exploitation. This automated and sophisticated approach makes attacks significantly more challenging to detect and disrupt, placing organizations in a perpetual game of catch-up. "We’re all trying to play catch-up to the rapid advances in the technology," Cromartie admitted.

IBM’s comprehensive 2025 annual report on the cost of data breaches further underscores the pervasive influence of AI in cyberattacks. The report revealed that approximately one in six data breaches involved attackers leveraging AI, with AI-generated phishing and deepfake impersonation attacks being the most prevalent methods. This data paints a clear picture of a rapidly evolving threat landscape where human vulnerability is being systematically exploited through increasingly sophisticated technological means.

The Evolving Role of Compliance in Cybersecurity

While AI is undeniably amplifying the problem, it is not the sole originator of cyber vulnerabilities. The fundamental weakness often lies in the human element, a factor organizations have long attempted to address through extensive training programs. Annual cybersecurity modules and simulated phishing exercises have become standard practice across businesses of all sizes and sectors. However, the persistent financial impact of Business Email Compromise (BEC) schemes, which accounted for over $3 billion in losses in the FBI’s 2025 report, and the fact that phishing remains the most common attack vector for data breaches, as identified by IBM, indicate that these efforts, while necessary, are not entirely sufficient.

"Humans do not always make the best decisions," Cromartie stated, highlighting how threat actors strategically exploit this inherent fallibility. The devastating potential of a single lapse in judgment was emphasized: "One person, one click can cause a lot of damage."

For Goldfoot, this human vulnerability, coupled with the technological sophistication of attackers, firmly places cybercrime within the purview of ethics and compliance. He posed a critical question to compliance leaders: "How are the interests that you work for, the values and ethics that you want your organizations to uphold, how is that affected by the new cybercrime threat?" He urged them to consider the tangible impact on their organization’s core mission. For instance, he questioned the efficacy of robust internal controls designed to protect patient information if an attacker can simply exfiltrate that data.

This line of reasoning leads to a more profound examination of compliance’s strategic positioning within an organization. What level of influence and oversight should compliance departments wield over cybersecurity practices? Furthermore, if an organization fails to accurately assess its cyber threats, is that a deficiency that compliance can and should address?

Cromartie suggested that compliance leaders are uniquely positioned to tackle these challenges. "You have the responsibility to understand almost every aspect of the business operations that you’re with," he noted. This broad understanding allows them to "see the big picture, you have to see what’s around the corner as well as over the horizon."

This forward-thinking approach must extend to the adoption of AI technologies. Cromartie strongly advised organizations to establish robust governance frameworks for AI, ensuring cross-functional ownership, clear mapping of technology usage and data flow, rigorous security flaw and bias assessments, and the implementation of stringent guardrails, including regular human audits. He also stressed the importance of involving a diverse range of stakeholders in this process, including Chief Information Officers (CIOs), Chief Security Officers (CSOs), legal counsel, and relevant subject-matter experts.

The Strategic Decision to Engage Law Enforcement

Despite the escalating threat landscape, a significant number of victims remain hesitant to report cyber incidents to law enforcement. Goldfoot recalled the FBI’s successful infiltration of the Hive ransomware group several years prior. During this operation, investigators were able to identify targeted companies and, in some instances, provide decryption keys. However, they also observed that only about 20% of victims had proactively contacted law enforcement.

This reluctance is mirrored in IBM’s report, which indicated a decline in the percentage of ransomware attack victims reporting to relevant authorities, falling from 52% in 2024 to 40% in 2025. The primary drivers for this hesitation are often embarrassment and the fear of reputational damage. Many organizations opt to pay ransom demands in the hope of swiftly resolving the crisis. However, this approach frequently proves to be a false economy. A 2025 CrowdStrike survey revealed that a staggering 83% of organizations that paid a ransom demand were subsequently attacked again, and 93% experienced data theft even after payment.

Both Cromartie and Goldfoot delivered a clear, unambiguous message: do not pay the ransom. "Blackmail does not end until the victim of the blackmail decides that it ends," Goldfoot asserted. Cromartie concurred, emphasizing that even after a second payment, "there is nothing that prevents them from having that data they’ve taken, selling it." Goldfoot further highlighted a critical legal consideration: some ransomware groups operate under U.S. sanctions, making payment a potential legal risk in itself.

In contrast, coming forward to law enforcement is presented not as an admission of guilt, but as a step towards recovery. Goldfoot reassured attendees that investigators treat those who report as victims, not suspects. "You don’t go to a crime victim and start lecturing the crime victim about all the things they could have done to prevent being a crime victim," he stated. Law enforcement collaboration is designed to be protective and supportive. Investigations are conducted in partnership with the victim’s own forensics firm, with investigators receiving only the information the company agrees to share. Court filings identifying victims are anonymized, and all information remains within the criminal investigative file. "We’re not regulators," Goldfoot clarified, underscoring the distinct role of law enforcement in these scenarios. He strongly recommended that companies proactively build relationships with law enforcement agencies, perhaps through programs like the FBI’s InfraGard, before an incident occurs.

Goldfoot concluded his remarks with a powerful reminder that law enforcement cannot single-handedly combat the escalating cyber threats. He drew an analogy to community policing, stating that all forms of law enforcement "only works when we have the support of the community that we’re trying to protect. And in our case, that means protecting everyone with a computer." He expressed a desire to amplify the impact of law enforcement efforts, noting, "We’ve struck fear in the hearts of some ransomware actors. But I want to do more of that." The message is clear: a collaborative, proactive, and ethically grounded approach to cybersecurity is not just a best practice, but an essential requirement for modern compliance.

By