Site navigation

Scot-Secure 2026 | Can We Survive a Machine Speed War?

Tom Quinn

,

Ai war
Opening DIGIT’s Scot-Secure Summit, McDonald’s senior threat analyst Ellie Hallam argued businesses must adapt to survive the flood of AI-driven malware, deepfake propaganda, and state-sponsored threats blurring the lines between military and civilian infrastructure.

It’s the dawn of a terrifying new era, one in which war, both online and off, belongs as much to machines as it does to humanity.

Drones powered by AI and cyber-attacks targeting critical services have transformed the war in Ukraine into a battle of the algorithms, and we’re living in a moment when conflict in the Middle East reverberates across Western societies, as Iran unleashes state-backed hackers against US giants like Stryker

The use of AI by these various, dangerous threat actors is, of course, being closely tracked by governments, intelligence agencies, journalists, NGOs, and activists. Also McDonald’s. 

You might think that the Golden Arches is just the best place for a drive-thru burger on a wet Friday night, but that McFlurry and fries are the product of a multi-billion-dollar enterprise, one with a huge attack surface, both physical and digital, making McDonald’s a tasty target for hackers the world over.

“We’ve got 40,000 plus restaurants across the world. We have a complex and highly digitised supply chain and digital infrastructure. We’re talking our point of sales, we’re talking delivery apps, and loyalty programs,” said Ellie Hallam, senior threat intelligence analyst at McDonald’s, taking to the stage for this year’s opening keynote at DIGIT’s Scot-Secure Summit.

“We have multiple attack vectors, from franchises, supply chains, customer data, and different markets, to name a few. We are one of the largest, most complex global enterprises operating across geopolitical, legal, and threat environments.”

That exposure has given Hallam a trenchside view of modern cyberwarfare, with the industrial‑scale adoption and militarisation of AI the defining feature she has observed in today’s threat landscape. 

“For McDonald’s, we’re talking about state-sponsored AI threats, AI-driven espionage and sabotage. We’re looking at deepfake propaganda for political destabilisation and global fragmentation.

“We’re seeing AI-powered phishing impacting our franchisees across the world, and automated vulnerability scanning of our global systems, and disinformation campaigns as well, which is something that we’re only just starting to touch on.”

When AI Went to War

AI first entered live conflict around four years ago, at the beginning of the Ukraine war, when a wave of deepfake content impersonating national leaders began circulating on what was then Twitter, but would soon be X. 

Since then, AI deepfakes have left their niche to become what Hallam calls “conflict escalators”, with the industrialisation of weaponsised genAI kicking up a gear in 2024, when state-linked actors began using it at scale to produce multilingual content, build personas, and amplify narratives across platforms.  

Last year, these operations matured, with hybrid human‑AI campaigns outperforming fully synthetic efforts and muddying attribution as their influence slipped into normal online conversation.

“In 2026, we’re now in a phase of continuous pressure. AI is integrated across the entire life cycle,” said Hallam. “It’s no longer episodic. It’s always operating below the threshold of conflict.”

What began as AI deepfakes designed to erode trust in governments has metastasised into voice cloning, personalised phishing campaigns, and AI malware targeting big organisations and small across the public and private spheres.

“Commercial enterprises are no longer collateral damage, they’re terrain,” said Hallam, “it’s no longer straight lines where one side is military, and the other side is the civilian infrastructure. The two merge very, very closely together, and one is impacting the other.”

But the question is, how exposed are Western firms to AI hostility, and what can we do about it?

AI in the Kill Chain

AI now touches every part of the cyber kill chain, said Hallam, beginning with targeting and reconnaissance, where it allows attackers to exploit security research in their hunt for vulnerabilities and easily set up their own infrastructure, like VPNs or proxies. 

It also makes it much easier to scour sites like LinkedIn to map out networks within organisations, build and maintain multiple personas with stacks of fake CVs, find leaked credentials for specific individuals, and identify assets for targeting. 

Adversaries, even unskilled ones, can use automated OSINT to profile executives, suppliers, infrastructure, and regions at scale, warned Hallam, then tailor their activity based on language, culture or even time zone, leaving defenders too many gaps to plug.

“Traditionally, targeting has been broad or campaign-based,” said Hallam, “with AI, that changes. Targeting becomes highly selective. It’s based on the environment, the role someone holds, or the specific data they can access.”

It has also changed how hackers gain initial access, which these days isn’t about breaking in but logging in, with AI abusing trust at scale. But Hallam notes that while tactics like AI-phishing and voice cloning are cracking open the door, these are supercharged takes on familiar techniques – what’s changed is the feedback loop.

“Telemetry and outcomes are fed straight back into the attack, allowing rapid replanning and retooling. Instead of a single attempt, defenders are now dealing with a system that learns what approaches work and then immediately tries again.”

That’s where things get even harder, as the attacker keeps learning while defenders are still triaging. Payloads adapt to the environment and learn which controls are present, tradecraft shifts based on what gets detected, and iteration happens faster than any human-led tuning cycle.  

“We’re now seeing early examples of what’s effectively just-in-time AI malware, like prompt floods and prompt steals,” said Hallam. “We’re dealing with malware that can evolve autonomously using polymorphic code, or even optimise ransomware behaviour in real time.”

This means indicators of compromise change during the compromise itself, so the malware signature you’re trying to attribute suddenly no longer exists. And if adaptive malware can run faster than human response cycles, defence is at risk of collapse.

But the goal isn’t destruction, stresses Hallam, it’s leverage. Operational disruption, reputational pressure, supply chain uncertainty, and even data exfiltration are all devastating for businesses, but in Hallam’s experience, attackers aren’t looking to trigger a response crisis.    

“No escalation threshold is crossed, and yet pressure is applied. The impact is in affecting individuals’ decisions, but also brand trust, market confidence, and ultimately stock prices, both locally and globally.” 

Where Does Defence Go From Here?

Whether it’s teenage hacking collectives looking for a payday or state-backed threat groups trying to coerce their enemies, Hallam is clear that defensive AI is not keeping up with how adversaries are using the tech.

“The AI integration, where threat actors may be able to get into our own large language model apps on our systems, is a huge problem and a threat that we’re not doing enough to defend against.

“Threat actors could use our own prompts against us, and businesses are not prepared for that. But this isn’t just an enterprise problem. It’s for government and critical national infrastructure as well, because it’s the same model, and we’re all facing the same problem.”


Recommended reading


While the light at the end of the tunnel is dim, Hallam argues that if we change our security tactics and behaviours, we stand a better chance against the AI onslaught.

First, identity must be treated as the primary attack surface, with identity telemetry acting as an early warning radar. Credential abuse, access anomalies, and third-party identity risk will surface long before malware detonates.

Defenders should also focus on matching detection, triage and response to machine speed, rather than grinding on with prevention, under the assumption that AI-driven attacks and malware are now the baseline threat model, not an emerging one.

Even more important, security must enforce discipline across third-party and franchise access, based on time-bound access, continuous monitoring, and minimum privilege enforcement, “absolute necessities”, according to Hallam.

But the last step in building resilience and countering global AI threats is perhaps the trickiest one in this turbulent moment – we must collaborate beyond our boundaries.   

“These threat models affect enterprises, governments, and critical infrastructure equally. Intelligence-led defence and shared visibility are essential to staying ahead of sustained low-pressure noise.

“The question is no longer if adversaries are using AI. It’s whether our assumptions, controls, and responses are still fit for the purpose, because in this environment, resilience is not about stopping every attack, it’s about absorbing pressure without losing trust.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data