Key Takeaways

  • Enterprise token shock is real: half of companies discover unexpected monthly bills of roughly $20,000 more per employee than budgeted.
  • AI-generated phishing emails pushed employee click-through rates from historical baselines of 11% to 12% up to over 60%.
  • Open-source models from global repositories give attackers access to cheap, zero-restriction social engineering tools.
  • Security asymmetry favors attackers: defenders operate under strict change control and compliance rules, while adversaries face zero guardrails.
  • Automated defense systems are mandatory because human vetting can no longer distinguish tailored phishing from legitimate messages.

The Defender Asymmetry Problem

Security teams operate with their hands tied behind their backs. Every defensive rollout requires change control, legal review, vendor audits, and board-level budget approval. Attackers face none of these obstacles.

At CrowdStrike's Fal.Con conference, CrowdStrike President Michael Sentonas explained the structural imbalance facing modern companies. “The defender has things like change control. The defender has things like regulatory guidelines and process that they need to follow,” Sentonas said. “Attacker doesn't care about any of that.”

Adversaries download open weights from anywhere in the world and run them privately without safety filters. “The adversaries get access to everything,” Sentonas noted. “And the best thing that's happened to them is the advancement in the open models. They can go and get a Chinese model. They can go and get a model effectively from anywhere that they run inside their framework.”

This gap means attackers iterate in seconds while corporate security teams take quarters to push policy updates.

When Phishing Click Rates Hit 60%

For decades, corporate security training relied on the assumption that phishing emails carried obvious tells: broken phrasing, odd formatting, or generic greetings. That era is over.

“We used to see about a year ago the click-through rate in phishing was about 11 to 12%,” Sentonas explained. “Today with AI that still feels incredibly high. It's over 60 now because written perfect grammatically they probably write better than us now.”

When malicious messages read as well as authentic executive communication, internal training fails. Six out of ten employees click. Relying on user discretion to stop credential harvesting is no longer a viable defensive strategy. Defenses have to catch the threat before it hits an employee inbox, because once it lands, human judgment loses.

The Token Shock Reality

Beyond external attacks, enterprise teams are running into severe budget surprises from internal AI experiments. Sentonas highlighted what he calls token shock across large organizations.

“Every second organization has token shock,” Sentonas said. “At the end of every month, they just realize that they spent 20,000 more than they should have per employee.”

Some technical leaders hope that AI models will eventually map all software vulnerabilities and stabilize the security environment. Sentonas rejects that premise: “Even today, when people say, 'Hey, all the models are going to find all the vulnerabilities and then we're going to get this state of normality.' No, we're not. We're going to get more vulnerabilities. We're going to get more attacks. It's only going to get harder.”

What to Do With This

Audit your internal email security rules this week. Strip reliance on employee vigilance and enforce hard security controls, such as mandatory hardware security keys for single sign-on access, so compromised credentials cannot grant access even when someone clicks a 60% success rate phishing link.