A company that’s bad at cybersecurity isn’t really complying with any of the policies it works so hard to enforce — that’s the case federal investigators made to compliance leaders at this year’s SCCE Compliance & Ethics Institute, CCI’s Jennifer L. Gaskin reports.
Compliance officers are accustomed to being labeled as their organizations’ internal cops (or much worse). Josh Goldfoot, a deputy assistant attorney general in the DOJ’s Criminal Division, sees them differently: as “advisers and architects that are creating systems that help your organizations follow the law, behave ethically and head off problems.” That’s why he recommends they make sure they’re taking up a particular agenda item: cybersecurity.
“If your organization is bad at cybersecurity, then ultimately, is it really complying with any of the policies you sought to enforce?” Goldfoot asked attendees this week at SCCE’s 2026 Compliance & Ethics Institute in Orlando, the organization’s 25th annual event.
The question is becoming more urgent as fraudsters increasingly use AI-enabled tools to scale their reach and improve their tactics. In 2025, the FBI’s Internet Crime Complaint Center logged more than 1 million complaints for the first time, up from about 860,000 the year before, with losses of nearly $21 billion.
Gone are the days when antivirus protection would suffice, even for companies that don’t think of themselves as exposed, Goldfoot said.
“If you have money, and you’re connected to the internet, you are of interest to sophisticated hacking groups,” he told the assembled crowd of compliance leaders.
AI is erasing the warning signs
Much of the acceleration the FBI’s cybercrime data highlights is being driven by AI, said Jason Cromartie, special agent in charge of the FBI’s Cincinnati field office, who opened the general session Monday. Phishing remains a leading way attackers get into networks, and generative AI tools have made messages appear more sophisticated than in years past. Bad grammar and spelling aren’t dead giveaways anymore.
“These tools reduce the traditional warning signs and allow attackers to exploit trust at a whole new level,” Cromartie said.
Deepfakes are becoming more realistic, and voice cloning is on the rise. Cromartie described an FBI investigation involving a Fortune 500 company that lost $1 million after an employee acted on a cloned voicemail from the CFO, who was overseeing a merger at the time.
The next frontier is agentic AI, he said. AI agents can search for information, select targets, create believable personas and attempt exploitation continuously, making attacks harder to detect and disrupt.
“We’re all trying to play catch-up to the rapid advances in the technology,” Cromartie said.
IBM’s 2025 annual report on the cost of a data breach indicated that about one in six data breaches involved attackers using AI, most often via AI-generated phishing and deepfake impersonation attacks.
The role of compliance
AI may be amplifying the problem, but it didn’t create the root cause of the issue, which often comes down to the human element. Organizations have spent years trying to train their way out of this problem. Annual cybersecurity modules and simulated phishing emails are standard fare across companies and organizations of all sizes and industries.
Still, business email compromise is the second-costliest category in the FBI’s 2025 report, accounting for more than $3 billion in losses. And IBM found that phishing was the most common attack vector, accounting for 16% of all data breaches in their report.
“Humans do not always make the best decisions,” Cromartie said. “Threat actors are often using that as a vector.” And it doesn’t take much: “One person, one click can cause a lot of damage.”
For Goldfoot, that makes cybercrime an ethics and compliance issue: “How are the interests that you work for, the values and ethics that you want your organizations to uphold, how is that affected by the new cybercrime threat?” he asked.
Consider the checks and balances an organization builds around protecting patient information, he said. How much is that work worth if an attacker simply walks off with the data? That leads to a harder question about compliance’s place in the organization. How much influence, and how much oversight, should compliance have over cybersecurity practices? And if the organization isn’t assessing the threat correctly, is that something compliance can help fix?
Cromartie suggested compliance leaders are well positioned to try. “You have the responsibility to understand almost every aspect of the business operations that you’re with,” he said. “You have to see the big picture, you have to see what’s around the corner as well as over the horizon.”
That includes AI. Cromartie urged organizations adopting AI tools to establish governance with cross-functional ownership, map who uses the technology and what data it touches, measure for security flaws and bias and deploy firm guardrails, including routine human audits. He also recommended bringing in as many stakeholders as possible, including the CIO, the chief security officer, legal counsel and subject-matter experts.
Why CISOs and Boards Must Speak the Same Language on Cybersecurity
Translating cyber risks into boardroom terms is essential for resilience
Read moreDetailsWhy call the feds
Despite the growing threat, many victims still don’t pick up the phone. When the FBI infiltrated the Hive ransomware group a few years ago, investigators could see which companies the group was attacking, Goldfoot said. They warned targets and, in some cases, handed over decryption keys. They could also see how many victims had already contacted law enforcement on their own: only about 20%.
That is mirrored in IBM’s report, which found that among organizations that had a ransomware attack, the share of those contacting relevant authorities actually fell from 2024 (52%) to 2025 (40%).
Companies have reasons for hesitation, to be sure: embarrassment and reputational damage, namely, and many pay the ransom demand and hope the crisis ends there. But it often doesn’t end there. A 2025 CrowdStrike survey found that 83% of organizations that paid a ransom demand were attacked again anyway, and 93% had data stolen.
The message from both Cromartie and Goldfoot is clear: Don’t pay.
“Blackmail does not end until the victim of the blackmail decides that it ends,” Goldfoot said. Cromartie agreed: Even after a second payment, “there is nothing that prevents them from having that data they’ve taken, selling it.” Goldfoot added that some ransomware groups are under US sanctions, which makes a payment a legal risk of its own.
Coming forward, by contrast, doesn’t put a company in the crosshairs, Goldfoot said. Law enforcement treats those who report as crime victims, not suspects: “You don’t go to a crime victim and start lecturing the crime victim about all the things they could have done to prevent being a crime victim.”
Investigators work through a company’s own forensics firm and receive only what the company agrees to share, he said. Court filings identify victims anonymously, and information stays in the criminal investigative file. “We’re not regulators,” Goldfoot said. He urged companies to build those relationships before an attack, including through the FBI’s InfraGard program.
Goldfoot closed with a reminder that law enforcement can’t solve the problem alone. Every type of policing, he said, “only works when we have the support of the community that we’re trying to protect. And in our case, that means protecting everyone with a computer.”
“We’ve struck fear in the hearts of some ransomware actors,” he said. “But I want to do more of that.”


Jennifer L. Gaskin is editorial director of Corporate Compliance Insights. A newsroom-forged journalist, she began her career in community newspapers. Her first assignment was covering a county council meeting where the main agenda item was whether the clerk's office needed a new printer (it did). Starting with her early days at small local papers, Jennifer has worked as a reporter, photographer, copy editor, page designer, manager and more. She joined the staff of Corporate Compliance Insights in 2021 and also hosts the CCI-produced podcast "Queering Compliance." 









