Organizations Are Struggling To Stop AI Cyber Attacks. Here’s Why
The age of automated cyber attacks is fast approaching, and many organizations are ill-prepared to keep up. Today, AI data security company Cohesity released its Global Cyber Resilience report , commissioning research firm Vanson Bourne, which surveyed 3,200 IT and security decision-makers at organizations with 1,000 or more employees across 11 countries.
Cohesity’s report found that three in four organizations (76%) reported that recovery from a material cyberattack exceeded their recovery time objective (RTO), taking nearly twice as long as the planned recovery time on average. At the same time, the study found a lack of preparedness to address frontier AI threats, with only 3% of survey participants believing their current recovery plans are equipped to withstand them.
According to the report, there are five assumptions organizations are making that are sabotaging their cyber recovery procedures: that once core systems are restored operations can safely resume, that decision makers will have access to adequate information when recovery actions are required, that there will be sufficient visibility into system and data dependencies, that incidents can be fully contained before recovery begins and that recovery can proceed step-by-step without significant backtracking.
The announcement comes less than a week after Anthropic CEO Dario Amodei released an essay calling for a slowdown in AI model development. In the post, Amodei referenced the Hugging Face incident, where a group of OpenAI’s agents collaborated to hack third party systems, and warned that a more powerful swarm of agents “could have caused catastrophic damage.”
Resilience And Agent Swarms
The offensive capabilities of AI have become increasingly advanced as frontier models have improved. Back in April, Anthropic announced Mythos, a model capable of discovering and chaining together vulnerabilities, including exploits in every major operating system and web browser. Since then, there was the Hugging Face Incident involving GPT-5.6 Sol, and Anthropic has disclosed four instances where models like Claude broke into external systems.
For Sanjay Poonen, CEO and president of Cohesity, the answer to this increasingly complex threat landscape is resilience. “I’ve obviously watched a lot of things in security, at least over the last 10, 15 years. I haven’t seen as intense a focus in this sort of post-Mythos world on resilience, and what do we do in case we get hit.” In the face of incidents like the Hugging Face breach, “the most important metric becomes how fast you can recover.”
He adds that there is a focus among enterprises of moving toward resilience and building a minimum viable entity or company, which is the smallest version of the company that can continue serving customers and maintain critical operations. That being said, Cohesity’s study finds only 22% of respondents have formally documented and stress-tested a minimum viable company. In addition, 78% of respondents agreed their cyber response and recovery plan is more focused on restoring systems than on maintaining critical operations and serving customers during recovery.
Poonen says that stress testing is like going through earthquake or fire hazard preparedness. “Here in San Francisco and Bay Area, we have to deal with the risk of earthquakes all the time. So every building, especially if you’re in a high-rise building, 20, 30 floors, you want to practice an evacuation procedure in case there’s an earthquake or a fire,” Poonen said. “That’s called stress testing in cyber.”
Lack of stress testing raises concerns over how prepared organizations are to restore critical operations in the face of more advanced AI-assisted threats, where vulnerabilities can be chained to gain access to a wide array of systems, infrastructure, applications and business functions.
Offensive vs. Defensive AI
As AI tools become increasingly advanced, attackers and defenders alike are using these tools as part of their operations. McKinsey’s Technology Trends Outlook 2026 , released today, found that AI is arming both sides of the cybersecurity fight, noting the same tools that help companies defend their networks are helping attackers break in faster.
For instance, IBM’s X-Force Threat Intelligence Index recorded a 44% jump in exploitation of public facing applications in a single year, which helped fuel a 49% increase in active ransomware and extortion groups.
“Being ready for the shifting, and more agentic, threat landscape requires more than technology. Leading organizations look at the modern landscape as an opportunity to rethink their operating model and ways of working to allow for faster and more efficient processes, whether agentic, automated, or still manual,” Charlie Lewis, partner at McKinsey & Company told me via email.
“Security organizations are making these shifts while also having to keep pace with improved models, closing vulnerabilities on their backlog, and governing their business’ implementation of agentic AI," Lewis said. He added that McKinsey is also seeing improved network resiliency and uptime with AI-based network capacity management, providing an example of how AI can be used defensively.
Lewis argued that rethinking operating models allows for faster detection, triage and response. Similarly, Cohesity’s study found organizations that experienced a material cyberattack in the past 12 months also reporting using AI-enabled tools across a wide range of response and recovery processes, with four in five (80%) saying those tools made a moderate to significant contribution in areas including threat detection, root cause analysis, recovery orchestration and identifying clean restore points.
Speed is also becoming a more significant factor in security operations. Most notably, the window between vulnerability discovery and exploitation is closing, with Google’s M-Trends report finding that the mean time to exploit vulnerabilities dropped to an estimated -7 days in 2025, meaning vulnerabilities are exploited before patches are even released.
As Mythos and other powerful closed and open source models come to market, attackers will have access to more tools they can use to discover and exploit vulnerabilities. When asked why so many organizations were struggling to identify and contain security incidents, Joni Klippert, CEO and cofounder of StackHawk, an application security startup which today announced the release of a Wingman, a tool that can autonomously fix security vulnerabilities, said “the answer is math.”
“Security teams have never had visibility into what engineering is actually shipping. Not fully. The industry has long cited a ratio of roughly 100 engineers for every security professional. Even at that ratio, security could not keep up with cataloging the attack surface, let alone testing it at the pace of delivery,” Klippert said.
Klippert notes that security incidents are rarely caused by one exotic flaw. They come from ordinary vulnerabilities, SQL injections and broken access controls, which are shipped without being tested and can then be chained together by an attacker who finds them before a security team knows they exist.
“The only way out is to stop treating security as something that happens after the code is written. Testing and fixing have to move into the moment of code creation, and they have to be done by machines, because that is the only thing operating at the same speed as the machines writing the code.,” Klippert said.
To prepare for more powerful AI-driven threats, security teams not only need to get to grips with identifying and mitigating vulnerabilities at machine speed, but also having the resilience to restore critical operations as fast as possible following a breach.