The AI Cyberattack Speed Gap Will Reshape Corporate America
Attackers can adopt a new offensive capability in an afternoon. Companies need budget, approval and a change window. That gap changes five things about how security gets bought and built.
Verizon has been counting data breaches for nineteen years. This year, for the first time, the most common way in wasn’t a stolen password. It was an unpatched flaw, at 31% of initial break-ins against 20% a year before. That’s the opening AI cyberattacks are built to widen.
The figures underneath are worse. Across scanner data from 13,000 organizations, the median time to fully patch a flaw already under attack rose to 43 days from 32. Only 26% of the government’s known-exploited list was fully remediated, down from 38%. Both numbers moved backwards in one year.
Both sides get the same tools. Only one can deploy them without asking. Software scales globally, and security gets fixed one company at a time.
The Fastest Movers Could Become The Hardest To Insure
Insurers don’t wait for legislation, and regulation of AI agents remains unsettled . Their sharpest lever isn’t what they charge. It’s whether they cover you at all. After September 11 the Insurance Services Office asked states to strip terrorism out of commercial cover, and 45 agreed . Reinsurers cut back or stopped writing it, cover became expensive or unavailable, and Congress passed the Terrorism Risk Insurance Act in 2002.
The same body has now reached for AI, on a smaller scale. In January 2026 the ISO issued generative AI exclusions for general liability, and a few carriers are adopting them. Underwriters are asking how you use it.
Follow that and the usual story inverts. The exposure carved out belongs to whoever deployed the most AI, which would make the fastest movers the hardest to insure.
Aon reports a soft cyber market with price cuts and higher limits for well-managed risks. Across commercial insurance it says “AI has not fundamentally changed pricing patterns – yet.” Watch the exclusions, not the premium.
Machines Take On The Authority To Pull The Plug
In August, Microsoft published an account of an intrusion at QNET, a direct-selling firm with a small security team. An attacker used a Windows utility already on the machine, and already trusted, to download malicious code. Microsoft Defender cut the machine off the network. First alert to enforced isolation: 128 seconds . The analyst arrived to a contained host. That’s a vendor describing its own product, but the capability is documented: Defender disables accounts, isolates devices and revokes sessions by itself, above a stated 99% confidence threshold.
The QNET example undercuts this article as much as it supports it. Lennart Maschmeyer, in International Security, argues AI favors the defender : attacking well takes creative deception, and defending well takes spotting patterns. Machines are good at patterns. Anthropic's own numbers lean the same way. Across 832 banned accounts , 84.4% used AI to hide from detection, and only 6.5% used it to spread from one system to the next.
The worst cases point the other way. Anthropic's highest-risk actors leaned on AI most heavily after they were already inside a network, and the share it rated medium risk or higher rose from 33% to 56% in a year.
The attacker figures are thinner than they look. A model in Anthropic’s testing crashed a Windows kernel in 31 minutes. Two researchers built exploits for 14 open-source packages at about a dollar each. Both were controlled demonstrations on artifacts handed to them, not attackers working unaided.
Those 128 seconds happened because somebody authorized them in advance. Capability isn’t permission, and permission is the slow part. The pre-authorized list grows past laptops to servers, payments, suppliers, production lines. An agent that misfires stops the business, not the attacker, and one can already be steered by a single web page . If these features are still in recommend-and-wait mode in 2027, the authority never moved.
Boards Shift From Prevention To Survival
Delegating that authority changes what a board answers for. Under the SEC’s 2023 cybersecurity rules , US public companies describe their board’s oversight of cyber risk in the annual 10-K. They also disclose an incident within four business days of judging it material. Europe went further. Its operational resilience rules took effect on 17 January 2025 and require covered financial firms to keep working through disruption.
“Are we secure” has no honest answer. “If something gets in tonight, can we still ship tomorrow” does, and it can be tested. If boards are still reporting oversight rather than recovery times in a few years, the filing changed and the company didn’t.
AI Cyberattacks Push Security Debt Onto The Balance Sheet
Windows 10 stopped receiving security updates on 14 October 2025 . Not because it stopped working. A support calendar moved, and machines that were fine on Monday needed paid extended support on Tuesday.
AI had nothing to do with that, but the mechanism matters. Cheaper exploitation points it at equipment that can’t ride a three-year refresh: hospital imaging, plant controllers, hardware from a vendor that no longer exists. Regulators are forcing the hardest case.
Under section 524B of the FD&C Act , makers of internet-connected medical devices must plan for fixing vulnerabilities after sale, supply patches, and list the software inside. The FDA has expected full compliance since October 2023, and a submission without it can be held at screening. The rule is prospective, so it reaches new devices, not installed ones. That turns a security requirement into a purchasing decision, and the bigger bill is the installed base.
ISACA calls the accumulated version security debt , the risk left by outdated systems. Pull those dates forward and the cost moves off the IT budget onto the capital plan. Firms that keep buying extended support keep it an operating expense.
AI Cyberattacks Squeeze The Middle, Not The Bottom
The intuitive version is big against small. It looks wrong. The US Treasury’s Office of Financial Research scored cyber risk by firm size in September 2025 using CyberCube’s model-based ratings, and the curve is U-shaped. The smallest firms do better than you’d expect, mainly because they hold too little to ransom. The trough sits at mid-size firms, $1 million to $10 million in revenue. The OFR calls them “rich enough to lure attackers yet often lack the resources to mount robust defenses.”
That analysis predates AI, but it maps where the weak points sit, and that’s where cheaper attacks land. Large firms can afford their own defenses. The middle will more likely rent them from Microsoft, Google, Amazon, CrowdStrike or Palo Alto Networks. That solves the problem for each and creates a different one. The GAO found nearly 18,000 customers received a compromised SolarWinds update , and the attacker picked a smaller set of high-value targets. Concentration is what makes that arithmetic work.
Defenders have powerful AI too. But equal access isn’t equal speed. OpenAI gates its Daybreak cyber models behind approved access and identity checks, with hardware keys required for individual accounts from September 1. An attacker can fail repeatedly and only has to land once. A company needs its defenses to hold across every employee, supplier and twenty years of equipment. The question isn’t whether companies can buy the tools behind AI cyberattacks. It’s how fast they’ll let them act, and who signs. That QNET analyst walked in to find the job already done, and only because somebody decided months earlier that a machine could pull the plug without asking.
Loading article...