AI speed is security’s biggest adversary

AI-driven cyberattacks

Artificial intelligence (AI) is transforming the threat landscape with one defining factor: speed. Attacks can be carried out faster, simultaneously and autonomously. Similarly, because AI has lowered the barrier to entry, threat actors no longer need to spend time developing entirely new methods. AI accelerates familiar processes and compensates for knowledge gaps, meaning where detailed expertise in vulnerabilities, exploits and attack tools were once required, attackers can now use the technology to select and apply suitable methods.

With agentic AI, this development goes one step further. Instead of triggering individual actions through prompts, attackers define an objective that an AI agent then pursues – largely independently. At the same time, multiple agents can operate in parallel. This makes attacks not only faster, but also more scalable. Unlike humans, an AI-powered attacker needs neither sleep nor rest. To tackle this challenge, businesses need comprehensive security operations which rethink how humans and machines work together.

The window for response is shrinking

For defenders, the time between detection and response is becoming a critical factor. With AI accelerating the pace of attacks and shrinking the exploitation window, what once took days or weeks can happen in hours or minutes, giving defenders less time to detect, assess and respond to threats. Managed Detection and Response (MDR) helps security professionals respond more quickly and effectively by combining advanced threat detection technologies with expert-driven oversight, analysis and response capabilities. Unlike traditional security tools, which primarily focus on prevention, MDR emphasises continuous monitoring, rapid detection and decisive response to confirmed threats – all essential capabilities to keep pace with AI threats.Simply detecting suspicious activity and then waiting for a human decision is no longer enough.

Effective defence must also operate around the clock. Autonomous attacks mean there is no longer a break from the attempts of malicious actors. When credential stuffing bots test millions of stolen usernames and passwords around the clock, there is no longer such a thing as ‘out of hours’ for cybercriminals. What’s more, periods when attackers expect there to be less human monitoring, such as national holidays, are often specifically targeted. An external Security Operations Centre (SOC) provides the continuous monitoring, experience and responsiveness necessary to combat AI threats. Successful detection and remediation demands a broad data foundation and continuous training, which a SOC provides. Organisations which only see their own environment and a comparatively small number of security incidents will find it more difficult to identify new attack patterns and further develop automated responses.

Humans as the cybersecurity bottleneck

The traditional human-in-the-loop approach is also changing. Until now, automation has often stopped where concrete countermeasures begin. While humans won’t disappear from the SOC, their role is shifting. Currently, an analyst reviews the incident and decides on the appropriate response. In the age of AI attacks, instead of reviewing every alert themselves, security professionals will monitor automated decisions, perform spot checks to ensure their quality, assess complex cases and use AI to improve defences. They are also critical in understanding new attack methods and developing suitable counterstrategies. Identifying and remediating most threats, however, must become more automated. For instance, if other stakeholders within the company need to be involved in decision-making, as well as analysts, minutes can quickly turn into hours. This creates a dangerous delay. Instead, remediation must shift towards a more automated response, ensuring human processes don’t slow down the response to AI-driven threats.

This does not mean immediately taking systems offline whenever suspicious activity occurs. While cyber defence is still in the early stages of AI, humans play a critical role in ensuring its outcomes are accurate and governed. As such, a tiered model makes more sense: measures with little impact on IT operations, such as additional authentication requirements or temporarily tightened access policies, can be triggered automatically at an early stage. The more significant the potential consequences of a measure, however, the more important human decision-making remains. It’s unlikely we will ever see a fully automated SOC. The nuance of the cybersecurity domain demands that humans remain in the loop for oversight, adaptation and ongoing reinforcement learning, making skilled threat researchers vital.

The cybersecurity race continues

In the future, security operations and AI must become more closely integrated. As the technology evolves, autonomous AI systems on both the attacker and defender sides will compete more aggressively, as only machine-speed can keep pace with machine-speed.

Comprehensive cybersecurity must be based on machine-speed detection and response, as well as a shift in the roles and responsibilities of cybersecurity professionals. While novel attack methods are still a concern, the scale of these threats is what risks overwhelming security practices. Cyber defence is increasingly becoming an AI race in which speed defines whether the ‘good’ or ‘bad’ guys win.

Dr. Sebastian Schmerl, Vice President Security Services EMEA, Arctic Wolf

Dr. Sebastian Schmer

Dr. Sebastian Schmerl is Vice President of Security Services EMEA at Arctic Wolf. With over 20 years of cybersecurity experience, Dr. Schmer has deep expertise in delivering cyber defence services for IT, OT, cloud domains, and enterprise building SOCs for global brands.

Author

Scroll to Top

SUBSCRIBE

SUBSCRIBE