Our recommendations
To effectively respond to the accelerating capabilities enabled by advanced AI models, organizations must adopt a balanced approach that reinforces foundational security practices while simultaneously modernizing their defensive architecture. While the threat landscape is evolving rapidly, many successful attacks still exploit well-known weaknesses. Strengthening core controls remains one of the most impactful actions security leaders can take.
Organizations should prioritize foundational measures such as phishing-resistant authentication, strong identity verification, least privilege access (including AI agents), and zero-trust architectures. Consistent patch management, comprehensive asset visibility, and disciplined configuration management are essential to reducing exploitable vulnerabilities. These controls form the baseline for resilience and are critical in limiting the scope and spread of both traditional and AI-era attacks. In many cases, improving execution on these fundamentals will deliver more immediate risk reduction than deploying new technologies alone.
At the same time, organizations must take an aggressive stance on eliminating structural risk. Any devices or software that cannot be patched, upgraded, or supported must be systematically removed and replaced with modern platforms. Modern systems incorporate advanced protections such as memory safety mechanisms and exploit mitigations that significantly increase the difficulty of weaponizing vulnerabilities. Even when vulnerabilities exist, these protections slow attackers and reduce the likelihood of successful exploitation. Building environments that are flexible, continuously upgradable, and designed for rapid patching is now a critical requirement—particularly for internet-facing services, where very little time will be available between disclosure and mass exploitation.
But strengthening fundamentals and modernizing infrastructure alone is insufficient. The speed of AI-driven attacks will compress the window between vulnerability discovery and exploitation to minutes or seconds. Traditional models based solely on detection and response are no longer adequate when used in isolation. Defenders must evolve their operating model to match the speed, scale, and adaptability of AI-era threats. This includes investing in machine-speed detection, automated triage and containment, and continuous monitoring of identity and data activity. This reduces reliance on manual intervention and enables faster, more consistent responses to high-confidence threats.
This evolution also requires a shift toward embedded active defense. Rather than relying exclusively on telemetry collection and post-event analysis, organizations should place protections directly within the workload, device, and traffic path, enabling security controls to act in real time. Examples include in-line enforcement mechanisms, runtime protections using technologies such as eBPF for low-level visibility and control, and independently updatable exploit shields that can respond to emerging threats without requiring full system upgrades. These capabilities must be designed to evolve rapidly, with the ability to update protections independently of major software or hardware refresh cycles.
Organizations should also harness AI capabilities for their own defense. Constant internal threat hunting, aided by the same capable models adversaries utilize, will be a key capability for successful defenders. AI-driven conformance and acceptance testing can replace labor-intensive manual verification with high-velocity, automated intelligence, thereby generating complex test cases that cover edge cases often missed by human testers. In high-stakes environments, AI-driven digital twins can simulate production networks at scale, verifying that updates adhere to strict security protocols and performance benchmarks without risking the stability of live environments. Integrating AI into acceptance and validation phases significantly reduces the deployment bottleneck, compressing the transition from code complete to field deployed from months to days.
Ultimately, success in this new environment requires a dual focus: executing foundational controls with discipline while advancing toward adaptive, real-time, and embedded security capabilities. Organizations that aggressively reduce legacy risk, modernize their infrastructure, adopt an assume-breach mindset, and embrace active defense models will be best positioned to manage the speed and scale of AI-driven threats.