CISOOnline

AI is turning offensive security into a continuous necessity

Prioritizing fixes requires more frequent pen testing

Most organizations have historically conducted compliance-based penetration tests once a year, or in some circumstances slightly more often. But now, in the AI era, threat actors can exploit vulnerabilities that cause serious problems within hours and minutes, making some form of ongoing penetration testing and monitoring necessary.

“You have to patch that quickly because somebody else using an AI system could find the same vulnerability, like, within hours now,” Nick Winter, SVP of frontier lab security at Gray Swan, tells CSO. “If you’re an offensive security professional, you need to be deploying these in loops, in an automated, ongoing, always-on fashion so that you’re always finding vulnerabilities very quickly so that then they can also get patched or mitigated very quickly on AI timelines.”

What these automated loops can deliver is rapid prioritization, helping CISOs to wade through the tsunami of vulnerability reports generated by frontier models such as Claude Mythos to quickly identify which deserve priority patching.



Source link