- Current cybersecurity investments are not significantly improving our digital resilience.
- 1. Machine-speed, AI-powered ransomware presents significant challenges.
- 2. Existing guardrails are insufficient. Stronger boundaries are necessary.
- Our focus must shift to the core issue.
- We are already late. Organizations must prioritize achieving breach readiness.
- Machine-speed attacks require machine-speed denial.
- What Enterprises Must Do Now
A critical flaw in current security operations is assuming time is on our side. Historically, attacks progressed slowly, allowing analysts and response teams time to detect, discuss, and respond. Even severe incidents operated at a human pace.
Our defenses have relied on human error, human speed, and human limitations.
That era is over.
AI-driven adversaries have fundamentally changed the pace of cyber conflict. They act without delay and do not follow the timelines our processes were designed for. This mismatch is most evident and most dangerous within AI infrastructure.
Cybersecurity is undergoing a significant shift. AI enables attackers to operate faster, more efficiently, and with greater sophistication, while also advancing defensive capabilities.
However, attack frequency remains high.
Current cybersecurity investments are not significantly improving our digital resilience.
Two key issues require attention.
1. Machine-speed, AI-powered ransomware presents significant challenges.
In July, threat researchers documented what they believe is the first fully agentic ransomware operation on record. No human directed each step. The agent found an unpatched login flaw, moved through the network on its own, and encrypted a production database before the day was out. When its first way in got blocked, it wrote new code and found another route instead of stopping. It did not wait for anyone to tell it what to do next.
Bridging the gap between machine-speed attacks and human-speed response must be a top priority for CISOs.
Boards must determine whether to invest in capabilities that enable machine-speed response or in measures that slow attackers while building rapid response capabilities.
2. Existing guardrails are insufficient. Stronger boundaries are necessary.
This gap extends beyond AI laboratories. AI infrastructure connects to code repositories, cloud services, vector stores, identity providers, model registries, observability systems, and software supply chains. Each connection, while often necessary, can also serve as an attack vector.
OpenAI tested whether its own models could find and exploit vulnerabilities inside a sealed environment. Instead, the model discovered a proxy service intended only for package downloads, used it to reach the open internet, and then used what it found to break into Hugging Face’s systems and retrieve the answers to the test it was supposed to solve honestly.
Guardrails must be demonstrable under real-world conditions. AI systems test defenses relentlessly, exploring every path, misconfiguration, forgotten proxy, and outdated credential. They do not tire or stop when documentation suggests they should.
Combining autonomous exploitation with autonomous persistence creates a threat landscape where attackers operate in milliseconds, while defenders are slowed by traditional processes. This presents an urgent and evolving challenge.
CISOs must assess whether their guardrails can withstand AI-driven breaches.
Boards should evaluate which investments establish true boundaries that AI cannot breach or modify.
Our focus must shift to the core issue.
With three decades of experience as a Group CISO, auditor, and digital resilience advocate, I have observed boards place undue confidence in next-generation firewalls and EDR platforms. These defenses often fail, not due to tool deficiencies, but because architectural weaknesses allow attackers to move freely once inside.
The core issue is that investments focus on defeating attacks, while adversaries aim to bypass or overwhelm these defenses. In an AI-powered environment, this mismatch is critical. Machine-speed attacks exploit overly permissive connectivity in AI training clusters, inference platforms, MLOps pipelines, and supporting hybrid environments, without waiting for SOC triage or change-control windows.
Enterprises have deployed AI infrastructure more rapidly than any previous technology. Model weights, training data, vector stores, and orchestration pipelines have become critical assets that are costly to lose, difficult to restore, and essential to business operations.
Adversaries are actively monitoring these developments.
We are already late. Organizations must prioritize achieving breach readiness.
For years, cybersecurity programs were built around prevention. Firewalls, MFA, encryption, audits, compliance checkboxes , all designed to keep attackers out. The key question is how quickly we can contain threats that have already penetrated our systems.
Breach readiness is not a slogan; it is an architectural approach measured in seconds, not policy documents. Implementing breach-ready microsegmentation should require hours, not months.
Breach readiness goes beyond visibility; it involves pre-designed denial. It restricts attackers’ ability to move within the enterprise undetected.
Breach readiness is not just detection; it requires immediate action. Enterprises must be able to quarantine affected areas instantly, ensuring unaffected areas remain operational.
Breach readiness is not solely about technology; it also involves preparing personnel. Non-technical teams must understand their roles during an incident.
Enterprises must adopt this mindset within AI infrastructure. AI systems do not provide defenders with time for SOC triage, change-control windows, or adherence to legacy architecture boundaries.
Machine-speed attacks require machine-speed denial.
The traditional incident response cycle of detect, analyze, contain, eradicate, recover was built for human adversaries. It assumes:
• Alerts arrive before damage.
• Analysts have time to investigate.
• Containment can be coordinated.
• Recovery can begin after decisions are made.
These assumptions do not apply to autonomous AI attackers.
When an agent can breach, escalate, and encrypt within minutes, analysis becomes a luxury, coordination a bottleneck, and meetings a liability.
The response cycle must shift from reactive investigation to proactive containment.
The new cycle looks more like this:
1. Assume compromise. Treat every workload, every identity, and every environment as potentially breached.
2. Shrink reachable surfaces. Microsegmentation becomes the default, not the exception. Architecture denies lateral movement, not hope.
3. Enforce identity at machine speed. Longlived shared credentials disappear. Identity becomes cryptographic, passwordless, shortlived, and tightly scoped.
4. Monitor sequences, not alerts. Zero Trust is not about checking whether an identity was let in — it is about watching what that identity does next. Behavior becomes the signal. Sequence becomes the anomaly.
5. Isolate instantly. Any compromised workload can be quarantined automatically, without human intervention, without delay, without debate.
This is not a multi-year transformation program. It requires a mindset shift from prevention to containment, from claims to proof, and from human to machine tempo.
Adopting a breach-ready posture must occur within hours, not months.
Within AI infrastructure, containment is the key differentiator. AI systems are inherently exploratory, generate unexpected behaviors, and identify misconfigurations unnoticed by humans. When compromised, they can be weaponized at unprecedented speeds.
Microsegmentation is fundamental. Agentless solutions leveraging existing EDR investments can identify traffic patterns, recommend policies, and enforce Zero Trust controls within days. These platforms can cover IT, cloud, and AI compute environments, creating a dynamic map that minimizes the attack surface. Even if an AI agent attempts lateral movement, network paths are restricted, making unauthorized attempts detectable and preventable.
Credential defense must also advance. Static passwords and long-lived service accounts are vulnerable to automated attacks. Implementing cryptographic, device-bound, short-lived credentials with continuous posture and context checks significantly increases security. Stolen tokens become ineffective outside approved devices and segments, and conditional access based on network-segment provenance further limits attacker opportunities.
Deception technology adds another layer of defense. High-fidelity decoys, such as fake model endpoints, honeytoken credentials, and simulated data pipelines, are placed along permitted paths. Any interaction with these decoys is anomalous. For autonomous agents, the effort to explore and validate decoys generates telemetry that enables early, confident intrusion detection.
Combined, these controls microsegment AI infrastructure into contained zones. Access to one microsegment does not grant access to critical assets. The blast radius remains limited, allowing business-critical operations to continue while affected zones are isolated and remediated. Digital architectures must continuously and automatically demonstrate real isolation, enforced segmentation, trustworthy identity, minimal blast radius, and instant containment, even under pressure.
What Enterprises Must Do Now
Boards and governing bodies now recognize that resilience is essential. Regulatory requirements increasingly hold leadership accountable for withstanding and recovering from sophisticated attacks.
Minimizing material impact and preserving digital business viability must become explicit criteria for every AI initiative.
Author: Agni is an ex-CISO and Chief Evangelist at ColorTokens Inc., where he helps enterprises build digital resilience through measurable metrics. He helps enterprises anticipate, contain, and evolve their cyber defense capabilities to combat threats from both humans and AI, while aligning cybersecurity strategies with critical business objectives. He is an industry speaker at various forums and is an expert contributor to international standards. For more than three decades, Agni has led global cybersecurity and resilience initiatives across IT, industrial systems, and cloud environments. And helped executive leadership teams bridge the gap between innovation and defense, enabling digital transformation and AI adoption. He has always preached urgency and action in preparing for the next attack; mere visibility of the attack surface is not enough; you need to enforce controls at machine speed that can delay and contain autonomous attackers.
Agni is a believer in “being breach-ready is the new normal”, and that is what he preaches.

