Security teams are entering a period where many of the assumptions that shaped modern cybersecurity programs no longer hold the way they once did.
Until recently, the security industry has largely abided by the same MO: vulnerabilities would gradually emerge, defenders would have some time to respond, encryption standards could be trusted to remain effective for years and access controls were designed around the idea that humans were the primary actors inside enterprise environments.
But now, that model is breaking down. The gap between innovation and governance continues to widen. Organizations are adopting new technologies faster than security models and regulatory frameworks can evolve around them. That’s creating an environment where many companies are still defending against yesterday’s risks while entirely new categories of exposure take shape underneath them.
The key challenge for security leaders today is designing systems that can remain resilient when compromise happens. This mindset change will require a shift away from security models built on static trust, long response windows and fixed assumptions about users. The organizations that successfully protect their data in the coming years will be the ones that stop optimizing for perfect prevention and start building for containment, flexibility and recovery from the outset.
Here are three emerging threat areas that are accelerating that shift faster than many organizations are prepared for:
- The Shrinking Window Between Vulnerability and Exploitation
Before, the time between vulnerability being disclosed and actively exploited was measured in weeks. Now, it can be measured in hours and, soon, it may be measured in minutes.
This isn’t happening because attackers suddenly became smarter. It’s happening because the discovery process itself has sped up. Large language models (LLMs) are extremely good at reading code, spotting patterns and surfacing weaknesses that may have gone unnoticed for years.
At a recent Pwn2Own conference in Berlin, researchers submitted so many newly discovered vulnerabilities that they hit a hard submission cap for the first time in 19 years history, which is an early signal of how quickly AI is accelerating the pace of bug discovery. AI not only speeds up bug discovery, it is getting better in chaining individual vulnerabilities into full, working exploits. Speeding up the discovery phase alone is enough to tilt the field, since defenders depend on having time to patch newly surfaced bugs before attackers weaponize them. And when discovery moves an order of magnitude faster, that window collapses. The patch-versus-exploit race stops being a fair fight.
Which leads to a difficult but important reality: patch management alone is no longer enough. Security teams need to start thinking less about reacting to vulnerabilities after they appear and more about limiting what attackers can access in the first place. That means reducing blast radius, segmenting systems, continuously monitoring for abnormal behavior and automating responses before a human ever has to intervene.
- The Quantum Encryption Reckoning
Quantum computing is still, in many ways, a future problem. We’re not yet at the point where quantum machines can suddenly break the encryption protecting the modern internet overnight. But the security implications are no longer theoretical either
The internet as it is now relies heavily on encryption standards like RSA and ECC to protect everything from banking transactions to private communications. The concern is that once sufficiently powerful quantum systems become viable, those standards may no longer provide meaningful protection. This means the data being encrypted today could eventually become readable in the future.
That is what makes the “harvest now, decrypt later” model so concerning. Hackers don’t need to break encryption immediately. Instead, they can simply collect and store encrypted data now, and then decrypt it once the technology catches up.
For organizations handling sensitive information that needs to stay protected for years, like financial records, healthcare data, government files or login systems, this introduces a new challenge. Many of these systems need to remain secure for 10, 15 or even 20 years, but companies also can’t realistically replace all of their current security technology overnight.
There are 3 quantum safe encryption standards formally published by NIST, another 2 are still being worked on. Because the new encryption standards haven’t been tested as extensively as the encryption methods that are already available today–the more practical focus right now should be to use a hybrid approach, which means to use traditional and quantum safe encryption at the same time. In addition, we must apply “crypto agility”, which means building systems that can easily update or swap out encryption without rebuilding everything from scratch. This combination will give companies flexibility and added protection while the technology continues to mature.
- Treating AI Agents Like Trusted Employees
The third threat may become the most disruptive because it is the easiest to underestimate. Across industries, organizations are integrating AI agents into operational workflows, often operating on behalf of users with all their privileges. These agents are being granted access to internal tools, production environments, APIs, file systems, customer data and financial systems–often with a level of trust organizations would never extend to a newly hired employee. This creates a dangerous mismatch between capability and oversight.
AI agents are not employees. They’re systems that happen to communicate in natural language. Yes, they can act autonomously, execute instructions quickly and interact with multiple systems simultaneously. But they don’t possess the judgment, context awareness or accountability needed to manage money or sensitive information.
Organizations shouldn’t avoid AI adoption altogether, but they should instead only allow it to operate within narrowly defined permission boundaries. High-risk actions like financial transactions, deployments, code merges, destructive changes or large-scale exports should still require human approval. Logging and observability should be comprehensive, and agent outputs should be treated as untrusted input rather than authoritative decisions.
What connects all three of these threats is the collapse of assumptions that previously defined modern security programs. Vulnerabilities are surfacing faster than organizations can patch them manually. Encryption standards trusted today may not hold tomorrow. The defensive mindset that worked in the past is becoming less effective under modern conditions. Now, being compliant and following the security standards is not enough, the organizations that design for compromise will be the ones that adapt successfully for what’s coming.
About the Author
Pawel Kurzelewski is the Head of Security at Opera. He has more than 20 years of Information Security experience in senior roles at large, regulated organizations in the banking and pharmaceutical sectors. Pawel has held roles at UBS and the Royal Bank of Scotland, being responsible for risk assessment and data protection, and at IQVIA where he was responsible for cyber defence. Throughout his career, he has been involved in all aspects of Information Security, from risk management and governance, through architecture and engineering, to hands-on incident response. He thrives in building and executing security strategies, developing high-performing teams, and solving problems.
Pawel can be reached at https://www.opera.com/.

