Enterprise cybersecurity has entered a new phase, requiring a practical security operating model that closes the gap between knowing about risk and protecting live systems.
As Cisco’s Talos Intelligence research team puts it, “The era of agentic attackers has effectively arrived.”
Just as concerning is Talos’ finding that model guardrails are not reliably stopping misuse. The researchers wrote:
“One of the immediate takeaways is that guardrails are not functioning as expected. We did not encounter any sophisticated encoding or techniques designed to trick the models — most of the time it was a simple ‘I’m allowed to do this,’ and the model complied. When guardrails did engage, they accomplished little.”
The teams’ findings challenge a common assumption that AI platforms’ built-in controls will be enough to prevent malicious or risky activity. In practice, organizations should assume that attackers can still use AI systems to support parts of their workflow, even when those systems have nominal safety restrictions.
That does not mean every attacker is suddenly advanced. Talos found that skill still matters, as novices often generate flawed tooling, while sophisticated actors use AI as a true force multiplier. But AI is clearly reducing friction across the attack lifecycle.
The enterprise response cannot be another static checklist. It has to be a practical operating model built around speed, prioritization, automation, and customer trust.
As Brian Gracely, Senior Director of Portfolio Strategy at Red Hat, told CX Today in a recent interview, the issue is getting fixes into production fast enough once vulnerabilities are uncovered.
“The reality for most enterprise customers is the amount of time it takes them to get from getting that patch to getting it into production, getting it into their systems that are live, oftentimes takes quite a long time… 40 days, 50 days, 90 days.”
In the AI era, that timeline is becoming harder to defend.
As Quincy Castro, Chief Information Security Officer at Chainguard, told CX Today, organizations are facing “an inherent mismatch” between the speed of AI-enabled vulnerability discovery and the slower processes many enterprises still rely on to remediate software risk.
So, what should enterprises do now?
-
Accept That Attackers Are Already Using AI
The first step is organizational acceptance. AI-enabled cyber risk is not theoretical, or limited to one frontier model. Attackers are already using AI because it helps them move faster.
Gracely put it plainly:
“Whether or not you love the AI technology or you have concerns about the AI technology, the reality is attackers don’t really care about your opinion of it, your emotions around it.”
“They’re looking at it as this makes my life easier, this makes my life faster in terms of being able to break into things or steal things or create situations that are advantageous to them,” Gracely added.
The team at Talos reached the same conclusion from its research:
“From an enterprise perspective, organizations need to understand that threat actors are heavily leveraging AI capabilities in their pipelines, and defenders need to do the same.”
Practical steps:
- Update threat models for AI-assisted reconnaissance, exploit development, phishing, and credential theft.
- Brief boards and executive teams on AI-enabled cyber risk as a current business issue.
- Treat AI cybersecurity as a shared concern across security, engineering, IT, compliance, legal, and customer experience.
- Stop assuming attackers need elite skills for every stage of an operation.
As Talos warns: “The capabilities exist; the only missing ingredient is malicious intent, and it’s a matter of time before threat actors supply it.”
-
Close the Patch-to-Production Gap
Many enterprises can now identify vulnerabilities faster than they can remediate them, creating a dangerous gap. A company may know a vulnerability exists, have a patch available, and still remain exposed because internal change processes are too slow.
Gracely described this as the “patch-to-production challenge” and framed the core question as: “How fast can we get you from having a patch to getting that into production?”
Castro made the same point from the vulnerability management side, telling CX Today that the ability of frontier models to find vulnerabilities changes remediation expectations.
“The policy says 30, 60, 90, and that’s how we do it — that’s dead. We’re just not going to live in that world anymore.”
Practical steps:
- Measure average time from patch receipt to production deployment.
- Create accelerated paths for critical and externally reachable vulnerabilities.
- Pre-approve emergency change processes before a crisis.
- Automate testing and deployment where possible.
- Maintain rollback plans to reduce outage risk.
- Prioritize remediation by exposure, exploitability, and business impact.
The goal is safe acceleration.
-
Prioritize Exploitability, Not Just Severity
Traditional vulnerability management often starts with severity scores. That still matters, but AI makes context more important.
Attackers can use AI to understand how multiple lower-severity weaknesses might be chained into a larger compromise. Castro warned that even less-skilled attackers could use AI systems to analyze many vulnerabilities and find a path to domain administrator access.
The Talos research team also observed adversaries using AI for vulnerability research, credential harvesting and expanding proof-of-concept code into more scalable exploitation pipelines.
Practical steps:
- Prioritize by exploitability, asset criticality, data sensitivity, and exposure.
- Identify attack paths across identity, network, cloud, and application layers.
- Reassess accepted risks where AI could make exploitation easier.
- Focus first on Internet-facing systems, customer data, authentication and revenue-critical services.
- Use compensating controls when full remediation cannot happen immediately.
Enterprises cannot fix everything at once. But they can stop treating every vulnerability as an isolated item.
-
Prepare for More Alerts, Vulnerabilities, and Incidents
AI will increase volume, the Talos researchers noted, stating: “Vulnerabilities will surface faster, exploitation will happen sooner and the actors behind it won’t need rest or downtime.”
That creates pressure on security operations teams already struggling with alert fatigue. Enterprises should not remove humans from critical decisions, but they should use automation and AI to help analysts focus on the highest-value work.
The researchers argue: “Organizations that aren’t already exploring agentic capabilities to let human analysts focus on the most important alerts will soon find themselves chasing that capability.”
Practical steps:
- Automate alert enrichment, deduplication and routing.
- Use AI to summarize incidents and support analyst investigation.
- Keep humans accountable for high-impact containment and response decisions.
- Test incident response plans against faster-moving AI-assisted attacks.
- Improve detection coverage for phishing, credential abuse and exploit chaining.
The SOC will need to become more agent-assisted, but still human-led.
-
Treat Technical Debt as Security Debt
Many enterprises still rely on systems that are hard to patch, poorly documented or dependent on manual change processes.
Gracely described this as technical debt that has been “accruing” over time.
“What sometimes happens is people think, ‘if I don’t touch it, then I don’t introduce as many problems.”
But in an AI-accelerated threat environment, not touching systems can become its own risk. “This is becoming very much a wake-up call for companies that have ignored that,” Gracely added. “Your technical debt—the bill on your technical debt is coming due.”
Practical steps:
- Identify systems that are hardest to patch.
- Rank technical debt by security exposure and business impact.
- Modernize systems tied to customer data, identity, payments and critical operations.
- Remove unsupported software and abandoned dependencies.
- Assign clear ownership for legacy platforms.
Technical debt is a cybersecurity liability as much as an engineering concern.
-
Use Layered Mitigations When Patching Is Delayed
Even mature enterprises cannot always patch immediately. Change freezes, regulatory requirements, fragile systems, and operational risk can delay deployment.
In those situations, organizations need compensating controls.
Gracely said technology partners can help by applying protections that do not require touching application code. For instance, some can work at the network level by making changes to firewalls and access lists.
Practical steps:
- Use segmentation, firewall rules, access restrictions and monitoring.
- Reduce public exposure for vulnerable systems.
- Apply temporary mitigations with owners and expiry dates.
- Track compensating controls separately from permanent fixes.
- Avoid letting temporary protections become permanent excuses.
Layered mitigation buys time but does not replace remediation.
-
Make Cybersecurity Part of Customer Trust
AI cybersecurity is also a customer experience issue. If an emergency patch breaks a customer-facing platform, customers feel it. If an AI agent leaks sensitive data, customers feel it. If a known vulnerability remains unpatched for months, customers feel it.
Castro argued that enterprises must stop treating security risk “as a tech issue that those eggheads over in the closet deal with.” Instead, he said, “This is a fundamental aspect of the brand promise and the value of the business.”
Practical steps:
- Include CX and product leaders in AI security planning.
- Map customer journeys to high-risk systems and data flows.
- Build customer communication into incident response.
- Connect security metrics to uptime, trust, retention, and service quality.
- Design AI-enabled services with security controls from the start.
Cybersecurity Has Become a Customer Trust Issue
AI has changed the speed of cybersecurity risk. As Gracely warned: “The marketplace isn’t going to wait for us.”
Talos makes the enterprise challenge equally clear: “The organizations best equipped to handle the coming deluge of additional vulnerabilities, alerts, and incidents will be the ones that prepare now.”
That preparation means practical change, from faster patching to better prioritization, stronger automation, layered mitigations, reduced technical debt and closer alignment between cybersecurity and customer trust.
The old model of slow, siloed, checklist-driven security is not built for AI speed. Enterprises now need cybersecurity operations that are continuous, collaborative and ready to move before attackers turn acceleration into advantage.