
Library
AI is changing cybersecurity, that much is clear. Attackers use automation to scan faster, to phish more convincingly and to run existing attack techniques more efficiently. Security vendors often use that development as an argument for a fully AI-driven defence. The message sounds attractive, but in our view it is too simple.
The debate tends to focus on speed. Attackers are said to operate at machine speed, and organisations are said to survive only with an equally fast AI defence. That reasoning sounds logical, but it lacks context. Speed matters. Even so, speed alone does not decide whether an attack succeeds.
Our view is therefore straightforward. AI can improve security processes, but AI does not replace baseline measures. An organisation does not win by reacting faster alone. An organisation wins by limiting attack paths in advance, connecting detection to concrete response and periodically testing whether the measures work together.
Machine speed literally means that an attack or a defensive action takes place at the speed of a machine. Not at the pace of a human operator, but at the pace of software. Think of automated attack tooling that inventories systems, privileges and vulnerable services within seconds.
In the current debate, machine speed is mostly used for the idea that attackers with AI can move through a network far faster than a person. For example from a first compromised workstation towards higher privileges, data theft or ransomware impact. The term is therefore not only about speed at the internet edge. It is mainly about how quickly an attacker can create impact after initial access.
That distinction matters. Many internet-facing attacks have run at machine speed for years. The real challenge lies in the combination of speed, context and coherence. A script can quickly test whether a port is open. An attacker or a specialist has to understand which combination of identity, network segmentation, configuration and business context actually leads to impact.
Machine speed suggests that attacks have suddenly taken on a new pace. In reality, speed has been part of the threat landscape for a long time. Internet-facing systems are scanned continuously. Known vulnerabilities are exploited quickly. Leaked credentials are tested automatically. That is not a new pattern.
The most damaging attacks usually consist of several phases. Initial access can be automated. What follows is discovery, privilege escalation, credential access, lateral movement, data collection and finally extortion, sabotage or disruption. Some steps automate well. Other steps require an understanding of permission models, dependencies, exceptions and operational impact.
An attacker has no need for a new model when existing techniques work well enough. Weak identity, poor segmentation, excessive privileges and insufficient logging remain usable attack paths. AI does not change that reality. It can accelerate existing techniques, but mainly it makes poor baseline security visible sooner.
A SOC is an important part of modern security. It detects unusual behaviour, investigates alerts and supports incident response. Even so, a SOC should never be the first and only line of defence. When an organisation relies too heavily on detection after the fact, it enters a race that is hard to win.
An alert generated within seconds stops no attack when credentials stay active, endpoints are not isolated and administrators first have to work through several layers of consultation before deciding. The total time from detection to containment is what counts, not the time to alert.
A purely reactive model is therefore fragile. More alerts, faster triage and extra dashboards do not solve the underlying problem when the environment itself allows too many attack paths. Security must not only look faster. Security must give attackers less room.
AI can be valuable when it is used as support. Think of smarter processing of alerts, logging and incident information, so that patterns become visible sooner and initial triage takes less time. In that role, AI can help analysts reach a better picture faster.
AI is less suited as a replacement for security architecture, risk assessment and technical decision making. A model can interpret a warning, but it needs to rely on trustworthy data, clear playbooks and predefined authority. Without those conditions, AI mainly accelerates existing ambiguity.
The right question is therefore not whether AI should be used. The right question is where AI adds demonstrable value. AI should strengthen analysts, not mask a lack of hardening. It should support decision making, not replace accountability.
The fastest response is an attack that cannot happen technically. Measures such as Credential Guard, LAPS, network segmentation and strong identity governance limit what an attacker can achieve after an initial compromise.
Measures of this kind are not new. They are not spectacular either. Even so, in many environments they decide the difference between an isolated incident and an organisation-wide crisis. An EDR alert after credential dumping is valuable. A situation in which the attacker cannot obtain usable credentials is more valuable.
Prevention does not have to mean that every business function is restricted. It does require technical choices about interactive logins, network access, MFA exceptions, management interfaces and the revocation of credentials. Those choices determine actual resilience.
Automated response belongs in a mature detection and response strategy. Not every alert needs the same handling. Some signals have a low chance of false positives and a high potential impact, especially when they point to credential misuse, persistence or lateral movement.
For that type of signal, an organisation can decide in advance which actions may take place immediately. Think of isolating systems straight away, revoking sessions or credentials and temporarily restricting access. This does not require generative AI. It requires clear agreements, technical integration and a mandate.
Automation only works well when the preconditions are right. It must be clear who owns a system, what impact isolation has and how recovery is carried out. Without those agreements, response stays dependent on consultation. The organisation then loses valuable time, even when detection is fast.
The basics remain decisive. Organisations need to know which systems they have, which access is possible from the internet, where high privileges exist and which components are critical to the business. Without that insight it is impossible to limit attack paths in a targeted way.
Technical hardening comes next. MFA must not only be registered, but also enforced on relevant access paths. Administrator rights must be limited. Service accounts must hold minimal privileges. Logging must carry enough detail to recognise lateral movement and credential access. Backups must be separated, tested and recoverable.
Segmentation deserves separate attention. Much ransomware impact arises because internal networks allow too much communication between systems. Segmentation is not only about VLANs. It is about effective access control between zones, management interfaces, identity systems and IT, cloud and OT environments.
An organisation has to assume that an attacker gets in at some point. That can happen through familiar routes such as phishing, vulnerable software, leaked credentials, supplier risk or a cloud configuration error. The question is then no longer only whether the perimeter holds. The question is what an attacker can do afterwards.
Assumed breach testing provides insight here. In such an engagement a tester is given controlled access to a representative starting point in the environment. From there, the test examines which attack paths exist towards higher privileges, critical systems, sensitive data or disruption of business processes.
The goal is not to find as many vulnerabilities as possible. The goal is to understand the chain. Which combination of configurations, privileges, network paths and credentials makes impact possible? Which detection is triggered along the way? Which preventive measure stops the chain earliest?
Testing advanced attack paths takes more than tooling. Scanners, scripts and AI can collect individual signals, such as open ports, vulnerable versions and known misconfigurations. That is useful, but not enough to assess real impact.
High-quality penetration testing requires specialists who assess coherence and context. A senior pentester looks at the combination of identity, technical configuration, segmentation, administrative processes, logging and business impact. That coherence is what decides whether a technical weakness is a limited finding or a realistic path to domain takeover, data theft or disruption.
AI often lacks that context. A model can recognise patterns, but it does not automatically understand why a service account is critical, why a temporary administrative path creates structural risk or why a segmentation rule in an OT environment is operationally sensitive. Human expertise therefore remains essential for validation, prioritisation and advice. Certainly when quality, independence and demonstrable impact matter more than the number of signals found.
For directors, AI in cybersecurity is mainly a governance question. AI can raise efficiency, but it must not become an excuse to postpone necessary baseline measures. The most important investment remains reducing the attack surface and improving containment.
The question is not only whether the organisation has a SOC. The right question is whether the organisation can detect, decide and contain within minutes. That requires a mandate, pre-approved response actions, technical integration and regular exercises.
Compliance does not change this reality either. NIS2, DORA and other frameworks require demonstrable control of risk, incident response and continuity. An AI solution can support that, but it delivers no demonstrable resilience when the underlying measures are missing.
A mature approach combines prevention, detection, automated response and periodic validation. Prevention reduces the attack surface. Detection makes misuse visible. Automated response limits the damage. Validation shows whether the measures work against realistic attack paths.
This requires coherence. Individual measures lose value when playbooks, logging, exception control or a mandate are missing. An organisation may then be able to spot something quickly, but not to contain it quickly enough.
DeepBlue therefore looks at attack paths and demonstrable impact. Not at individual measures on paper. An organisation needs to know which steps an attacker can realistically take and where that chain is stopped. That insight requires technical depth, independent assessment and experience with IT and OT environments.
When an incident does occur, the same coherence matters. Containment, evidence preservation and recovery must not get in each other's way. Our specialists for Incident Response and Forensics help organisations to act quickly without needlessly weakening the technical investigation or the legal evidential position.
AI changes parts of cybersecurity, but it does not change what good security is. Attacks are getting faster, but many techniques are familiar. The organisations that hold up better against fast attacks are not the ones that only process alerts faster, but the ones that limit attack paths technically.
A SOC remains crucial, but it belongs as the last line of defence. Not as a replacement for preventive hardening, segmentation, identity security and automated response. AI can help to process signals faster, but it must never become the foundation on which all resilience rests.
The core stays the same. Get the basics right, test whether the basics work and set up security so that a first compromise does not automatically lead to organisation-wide impact. That is technical resilience.
CrowdStrike, 2026 Global Threat Report | AI Security Institute, Our evaluation of Claude Mythos Preview’s cyber capabilities | Microsoft Learn, Credential Guard overview | Microsoft Learn, Windows LAPS overview
Last reviewed: 4 September 2026.
Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.
Urgent assistance required?
Call +31 (0) 70 290 6 290
or email info@deepbluesecurity.nl