For decades, cybersecurity was built on a quiet assumption: attacks needed time to break in, move laterally, and compromise systems. Defense could use that time to detect, contain, and recover.
The logic was sound: firewalls, endpoint detection, identity and access management, and a security operations center were armed to catch what got through. Together, these were built to slow down, if not stop, an attacker long enough for a human to notice, investigate, and respond. It worked often enough to become a standard approach.
That was the bet. Perimeter and prevention tools would stop most things, and a human-speed response process would catch the rest, with enough time to react and respond. Recovery, when it was needed, was a project that started after the incident was declared: assess the damage, locate clean backups, rebuild the environment in the right order. Human speed, but survivable because the attacker was usually working at a similar pace.
AI ended that assumption. Now we need New Rules for a world where attackers have access to frontier and open source models.
AI Gives Attackers an Unfair Advantage
AI has collapsed two of attackers' biggest constraints: time and skill. What once took a skilled team days can now be executed by one bad actor with AI in minutes. The result is a threat landscape that moves faster and welcomes more attackers than security teams were built to handle.
Machine Speed Execution: When MGM Resorts was breached in 2023, the attack started with a person: a single phone call to a help desk that was convincing enough to get an employee to hand over their credentials. What followed was roughly ten days of disrupted operations and an estimated $100 million in losses. While the impact was severe, the attack unfolded slowly enough for a security team to mitigate and contain the damage.
Times have changed. According to Crowstrike, the average breakout time fell to 29 minutes over the past year, with the fastest recorded intrusion clocking in at 27 seconds. A human-speed response generally can't operate in that window. By the time an alert is interpreted, the breach might already be over, and data and applications already compromised.
Low Skill Barrier: In late 2025, Anthropic disclosed that it had disrupted a state-linked espionage campaign in which operators used an agentic coding tool to run reconnaissance, exploit vulnerabilities, move laterally, and compromise data across roughly 30 organizations. Anthropic estimated that AI handled as much as 90 percent of the work. Humans were only involved as checkpoint approvers, not operators executing each step themselves.
Agents Are Operating Inside the Perimeter
The uncomfortable part for IT and security leaders is that this same autonomy isn't only arriving from outside. It's being deployed from within.
In July 2025, an AI coding agent deleted a live production database in the middle of a project.
A year later, an autonomous AI agent breached Hugging Face's internal systems, harvesting credentials and moving laterally through infrastructure that ultimately had to be rebuilt.
None of these agents were adversarial in the traditional sense. They were doing what they were built to do, with more access and less oversight than human users get. An agent isn't bound by human limits. It acts at machine speed, holds whatever privilege it was granted, and can touch every system that privilege reaches—sometimes more than intended.
Identity is the Perimeter
These days, an attacker's first move is not to break through a digital wall. Increasingly, cyber threats assume the identity of someone, or something, that already holds a key to your enterprise.
This is getting easier and easier, given the number of credential keys in circulation. Machine identities now outnumber human ones by roughly 109 to 1 and most of that growth is from AI agents.
Identity, not the network boundary, is the security perimeter.
New Rules for a New World
None of this means prevention doesn't matter. But it does mean that prevention is no longer sufficient on its own. The rules that governed cybersecurity weren't wrong. They were built for a different world—one with an adversary who needed time,and systems that only humans could operate.
We don’t need a better version of the same playbook. We need resilience built for today’s reality.
We need Agentic Cyber Resilience that replaces the reactive chaos with continuous readiness and autonomous action.
We need New Rules of Agentic Cyber Resilience.