Technology Report
|
|
Executive Summary
This article is part of Bain’s Technology Report 2026 Most businesses will know that AI has made cyberattacks faster and more powerful. High-profile incidents, notably involving frontier AI model tests, have illustrated the pressure being put on organizational defenses that are designed to operate at the speed of human decisions, not the quicksilver rapidity of AI automation. However, with emerging best practices in AI-powered defense gaining fewer headlines, executive teams might be unaware of the early progress that some companies have made in addressing the new threats, notably in vulnerability discovery. The danger at the heart of this evolution has not been exaggerated. Malign actors without coding expertise can now hack with the sophistication of a nation-state. Skilled hackers that used to spend weeks on a campaign now only need hours (see Figure 1). Whereas hackers used to down tools to sleep, AI enables 24/7 fraud. Future attacks might not even need human intent amid signs that AI agents will sometimes act illicitly to fulfill a legitimate mandate.
Figure 1
Companies are feeling the impact. For one thing, the volume of phishing attempts has rocketed. Those attacks are now more convincing, too, through increased personalization of content and use of QR codes as a lure. AI-powered voice cloning and real-time video impersonation are also now occupational hazards for many businesses. The adoption of AI agents has expanded the attack surface, too. Many companies would struggle to say how many agents they have, who owns them, and what they are permitted to do—let alone take the crucial step of installing a kill switch in each agent. Poor agentic housekeeping is a glaring weakness with an understandable cause: The lack of a silver-bullet solution from vendors is leading many firms to hesitate when they should be proactively creating a pragmatic and flexible solution through a build/buy/partner approach. For their part, chief information security officers (CISOs) at large enterprises understand that AI-related risks require an overhaul of capabilities going well beyond vulnerability management to span AI workload and agentic discovery, hardening, monitoring, threat detection and response, governance, risk, and compliance. However, the scale of the vulnerability management challenge is currently all-consuming. The CISOs we surveyed also highlighted supply chain risk as an issue. Companies must understand and control how vendors deploy AI through the whole life of a contract, including midcycle changes and fourth-party exposure. But with vendors shipping changes to models and software daily, oversight systems based on infrequent questionnaires aren’t coping. Companies instead need to start assessing third-party risk continuously, particularly with the vendors that are most integrated with their operations. Firms must tighten contracts to hear about and penalize breaches quicker, demanding preapproval of new AI deployment by vendors. At best, this is a work in progress for many. How leaders are adapting cybersecurity to the AI eraOf course, AI is not just a tool for attackers. Some big companies are already deploying frontier AI at enterprise scale to strengthen defenses and accelerate their responses to machine speed. But that’s creating its own challenge, with vulnerability alerts increasing by as much as eightfold. These surges can rapidly exceed a firm’s ability to validate, prioritize, and fix weaknesses. While AI-enabled vulnerability management is still at an early stage, leading companies are making progress. Rather than analyzing vulnerabilities in a vacuum, these leaders are taking a more holistic view, emphasizing exploitability, reachability, systemic dependency, and blast radius. They are strengthening their remediation operating model, too. Leaders have increased remediation budgets, typically by a double-digit percentage, while redirecting as much as 20% to 25% of their cybersecurity human resources from other work to remediate alerts from AI-powered scans (using third-party partners to maintain normal operations). One leader even tripled the size of its remediation team. Other cybersecurity leaders are now pushing their DevOps teams to spend more time finding and mitigating vulnerabilities. For instance, the CISO at one large enterprise said they were now taking a harder line on enforcing an internal guideline that asks developers to spend around 30% of their time on proactive vulnerability management. Some companies have made board reporting more frequent. Accelerating critical patches is another focus. We also see a pattern emerging in the structural exposures that AI-powered cybersecurity leaders are prioritizing, with legacy platforms, network layers, and critical software-as-a-service (SaaS) vendors singled out for action ahead of other risks in areas such as in-house code and open-source dependencies (see Figure 2).
Figure 2
Note: Bubble size reflects the number of chief information security officers who identified this as their most material unresolved exposure Source: Bain analysisFor companies still formulating their AI-powered response to the recent turbocharging of cyberattacks, we see six key imperatives emerging from early-stage best practices.
While the news may have been dominated by the cybersecurity risks posed by frontier models, most companies should still be able to reap a defense dividend from AI advances, one that at least reduces the asymmetrical advantage recently gained by attackers. More from the report
Read our Technology Report 2026 |