When AI takes over the attack chain: why "fully patched" is no longer a guarantee
Cybersecurity is undergoing a fundamental shift. The trigger lies less with the attackers themselves than with the tools available to them. A guest article in the trade publication Security-Insider describes a new class of specialized AI models. They no longer merely assist with individual tasks; they plan and execute a complete attack chain on their own: from finding vulnerabilities to building the exploit to the actual exploitation. Human defenders can hardly keep up with the pace. When AI takes over the chain, being patched is no guarantee anymore.
For companies, this brings an uncomfortable realization: the status "fully patched" no longer works as a reliable security indicator; it is merely a snapshot. Anyone relying on it alone is defending against yesterday's threat. We have put the article's key statements into context and show what they mean in practice and what, from our perspective as a managed security service provider, matters most now.
What makes up an attack chain, and why AI is changing it
A cyberattack is rarely a single moment. It is usually a chain of steps. Classically, it can be roughly divided into phases: reconnaissance of the target, finding an initial entry point, exploiting a vulnerability, establishing a foothold in the system, spreading sideways through the network (so-called lateral movement), and finally the actual objective: data theft, encryption, or sabotage. Until now, each of these steps required time, experience, and often several specialists.
This is exactly where the new model generation comes in. It can consolidate several of these phases and run through them automatically. What used to be a division-of-labor process spread over days is compressed into a largely autonomous sequence. The difference is not just speed; there is also the ability to think in context: instead of looking at a vulnerability in isolation, the models examine how it can be combined with other gaps into a working chain.
What changes with specialized AI models
The article names concrete examples of this new model generation, such as Anthropic's "Claude Mythos" or a competing system referred to as "GPT-5.5-Cyber" tailored specifically to security tasks. The individual names matter less than the shared pattern: these systems are so capable that parts of them are not made publicly available at all, for security reasons. They can identify vulnerabilities that went undetected for years and use them immediately to execute attacks.
Three shifts stand out. First, the barrier to entry: attacks that used to require deep specialist knowledge and a lot of manual work can increasingly be delegated to a model; the expertise is baked into the tool. Second, the volume: AI generates masses of adaptive attack variants that deliberately slip past traditional, signature-based detection. Third, the reach: once a gap is found, exploitation follows quickly and broadly across entire attack surfaces instead of slowly and selectively.
The "mean time to exploit" shrinks to under a day
Perhaps the most important metric in this context is the "mean time to exploit": the average span between a vulnerability becoming known and its active exploitation. According to the article, this value drops below one day in 2026. Just a few years ago, it was weeks or months.
A simple example shows what this means in practice: if a critical vulnerability is published on a Friday evening, an automated system can be running working attacks against every reachable, still unpatched system by Saturday morning. A maintenance window on Monday comes too late. The window between "vulnerability known" and "vulnerability exploited" is no longer a buffer zone you can plan around.
Why "patched" no longer means "secure"
Traditional security cycles assume there is enough time between the release of a patch and the first widespread attack to react. That assumption is falling away. When a new vulnerability is exploited within hours, a monthly or weekly patch window is no longer enough. Even a cleanly patched system is only secure until the next gap becomes known.
"Fully patched" thus describes a state that can already be outdated the moment it is established. This emphatically does not mean patch management becomes obsolete. On the contrary: it remains mandatory and is the foundation of any serious defense. But it loses its role as the sole, or even the most reliable, line of defense.
Prevention alone loses the race
The consequence is uncomfortable but clear: prevention alone wins no race against an adversary that works automated and around the clock. A wall built ever higher helps little when the attacker can generate the ladder in seconds. The question "How do we keep attackers out?" is therefore joined by a second one: "How quickly do we notice that someone is inside, and how tightly do we limit the damage?".
This puts a second metric center stage: dwell time. How long can an attacker operate undetected in the network, and how far do they spread in that time? Cutting this span from weeks to hours or minutes turns a potential total loss into a manageable incident.
The focus shifts: from prevention to detection and response
The logical conclusion the article draws: the focus has to shift. Not away from prevention, but much more strongly toward the ability to detect an ongoing attack early and contain it quickly. In the future, success will be measured less by the number of blocked attempts than by the time to detection and the time to an effective response.
That requires continuous visibility across all data flows, detection based on behavior instead of rigid signatures, and well-rehearsed response processes that kick in without lengthy searching when it matters. This combination can be delivered far more reliably as a managed service than by a small internal team that hits its limits at night and on weekends, precisely when automated attacks are most active.
Our answer: Zero Trust microsegmentation
When not every attack can be prevented anymore, what happens after the first successful step becomes decisive. This is where one of our core services comes in: Zero Trust microsegmentation. The basic idea is to contain attacks before they spread, denying the automated attacker the very step that turns a single compromised machine into a company-wide incident.
The core idea of Zero Trust is simple: no access is implicitly trusted, every connection is verified. Traditional networks are often flat on the inside: once you are in, you can move relatively freely. Microsegmentation reverses this principle: it divides the network down to the level of individual workloads and allows only the connections that are actually needed. Everything else is blocked.
For an automated attack, this massively complicates lateral movement, the very step the new AI models orchestrate so efficiently. If that spread is blocked or slowed, the intended wildfire often remains a locally contained fire that monitoring detects and boxes in early enough.
This is how we approach it at KAEMI:
- Visibility first: we make all data flows and dependencies between applications visible, the foundation of any meaningful segmentation.
- Least privilege down to the workload level: each application may only communicate with what it really needs. Paths that are not required are consistently closed.
- Implemented to fit: we choose the segmentation technology based on the environment's requirements, not on a product line.
- Delivered as a managed service: rules are continuously monitored, adjusted, and hardened. Segmentation is an ongoing task, not a one-off project.
How we implement Zero Trust microsegmentation in concrete terms is shown on our microsegmentation page .
Backups and recovery, the last line of defense
Even with the best detection and containment, you have to assume that at some point an attack will get through. That is why the article rightly emphasizes the fundamentals, which include regularly tested offline backups. The key word is "tested": a backup that cannot be cleanly restored in an emergency is not a safeguard, just a hope.
Especially important are backups an attacker cannot encrypt or delete along the way, meaning backups physically or logically separated from the production network. They are the insurance against a ransomware attack hitting the lifeline together with the production data. In the end, a rehearsed recovery plan decides whether an incident costs hours or weeks.
What companies should do now
The Security-Insider article recommends a series of pragmatic steps that match our experience from day-to-day managed services:
- Assess your readiness honestly: use a gap analysis to determine where detection and response stand today: in a real incident, not just on paper.
- Rehearse the emergency: run regular tabletop exercises so that in a real incident it is clear who decides what and in which order to act.
- Shift the focus: steer investments from pure prevention more toward detection and response, without abandoning the fundamentals.
- Keep the fundamentals: consistent patch management and regularly tested offline backups remain indispensable, especially backups an attacker cannot encrypt along the way.
- Limit the spread: use Zero Trust segmentation to ensure a single compromised system does not drag down the entire network.
- Create structures: define clear decision paths, responsibilities, and budgets so that in an emergency, seconds count rather than questions of who is in charge.
Especially relevant for midsize companies
For large corporations with their own security operations center, around-the-clock monitoring and rapid response are a question of resources. For midsize companies, this is the real challenge: the threat is the same, but an in-house team ready to respond at night, on weekends, and on holidays is hard to maintain economically.
Automated attacks, however, pay no attention to business hours. They prefer to strike when no one is watching. A managed service closes this gap: it provides the capabilities of a large security team as a service, without every company having to build them individually.
Security becomes a question of the ability to act
The article's central message: what matters is less a detailed understanding of every new technology than the ability to respond to threats quickly and in a coordinated way. Cybersecurity thus also becomes a question of digital sovereignty: control over your own ability to respond, regardless of how fast the attackers' tools evolve.
This is where our managed services come in. As a managed security service provider, we take on monitoring, containment, and response around the clock, with Zero Trust microsegmentation as the core building block, continuous monitoring, and clearly agreed response times. Microsegmentation ensures that a successful first step does not engulf the entire company; monitoring ensures it gets noticed in the first place; and well-rehearsed response processes stop the damage before it grows.
This keeps a company able to act even when attacks unfold faster than traditional processes can react. It works not because every threat can be prevented, but because in an emergency every move is practiced and the spread is contained from the outset. If you want to know how resilient your own segmentation and response capability is today, we offer a good starting point: in a joint analysis workshop, we make data flows, attack surfaces, and gaps visible and derive concrete next steps from them.
The full guest article (in German) was published at Security-Insider: AI models and attack chains .