Advertisement

Cybersecurity strategies shift towards continuous threat monitoring

Traditional cybersecurity models are facing mounting pressure as artificial intelligence accelerates cyberattacks, forcing organisations to replace periodic security assessments with continuous monitoring, faster vulnerability management and automated responses.

New industry findings and expanded artificial intelligence security programmes highlight a widening gap between the speed of attackers and the ability of businesses to identify and contain threats.

Anthropic announced on October 6 that it was expanding access to advanced artificial intelligence models for cybersecurity professionals through a revamped Cyber Verification Program. The initiative follows vulnerability discovery work that identified at least 129,000 verified software weaknesses between April and July, including 33,000 classified as critical or highly severe.

The programme provides security specialists with advanced models for vulnerability research, incident response, malware analysis and authorised penetration testing. Access arrangements include additional safeguards for sensitive systems, reflecting concerns about powerful technology being misused for offensive operations.

The development underscores growing recognition that conventional defences built around scheduled audits, perimeter protection and delayed patching cannot independently address increasingly automated attacks.

Verizon's 2026 Data Breach Investigations Report found that exploitation of software vulnerabilities accounted for 31% of breaches examined, overtaking stolen credentials as the leading initial entry method for the first time in the report's history.

The findings also exposed a persistent weakness in remediation. The median time required to resolve identified vulnerabilities increased from 32 days to 43 days, extending the period during which attackers could exploit known security gaps.

Only 26% of critical vulnerabilities listed in the US Cybersecurity and Infrastructure Security Agency's catalogue of known exploited weaknesses were fully remediated during 2025, compared with 38% the previous year.

These figures reinforce the case for continuous exposure management, an approach that identifies vulnerable assets, evaluates their importance and prioritises corrective action according to the likelihood and potential consequences of exploitation.

Unlike conventional vulnerability scanning conducted at fixed intervals, continuous exposure management examines changing infrastructure, cloud services, applications and external connections as potential entry points for attackers.

Security specialists increasingly distinguish between discovering weaknesses and determining which vulnerabilities represent immediate operational danger. A critical flaw affecting an isolated system may present less practical exposure than a moderately rated weakness in an internet-facing application.

Artificial intelligence is also changing the financial consequences of cyber incidents.

IBM's 2026 Cost of a Data Breach Report found that one quarter of malicious breaches involved AI-enabled techniques, representing a 56% increase over the preceding year. Such incidents generated average organisational costs of approximately $6 million.

The research identified deepfake impersonation and AI-enabled malware among the principal techniques associated with this expansion. It also found that organisations deploying artificial intelligence and automation extensively in security operations achieved substantially lower breach costs than those without comparable capabilities.

However, automation introduces its own governance requirements. Security teams must ensure that automated responses do not interrupt essential services, remove legitimate access or act on inaccurate threat assessments.

The expanding use of artificial intelligence within businesses presents another challenge. Employees increasingly interact with external models, automated assistants and connected applications that may operate outside established corporate security controls.

Unapproved systems can expose confidential information, introduce additional access permissions and complicate investigations when sensitive data moves between services.

Consequently, identity management, application inventories and monitoring of machine-generated activity are becoming important components of enterprise security programmes.

Continuous visibility also depends on reliable information about third-party suppliers. External software providers, cloud platforms and business partners can create pathways into otherwise protected networks.

Verizon's findings identified substantial exposure associated with supply chains, strengthening the argument for monitoring dependencies beyond an organisation's immediate infrastructure.

Nevertheless, established security measures remain essential. Multifactor authentication, secure configuration, network segmentation, reliable backups and prompt installation of security updates continue to reduce opportunities for attackers.

The emerging distinction concerns how these protections are managed rather than whether they should be abandoned. Continuous assessment can help organisations identify failing controls before weaknesses develop into serious incidents.

For smaller organisations, the transition presents practical difficulties involving staffing, expenditure and the integration of security tools. Automated monitoring systems also generate alerts that require investigation, making prioritisation important.

Regulatory obligations add another dimension, particularly where automated systems process personal information or operate across jurisdictions with differing privacy requirements.

Security teams must therefore maintain records of automated decisions, establish human oversight for consequential actions and regularly test whether detection systems perform as intended.

The expanded Anthropic programme includes specialised access for vetted organisations examining safety-critical environments, including electricity infrastructure and flight systems, where testing requires additional controls to prevent operational disruption.
Previous Post Next Post

Advertisement

Advertisement

نموذج الاتصال