Blog
Aug 10, 2026
6 min read

As AI Compresses the Time to Compromise, We Must Compress the Time to Contain

By making cyberattacks faster, cheaper, and easier to scale, AI is shrinking the time between compromise and impact. This article explores why cyber resilience increasingly depends on security architectures that can contain attacks just as quickly—especially in OT and critical infrastructure.

Written By

Eran Shmuely

I recently returned from the annual Merlin Cyber Safari, and as always, it was a great few days. 

The Safari is a pretty unique event. It brings together founders, CISOs, investors, and some of the biggest names in cybersecurity in a setting that makes the conversations feel much more open than your typical conference. This year’s event included talks and discussions with leaders like Daniel Bernard from CrowdStrike, Lee Klarich from Palo Alto Networks, and many others. 

There was a lot to take away, but one conversation in particular has been running on replay in my head. 

Jason Clinton, Deputy CISO at Anthropic, spoke about how quickly AI capabilities are advancing. At one point, he said his team expects that within roughly nine months we could start seeing open-weight models reaching what he described as Mythos-level capabilities. 

Whether his timeline is exactly right isn't the interesting part for me. What caught my attention was what it means when capabilities that are currently available only through the most advanced AI models become broadly accessible. 

Someone asked Jason what security teams should be doing now to prepare. His answer was surprisingly simple: Zero Trust and network segmentation. 

This obviously resonated with me because of what we do at Cyolo, but I've also been thinking about why that answer makes so much sense.

How AI Is Changing the Economics of Attack 

I don't think the biggest change AI will bring to cybersecurity is necessarily some completely new type of attack. The bigger impact will come from the fact that AI makes many existing attacks cheaper and easier.  

Conducting a cyberattack has historically required significant time and expertise. Necessary steps include researching a target, finding vulnerabilities, creating convincing social engineering, understanding a compromised environment, discovering what to attack next, and adjusting when something doesn't work.  

AI can increasingly assist with, accelerate, or automate many of these steps. And when the cost of doing something goes down, you tend to get more of it. 

So we should probably expect more attacks, happening faster and carried out by more people. At least to me, this feels like the more substantial shift. 

And thanks to AI, not only will sophisticated attackers be able to work faster, but people who previously lacked the skills or resources to launch sophisticated attacks may suddenly be able to do things that were once out of reach.

The Time Between Compromise and Impact Is Shrinking 

Think about what happens after an attacker gets a foothold. They need to understand where they are. Discover systems. Find credentials. Identify valuable targets. Figure out which machines can communicate with which others. Move laterally. Escalate access. 

Simply put, there’s a lot of work between getting in and actually achieving an objective. Historically, much of that work required a human in the loop. 

Increasingly, that won’t be the case. 

If AI can help automate more of that journey, then the important change isn't just that compromise becomes easier. It's that the time between compromise and impact gets compressed. 

For me, this is where things start to get really interesting.

For a long time, cybersecurity has centered around one question: How do we stop attackers from getting in? Obviously, we should keep trying to do that. 

But if attacks become dramatically more frequent and attackers can move much faster once they're in, then betting everything on preventing every compromise becomes an increasingly risky strategy.

Going forward, success will depend more than ever on what happens after the initial compromise. How quickly can defenders detect the threat, contain it, and prevent it from becoming a widespread incident?

Containment is Becoming the Critical Race

This is where Jason's recommendation to focus on zero trust and segmentation really clicked for me. Neither of these is a new concept, and neither was invented because of AI. That’s actually what I find most interesting.

If an endpoint gets compromised but can communicate with only a handful of explicitly authorized systems, the attacker has a much smaller environment to work with. Likewise, if a contractor's credentials are stolen but only grant access to the specific application or machine they need, those credentials have far less value to an attacker.

None of this means the original compromise didn't happen, but it does mean it's much harder for that compromise to become something bigger.

As AI compresses the attacker's timeline, this distinction grows in importance. Attackers will have less time between gaining access and achieving their objective, leaving defenders with less time to detect, respond, and contain the threat.

That means security increasingly becomes a race between impact and containment. Can the attacker achieve their objective before defenders like us isolate the compromise?

How Critical Infrastructure Changes the Equation

All of this matters even more in OT and critical infrastructure. Industrial environments contain many systems that can't be patched immediately (or at all). Some are old, some are fragile, and others can't easily be taken offline. Many were built long before anyone imagined today's AI-driven threat landscape.

When an attack on critical infrastructure succeeds, the consequences are likely to extend far beyond data loss. Production can be disrupted, vital services interrupted, and, in some cases, physical safety put at risk.

This is why trying to eliminate every possible vulnerability is doomed to be a losing game. In OT environments, containment is at least as important as prevention. Security teams must consider—and plan for—what happens after a system is compromised.

Can one compromised workstation reach an entire production network?

Can an attacker move freely between environments?

Can credentials intended to maintain one machine be used to access ten others?

Or does your security architecture allow the problem to remain small?

To me, this is what cyber resilience is really about. 

My Biggest Takeaway

I left this year’s Safari thinking less about the exact capabilities of the next generation of AI models and more about what they do to time. 

AI makes the attacker faster. It makes expertise cheaper.  And it means security teams are going to be dealing with more attacks in less time. 

We won't win that game by assuming we can prevent every compromise. 

Instead, we need architectures that make it difficult for a compromise to become an incident. 

That's a major reasons Jason’s talk resonated so much with me. At Cyolo, we spend a lot of our time thinking about these exact problems: limiting access to what is actually needed, reducing unnecessary connectivity, segmenting environments, and making it easier to contain attacks when they occur.

But the lesson extends well beyond any one product or technology.

It's a shift in how I think about cyber resilience—and how I think we need to approach it in an AI-driven world.

Because AI is compressing the time to compromise, our job is to compress the time to contain.

And if the predictions we heard at Safari prove even partially true, there's no better time to start.

OT Security Fundamentals Hold Strong Against AI-Assisted Cyberattack

 

Eran Shmuely

Author

Eran Shmuely is the Chief Architect and Co-Founder of Cyolo. Prior to Cyolo, Eran was the Senior Security Engineer at Salesforce and the Open-Source Security Research Leader at GE Digital.

Subscribe to Our Newsletter