The window between vulnerability disclosure and exploitation is disappearing. What organisations once measured in weeks is increasingly measured in days and, in some cases, hours.
Andre den Hond, a cyber security professional and Solutions Architect at Arctic Wolf, believes artificial intelligence is reshaping an already sophisticated threat landscape.
“AI is accelerating cyber risk. We’ve already seen ransomware evolve from manual attacks to scripted automation and then to Ransomware-as-a-Service. Agentic operations are the next phase of that evolution.”
He adds that we can think of it almost as the Wright Brothers moment for agentic cybercrime.
“It’s not yet the dominant model for ransomware operations, but it demonstrates that autonomous AI-driven orchestration is feasible in the real world.”
The significance of that moment isn’t that cybercrime has suddenly changed overnight. It’s that attackers have shown autonomous AI-driven attacks are feasible in the real world, and den Hond argues the pace of change will only accelerate from here.
What concerns him most isn’t simply the technology itself, but what it does to the economics of cybercrime.
“A traditional ransomware attack is sequential with human-led operations, whereas an agentic attack performs operations autonomously at machine speed. Humans get tired. Machines don’t.”
For years, ransomware attacks depended on skilled operators, time and coordination. AI agents reduce the skill and effort required, allowing one operator to supervise multiple campaigns at the same time.
“The most expensive part of an attack today is the human effort required between initial compromise and business impact. That’s where agentic AI adds the most value to attackers.”
As that human effort falls away, he has no doubt that malicious campaigns will become more prolific.
“There will most certainly be more attacks. The reason is cost. A ransomware attack no longer requires skilled operators, time, coordination and supervision.”
While much of the discussion around AI-enabled cybercrime has centred on incidents overseas, den Hond is convinced South African organisations risk underestimating how quickly these threats will become relevant locally.
“I don’t think companies in South Africa have fully realised just how impactful this could potentially be for them.”
It’s an easy assumption to make. Sophisticated cyberattacks are often seen as something that happens to large organisations overseas, creating the perception that local businesses still have time to prepare. Den Hond stresses that they couldn’t be more wrong.
“Cybercrime doesn’t discriminate. It doesn’t care where you live, what industry you’re in or how big your organisation is. Every organisation has an online presence to some extent, which means every organisation is a potential target.”
If attackers are evolving, he warns that defenders need to evolve too.
“Gone are the days where we can have a tactical approach to cybersecurity. We’ve got to be proactive. We’ve got to have the adaptability of speed and security because this is effectively the start of what AI is going to do, and it’s only going to accelerate.”
That acceleration creates another challenge.
“Cyberattacks are becoming increasingly automated and the time from vulnerability identification to exploitation is shrinking drastically. Security teams will get to a point where they simply cannot patch vulnerabilities fast enough.”
For him, that doesn’t mean patching becomes less important. It means organisations need to become far more deliberate about where they focus their remediation efforts.
“Companies can’t just tackle risk based on the CVSS vulnerability score alone anymore. They need to understand the actual exposure risk to the organisation, taking into account the business context, the user context and the exploitability of that risk. They need to know exactly where to focus their remediation efforts.”
Even as AI changes how attacks are launched, he emphasises that the fundamentals of cybersecurity remain unchanged.
“If you strip away the AI element, the attack still succeeds because of familiar security failures. If you haven’t solved the fundamentals, AI will exploit those weaknesses faster than humans.”
That means continuing to harden systems, fix vulnerabilities, secure identities and reduce unnecessary exposure across the attack surface.
Where organisations do need to rethink their approach is in how they defend themselves.
“If attackers are beginning to move at machine speed, organisations need a defence strategy that operates at machine speed too.”
That thinking led Arctic Wolf to reinvent its traditional Security Operations Centre, moving to an agentic-led framework where AI handles detection, investigation and response workflows at machine speed while experienced security specialists remain responsible for judgement and oversight.
“The agents are built into the platform, not bolted on. They’re trained on our SOC domain expertise built over the last 14 years. They know what to do because of our data.”
For boards, the conversation also needs to evolve.
“If I were briefing a board after the emergence of agentic AI threats, I wouldn’t ask whether we have an AI strategy. I’d ask whether our security model assumes attackers operate at human speed or machine speed. How quickly can we contain an attacker operating at machine speed? Do we know exactly when and where to focus our remediation efforts?”
The Wright Brothers proved powered flight was possible. Agentic AI has just done the same for the next generation of cyberattacks.
“What’s emerging today is only the start. The technology will continue to evolve, and so will the attackers using it. The challenge for defenders is to ensure they evolve just as quickly.”
Three actions security teams can take today
Review your vulnerability priorities – Don’t assume every critical vulnerability deserves the same response. Reassess your remediation priorities using business context, exploitability and exposure, not just CVSS scores.
Measure your response speed – Ask how long it would take your team to detect, investigate and contain an attacker operating at machine speed. Where manual processes slow you down, look for opportunities to automate.
Revisit the fundamentals – Pressure-test your identity controls, privileged access, patch management and attack surface. AI doesn’t create new weaknesses; it exploits existing ones faster.