AI-powered attacks push cybersecurity patch windows down to hours
Security leaders warn AI-powered attacks are outpacing defenses even as human judgment remains impossible to replace
Security teams that once had 30 to 60 days to patch a critical vulnerability now have as little as 12 to 24 hours, according to cybersecurity leaders who track how artificial intelligence (AI) is accelerating the pace of cyberattacks.
Attackers are automating individual stages of an intrusion rather than the whole attack at once, cybersecurity leaders say, compressing the time between a flaw’s discovery and its exploitation.
“We’re no longer in this 30-day, 60-day window of time where we’ve got time to patch,” said Spencer Scott, head of information security at RPC LLP. “We are literally in this 12-hour, 24-hour window, and that’s only what’s publicly being disclosed through Anthropic and OpenAI.”
He said the shift followed a conversation with a vulnerability management provider about AI-powered exploitation, in which even a major, unnamed AI vendor was already grappling with the same shrinking window.
“Threat actors are using bits of the kill chain and automating each part rather than going from A to Z,” said Ellie Hallam, senior analyst in cyber defense at McDonald’s. “Things are speeding up so much more, and it’s much more difficult for us as defenders to catch things before they become a significant risk to the business.”
Alice Smith, senior cyber threat intelligence analyst at Live Nation Entertainment, said AI is often dismissed as a buzzword but has become essential for cutting through the volume of data security teams now face.
She pointed to MITRE ATLAS, a framework cataloging attacks against AI systems, as evidence that AI models themselves are now part of the attack surface.
Matt Gregory, information security director for managed hotels at IHG, said the pattern of attackers and defenders adapting to one another has held throughout his 20 years in the industry. New tools make detection easier, he said, but human oversight has not gone away.
Lee Clark, manager of cyber threat intelligence (CTI) production at the Retail and Hospitality Information Sharing and Analysis Center, said his team applies a simple test before automating any part of its intelligence process.
Machines can produce and process intelligence with human safeguards built in, he said, but any decision ultimately acted on by people requires people to be involved throughout the process.
The center shares threat intelligence in real time among member companies across retail, hospitality, travel and other consumer-facing sectors.
Scott said his own team ran a six-month vendor review to add AI-assisted detection tools, aiming to let automation handle routine analyst work so people can focus on the judgment calls that still require them.
Humans still hold ground
The panel, titled Communal Defense: Tracking and Responding to Cyber Threat Trends Across Industries, took place at Infosecurity Europe 2026 in London, organized by Reed Exhibitions. Clark moderated the discussion, bringing together security leaders from consumer-facing industries to discuss how evolving threat landscapes are reshaping defense strategies across sectors.
Joining him were Hallam, Gregory, Smith and Scott, representing fast food, hotels, live events and law. All four agreed that AI has not displaced the need for experienced analysts.
“We’re not going to lose our jobs to machines,” Hallam said. “SOC (Security Operations Center) line one is mostly automated now, but you still need SOC line two and three analysts. You’re always going to need the human element to control the AI.”
Scott described the relationship as continuous supervision rather than blind trust.
“It’s not human in the loop, it’s human on the loop,” he said. “It’s a continuous review of what’s happening with AI as a partner, until you feel confident it can take those low-level tasks with complete certainty it’s doing the right thing and not hallucinating or going outside the guardrails. We’re not there yet.”
Gregory answered with an older phrase: trust but verify.
Smith closed the point with the panel’s broadest defense of human judgment.
“Humans are amazing,” she said. “Every single person in this room has something to bring to the table that’s never going to be replaced by AI. You know your organization's culture, read the room and understand the nuances. AI can organize the data for you, but especially in intelligence, there has to be a human there making that judgment.”
Familiar threats are also mutating.
“A lot of the same things are coming back around again,” Gregory said. “Phishing has never gone away, and if anything it’s evolving constantly.”
Scott said his sector is seeing a shift toward impersonation.
“We’re seeing an uptick in deepfake and voice cloning,” he said. “This is where we have people impersonating C-suite, joining Teams calls or calling over the phone, pretending to be the managing partner asking for help through a WhatsApp message. There’s also the vishing attacks (phone scams) to the service desk.”
He said he saw similar attacks firsthand at a previous employer, prompting new staff training.
Hallam said the same automation is fueling voice-cloning scams that increasingly target remote workers.
“If you have an organization that’s reliant on remote workers, you’re far more likely to fall victim to that because they’re so good at using AI voice cloning,” she said. “Now you need three seconds of voice to clone somebody’s voice. I think that’s remarkable and scary and difficult for defenders like us.”
Clark said his organization tracks two dominant clusters of activity across member companies: call center social engineering, in which attackers impersonate employees to reset multi-factor authentication and steal data, and Famous Chollima, the category for North Korean government employees who use false identities to gain jobs at Western organizations.
Building trust across silos
Getting security leaders to invest also depends on proving intelligence has value, not just producing it.
“It has to be actionable intelligence,” Hallam said. “If the intelligence isn’t actionable and it’s just noise. It’s not useful to the members of your organization who need to use it.”
Clark said that pressure is constant.
“As a cyber intelligence officer, your name is red on the budget spreadsheet always,” he said. “We’re not sales; we don’t produce value in that way. So if you’re making the executive’s job harder by producing noise, then it gets redder and redder over time.”
Smith, whose team is relatively new to the discipline, said proving value often comes down to small wins, such as showing leadership that a recommended change made an attacker’s method stop working. He added that feedback tends to arrive only at the extremes, leaving teams unsure how they are doing in between.
Communication, more than organizational charts, was named as the hardest barrier to break. She said a poorly worded intelligence bulletin can trigger an unnecessary incident response if it does not make clear that a threat is not yet active.
Scott recalled working at a company with business units that operated almost independently across Asia.
“I’ve worked for an organization that had parts of the business that were decentralized, so they were literally little islands on the outside while we were at the core,” he said.
He said it took a long process to persuade a regional managing director to accept centralized security policy, until leadership accepted that a breach in a smaller unit was still a reputational problem for the wider brand.
Clark said the fix has to happen before an incident, not during one.
“One of the things we see the most is organizations not establishing relationships in advance of an incident,” he said. “If you build this into incident response processes and practice them in advance, the intelligence team and the legal team already know each other, and that helps build trust.”
Regulatory pressure is also reshaping how firms operate across borders, particularly for Scott’s law firm, RPC, which has offices in the UK and Asia.
“Regulation comes from the SRA (Solicitors Regulation Authority) here in the UK, and there’s a separate regulating body in Asia,” he said. “I think regulation is what keeps us honest.”
Singapore’s forthcoming Cyber Trust Mark, similar to the UK’s Cyber Essentials Plus, is one benchmark RPC is working toward, though Scott said clients now push harder than regulators do.
Gregory said keeping pace with shifting rules is a job in itself, evolving everywhere at once.
For a panel that spent much of its hour on AI, the consensus was that the technology remains a tool rather than a replacement. Panelists said the next test will be whether security teams can shrink their response times as quickly as attackers have.



