GROW YOUR STARTUP IN INDIA
Image generated by The Tech Panda using Nano Banana 5

SHARE

facebook icon facebook icon

A cyberattack has traditionally involved a series of steps: identifying a target, mapping its environment, finding an exploitable weakness, gaining access, and determining how far that access can be extended. Each of these steps takes time. AI is beginning to compress that entire cycle.

Security teams are already responsible for thousands of endpoints, applications, identities, cloud workloads, network devices, and connected operational systems. If the time between identifying a weakness and attempting to exploit it continues to shrink, the time available to detect, investigate, and contain an attack shrinks with it.

Reconnaissance that once required considerable manual effort can now be automated. Publicly available information can be analysed at scale, vulnerabilities can be matched against exposed infrastructure more quickly, phishing attempts can be tailored to individual targets, and malicious code can be modified repeatedly when an initial attempt fails. The result is not necessarily a new category of cyberattack, but a much faster and more adaptable adversary.

This distinction matters because most enterprise security environments were not designed around an attacker capable of modifying tactics at this pace. Security teams are already responsible for thousands of endpoints, applications, identities, cloud workloads, network devices, and connected operational systems. If the time between identifying a weakness and attempting to exploit it continues to shrink, the time available to detect, investigate, and contain an attack shrinks with it.

The numbers indicate that this is already becoming a practical security concern. According to IBM’s 2026 Cost of a Data Breach Report, 26% of malicious breaches in India were AI-generated. The average cost of a data breach in the country also reached ?25.5 crore, an increase of 15.9% over the previous year.

For security leaders, the question is therefore no longer whether AI will influence cyberattacks. The more pressing question is whether existing security architectures can detect and contain an adversary that can operate, learn, and adapt considerably faster than before.

The Window Between Discovery and Exploitation Is Shrinking

One of the clearest signs of this shift can be seen in vulnerability exploitation. The Verizon 2026 Data Breach Investigations Report found that exploitation of vulnerabilities accounted for 31% of breaches, overtaking credential abuse as the leading initial access vector for the first time in the report’s history. The report also points to the growing use of AI by threat actors to accelerate the exploitation of known vulnerabilities.

This presents a difficult operational challenge for enterprises. Large organisations may have thousands of applications, endpoints, APIs, cloud workloads, network devices, and connected assets. When a vulnerability is disclosed, security teams first have to determine which systems are affected, assess their exposure, understand dependencies, prioritise critical assets, test remediation, and deploy patches without disrupting business operations.

Attackers face none of these operational constraints. AI can help automate reconnaissance across exposed infrastructure, correlate vulnerability information with potential targets, assist in modifying exploit techniques, and test multiple routes into an environment. What previously involved significant manual effort can increasingly be executed at greater speed and scale.

Patching therefore remains fundamental, but organisations cannot assume that every vulnerability will be remediated before somebody attempts to exploit it. There will always be a period between vulnerability discovery and remediation, particularly in complex enterprise and operational environments. Security controls need to protect the organisation during that window and limit what an attacker can access even if the first line of defence is breached.

Detection Cannot Depend Only on Known Patterns

Firewalls, endpoint protection, identity controls, vulnerability management, segmentation, and access management remain essential components of enterprise security. The limitation arises when detection depends too heavily on known signatures, static rules, or previously observed indicators of compromise.

An AI-assisted attacker can vary payloads, communication patterns, infrastructure, and attack sequences more rapidly. Even small modifications can make malicious activity appear different from previously observed attacks while the underlying objective remains unchanged. Security teams therefore need to understand behaviour in addition to matching activity against known attack patterns.

A suspicious outbound connection, for instance, may not indicate an attack by itself. Neither would a device communicating more frequently than usual or an employee account accessing a different system. But when these events occur together, along with changes in network traffic, authentication behaviour, or data movement, they can indicate reconnaissance, lateral movement, command-and-control activity, or an attempt to exfiltrate information.

This is where behavioural baselining becomes important. Organisations need to understand what normal communication and activity look like across users, devices, applications, and networks so that deviations can be identified early. In an environment where attack techniques can change rapidly, recognising abnormal behaviour can provide an important layer of defence even when the specific attack method has not been encountered before.

Security Has to Follow the Data

Modern enterprise infrastructure is highly distributed. Information moves continuously between users, applications, cloud environments, data centres, branch locations, IoT devices, operational systems, and third-party platforms. In critical infrastructure, these connections may extend further to signalling equipment, sensors, control systems, surveillance networks, and remote assets.

Yet security controls are still frequently concentrated around endpoints and the perimeter. This creates a problem because attackers rarely remain at the point where they first gain access. Once an endpoint, application, or credential has been compromised, the attacker begins looking for other systems that can be reached, privileges that can be elevated, and information that can be accessed.

Protecting data while it moves across the network therefore becomes as important as protecting the systems where it originates or is stored. Encryption is central to this, particularly when sensitive information is travelling across distributed or untrusted networks. At the same time, security teams need an understanding of how systems are communicating so that unusual connections, unexpected data flows, and lateral movement can be identified.

This requires treating the network as part of the security architecture rather than simply as the transport layer between security products. Secure communication, segmentation, encryption, network telemetry, and behavioural analysis need to work together so that a compromised system does not automatically become a pathway to the rest of the environment.

IT-OT Convergence Raises the Stakes

The challenge becomes considerably more complex in critical infrastructure, where traditional IT systems increasingly interact with Operational Technology. Railway networks, telecom infrastructure, power systems, manufacturing facilities, airports, and other industrial environments now combine control systems with IP-based networks, remote connectivity, cloud applications, sensors, IoT devices, and central management platforms.

This convergence improves efficiency and enables operators to manage infrastructure at a scale that would otherwise be difficult. It also means that systems designed at different points in time and for very different purposes increasingly communicate with each other.

An operational environment may contain equipment designed to remain in service for decades alongside modern connected systems. Some assets cannot be patched frequently, while others may use legacy protocols or have strict availability requirements. Taking a system offline to deploy an update may be straightforward in an enterprise IT environment but impossible when that system controls an industrial process, railway operation, or another essential service.

Security in these environments therefore has to account for operational requirements as well as cyber risk. Availability, integrity, and predictable performance are critical, which means security controls cannot introduce latency, instability, or disruption into systems that are expected to operate continuously.

This makes segmentation, secure communication, and continuous monitoring particularly important. If an attacker compromises one part of an environment, security teams need to know which systems it can communicate with, whether those interactions are legitimate, and whether unusual traffic indicates an attempt to move from an IT environment towards more sensitive operational assets.

As AI accelerates reconnaissance and attack activity, understanding these relationships becomes even more important. Detecting an individual compromised device is useful, but understanding how that compromise could propagate through interconnected infrastructure is what allows an organisation to contain the incident before it affects critical operations.

AI Has a Role on Both Sides of the Security Equation

The same capabilities that allow attackers to process information and adapt techniques more quickly can also strengthen cyber defence. Large organisations generate enormous volumes of security telemetry across endpoints, identity systems, applications, networks, cloud environments, and operational systems. The challenge for security teams is determining which signals indicate genuine risk and which are simply part of normal activity.

AI can help correlate activity across these sources, establish behavioural baselines, identify deviations, and detect relationships that may be difficult for analysts to recognise manually. For example, an authentication anomaly may appear relatively minor until it is correlated with unusual network communication, privilege escalation, or unexpected data movement involving the same account or device.

The value of AI in security therefore lies less in generating another layer of alerts and more in improving the context around those alerts. Security teams need to know what changed, which assets are involved, how those assets are connected, and whether the activity represents a meaningful deviation from normal behaviour.

This does not remove the need for human expertise. Cyber incidents often involve business, operational, and risk considerations that cannot be determined from telemetry alone. Security teams still need to decide whether a system should be isolated, whether an operational process can be interrupted, how an incident should be contained, and what the wider business impact could be. AI can accelerate the analysis, but these decisions require organisational context and judgement.

Building Security for a Faster Adversary

The response to AI-enabled attacks should not be to discard existing security practices. Strong identity management, vulnerability management, endpoint security, segmentation, encryption, access control, and patching remain fundamental. What needs to change is how these controls work together and how quickly organisations can identify behaviour that falls outside what is expected.

Enterprises also need to design for the possibility that prevention will fail. A compromised credential, an unpatched vulnerability, or an exposed device should not automatically provide an attacker with access to a wider environment. Segmentation, encrypted communications, least-privilege access, continuous monitoring, and behavioural analysis can help limit the impact of that initial compromise.

For critical infrastructure, these principles need to be incorporated into the network and system architecture from the beginning. Security cannot depend solely on controls deployed at the perimeter when data and commands are continuously moving between IT systems, operational assets, cloud platforms, remote devices, and third-party environments.

The growing use of AI by attackers ultimately changes the speed at which security decisions need to be made. An organisation may have extensive security telemetry and multiple layers of protection, but their value diminishes if suspicious behaviour cannot be connected and understood quickly enough to contain an attack.

The next phase of cybersecurity will therefore depend on an organisation’s ability to understand its environment continuously, secure communications as data moves across it, recognise deviations from expected behaviour, and restrict how far a compromise can travel. As attackers gain tools that allow them to operate faster and adapt their methods more readily, defensive architectures will have to become equally capable of responding at that speed.

Guest author Srinivas Shekar is the Co-founder and CEO, Pantherun Technologies, a deep-tech cybersecurity company, specialised in patented real-time data encryption technology. Any opinions expressed in this article are strictly those of the author.

SHARE

facebook icon facebook icon
You may also like