By Ashley Leonard
Malicious actors are already using AI to increase the speed and scale of cyber attacks, while many defenders are still relying on manual processes that simply can’t keep up.
Security teams remain overly committed to keeping humans in the loop for every decision, every alert, and every response. This approach worked when threats moved more slowly, but today it creates delays when organizations need to move faster.
Organizations must shift more operational control to automation while applying human expertise to oversight, guidance, and decision-making rather than manually carrying out every task.
Absolute Security’s latest research shows this strain clearly: 55% of CISOs experienced an attack in the past year that rendered endpoints used for remote or hybrid work inoperable, while many organizations are juggling dozens of disconnected security tools without achieving full endpoint visibility.
Legacy cyber security tools and manual strategies can no longer keep pace with an AI-driven threat landscape. Attackers are accelerating through automation, while defenders are still tied to workflows built for a slower era.
A core cyber resilience concept is that prevention alone is no longer enough. Organizations must be able to withstand disruption and continue operating even when systems are compromised.
The AI acceleration gap
Cybercriminals are no longer operating only manually. As they adopt automation and AI, their attacks are moving faster and on a greater scale, while most organizations are still relying on processes that need human intervention at every step.
61% of CISOs say the current combination of accelerating AI capabilities and changing regulations is making it harder to protect their organizations. While attackers move faster, the gap between what they can do and how quickly defenders can respond continues to widen.
Many modern threats are designed not just to breach systems, but to disrupt operations and weaken the security controls meant to stop them. The recent Stryker incident in Ireland is a clear example of this, as attackers managed to turn organizational security tools against the organization itself, exposing just how fragile environments reliant on manual processes can be under pressure.
Even when organizations have the right tools in place, those tools may not remain effective when systems are under strain.
Closing this gap means moving away from reactive defence and towards more autonomous, self-directed but well-governed systems, that can respond in real time and keep working without waiting for human input.
Why manual security fails
Today’s security teams are confronted with an impossible mixture of overwhelming complexity and uncertainty.
Nearly half of organizations lack visibility into how AI is being used inside their own environments, creating a growing shadow AI problem. Even more concerning, a significant majority of CISOs believe this lack of visibility will ultimately lead to a data breach.
This is not only about defenders giving up more operational control to automation, but also about recognizing that CISOs have blind spots within their own organizations.
Unmonitored AI use introduces risks such as malicious ‘skills’ in LLMs and prompt injection that can quietly bypass established controls. These behaviours often blend into everyday activity, making them harder to detect without stronger automated oversight.
At the same time, security teams are overwhelmed by the sheer volume of alerts and the complexity of disconnected security tools, leaving organizations vulnerable.
Automation as defence
If attackers are scaling through automation, defenders must do the same. Stopping threats is no longer the only concern; it is also about ensuring that systems remain operational and can recover quickly when incidents occur.
This is driving a change in priorities, with 65% of CISOs now prioritising cyber resilience over traditional prevention and detection strategies, emphasising a fundamental shift in how security effectiveness is measured.
As organizations adapt to this shift, it is becoming clear that today’s environments carry an inherent instability. The sense of control that security teams once had is now an illusion. Weaknesses can appear faster than human processes can react and, once they do, attackers often move before teams have a chance to respond.
Understanding this shift moves the focus from prevention to operational reliability and rapid recovery. As a result, maintaining continuity increasingly depends on automated systems that can respond and recover at machine speed.
Today, resilience is not only about preventing an attack, but also about how quickly systems can be restored and operations resumed, making automated recovery a critical capability.
Yet, nearly 20% of enterprise devices still can’t be reliably protected, updated, or recovered during disruption. That level of exposure is unacceptable in a world where attackers move at machine speed.
Built for failure
A resilient organization is one that assumes that failure is inevitable. In today’s environment of AI-driven attacks and constant disruption, cyber resilience must become a strategic priority rather than a secondary consideration. It can no longer remain just another industry buzzword, but must instead become a strategic imperative.
Organizations relying on manual processes risk being outpaced not just by attacks, but by the complexity of their own systems.
As AI accelerates both the speed and sophistication of threats, resilience must evolve as well, shifting towards intelligent capabilities that can adapt and recover at machine speed.
To prepare for the inevitable, organizations should apply concepts such as antifragility, chaos engineering, and Chaos Monkey testing when planning and testing for system-wide failure, rather than isolated incidents. This means considering scenarios where multiple tools fail, endpoints go offline, or visibility is lost.
Building resilience at a systemic level strengthens overall cyber readiness, enabling organizations to recover quickly and minimise downtime, even during significant disruptions.
Resilience becomes both a defensive strategy and a competitive advantage, moving the focus from preventing every attack to keeping the organization running under pressure.
Recovery is just as critical as prevention. It requires more than technology and demands close collaboration with DevOps and SRE teams to understand what truly keeps the organization running.
Practices such as chaos engineering, pioneered by Netflix, offer valuable inspiration by testing environments against real-world failure scenarios.
By proactively simulating outages and attacks, teams build the muscle memory needed for rapid and effective recovery, a core requirement in an era where attackers move at machine speed.
In the end, resilience is what gives an organization the ability to stay operational during disruption.
The author
Ashley Leonard is SVP of Product Management at Absolute Security.






