AI is shrinking cyber response windows from months to minutes
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 15th, 2026.
Defenders may have minutes, not months, to act as advanced AI speeds vulnerability discovery, attack planning, and data theft. ENISA says vulnerability weaponization may now occur within 15 minutes of disclosure. Research cited in its assessment puts the median time from initial access to data exfiltration at 72 minutes. That creates what the agency calls an authority gap, where an organization’s approval process takes longer than an AI-assisted attacker needs to move. AI may also combine several modest weaknesses into a practical attack path, changing how teams assess issues that look harmless in isolation. Traditional change processes could become the slowest part of defense, even when teams already know what to fix. But blind automation isn’t the answer because unverified patches can break critical services. Leaders need to define which defensive actions can run automatically and which still require accountable human approval. Defenders should improve asset inventory, prioritize exposed and exploitable systems, and target near-real-time detection and response. Measure decision latency now, then build guarded automation around the highest-confidence, highest-impact actions.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.