AI Changed The Economics Of Cybersecurity: CEOs Need To Change The Equation

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Investment alone is an increasingly poor proxy for resilience, and the more important question is becoming, "How quickly can we understand what is happening and act?"

Shane Buckley is President and Chief Executive Officer of Gigamon, a leader in deep observability.

getty​What happens when AI becomes capable of discovering vulnerabilities faster than organizations can fix them? That question became tangible when OpenAI disclosed that an experimental cybersecurity model escaped its testing environment and compromised Hugging Face’s production systems.​

For business leaders, the significance goes well beyond a new cybersecurity capability. AI is changing the economics of enterprise risk. The cost of discovering vulnerabilities is falling rapidly, while the cost of validating findings, understanding business exposure and safely deploying fixes is not.​

Today’s investment numbers illustrate the challenge. My company’s 2026 Hybrid Cloud Security Survey found that 93% of organizations invested in new security tools, yet 65% still experienced a breach in the last year, with AI involved in 83% of reported breaches. ​

The lesson is that investment alone is an increasingly poor proxy for resilience. The more important question is becoming, “How quickly can we understand what is happening and act?”

Cybersecurity has always contained an inherent imbalance. Defenders must protect sprawling environments, while attackers need to find only one viable path. AI magnifies that asymmetry.

Models capable of finding vulnerabilities and identifying attack paths can dramatically reduce the time and expertise required for discovery. Tasks that once required teams of specialized researchers may increasingly be performed at machine speed and repeated at an enormous scale.

Defense has not accelerated at the same rate. Organizations must determine which systems are affected, understand the business consequences of remediation, and test and deploy fixes without disrupting critical operations. Human judgment remains essential because an automated patch that solves one problem can create another.

Discovery may increasingly happen in minutes, while remediation still takes days, weeks or even months. Many enterprises’ security processes were built for a world in which threats developed at roughly human speed. That assumption is disappearing with AI.

Organizations cannot eliminate that asymmetry entirely, but they can reduce the time between new risks emerging, understanding their impact and taking action.​

Companies increasingly rely on common cloud platforms, identity systems, SaaS applications, operating systems and security technologies. That standardization has enormous economic benefits, but it also has consequences. As AI makes experimentation cheaper, attackers can test more combinations, identify common weaknesses and refine techniques against widely used architectures.

This changes how leaders should think about security investments. Most large enterprises already have endpoint protection, identity security, firewalls and security operations platforms. However, when one of those controls is compromised, resilience depends on having independent means of understanding what is actually happening across the environment.

For CEOs and boards, that translates into a straightforward question: “If one of our primary defenses failed today, how quickly would we know?”

While AI accelerates attacks, models and autonomous agents are becoming embedded in applications, workflows and internal systems. They are accessing corporate data, communicating with other systems and taking actions on behalf of employees.​ It’s not uncommon for employees to misuse approved AI tools, while others may be running open-source models locally and connecting them directly to corporate systems. ​

Often, employees are simply trying to move faster. But speed without visibility creates risk, and AI tools operating outside established governance can bypass approved authentication and monitoring controls. As agents become more autonomous, distinguishing legitimate AI activity from malicious activity will also become more difficult.

Companies must capture the benefits of AI without allowing adoption to outpace their ability to understand and govern it.

The instinctive response to new security risks is often to add another security tool. However, that approach has limits. Organizations should instead think about resilience in terms of independent evidence.

Every security control operates with a particular scope, set of assumptions and potential blind spots. Organizations therefore need multiple sources of corroborating evidence across networks, endpoints, identities, applications and cloud infrastructure so they can assess whether controls are working as intended and reconstruct what happened when they are not. This becomes especially important as attackers exploit newly discovered vulnerabilities, novel techniques or gaps between security tools that may not yet be reflected in established detection logic.​​

The objective is not perfect prevention; it is to make the organization harder to surprise and faster to respond when something inevitably gets through. Resilience comes from an organization’s ability to recognize when defenses have failed, understand the consequences and act before a security event becomes a business crisis.

1. How quickly can we determine whether we are exposed? When a significant new vulnerability emerges, leadership should understand how long it takes to identify affected systems, determine whether they have been exploited and prioritize remediation.

2. How quickly would we know if a trusted control failed? Organizations should assume any individual security control can eventually be bypassed. Leaders should understand what evidence would reveal that failure.

3. Do we know where AI is operating across the business? That means more than maintaining a list of approved AI applications. Organizations need to understand where models and agents access corporate systems and sensitive data, and where AI activity occurs outside approved channels.

4. Are we measuring security outcomes or security investment? The number of products deployed or dollars spent says little about an organization’s ability to withstand an attack. Measures such as time to understand exposure, detect malicious activity, contain an incident, remediate vulnerabilities and recover operations provide a much clearer picture.

5. Is our operating model getting faster as the threat environment gets faster? Technology alone cannot solve the AI security challenge if decision-making, ownership and remediation remain slow. CEOs should look for organizational bottlenecks that prevent security teams from acting quickly when risk arises.

One of the most important measures of enterprise resilience may be how quickly an organization can understand what is happening and respond, rather than whether it can prevent every attack. AI is changing the underlying economics of attack and defense. The organizations that succeed will be those with the evidence, operational discipline and layered defenses needed to adapt as quickly as attackers do. ​​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/15/ai-changed-the-economics-of-cybersecurity-ceos-need-to-change-the-equation/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business