Rewiring Cyber for AI Speed: A New Operating Model for AI-Era Threats 

cover story

Reimagining Cyber for a Faster Fight

Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days.

By Brad Medairy and Andrew Turner
Velocity Magazine | V5. Summer 2026

Speed Read ↗︎

  • AI-powered cyberattacks have compressed the cyber kill chain to minutes, overwhelming human-paced decision structures, and exposing visibility gaps that let adversaries move faster than defenders can respond.
  • Operating at AI speed means disrupting the operating model: shifting human judgment upstream, empowering AI-speed containment, and adopting a continuous "attack to defend" posture. 
  • Exclusive survey of more than 100 federal cyber leaders quantifies the urgency: 79% are extremely or very concerned about AI-enabled attacks in the next 18 months, yet only 6% consider themselves fully prepared—a gap requiring immediate action.
This is a web summary.

Download the article for extended analysis, the complete federal cyber leader survey findings, and expanded operating-model guidance, or download the full edition of Velocity Magazine for more insights for innovators.

Speed Read ↗︎

AI-powered cyberattacks have compressed the cyber kill chain to minutes, overwhelming human-paced decision structures, and exposing visibility gaps that let adversaries move faster than defenders can respond. Operating at AI speed means disrupting the operating model: shifting human judgment upstream, empowering AI-speed containment, and adopting a continuous "attack to defend" posture. 

This is a web summary.

Download the article for extended analysis, the complete federal cyber leader survey findings, and expanded operating-model guidance, or download the full edition of Velocity Magazine for more insights for innovators.

AI is now operating across the entire cyber kill chain.

From vulnerability discovery, to exploit development, to effect delivery, it's no longer theoretical—Google recently identified what it believes is one of the first zero-day exploits developed with AI assistance: a bypass of two-factor authentication in a widely used admin tool, marked by telltale signs like a hallucinated CVSS score and unusually textbook code.

The trend is accelerating. The Five Eyes intelligence alliance recently warned that major businesses and governments are only "months" from broad exposure to AI-enabled breaches. One recent research report found attackers using Claude successfully with nothing more than vague, low-skill prompts—letting the model handle reconnaissance, exploit development, and data harvesting on its own. Booz Allen's Incident Response teams are seeing the same pattern accelerate across public and private-sector engagements.

The widening gap between the pace of these attacks and the speed of response is the most urgent fault line to address in cybersecurity today.

AI-enabled adversaries are demonstrating an ability to move far faster than defenders that rely on human speed, compressing the lifecycle of attacks from weeks or days into hours and minutes.

The UK's AI Security Institute found Claude Mythos automating multi-stage attack tasks that would take skilled humans days. In Senate testimony, Sen. Mark Warner said Mythos "broke into almost all of our classified systems, not in weeks, but in hours" during an authorized test. In Booz Allen's own Vellox Striker simulations, a traditional SOC took 45 minutes to move from alert to incident commander approval—the autonomous red team achieved full domain compromise in six minutes.

This asymmetry is compounded by additional pressures. First, SOCs are drowning in telemetry. Sprawling, AI-embedded environments generate enormous ambient data volume even without an active threat; AI-driven attacks add more probes and vectors on top of that. The result isn't heightened vigilance—it's analyst overload.

What Federal Leaders Are Telling Us:
The Concern Isn't Hypothetical

79%
are extremely or very concerned about adversaries using AI-accelerated attacks

top fear
The shrinking window between vulnerability discovery & weaponization

A deficit in landscape visibility highlights another problem. Theoretically, AI should empower attackers and defenders proportionally—and in narrow domains it does. Microsoft used AI tools to find and patch over 500 vulnerabilities in just a few months this year. This suggests that defenders should have an edge: They know their own systems better than attackers do. In reality, many organizations lack the situational awareness to make that advantage operational. The intelligence needed to anticipate attacker movement—rather than simply react to it—is either unavailable or not actionable at speed.

These compounding pressures—faster attacks, SOC overload, and insufficient landscape visibility—define the challenges security leaders must now address:
Faster Responses

Build human-AI teaming models that minimize human-in-the-loop delays and enable response at AI speed.

Detection Fidelity

Enrich cyber data, recalibrate signal-to-noise ratios, and rebuild SOC architecture for signal over noise.

Cyber Resilience

Adopt an "attack to defend" posture that identifies and mitigates vulnerabilities before adversaries can exploit them.

The New Math of AI at Cyber Speed

26 seconds

Time it took to discover 13 exploit chains for one AI-supported framework.


MIT / Univ. of Naples

34 minutes

Average time to achieve lateral movement—fastest breakout was 4 minutes.

ReliaQuest, 2026

1.2 hours

Time for fastest top 25% of intrusions to achieve exfiltration, 3x faster than in 2025.

Palo Alto

The CISO's Operating Model Imperative

Better AI tools deployed inside an outdated operating model will simply enable the wrong decisions faster. The strategies that follow require a new foundation and a new way of thinking that breaks with old assumptions and ideas underlying traditional security architecture. Building this new foundation is a leadership challenge before it is a technical one—and CISOs are positioned to lead it because the required changes cut across legal, finance, compliance, and business operations simultaneously. Three priorities should anchor that effort.

Reevaluate the Risk Equation

Most organizational risk models were calibrated for a different threat environment—one in which attacks unfolded over days, giving defenders time to detect, deliberate, and respond. AI has broken that assumption. When adversaries move from access to full compromise in minutes, SEC disclosure timelines and cyber insurance assumptions built for human-speed incidents become strained.

CISOs need to start with an honest assessment of what the current risk model was actually built for—and where it no longer holds. That means revisiting assumptions about threat velocity, reexamining software supply chain exposure, and ensuring that zero-trust and data protection strategies are tightly aligned to crown-jewel assets. The risk model is the foundation on which everything else is built. If it is out of date, every downstream decision inherits that misalignment.

What Federal Leaders Are Telling Us:
Readiness Lags the Threat

6%
are fully prepared with AI-powered cyber defenses actively deployed

top barrier
Integrating AI-powered defense tools with existing infrastructure

Rethink Human-AI Teaming

The deeper question isn't just how to move faster—it's where human judgment sits in a loop when the adversary no longer operates at human speed. The fix isn't removing humans; it's moving their judgment upstream into pre-authorized, tiered response: low-risk actions (quarantining files) run autonomously, medium-risk actions (revoking credentials) run with single-human confirmation, and high-risk decisions stay human but pre-scripted against known trigger conditions rather than improvised under pressure. Tabletop exercises simulating AI-speed attacks are the most effective way to build this.

This is ultimately a workforce question as much as a policy one. Analysts who once monitored and triaged will increasingly serve as orchestrators and decision authorities. The organizations that treat Human-AI teaming as a core competency—rather than a tool adoption—will be the ones that close the speed gap.

Communicate the Resourcing Reality

The changing threat landscape has resourcing implications that leadership needs to understand explicitly—and CISOs need to be the ones making that case. This is a structural shift, not a technology refresh. Vulnerability management illustrates the point: In its first month alone, Anthropic's Project Glasswing uncovered roughly 10,000 critical and high-severity vulnerabilities across its own and partner efforts—a backlog that requires sustained, multi-year investment, not a one-time budget line.

CISOs who frame this conversation in business or mission terms—exposure to material breach, insurance gaps, supply chain liability, the compounding cost of reactive versus proactive posture—will be better positioned to secure the operating model changes and resources these strategies require.

The most durable advantage in AI-speed cybersecurity isn't faster reaction; it's making reaction less necessary.

A New Cyber Operations Model for AI Speed

The challenges are clear. Attacks are outrunning human response timelines. SOC architectures are drowning in telemetry while meaningful signals slip through. And defenders lack the landscape visibility to get ahead of threats rather than simply react to them. What follows is a framework for addressing all three—not as a future-state aspiration, but as an operational imperative that leading organizations are building now.

Develop Faster Responses

Closing the speed gap requires moving human judgment upstream and machine execution downstream. Autonomous agents can now increasingly handle endpoint detection, triage, and initial response—from alert prioritization to recommended containment action—surfacing only the decisions that genuinely require human authority. For example, testing by Booz Allen shows that automated malware analysis can compress work that would take human teams up to 10 days into just minutes.

The authorization framework built in the operating model phase is what makes this executable. Pre-authorized, tiered response thresholds—developed across legal, compliance, and leadership before any crisis requires them—mean that when an agent recommends containment, the decision has already been made. The goal is to move human decision-making into the planning cycle where it strengthens response, rather than leaving it as a gate on every containment action in real time.

Improve Detection Fidelity

Speed only matters if detection is accurate, and most SOC architectures weren't built to reliably handle today's data volume. Rebuilding detection fidelity to address sensor overload requires two simultaneous moves. The first is data enrichment: smart pipelines that contextualize raw telemetry against threat intelligence, asset criticality, and behavioral baselines before it reaches an analyst. The second is structural: fusing SOC and NOC functions to eliminate the handoff delays that create exploitable windows, and deploying AI agents to clear routine alerts so analysts can focus on the detections that require genuine judgment.

Zero-trust architecture is the structural complement to both. Continuous verification of devices and identities, least-privilege access, and granular segmentation constrain what an attacker can reach even after a breach. As AI agents themselves become an expanding attack surface, zero-trust principles apply to machine identities with the same force they apply to human ones.

What Federal Leaders Are Telling Us:
Uncertainty Prevails Over Confidence

36%
believe AI defenses can keep pace with AI-enabled attacks

50%
are unsure whether AI defenses can keep pace—the top response

Enhance Cyber Resilience

The most durable advantage in AI-speed cybersecurity isn’t faster reaction—it’s making reaction less necessary. An "attack to defend" posture is the operational expression of this principle. Frameworks like Continuous Threat Exposure Management (CTEM) formalize the approach: rather than treating vulnerability management as a periodic exercise, organizations continuously assess their own attack surface from the adversary's perspective, prioritizing exposure by actual exploitability and business impact rather than raw severity scores.

Agentic red-teaming programs, in which AI-powered tools continuously probe for weaknesses across the environment, are generating the kind of systematic, attacker-perspective visibility that traditional annual pen tests could never provide. Leading cybersecurity programs are already orchestrating dozens to over a hundred AI agents for this purpose—not as a one-time audit, but as an always-on capability that maps exposure before adversaries can exploit it. As AI compresses the window between vulnerability discovery and weaponization, the ability to find weaknesses first is no longer a best practice. It is the primary competition.

The Bottom Line

AI isn’t an emerging threat on the horizon—it’s a disruptive reality already reshaping the cyber kill chain and compressing attack timelines from days to minutes. Our survey of federal cyber leaders puts a number on it: 79% are extremely or very concerned, and only 6% consider themselves fully prepared. That gap between concern and readiness is the real finding—and closing that gap takes more than deploying new tools. It requires rebuilding risk assumptions, authorization frameworks, and detection architecture around the actual threat timeline. 

The fundamentals of cybersecurity haven’t changed, and neither has the essential challenge: Find the threat before it finds you. What has changed is the speed at which that competition plays out and the organizational capacity required to win it. The frameworks exist. The strategies outlined here are being deployed by leading programs today. What determines outcomes is whether organizations treat this moment with the urgency it demands—because the adversary already is.

Survey Methodology
Market Connections and Booz Allen partnered to design an online survey of over 100 federal government decision makers/influencers, involved with IT and cybersecurity, regarding AI's impact on government cybersecurity practices. The survey consisted of 14 questions and was fielded in April of 2026. Due to rounding, responses may not add up to exactly 100%.

Read the Full Article

The full article PDF goes deeper on the strategies above—including the complete findings from our federal cyber leader survey, expanded guidance on building pre-authorized, tiered response frameworks, and a closer look at how leading organizations are scaling CTEM and agentic red-teaming programs to enhance cyber resilence.

New edition | v5. summer 2026

Explore the New Velocity

cover story

Reimagining Cyber for a Faster Fight

Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days. 

graphic representing AI agent

tech spotlight

How Can You Trust Agentic AI? Start with Engineering

Why trust must be designed, governed, and validated—not assumed.

image of city infrastructure

mission spotlight

Infrastructure Under Attack: The Zero Trust Imperative

Cybersecurity must go beyond compliance to defeat new threats.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It: Zero-Knowledge Proofs

Trusting more (but revealing less) with zero-knowledge proofs for government.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It

Trusting more (but revealing less) with zero-knowledge proofs for government.

New edition | v5. summer 2026

Explore the New Velocity

cover story

Reimagining Cyber for a Faster Fight

Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days. 

graphic representing AI agent

tech spotlight

How Can You Trust Agentic AI? Start with Engineering

Why trust must be designed, governed, and validated—not assumed.

image of city infrastructure

mission spotlight

Infrastructure Under Attack: The Zero Trust Imperative

Cybersecurity must go beyond compliance to defeat new threats.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It: Zero-Knowledge Proofs

Trusting more (but revealing less) with zero-knowledge proofs for government.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It

Trusting more (but revealing less) with zero-knowledge proofs for government.

New edition | v5. summer 2026

Explore the New Velocity

cover story

Reimagining Cyber for a Faster Fight

Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days. 

graphic representing AI agent

tech spotlight

How Can You Trust Agentic AI? Start with Engineering

Why trust must be designed, governed, and validated—not assumed.

image of city infrastructure

mission spotlight

Infrastructure Under Attack: The Zero Trust Imperative

Cybersecurity must go beyond compliance to defeat new threats.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It: Zero-Knowledge Proofs

Trusting more (but revealing less) with zero-knowledge proofs for government.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It

Trusting more (but revealing less) with zero-knowledge proofs for government.

New edition | v5. summer 2026

Explore the New Velocity

graphic of technology intersecting with Washington DC

cover story

Reimagining Cyber for a Faster Fight

Learn how CISOs are rebuilding to keep pace with AI-powered attacks.

graphic representing AI agent

tech spotlight

How Can You Trust Agentic AI? Start with Engineering

Why trust must be designed, governed, and validated—not assumed.

image of city infrastructure

mission spotlight

Infrastructure Under Attack: The Zero Trust Imperative

Cybersecurity must go beyond compliance to defeat new threats.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It: Zero-Knowledge Proofs

Trusting more (but revealing less) with zero-knowledge proofs for government.