top of page

Don’t let AI distract you from the basics

August 2026

There is a lot of noise right now about AI discovering novel zero-days and inventing complex new ways to breach organisations. While these stories are exciting (and a little scary), they are largely a distraction from what is actually driving breaches today.

It is not unique exploits, but rather the rapid acceleration of existing methods that needs highlighting and should be influencing how we prioritise our defence. According to Microsoft, more than 99.9% of compromised accounts do not have Multi-Factor Authentication (MFA), leaving them vulnerable to simple password spraying, phishing, and password reuse.

The Shrinking Time to Exploit

 

The timeline to reverse engineer a published CVE or string multiple known vulnerabilities into an attack chain has effectively evaporated.

  • 2024 Average: The average time from CVE disclosure to a working exploit was 56 days.

  • Current Baseline: That window has fallen to roughly 10 hours.

  • Negative Exploitation Windows: Mandiant trends now put the mean-time-to-exploit at negative 7 days. On average, exploits are being released a week before patches are available.

Breakout Time and Lateral Movement

 

It is not just the timeframe to initial access that has changed; post-compromise execution is faster than ever. Breakout times now average under 30 minutes and in extreme cases, less than a single minute. As a result, detection and response capabilities must be measured in minutes, not hours.

Attacks Haven’t Changed and Neither Have the Controls

 

The most common attack vectors haven't changed: a lack of MFA remains king, attributed to almost half (44%) of all breaches. These are the same exploit methods security teams have dealt with for decades, just operating at unprecedented speeds.

Because exploitation now occurs faster than disclosure, traditional monthly patching cycles can no longer serve as a front-line control. Furthermore, controls that simply block known bad signatures or Indicators of Compromise (IOCs) must be complemented by default-deny mechanisms such as application allow listing and Web Application Firewalls (WAFs) that prevent fields from accepting malicious inputs.

Prioritisation must be placed on foundational controls that reduce exposure and minimise impact:

  • Non-phishable MFA

  • Immutable backups

  • Network segmentation

  • Centralised logging & incident detection

  • Principle of least privilege

  • Secure build configurations and system hardening

 

(For New Zealand organisations, frameworks like the NCSC Critical Controls remain a key benchmark for prioritisation.)

What Can You Do Today?
  1. Understand Your Attack Surface: Map your exposure and review basic hygiene. Prioritise systems and devices directly exposed to the internet.

  2. Evaluate Implementation Quality: Focus on how a control has been implemented, not just if it exists. Identify user exceptions and establish near real-time metrics to test control effectiveness.

  3. Assume Breach: Prepare for faster attack timelines by strengthening detection and response. Ensure centralized logging metrics are tracked in minutes and playbooks are regularly tested.

Contact

Media enquiries

bottom of page