Index  ›  defence  ›  Forbes
defence · Forbes ↗

Why Cybersecurity Leaders Need AI Strategy, Not Just AI Speed

Forbes Published Jul 20, 2026 Reviewed Jul 20, 2026 ✓ Reviewed by citations.press editors
Anthropic's Mythos model recently identified more than 23,000 potential vulnerabilities across open-source software, including over 1,000 rated 'high' or 'critical' severity by external security firms, according to SecurityWeek.
23000 vulnerabilities · potential vulnerabilities across open-source softwaremore than 1000 vulnerabilities · vulnerabilities rated high or critical severity
Microsoft Threat Intelligence found that most malicious AI use still centers on producing text, code or media, including phishing lures, translated content, stolen-data summaries, malware debugging and scripts or infrastructure.
A team that once needed a month to review threat reports, correlate them with its environment and update its risk register can now do meaningful work in hours, according to the article.
more than 720 hours · time to review threat reports, correlate environment, and update risk register

As Corelight's CISO, Bernard Brantley leads governance, risk and compliance, secure infrastructure, security operations and IT.

​AI is changing cybersecurity, but not just because attackers are moving at machine speed. New AI models are surfacing long-standing vulnerabilities at scale.

Anthropic's Mythos, for example, recently identified more than 23,000 potential vulnerabilities across open-source software, including over 1,000 that external security firms rated "high" or "critical" severity, according to SecurityWeek.​

Since these vulnerabilities are being exposed much faster than humans can respond to every new alert, defenders need to step back, think broader and plan better, especially when using AI to respond to these emerging cyberthreats.

Microsoft Threat Intelligence found that most malicious AI use still centers on producing text, code or media, including phishing lures, translated content, stolen-data summaries, malware debugging and scripts or infrastructure.

In other words, attackers are moving faster, but many of the techniques are familiar. They are using AI mainly to move through the kill chain faster, reduce technical friction and scale operations.

The problem for many businesses is that their own goals for using AI for cyberdefense are much less defined. ​

Too often, the business motivation is more FOMO than bottom line. Companies want to use AI to move faster, but where are they going? Are they trying to improve efficiency, expand capability, update threat modeling or ship a more secure product?

Until the business defines the MO driving FOMO, defenders may point AI at the wrong problem. Speed matters, but velocity requires knowing what is business critical, why it matters and how to protect it.

Detection engineering is one place where teams often misapply AI.

AI can help teams develop detection logic faster, but speed alone does not tell whether those detections map to real attack paths or business risks. A cryptominer on an exposed cloud instance costs money, but it is not the same risk as a path to source code, customer data or a supply chain attack.

The first job is to understand an organization’s relationship to the threat environment. Who would target us? What do we hold? Are we the end target or a path to another target? Are we disrupting a specific stage of the kill chain or improving hygiene against opportunistic attackers?

Before deploying AI into a workflow, teams should define the assets at risk, the adversary paths they are trying to disrupt and the metric that will show whether risk changed.

For these tasks, AI can help teams develop a hypothesis about why their company could be a target by comparing internal architecture, business processes, threat intelligence and control coverage faster than humans can manually reconcile those inputs. From there, teams can build a learning engine: Are we mitigating the path that matters, and are we improving velocity toward a measurable outcome?

AI can help users look at a problem from a broader perspective. A security leader can test a proposed strategy against the views of an auditor, board member, executive sponsor or practitioner. While AI can’t know exactly how a board member will respond, it can surface likely questions and test whether the plan makes sense to the people who will fund, govern and execute it.

However, companies should not use AI to make final decisions. They should use it to bring in context outside of daily roles, help smaller teams reason across business domains and expose weak framing before teams run off in the wrong direction.

AI-enabled vulnerability discovery is already changing the economics of software security.

When AI finds a large volume of vulnerabilities, like Anthropic's Mythos model recently did, it does not necessarily mean the organization was negligent or the model found novel zero-days. Usually, it means threat modeling stopped at a service, component, architectural assumption or level of abstraction that seemed reasonable at the time.

AI can extend threat modeling deeper into the code, down to the library-call level, by surfacing routes and relationships that teams lacked the time, resources or tooling to analyze in the past.

The response shouldn’t just focus on prioritizing tickets. Teams should ask what the findings say about how code is built and maintained: Do we need 15 components for one function, or can the architecture be simplified? Where should security be built in by default? How can we reduce the potential attack points?

This makes the relationship between security and engineering teams more important going forward. Security teams should frame the work to engineering this way: We have better ways to look, so we will help sort the patterns and we will improve the process so fewer issues reappear.

The most important defensive opportunity is not building an AI system that wins a one-on-one race against attacker AI. It’s using AI to reduce the time between the latest information and the best response.

A team that once needed a month to review threat reports, correlate them with its environment and update its risk register can now do meaningful work in hours. Controls planned for next quarter can be tested against actor activity reported this week. Penetration test priorities can be adjusted based on recent intelligence, and risk discussions can be grounded in the current environment, not last quarter’s threats.

Ultimately, that’s how AI will make security teams more effective. Instead of making the existing security machine faster, it can help leaders ensure the machine is pointed in the right direction.

Attackers will keep using AI to move faster. Defenders should use it to think more broadly, make better decisions and turn speed into velocity.​​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

This article was originally published by Forbes ↗. citations.press indexes the source-backed facts above and links to the original. Something wrong? Corrections policy · Report an error