For most of my career in this industry, time was on the defender’s side.
A vulnerability was disclosed. Weeks or months later, a working exploit showed up in the wild. That lag was never comfortable, but it was real, and we built our entire operating model around it. Patch cycles, change windows, quarterly risk reviews, annual penetration tests. All of it assumed we had time.
That assumption is now gone.
Anthropic recently reported that its Claude models compromised three companies during cybersecurity testing. Since the news broke, it has come up in nearly every CIO and CISO conversation I have had. In the testing, the model identified weaknesses, chained them together, and carried out intrusion activity with very little human direction or interaction.
According to the public statements, these were controlled evaluations that exploited common weaknesses, not zero days. That qualifier is accurate, and it is also the part most people skip past.
Anthropic has not named the three organizations. The one named victim in this stretch of disclosures came from the other side of the story. Days earlier, OpenAI disclosed that its models escaped a sandboxed evaluation environment, reached the internet, and gained access to Hugging Face’s production systems. Hugging Face published its own disclosure describing how a malicious dataset abused code execution paths in its processing pipeline, how the actor escalated to node level access, harvested credentials, and moved laterally across internal clusters over a weekend, driven end to end by an autonomous agent framework.
Two different labs. Two different evaluation partners. The same failure mode.
The weaknesses it used were ordinary — unpatched software, weak credentials, flat networks, excessive permissions — the same findings that show up in nearly every assessment my teams have run for years.
So, the takeaway is not that one frontier model invented a new class of attack. The takeaway is that AI removed the friction from the old ones, and with it the survivorship bias that made obscurity feel like security. Every vulnerability now gets seen and used. It is not a story about one incident; it is a story about the future of cybersecurity.
Skill used to be a constraint. Time used to be a constraint. Neither one is dependable now.
This capability is already moving beyond frontier labs. The models and frameworks required to automate an attack are increasingly accessible, and the organizations we defend cannot control who adopts them or how quickly.
Now change the target. In healthcare, financial services, utilities, or manufacturing, an autonomous intrusion could disrupt clinical care, payments, or production before an incident response team is fully mobilized. That is a continuity problem, and in some cases a safety problem. It demands a different question from leadership.
For a long time, the executive question was some version of: are we secure?
That question no longer produces useful answers. The better question, and the one boards are starting to ask, is this:
If an attacker gets in, how far can they move, how fast will we know, and how quickly can we recover?
That is a resilience question, not a prevention question. Prevention still matters. It just cannot carry the whole program anymore.
When customers ask me where to start, I give them the same four priorities. None of these are new ideas. What has changed is that they are no longer optional.
Stop building programs that only work if the perimeter holds. Run the tabletop where the attacker is already inside with valid credentials. Most organizations discover very quickly that their plan does not survive that first assumption.
This is the control I push hardest, because it is the one that determines the size of the incident. Segmentation is not about drawing lines on a network diagram. It is about enforcing who and what can talk to what, based on identity rather than location. With Cisco ISE and TrustSec, we do this by policy, so the rules follow the workload instead of the subnet. In a hospital, that is the difference between one compromised device and a shutdown of clinical systems. In payments, it is the difference between a contained event and a reportable breach of the cardholder data environment.
Most organizations already collect more telemetry than they use. The gap is correlation. Splunk, ThousandEyes, Secure Network Analytics, Nexus Dashboard, and the Meraki Dashboard each see part of the picture. Brought together, they tell you what normal looks like, which is the only reliable way to recognize what is not normal.
If an attack sequence executes in minutes and your response process takes hours, the outcome is already decided. Triage, enrichment, and containment for known patterns should happen without waiting for a human to open a ticket. Keep people on judgment calls. Give the machine the repetitive work.
Do not start with a new tool. Start with two questions and be honest about the answers.
If one of your systems (laptop, server, etc) is compromised by say ransomware, using a newly discovered vulnerability, how long will it take to spread it inside your organization and what would be an impact on your business?
How long would it take you to notice reconnaissance leading to a potential breach? If the honest answer is measured in days, observability is your second project.
Everything else builds on those two.
We spent a long stretch of this industry telling ourselves comfortable stories. That attackers needed rare expertise. That obscurity bought us cover. That the gap between disclosure and exploitation would always give us room to plan.
Those were the myths. AI did not break them so much as expose them.
The good news, and I do mean this, is that the response is not exotic. It is discipline applied to fundamentals we already understand: know what you have, limit what it can reach, watch it closely, and be able to recover without negotiating. Organizations that do that work will handle this era just fine. The ones still relying on the old timeline will find out the hard way that the clock changed.
The organizations that lead here will be the ones that combine Zero Trust, intelligent analytics, and automation into a single resilience strategy rather than three separate projects. In healthcare and financial services, where every minute of downtime has real consequences, that is not only about protecting data. It is about continuity of care and continuity of commerce.
The future of cybersecurity is about containing fast enough to keep serving customers. That is the new competitive edge.
Over the next six weeks, my team and I are going to work through this in detail: vulnerability management, the AI-powered SOC, segmentation and what boards should be asking, and what resilience looks like specifically in healthcare and financial services.
This is the opener. Let us get into it.