Cybersecurity / Source date:

Agentic AI Attacks: Automated Intrusion at Machine Speed

Attackers chained models to scan, exploit, and pivot faster than human response cycles allow.

Illustration of an on-call technician rehearsing escalation beside a locked network cage.

The security conversation about artificial intelligence has, for two years, been about content: better phishing text, convincing voice clones, plausible fake documents. That was a real change and it was a change of degree — attackers writing more convincingly and at greater volume. What is now appearing is different in kind. The tooling that lets a model plan a task, call other software, read the results and decide what to do next is the same tooling that lets an intrusion proceed without an operator watching. The attacker's constraint has never been imagination. It has been attention.

Automation removed the cost of sending a million messages. Agency removes the cost of an operator sitting at a keyboard deciding what to do with the one that worked

That is the shift worth planning for this year, and the defensive implications are narrower and more practical than the framing suggests.

What actually changes for the attacker

Three things, none of which require novel capability. Reconnaissance becomes exhaustive. A human operator checks the obvious exposures. A tasked agent enumerates everything, reads the documentation, correlates the employee list with the job advertisements, and keeps going through the night. Depth of reconnaissance stops being a cost. The gap between access and action closes. The valuable window for a defender has always been the interval between an initial foothold and someone deciding what to do with it — frequently hours or days, because the operator was asleep or working another target. Agentic tooling compresses that to minutes. Lateral movement adapts. Rather than executing a fixed playbook that a detection rule recognises, the sequence is chosen in response to what it finds. That defeats signature-based detection of technique sequences, which is a substantial fraction of current detection content. What does not change: the initial access still comes from a phished credential, an unpatched edge device, an exposed service or a compromised supplier. The entry points are the same ones.

What this means defensively, in order of value

Time-to-contain becomes the metric that matters. If the interval between foothold and consequence is now minutes, a detection capability with a two-hour triage queue is a reporting function rather than a defence. This is the single most important implication. Identity controls carry more weight than ever. Phishing-resistant authentication, short-lived credentials and removing standing privilege all still work, because an agent cannot reason its way past a hardware-bound credential. Segmentation pays differently. Its value was always in slowing an operator down. Its value now is in bounding what an automated sequence can reach before anything notices, which is a stronger argument for it. Behavioural detection over sequence signatures. Detecting a known technique order is less useful when the order is generated. Detecting an account doing something it has never done remains useful. Automated response is no longer optional. If attack sequences run at machine speed, a purely human response loop cannot keep pace. Start with narrow, reversible automatic actions — isolate a host, disable a session, revoke a token — with defined triggers.

What not to do

Do not buy a product because it uses the word agentic. Do not rewrite your risk register. And do not let this displace the unglamorous work — patching internet-facing systems, removing dormant accounts, getting multi-factor authentication onto the last twelve per cent — because that is still where every one of these intrusions begins.

Defensive priorities that do not depend on the forecastQualitative controls described in the article. The predicted speed and prevalence of agentic attacks are not measured here.
ExposureDefensive priority
Initial accessPatch exposed systems and use phishing-resistant authentication
Credential reachRemove standing privilege and shorten credential lifetime
Movement after accessSegment to bound reachable systems
Delayed responseRehearse narrow, reversible containment and out-of-hours escalation

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Practical Guidance for AI Threat Readiness Review

  • Measure time-to-contain, not just time-to-detect.
  • Automate narrow containment actions with reversible effects.
  • Complete phishing-resistant authentication everywhere it is possible.
  • Eliminate standing privilege and shorten credential lifetimes.
  • Shift detection toward behavioural anomalies and away from sequence signatures.
  • Segment to bound reach, not merely to slow movement.
  • Rehearse an out-of-hours compromise with the actual on-call staff.
  • Keep patching the edge; it is still the front door.

The Regional Angle

The first factor here is the working week, which creates an exposure window regional organisations rarely account for. A Gulf-based security operation is typically staffed lightly from Thursday evening through Saturday, with Friday effectively a holiday, while the wider group's European or Asian teams are also partly absent depending on the country. Against a human adversary that mattered somewhat; against an automated sequence that proceeds without an operator, a forty-eight hour thin-coverage window is the entire attack. Two practical responses: place your automated containment triggers specifically around the low-coverage hours, and if you use a managed detection provider, confirm in writing what its coverage is on Friday and during Eid rather than assuming a follow-the-sun model that may route to a team unfamiliar with your environment. The second is a reconnaissance surface that is unusually rich in this region and almost entirely public. Commercial licence registries, chamber of commerce records, free zone directories, tender portals and government procurement notices publish company structures, authorised signatories, trade licence details and project awards. A human attacker sampled that material. An automated one reads all of it, and can construct an accurate picture of which entity in a group holds which contract, who is authorised to approve what, and which supplier relationships are live. That is exactly the material that makes a business email compromise attempt convincing. The defensive response is not to hide public filings but to stop treating knowledge of internal structure as a signal of authenticity in payment and approval processes. The third concerns the regulatory position, which is moving faster here than the defensive practice. Financial regulators across the Gulf have tightened incident reporting expectations, the Saudi and Emirati national cyber authorities issue binding controls for regulated and critical sectors, and reporting windows are measured in hours. An organisation whose containment takes a day and whose forensic timeline takes a week will be reporting to a regulator before it understands what happened — and an automated intrusion produces a great deal of activity in a short period, which makes the timeline reconstruction harder rather than easier. Make sure your logging retention and clock synchronisation are adequate to reconstruct a fast-moving sequence, because that is the evidence the notification will depend on.

The objection worth taking seriously

The strongest objection is that this is a projection rather than an observation. Publicly documented intrusions still show human operators, familiar tooling and recognisable playbooks; the agentic attack is being described in vendor material and conference talks well ahead of any evidence that it is happening at scale. Security budgets have been redirected before on the strength of a compelling narrative — the same was said about machine-learning-generated malware for several years with little to show — and a chief information security officer who reallocates spend toward this while the last twelve per cent of accounts lack multi-factor authentication has made a poor trade. That is correct about the evidence, and the prioritisation warning is exactly right. What makes it worth attention anyway is that the defensive recommendations here do not require the prediction to be true. Shorter time-to-contain, narrow automated containment, phishing-resistant authentication, removal of standing privilege and behavioural detection are all things you would do against an entirely conventional adversary; they simply become more valuable if the speed assumption changes. There is no separate agentic-defence budget line, and any vendor proposing one should be declined. The correct posture is to keep doing the unglamorous work and to add one specific test: rehearse a compromise that escalates inside an hour, at two in the morning on a Friday, and see whether your process copes. If it does not, you have learned something that is true today.

Common Questions

Do we need a new product category for this?

No. The requirements are faster containment, better identity controls and behavioural detection — all existing categories. Treat agentic branding as marketing until a vendor can demonstrate a capability you do not already have.

Is automated response too risky?

It is riskier to have none. Start with actions that are narrow, reversible and clearly triggered, and expand as confidence builds. Isolating a workstation is recoverable; a four-hour dwell time may not be.

Should we worry about our own agents being attacked?

Yes, and that is a related but distinct problem concerning what your assistants are permitted to do and whether their instructions can be influenced by content they read. Address it separately.

What should we expect over the next twelve months?

Expect the first credible public incident reports involving genuinely automated intrusion sequences, probably in the second half of the year. Expect detection vendors to reposition existing behavioural capability under new language. Expect regulators to ask about containment times rather than tooling. And expect initial access to remain overwhelmingly phishing and unpatched edge devices, as it has throughout.


AI Threat Readiness Review — we test whether your containment keeps pace with an intrusion that does not need an operator awake.

Continue reading

Talk to OPS

Start with the operating problem.