18 Months Ago, AI Could Barely Start a Simulated Cyberattack. Now It Can Get Nearly Halfway Through One for About $87


Government Research
AI Threat Trend
September 2026  ·  7 min read

For years, your best defense was that attacking your business took real skill and real time. UK government researchers just measured how fast that's changing, and put a price on it: about $87 for an AI system to work through nearly half of a realistic attack sequence that would take a trained human roughly fourteen hours. Small businesses are still largely defending at human speed. Attackers increasingly don't have to.


For years, one of the quiet advantages defenders had was that attacking a business took work. Someone had to find the target, probe it, understand what was exposed, figure out what might work, try something, fail, adjust, try again, move deeper into the network, find credentials, and decide what to do next. Automation has always been part of cybercrime, but much of that difficult middle stretch still required a person with real expertise and real time.

Artificial intelligence is beginning to change that equation. One of the clearest measurements of the change doesn't come from a vendor with something to sell. It comes from government researchers testing what today's AI systems can actually do against a realistic target.

$87

the reported cost of a full attempt at a simulated, realistic enterprise attack — using AI to do most of the work

The UK's National Cyber Security Centre ran the test: a 32-step attack sequence against a realistic simulated enterprise network, the kind of multi-stage intrusion a skilled human attacker would need roughly fourteen hours to complete. An AI-driven attempt cost about $87 at current exchange rates. No public model has completed the full sequence end to end — an important limit, and one worth taking seriously. But the number worth focusing on may not be where the ceiling currently sits. It's how fast the floor has been rising.

The change in eighteen months

The trajectory is the real story here, more than any single test result.

Steps completed of a 32-step simulated attack
18 months earlier fewer than 2 → 15.6 (~49%)

Eighteen months before this year's test, the best available AI models could complete fewer than two of the thirty-two required steps. By early 2026, the best-performing model averaged 15.6 — nearly half the entire attack sequence, worked through largely on its own.

14 hrs estimated time for a skilled human expert to complete the same 32-step attack scenario from start to finish UK National Cyber Security Centre, 2026
~49% of the full attack chain the best-performing AI model completed on average — up from under 2 of 32 steps eighteen months earlier UK National Cyber Security Centre, 2026
0 public models have completed the entire 32-step sequence end to end, as of this test — a real, current limit worth taking at face value UK National Cyber Security Centre, 2026

Why this changes the economics of attacking you

Think about what normally limits an attacker: time, expertise, labor, attention. If attacking a hundred businesses requires roughly a hundred times as much skilled human effort as attacking one, an attacker has to choose targets carefully. Yours may simply not be worth the trouble.

AI changes that calculation — and not because it needs to out-hack the world's best human attacker. It becomes valuable to criminals long before that point. It only needs to handle enough of the repetitive research, reconnaissance, testing, and troubleshooting that one person can attempt far more attacks in the same amount of time than before.

That's the real shift in the question worth asking. Not "can AI hack a company entirely on its own?" — the honest answer, today, is still no. The more useful question is: "how much more attacking can one person now do, because AI is doing part of the work for them?" On the evidence of this test, the answer to that second question is moving quickly, even while the answer to the first stays no for now.

This is the defense gap

Most small businesses haven't changed their defensive model anywhere near this quickly, and there's no real criticism in that — it's simply been reasonable, until recently. A vulnerability appears. Someone eventually notices it. A patch gets added to a list. An IT provider reviews the list. Someone decides whether it actually matters. A maintenance window gets scheduled. The patch gets installed.

That process is perfectly sound in a world where attackers move at roughly human pace. It becomes considerably more dangerous once one side starts compressing hours of work into minutes, running tasks in parallel, and repeating them at almost no additional cost. The National Cyber Security Centre has described essentially this as a widening digital divide — organizations whose defenses keep pace with AI-enabled threats, and organizations that fall further behind every cycle they don't close the gap.

For a small business, that divide matters specifically because hiring ten more security analysts isn't the available response. The realistic answer is making the defenses you already have work faster and more precisely — which is a resourcing problem this series has addressed all year, not a new one this trend invents.

The good news: this doesn't make the basics obsolete

Something important in the government's findings is easy to lose under the more alarming headline. AI isn't magic. It still needs something real to exploit.

What an AI-driven attack still needs to find
An exposed service reachable from the internet
An unpatched vulnerability
A compromised credential
An unnecessary administrative account
A configuration mistake
A system nobody remembered was still connected

The fundamental work of cybersecurity still matters — arguably more than ever. What changes is how much time a business realistically has to find and fix those weaknesses before something automated finds them first. The National Cyber Security Centre has specifically warned that AI is likely to make exploiting already-known vulnerabilities faster and more scalable, and that organizations running outdated defenses risk falling further behind with every cycle. The basics aren't becoming irrelevant. They're becoming more urgent.

What to actually do differently

The answer isn't buying a product simply because it has "AI" in the name. It's shortening the distance between discovering a problem and fixing it.

1

Know what's exposed to the internet, and which vulnerabilities are actually being exploited

Ongoing

An inventory of your internet-facing systems, checked against what's confirmed to be under active attack — not a severity score alone — is the single highest-leverage habit in this entire series, and it's the first thing an automated attacker also checks for.

2

Know whether credentials tied to your business are already compromised

Free

A compromised credential removes several steps from an attacker's path in one move — human or automated. Checking is free and takes minutes; not checking leaves the door open without you knowing it.

3

Keep critical systems patched, and remove what you no longer use

Ongoing

Unused services and dormant accounts are pure risk with no offsetting benefit. Every one you remove is one less thing an automated scan can find on your behalf.

4

Use multi-factor authentication, and review what your vendors can reach

Ongoing

Both remain genuinely high-value controls. Neither requires a large budget, and both close paths that an AI-assisted attacker would otherwise be able to try far more cheaply than a human one.

5

Maintain tested backups, and make sure someone is actually responsible for acting

Essential

A backup that's never been restored is an assumption, not a safeguard. And a new finding with nobody assigned to act on it is functionally the same as never having found it at all.

Most importantly: don't treat cybersecurity as something assessed once a year. An annual assessment measures a single moment. The threat environment underneath it no longer moves on an annual schedule — on this test's own evidence, it moved from barely functional to nearly half-complete in a year and a half.
This is precisely the problem the ThreatAngel CyberScore is built around. Small and midsize businesses don't need another dashboard listing hundreds of findings — they need to know what matters, what changed, and what deserves attention first. ThreatAngel brings your business profile, security assessments, external exposure, vulnerability findings, and current threat intelligence together into one continuously updated view, with guidance on what to fix first and a Threat Intelligence feed that separates a theoretical vulnerability from one already being exploited. The goal isn't making a small business run like a Fortune 500 security operation. It's helping one respond faster without needing to become one.

The short version

Eighteen months ago, AI could barely begin this test's attack sequence. Today it completes nearly half of it, for about the cost of a nice dinner. No public model has finished the whole thing yet — that limit is real, and worth remembering the next time a headline overstates the threat. But the rate of change is the number that should hold your attention, because it's the one moving fastest.

Attackers are gaining machine speed. Small-business defense can't stay entirely human-speed.

Know what matters, what changed, and what to fix first — continuously, not once a year.

View the Threat Intelligence feed → Find Out More About ThreatAngel →
TA
ThreatAngel Team AI-powered cyber risk clarity for SMBs  ·  threatangel.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.