18 Months Ago, AI Could Barely Start a Simulated Cyberattack. Now It Can Get Nearly Halfway Through One for About $87
For years, your best defense was that attacking your business took real skill and real time. UK government researchers just measured how fast that's changing, and put a price on it: about $87 for an AI system to work through nearly half of a realistic attack sequence that would take a trained human roughly fourteen hours. Small businesses are still largely defending at human speed. Attackers increasingly don't have to.
For years, one of the quiet advantages defenders had was that attacking a business took work. Someone had to find the target, probe it, understand what was exposed, figure out what might work, try something, fail, adjust, try again, move deeper into the network, find credentials, and decide what to do next. Automation has always been part of cybercrime, but much of that difficult middle stretch still required a person with real expertise and real time.
Artificial intelligence is beginning to change that equation. One of the clearest measurements of the change doesn't come from a vendor with something to sell. It comes from government researchers testing what today's AI systems can actually do against a realistic target.
the reported cost of a full attempt at a simulated, realistic enterprise attack — using AI to do most of the work
The UK's National Cyber Security Centre ran the test: a 32-step attack sequence against a realistic simulated enterprise network, the kind of multi-stage intrusion a skilled human attacker would need roughly fourteen hours to complete. An AI-driven attempt cost about $87 at current exchange rates. No public model has completed the full sequence end to end — an important limit, and one worth taking seriously. But the number worth focusing on may not be where the ceiling currently sits. It's how fast the floor has been rising.
The change in eighteen months
The trajectory is the real story here, more than any single test result.
Eighteen months before this year's test, the best available AI models could complete fewer than two of the thirty-two required steps. By early 2026, the best-performing model averaged 15.6 — nearly half the entire attack sequence, worked through largely on its own.
Why this changes the economics of attacking you
Think about what normally limits an attacker: time, expertise, labor, attention. If attacking a hundred businesses requires roughly a hundred times as much skilled human effort as attacking one, an attacker has to choose targets carefully. Yours may simply not be worth the trouble.
AI changes that calculation — and not because it needs to out-hack the world's best human attacker. It becomes valuable to criminals long before that point. It only needs to handle enough of the repetitive research, reconnaissance, testing, and troubleshooting that one person can attempt far more attacks in the same amount of time than before.
This is the defense gap
Most small businesses haven't changed their defensive model anywhere near this quickly, and there's no real criticism in that — it's simply been reasonable, until recently. A vulnerability appears. Someone eventually notices it. A patch gets added to a list. An IT provider reviews the list. Someone decides whether it actually matters. A maintenance window gets scheduled. The patch gets installed.
That process is perfectly sound in a world where attackers move at roughly human pace. It becomes considerably more dangerous once one side starts compressing hours of work into minutes, running tasks in parallel, and repeating them at almost no additional cost. The National Cyber Security Centre has described essentially this as a widening digital divide — organizations whose defenses keep pace with AI-enabled threats, and organizations that fall further behind every cycle they don't close the gap.
The good news: this doesn't make the basics obsolete
Something important in the government's findings is easy to lose under the more alarming headline. AI isn't magic. It still needs something real to exploit.
The fundamental work of cybersecurity still matters — arguably more than ever. What changes is how much time a business realistically has to find and fix those weaknesses before something automated finds them first. The National Cyber Security Centre has specifically warned that AI is likely to make exploiting already-known vulnerabilities faster and more scalable, and that organizations running outdated defenses risk falling further behind with every cycle. The basics aren't becoming irrelevant. They're becoming more urgent.
What to actually do differently
The answer isn't buying a product simply because it has "AI" in the name. It's shortening the distance between discovering a problem and fixing it.
Know what's exposed to the internet, and which vulnerabilities are actually being exploited
OngoingAn inventory of your internet-facing systems, checked against what's confirmed to be under active attack — not a severity score alone — is the single highest-leverage habit in this entire series, and it's the first thing an automated attacker also checks for.
Know whether credentials tied to your business are already compromised
FreeA compromised credential removes several steps from an attacker's path in one move — human or automated. Checking is free and takes minutes; not checking leaves the door open without you knowing it.
Keep critical systems patched, and remove what you no longer use
OngoingUnused services and dormant accounts are pure risk with no offsetting benefit. Every one you remove is one less thing an automated scan can find on your behalf.
Use multi-factor authentication, and review what your vendors can reach
OngoingBoth remain genuinely high-value controls. Neither requires a large budget, and both close paths that an AI-assisted attacker would otherwise be able to try far more cheaply than a human one.
Maintain tested backups, and make sure someone is actually responsible for acting
EssentialA backup that's never been restored is an assumption, not a safeguard. And a new finding with nobody assigned to act on it is functionally the same as never having found it at all.
The short version
Eighteen months ago, AI could barely begin this test's attack sequence. Today it completes nearly half of it, for about the cost of a nice dinner. No public model has finished the whole thing yet — that limit is real, and worth remembering the next time a headline overstates the threat. But the rate of change is the number that should hold your attention, because it's the one moving fastest.
Attackers are gaining machine speed. Small-business defense can't stay entirely human-speed.
Know what matters, what changed, and what to fix first — continuously, not once a year.
View the Threat Intelligence feed → Find Out More About ThreatAngel →📚 Credential Security Series → Read the full series

Comments
Post a Comment