Sicra Header Logo
  • Careers
  • About us
  • People
EnglishNorsk
Talk to us
  1. Knowledge
  2. Insights
  3. Blog
Blog
12.04.2026
min read

When attacks happen in hours, security measures that take weeks are not enough

AI does not change what is vulnerable in your organization. It changes how quickly those weaknesses are found and exploited. That means security efforts need to move faster than before, not necessarily become more complex.

<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >When attacks happen in hours, security measures that take weeks are not enough</span>
Eivind Seip Haugsnes-Sicra
Eivind Seip HaugsnesSecurity manager (CISO-for-hire)

Eivind Seip Haugsnes strengthens Sicra as a CISO-for-hire.

In recent weeks, there has been extensive media coverage of a new AI model from Anthropic, which according to the company itself can identify and exploit vulnerabilities far faster than before. The model is currently being tested in a closed collaboration with major technology companies to find and fix weaknesses before attackers do, as reported by Wired.

Bloomberg describes how companies like Apple and Amazon are given early access to the technology to strengthen their own security before it is potentially made more widely available. At the same time, The Guardian points out that parts of these claims have not been independently verified, and that the communication may also reflect strategic positioning in a highly competitive AI market.

For Norwegian organizations, this is not primarily a new type of threat. It is an amplification of something we already know.

This is not a new problem

The same weaknesses still apply. Lack of patching. Exposed services. Excessive access. Lack of visibility. These are not new problems. They are problems we have been discussing for years. The difference is the pace.

The pace has changed

Where it previously could take weeks to discover and exploit a vulnerability, it can now in some cases happen in days or hours. AI does not necessarily make attackers smarter. But it makes them faster and more scalable. This means the time you have to respond is shorter.

The real risk is the gap

The biggest risk now is not new technology in itself. It is the gap between what you know you should be doing and what you actually get done. Many organizations have a good understanding of their own risk. Still, actions are delayed because the organization is complex, because technical debt takes time to address, or because other initiatives are prioritized higher. As the pace of the threat landscape increases, this gap becomes more dangerous. This is not about becoming the best at security. It is about not being the easiest to attack.

Four actions leadership should ensure now

For leadership, this means ensuring that some very fundamental things actually happen.

  • Ensure patching happens fast enough: If it takes weeks to update critical systems, that represents a real risk. Automate where possible, and make sure the rest is handled within days, not weeks.
  • Reduce what is exposed: Review what is accessible from the internet. Close what does not need to be open. Most attacks do not start advanced, they start with something that should not have been accessible.
  • Gain visibility into your exposure: Many organizations lack an up-to-date overview of what is actually exposed, what is vulnerable, and where access is too broad. Without this, it is difficult to prioritize correctly.
  • Plan for failure: No security control is perfect. Ensure the organization can withstand one or more failures. This includes limiting the impact of an attack, ensuring critical data can be restored, and that important services can be maintained or scaled down in a controlled manner, rather than stopping completely.

You do not need to wait for all claims about AI and security to be fully documented before taking action. If the development is as fast as some suggest, it becomes even more important to get started. If it turns out to be exaggerated, these are still measures you should have implemented regardless.

AI does not change the rules of the game. It increases the pace. Whether it is possible to catch up depends on how far behind you are. Either way, it becomes more challenging the longer you wait.

Sources

Wired: Anthropic Teams Up With Its Rivals to Keep AI From Hacking Everything

Bloomberg: Apple, Amazon Gain Early Access to Anthropic’s Powerful Mythos AI Model

The Guardian: ‘Too powerful for the public’: inside Anthropic’s bid to win the AI publicity war

Bloomberg Law: Bessent Urgently Summons Bank CEOs Over Anthropic’s New AI

Need Assistance?

We are happy to have a non-binding conversation. 
Contact us

Explore more

2026 - Microsoft Defender XDR optimizations and configuration
Blog

2026 - Microsoft Defender XDR optimizations and configuration

Tech blog
Cybersecurity
Microsoft
How to take control of Defender XDR and close critical security gaps.
Arctic Wolf 2026 Threat Report: Monitoring, identity, and access control become more important
Blog

Arctic Wolf 2026 Threat Report: Monitoring, identity, and access control become more important

Learn more about the findings in the Arctic Wolf 2026 Threat Report.
Cyber Threat Landscape 2026: Insights from Arctic Wolf’s threat report
Blog

Cyber Threat Landscape 2026: Insights from Arctic Wolf’s threat report

Arctic Wolf Threat Report 2026: Ransomware remains the #1 threat.
IAM for dummies
Blog

IAM for dummies

A simple, practical introduction to IAM and why correct access is critical.

Stay updated
Receive the latest news

Links
SustainabilityFAQPartnersCertifications and awardsCareerPress & brand
Contact
Tel: +47 648 08 488
E-mail: firmapost@sicra.no
Posthuset, Biskop Gunnerus’ gate 14A, 0185 Oslo, Norway
Follow us on LinkedIn
Certifications
iso27001-white
ISO 27001 compliance
miljofyrtarnlogo-hvit-rgb
Eco-Lighthouse
Sicra Footer Logo
Sicra © 2025
Privacy Policy