The attacker has one AI. You have 12 dashboards

The attacker has one AI. You have 12 dashboards


The author, RedRok CEO Uri Levy

For most of enterprise security’s history, the adversary’s real constraint was skilled human labour. Reconnaissance took weeks, exploit development took expertise and phishing that worked took a writer. Every intrusion consumed an operator’s time, which is why most organisations were never worth the effort.

Offensive AI has removed that constraint, and with it a form of protection that mid-sized organisations never knew they had.

What actually changed

Every step of an attack has been automated and made cheap. A newly disclosed vulnerability can be weaponised in minutes rather than weeks. Reconnaissance runs continuously and unattended. Phishing is generated per target, in the local language, referencing real suppliers and real people. Most significantly, the skill floor has collapsed: offensive capability is now rented rather than learned.

The offensive AI toolkit, as documented today

  • Uncensored “dark” large language models (LLMs). WormGPT, FraudGPT and successors such as KawaiiGPT are sold by subscription for business email compromise, phishing at scale and malware scaffolding. Palo Alto Networks’ Unit 42 threat intelligence team classifies them as purpose-built malicious models.
  • Agentic attack frameworks. HexStrike AI drives more than 150 offensive tools from a single stated objective; Check Point reported attackers claiming Citrix NetScaler compromises in under ten minutes, and forked builds strip out the human-in-the-loop checks. Villager layers LLM automation onto the Cobalt Strike attack-simulation tool, and Strix automates finding and validating vulnerabilities.
  • Borrowed infrastructure. Through 2026 researchers have caught operators hijacking exposed self-hosted inference endpoints, running these agents on someone else’s compute and bill.

The compression shows up clearly in incident data. Unit 42’s 2026 Global Incident Response Report records 72 minutes from initial access to confirmed data exfiltration in the fastest quarter of cases, and roughly a fourfold year-on-year compression in attack timelines. CrowdStrike’s 2026 Global Threat Report puts average breakout time to lateral movement at 29 minutes. Unit 42 also finds that around 65% of initial access is identity-based rather than a CVE (a publicly catalogued software vulnerability): valid credentials, stolen tokens, cloud misconfiguration and trust relationships that never receive a severity score at all.

No longer an enterprise-only problem

Automation does not select its targets by revenue. When reconnaissance is free and continuous, the sweep covers everyone at once: a mid-market manufacturer, a private hospital group, a municipal utility and a forty-person supplier to a large bank all sit inside it alongside the listed enterprise.

Obscurity has therefore stopped being a control: being small now usually means a smaller team facing the same machine. Smaller organisations are also attacked for who they serve, because a supplier with federated access into a larger customer is a cheaper route in than that customer’s own perimeter.

The defender’s structural disadvantage

Set the two sides next to each other and the imbalance is not about effort or budget. The attacker runs one continuous, integrated operation with a single objective and no off switch. The defender runs six or more tools, each seeing a slice: a scanner; endpoint detection and response (EDR); cloud security posture management (CSPM); identity and access management (IAM); security information and event management (SIEM); governance, risk and compliance (GRC). Each is competent inside its own boundary; none sees the route between them, which is precisely where an intrusion lives.

Validation follows the same pattern: a quarterly penetration test, in scope only, leaves most of the year unobserved. Prioritisation is worse, because a mid-sized estate carries tens of thousands of findings sorted by severity in isolation while only a small fraction sit on a path an attacker can walk. A seventh tool adds findings, not answers.

RedRok Solid8 Technologies

Restoring the balance

Parity does not come from more scanning. It comes from adopting the attacker’s own model: build a single graph of every asset, identity, credential and exposure, and walk it the way an adversary would, so risk becomes a property of the path rather than the finding. Validate rather than assume, so a chain is proven exploitable before it enters the remediation queue. And run the loop continuously rather than quarterly.

This is what Gartner’s continuous threat exposure management (CTEM) framework describes, and most CTEM programmes stall on one word. Scoping, discovery, prioritisation, validation and mobilisation are all achievable manually. Doing them continuously is not. Automation is the missing half, and agentic AI supplies it.

RedRok was built for that gap. Four agents each own one view of the estate, and the platform merges what they find into a single validated graph, so a route no individual agent could see becomes one proven chain. Because chains converge on shared infrastructure such as a directory service or a bastion host, RedRok computes the choke points: in a typical estate, three remediations break nine of eleven proven chains. A fixed remediation capacity then buys a disproportionate reduction in real risk, rolled up into one posture score a board can follow.

The adversary automated their side of this fight. Defenders can do the same, and until they do, the imbalance only widens.

  • The author, Uri Levy, is CEO and active chairman, RedRok. RedRok is an agentic AI platform for continuous threat exposure management, available in South Africa through Solid8 Technologies. Contact [email protected] for more information or to see a demo
  • Read more articles by Solid8 Technologies on TechCentral
  • This promoted content was paid for by the party concerned