Book a FREE consult now

We'd love to give you a full tour of our solutions.

Book a FREE consult

Published on:

October 5, 2026

Six questions to discuss with your team and your board

‍

“Before we start, just to make it clear: I’m real. Not a deepfake.”

A few years ago, opening an online meeting like that would have sounded strange. Now it gets a knowing laugh, and half the audience starts wondering whether they should say it too. Faces, voices, emails... in the AI era, everything seems to need a second look.

Today, the AI security debate tends to swing between two extremes: an AI-driven attack wave nobody can stop, or vendor hype with nothing behind it. However, both miss what has actually changed. Attackers aren't using new techniques. They're using the old ones faster. As a result, the gap between a weakness appearing and someone exploiting it is getting shorter.

This hits hardest on the risks teams have already accepted. A control that was good enough when attackers needed weeks may not hold when they need days. Here are five blind spots worth checking, each with one question to take to your team or your board.

1. “We’ve got the basics covered” now has an expiry date

Segmentation, zero trust access and MFA still work, AI or not. The sceptics are right that much of the AI threat talk is hype, and that most incidents so far came from test labs, not the wild.

What changed is who does the work. Older tools needed a human to decide the next move. A frontier model decides for itself, retries when blocked, and never clocks off. A gap you could tolerate for a quarter may now be found in a week.

Ask your team: Which known gap have we accepted because “nobody will find it”?

2. Your board sees time-to-patch. The risk sits in time-to-protect

Recent figures show the exposure window widening from both ends:

•       More than 71,000 CVEs were published in 2026 by late September.

•       In one report, average time-to-exploit fell from about 23 days to 1.3 days.

•       The median time to fully patch known exploited vulnerabilities rose from 32 to 43 days.

Patching won’t reach machine speed; testing and change windows see to that. But an exploit can be made useless much sooner, through virtual patching, blocking or isolation. That is time-to-protect, and it's the number that reflects real risk.

Ask your team: Do our security reports show how long we were exposed, or only how fast we patched?

3. An unreachable 9.8 can often wait. An exposed 6.3 can’t

Working down the list by CVSS score feels responsible. With more CVEs than hours, it quietly sends effort to the wrong place. What matters is reachability: what can be reached, from where, and by whom, including from inside once an attacker has a foothold.

Ask your team: Do we have a list of the open vulnerabilities an attacker could reach?

4. Stolen passwords are no longer the main way in

Many security budgets were built around credential theft. According to the latest Verizon Data Breach Investigations Report, exploited vulnerabilities have now overtaken it as the top entry point, at 31% of confirmed breaches. Identity controls still matter. But if most of the spend still guards last year’s front door, the balance is off.

Ask your team and the board: Is our budget and effort still focused on credentials, while the bigger risk is now unpatched systems?

5. Former employees whose AI agents still work for you

Offboarding closes the account and collects the laptop. It rarely touches the AI agents that person set up, or the API keys and OAuth tokens those agents run on. These identities don't expire, skip MFA, and sit outside access reviews.

OWASP ranks improper offboarding as the top risk in its Non-Human Identities Top 10. The Cloud Security Alliance cites research that around half of organisations have no clear owner for their AI identities (CSA).

Ask your team and the board: When an employee leaves the organisation, who switches off their AI agents, or do they keep running?

Now, from the attacker’s view: what if every step looks normal?

In a recent live demo, a simulated AI attacker with a foothold in the network used only legitimate tools and was still stopped before any data left.

Here’s what the attacker did:

Every tool was legitimate. Admins use rclone daily. Only the sequence, on that host, at that hour, gave it away. The same steps from a red-team engineer are routine; from an HR laptop at 2 a.m., after a blocked download, they are not. Rules that judge one event at a time won't see the difference.

Ask your team: Would our tooling connect these dots, or log five harmless events?

‍

Before your next meeting

There is no need to panic. Start by getting honest answers to the questions above, from yourself, your team, as well as the board. The ones that are hardest to answer are usually where the value is.

The risks we accepted made sense when attackers were slower. And it’s important to know with confidence whether they still do.

‍

This article is based on the webinar, “How Do We Deal With Frontier AI”, co-hosted by IPknowledge and Cato Networks.

Want to watch the full session, or talk through these questions for your own environment? Contact us.

‍

Sources

Figures on CVE volumes, time-to-exploit and patch times, and the 31% breach figure from this report.

Non-human identity figures: OWASP Non-Human Identities Top 10 and the Cloud Security Alliance.

‍

Written by:
Xiao Yang
Book a demo now

We'd love to give you a full tour of our NaaS solutions.

Book a demo now

IPknowledge

Internet access without complications

Read article

How Does IoT Benefit from 5G Networks?

Read article

Can't find the answer?
‍Ask us directly.

We've build a huge library with all there is to know about IT networks and security. If you're looking for some deep information, than this is the place to be.
Reach out to us

What we promise

Monthly trails & demos
You're always up-2-date
We're here to help, 24/7
We're always down to business
Ask and we'll answer
Seamless site integration
Simple solutions for big problems
Monthly trails & demos
You're always up-2-date
We're here to help, 24/7
We're always down to business
Ask and we'll answer
Seamless site integration
Simple solutions for big problems