TL;DR: AI is shrinking the window between vulnerability discovery and exploitation to minutes or hours, while traditional vulnerability management and periodic assessments struggle to keep pace, according to Horizons.ai. For identity and security teams, the shift makes exploitability, attack-path validation, and blast-radius control more important than raw vulnerability volume.
NHIMG editorial — based on content published by Horizons.ai: Cyber Resilience in the Age of AI-Driven Warfare
By the numbers:
- The European Central Bank’s 7 July 2026 letter requires 110 significant institutions under its direct supervision to submit comprehensive action plans addressing AI-enabled cybersecurity threats by 31 October 2026.
Questions worth separating out
Q: What breaks when organisations rely on periodic assurance against AI-accelerated threats?
A: Periodic assurance breaks because it assumes exposures remain stable long enough to be reviewed.
Q: Why do machine-speed attackers change the way teams should think about access and exposure?
A: Machine-speed attackers compress the time available to detect, assess, and respond, which makes standing trust and broad privilege far more dangerous.
Q: How do security teams know whether active defence is actually working?
A: Active defence is working only if it changes attacker outcomes in testing and in live operations.
Practitioner guidance
- Prioritise exposures by exploitability, not scan volume Rank vulnerabilities, credentials, and misconfigurations by whether they are reachable, chainable, and tied to business-critical systems.
- Validate attack paths continuously Test whether privileged pathways, service accounts, and adjacent trust relationships can actually be used in a live environment.
- Reduce blast radius around privileged and non-human access Tighten segmentation, shorten credential lifetimes, and remove standing access where possible.
What's in the full report
Horizons.ai's full whitepaper covers the operational detail this post intentionally leaves for the source:
- Practical guidance on prioritising what not to fix when vulnerability volume exceeds remediation capacity
- The three-pillar Post-Mythos resilience framework and how it maps to board and regulator expectations
- Validation approaches for active defence, including EDR testing, deception, and recovery exercises
- Metrics security leaders can track to show measurable progress in AI-driven threat conditions
👉 Read Horizons.ai's whitepaper on cyber resilience in the age of AI-driven warfare →
AI-driven cyber resilience: are your defenses keeping up?
Explore further
AI speed turns vulnerability management into an evidence problem, not a counting exercise. When attackers can move from discovery to exploitation in minutes or hours, backlog size tells leaders very little about risk. The meaningful question is which exposures are reachable, chainable, and business-critical. That shifts governance from remediation volume toward proof of exploitability and consequence, which is the right lens for both human identity and NHI-enabled environments.
A question worth separating out:
Q: Who is accountable when cyber resilience fails?
A: Accountability sits with the executive owners of continuity, security, and identity governance, because resilience is cross-functional. The board expects a coordinated operating model, not isolated technical ownership, and insurers will evaluate whether the organisation can demonstrate evidence, containment, and recovery under policy conditions.
👉 Read our full editorial: AI-driven cyber resilience is outpacing vulnerability management