TL;DR: Cheap AI is collapsing attacker economics by compressing recon, exploit development, phishing, and command-and-control work to model speed and cent-per-million-token cost, according to Netwrix and cited industry research. The result is not the end of defense, but a shift toward predicting intent from behaviour before an identity or token is abused.
Editorial analysis by NHI Mgmt Group, based on content published by Netwrix: “Mythos and the cost of attacking”.
Key questions
Q: How can security teams defend identity controls against machine-speed parallel attacks?
A: Security teams should focus on reducing the attacker’s usable time, not just improving detection coverage.
Q: Why does cheap intelligence make identity abuse harder to stop with signatures alone?
A: Because signatures only work when the attacker repeats a recognizable pattern.
Q: What breaks when access reviews and alerts still depend on human-paced response?
A: What breaks is the assumption that there will be enough time to notice, review, and act before the attacker moves on.
Practitioner guidance
- Prioritise behavioural identity signals Correlate access novelty, privilege escalation, and sensitive data reach so one permitted event does not hide a malicious sequence.
- Reassess alerting for machine-speed abuse Measure how long it takes from unusual identity behaviour to containment, then compare that window with the pace at which attackers can iterate lures, probes, and follow-on access attempts.
- Reduce trust in single-control decisions Assume phishing, token theft, and privilege misuse will be tested together, not separately.
Bottom line: Cheap intelligence lowers the cost of trying many attack paths, which makes repeated identity probing a more realistic threat than isolated compromise.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Cheap intelligence turns attacker iteration into the primary risk multiplier: the decisive change is not that AI invents a new class of attack, but that it collapses the cost of trying many access paths. That shifts the economics of identity abuse across human, NHI, and autonomous environments. The practitioner conclusion is that control design must assume repeated, low-friction probing, not isolated compromise attempts.
A question worth separating out:
Q: Should organisations prioritise behavioural detection over blocking known bad indicators?
A: Yes, when the threat model includes cheap model-assisted iteration. Blocking known bad still matters, but it is no longer enough on its own because the attacker can cheaply change tactics. Behavioural detection gives defenders a better chance of catching intent before identity abuse turns into exfiltration or persistence.
👉 Read our full editorial: Cheap intelligence is reshaping cyber defense economics