For years, cybersecurity leaders have worked under the assumption that the right combination of tools, processes, and expertise could largely keep attackers at bay. Today, however, advances in AI are forcing many security experts to reconsider that assumption.
The emergence of frontier AI models such as Claude Mythos has demonstrated how quickly AI capabilities are advancing. These systems are becoming increasingly proficient at coding, reasoning, analyzing complex datasets, and solving technical problems that once required significant human expertise. While these developments promise major productivity gains, they also raise uncomfortable questions about how the same capabilities could be leveraged by cybercriminals.
The capabilities demonstrated by Mythos are so impressive that this has moved beyond a theoretical future concern into an immediate warning. Recently, the Five Eyes security alliance issued a joint warning that advanced AI models could outpace existing cyber defenses within months rather than years.
Against that backdrop, Morgan Adamski, Principal at PwC, argued that organizations need to start planning for a future in which cyber incidents are no longer a question of if, but when:
"Everyone should really be preparing for a breach in the next two years."
Rather than viewing cybersecurity solely through the lens of prevention, organizations may need to place equal emphasis on resilience and recovery.
Why AI Has Changed the Nature of Cyber Risk
Cyberattacks have traditionally been constrained by human limitations. Discovering vulnerabilities, analyzing code, developing exploits, and identifying potential attack paths all required time, expertise, and resources. Even highly capable attackers could investigate only so many targets at once, creating a natural bottleneck that limited the scale and speed of many operations.
AI is beginning to remove those constraints. Advanced models can rapidly analyze large volumes of code, identify potential weaknesses, summarize technical documentation, and assist with research tasks that would previously have required significant manual effort. While AI does not eliminate the need for human involvement, it can dramatically accelerate many stages of the attack lifecycle, allowing adversaries to move from discovery to action much faster than before.
At the same time, organizations are continuing to expand their digital footprints. Cloud services, remote work environments, connected devices, third-party integrations, and increasingly complex software ecosystems have all contributed to larger attack surfaces. Security teams are often tasked with protecting thousands of assets while managing growing volumes of alerts and an evolving threat landscape. The challenge is not simply keeping up with attackers, but with the pace of technological change itself.
As attack surfaces expand, the number of potential vulnerabilities expands with them. According to Adamski, one of the most significant concerns is the speed at which AI could expose weaknesses across an organization's technology stack. She points to "the significant amount of vulnerabilities that may be discovered by AI and not just discovered but also exploited at an extremely fast rate." This distinction is critical. Organizations have always had to contend with vulnerabilities, but the window between identifying a weakness and exploiting it may shrink dramatically as AI capabilities improve.
The result is a cybersecurity environment that moves faster than many organizations are accustomed to. Security teams may have less time to detect threats, fewer opportunities to patch vulnerabilities before they are exploited, and greater pressure to respond quickly when incidents occur. In such an environment, planning exclusively for prevention may no longer be enough.
Preparing for the Breach Before It Happens
If breaches are becoming more likely, organizations need to shift part of their attention toward preparedness. While preventing attacks remains essential, resilience planning can determine whether an incident becomes a manageable disruption or a business-threatening crisis. The organizations that recover most effectively are often those that have considered their response long before an attack occurs.




