powering productive workplaces
Front page
FeatureTrust & Risk1h · 10:01 BST · 6 min read

You WILL Soon Have a Security Breach, So How Do You Prepare?

AI is accelerating both the scale and speed of cyber threats, and security agencies are warning that this is shrinking response windows to the point that organizations must start planning for breaches as a certainty rather than a mere possibility that may happen

You WILL Soon Have a Security Breach, So How Do You Prepare?

For years, cybersecurity leaders have worked under the assumption that the right combination of tools, processes, and expertise could largely keep attackers at bay. Today, however, advances in AI are forcing many security experts to reconsider that assumption.

The emergence of frontier AI models such as Claude Mythos has demonstrated how quickly AI capabilities are advancing. These systems are becoming increasingly proficient at coding, reasoning, analyzing complex datasets, and solving technical problems that once required significant human expertise. While these developments promise major productivity gains, they also raise uncomfortable questions about how the same capabilities could be leveraged by cybercriminals.

The capabilities demonstrated by Mythos are so impressive that this has moved beyond a theoretical future concern into an immediate warning. Recently, the Five Eyes security alliance issued a joint warning that advanced AI models could outpace existing cyber defenses within months rather than years.

Against that backdrop, Morgan Adamski, Principal at PwC, argued that organizations need to start planning for a future in which cyber incidents are no longer a question of if, but when:

"Everyone should really be preparing for a breach in the next two years."

Rather than viewing cybersecurity solely through the lens of prevention, organizations may need to place equal emphasis on resilience and recovery.

Why AI Has Changed the Nature of Cyber Risk

Cyberattacks have traditionally been constrained by human limitations. Discovering vulnerabilities, analyzing code, developing exploits, and identifying potential attack paths all required time, expertise, and resources. Even highly capable attackers could investigate only so many targets at once, creating a natural bottleneck that limited the scale and speed of many operations.

AI is beginning to remove those constraints. Advanced models can rapidly analyze large volumes of code, identify potential weaknesses, summarize technical documentation, and assist with research tasks that would previously have required significant manual effort. While AI does not eliminate the need for human involvement, it can dramatically accelerate many stages of the attack lifecycle, allowing adversaries to move from discovery to action much faster than before.

At the same time, organizations are continuing to expand their digital footprints. Cloud services, remote work environments, connected devices, third-party integrations, and increasingly complex software ecosystems have all contributed to larger attack surfaces. Security teams are often tasked with protecting thousands of assets while managing growing volumes of alerts and an evolving threat landscape. The challenge is not simply keeping up with attackers, but with the pace of technological change itself.

As attack surfaces expand, the number of potential vulnerabilities expands with them. According to Adamski, one of the most significant concerns is the speed at which AI could expose weaknesses across an organization's technology stack. She points to "the significant amount of vulnerabilities that may be discovered by AI and not just discovered but also exploited at an extremely fast rate." This distinction is critical. Organizations have always had to contend with vulnerabilities, but the window between identifying a weakness and exploiting it may shrink dramatically as AI capabilities improve.

The result is a cybersecurity environment that moves faster than many organizations are accustomed to. Security teams may have less time to detect threats, fewer opportunities to patch vulnerabilities before they are exploited, and greater pressure to respond quickly when incidents occur. In such an environment, planning exclusively for prevention may no longer be enough.

Preparing for the Breach Before It Happens

If breaches are becoming more likely, organizations need to shift part of their attention toward preparedness. While preventing attacks remains essential, resilience planning can determine whether an incident becomes a manageable disruption or a business-threatening crisis. The organizations that recover most effectively are often those that have considered their response long before an attack occurs.

For Adamski, preparation starts with establishing clear response procedures. "Building really strong playbooks" is a critical first step, she says. Effective incident response plans should clearly define roles and responsibilities, establish escalation paths, identify key decision-makers, and outline the actions that need to be taken during the first hours of a security incident. Without these frameworks in place, organizations can lose valuable time coordinating their response while an attack is actively unfolding.

Preparation also requires a clear understanding of operational priorities. Adamski advises organizations to consider "what systems you could do without for a number of days and ones that you can't." This process involves identifying critical business functions, mapping dependencies, and understanding which systems must be restored first following an incident. Organizations that have not undertaken this exercise may discover too late that essential services depend on systems they had not previously identified as high priority.

Communication planning is another often-overlooked component of breach readiness. Adamski highlights the importance of "understanding what you're willing to communicate" before an incident occurs. Whether communicating with customers, employees, regulators, investors, or the media, organizations benefit from having clear communication frameworks established in advance. In the aftermath of a breach, uncertainty and confusion can amplify reputational damage, making effective communication almost as important as technical remediation.

Ultimately, resilience depends on preparation. Organizations cannot predict every attack they may face, but they can determine how they will respond when one occurs. The more decisions that can be made before an incident happens, the less likely organizations are to find themselves reacting under pressure during a crisis.

Building Security for an AI-Driven Future

While preparedness is essential, organizations must also recognize that cybersecurity itself is entering a period of transformation. Many existing security strategies were developed for a world in which human attackers operated at human speed. As AI accelerates both offensive and defensive capabilities, security teams will need to rethink how they approach risk management and threat detection.

Adamski believes the industry must adopt a more forward-looking mindset:

"It's a time to be proactive, not reactive."

Rather than waiting for threats to emerge and then responding, organizations should actively assess how AI may alter their risk profiles, security requirements, and operational processes. This shift requires leadership teams to view cybersecurity as a strategic business priority rather than simply a technical function.

A major component of this transition involves modernizing security operations. Adamski emphasizes the importance of "investing a lot in your security operations center and ensuring it is modernized and fit for purpose." As threat volumes increase and attacks move more quickly, security teams will increasingly rely on automation, advanced analytics, and AI-assisted detection capabilities to help identify and respond to threats at scale.

However, adopting AI-powered security tools alone is unlikely to be enough. Adamski argues that organizations should ensure AI is embedded throughout security operations rather than treated as an isolated technology initiative. "It is really critically important that you are using it in every aspect of your workflows. You're not just bolting it on but you're reimagining how you're starting from the ground up." In practice, this means examining how AI can enhance everything from threat intelligence and detection to incident response and operational efficiency.

The reality is that cybersecurity has always been a race between attackers and defenders. What is changing is the pace of that race. As AI continues to evolve, organizations may find it increasingly difficult to prevent every breach. Success will depend not only on strengthening defenses but also on building resilience, modernizing security operations, and preparing for a future in which managing attacks becomes as important as defending against them.

rate this story
helps rank stories across uc today
The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
picked for this story

Workday Eyes AI Agent Issues With New Research Team

20 Aug 2026
picked for this storyGeopolitical Tensions Are Reshaping European Tech Decisions, Study Finds6 Aug 2026picked for this storyOpenAI Expands Daybreak With GPT-5.6-Cyber as Autonomous Threats Grow11 Aug 2026