top of page
Search

AI Got Dangerously Good at Attacking You. The Version You Are Purchasing To Defend You, Did Not

AI is not breaking the commodification of security work, it is pouring rocket fuel on it. IT audits, penetration tests, infrastructure reviews, vulnerability scans, configuration assessments, control testing, risk assessments, the whole catalog is being repackaged into a leasing model where you do not buy expertise, you rent a subscription to a tool that runs on a schedule. 


Here is the part the sales deck leaves out. AI is now dangerously good at offense. It is finding novel zero days, chaining exploits, and probing combinations no human would have time to test, at machine speed, and attackers already have it. So sit with the asymmetry. The offense you face is proactive, creative, and tireless, while the defense most firms lease you is a scheduled scan that pattern matches what has already been published, wraps it in a confident report, and hands it to one person who could not tell you what it missed. 


Let me be fair, because this matters. Automated, leased work is not worthless. As a first pass, as baseline coverage between real engagements, it has a place. What I refuse to accept is watching it bid head to head against the practitioners who actually do this work, the people with the background to interrogate and walk around what the tool surfaces, as if the two are the same deliverable at a cheaper price. They are not. Pretending they are misleads the client/end user into believing they bought assurance when they bought a scan. On paper the two look identical, a tidy report full of findings, which is exactly why the comparison fools a procurement team and falls apart the day a real attacker shows up. 


I have seen the gap up close. A leased scanner returns clean because the path I chained to domain admin was three individually acceptable settings that only became a breach when a human decided to connect them. The tool was never wrong about a single finding. It simply never asked the question a curious adversary asks. That judgment is exactly what disappears the moment the work is fully automated and nobody senior touches it. 


So if you are buying this, write the protection into the contract. Demand that a named human performs and signs off on at least eighty percent of the engagement, with hours documented, not generated and rubber stamped. Demand the person who sold you the work is personally on the keyboard for fifty to seventy five percent of it, in writing. The breach that takes you down will not be the one in the report. And I will be curious if your cyber insurance will pay when they find a rubber stamped report which no one really critically reviewed. 


Reach out if you want to discuss.

 
 

Recent Posts

See All

Timcke Risk Management, LLC

660 Massachusetts Ave

6th Floor, Boston, MA 02118

 

© 2025 by Timcke Risk Management, LLC

 

bottom of page