THEMETASEC

Cybersecurity News, Aggregated

Most organizations aren’t ready for a Hugging Face-level event

CSO Online · 1 hour ago Breach

The National Security Agency (NSA) and Central Security Service recently published an advisory statement on behalf of the Five Eyes Cyber Security Agencies, warning that AI technologies are making it easier than ever for would-be malicious actors to infiltrate and compromise sensitive networks. “AI is not a future consideration — it is already here,” the statement says. “It lowers barriers for malicious actors and increases the speed and complexity of attacks, shrinking the window between vulnerability discovery and exploitation ever more quickly. At the same time, AI offers powerful tools to strengthen defense.” AI is becoming an increasingly vital layer in cybersecurity, but the NSA’s advisory statement fails to acknowledge that today’s threat environment is profoundly asymmetric; for now, threat actors have the upper hand in the ever-escalating cyberdefense arms race. One of the most worrisome aspects of the statement is that it understates the severity of the current threat environment to such a degree that it could well have been published years ago. “Organizations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behavior and respond faster to incidents — reducing both the cost and impact of incidents,” the statement says. “Success will not come from having the most tools. It will come from getting the basics right, acting quickly and integrating cybersecurity into core business strategy.” While it’s true that agentic security can detect intrusions earlier and monitor aberrant network activity that human specialists may overlook, we are far past the point at which “getting the basics right” and “integrating cybersecurity into core business strategy” are sufficient to mitigate the asymmetric threat posed by AI-powered cyberattacks. Security leaders must act preemptively to mitigate previously unseen threats, and the only way to do so is by truly understanding the capabilities — and limitations — of their cyberdefensive posture. We surveyed 93 CISOs and senior cybersecurity practitioners between December 2025 and March 2026, and combined the findings with real-world performance data from SimSpace environments to gauge how SOCs across the enterprise are testing their resilience to AI-driven threats. The response indicates that 78% of security professionals surveyed have high confidence in the capabilities of their agentic defenses. However, detection and response times still cluster in 1–6-hour windows, and 20% of survey participants cannot consistently measure mean time to detect and respond (MTTD/MTTR). This shows that AI is being deployed into SOC environments faster than it is being tested, measured, proven and trusted. As recent high-profile incidents such as OpenAI’s breach of Hugging Face’s systems have demonstrated, the fundamental assumptions about cyberdefensive posture must change. While OpenAI took responsibility for the attack on Hugging Face’s system, the company failed to detect its model’s intrusion for almost a week, and only became aware of the breach after the FBI began an investigation. Triaging intrusions, no matter how rapidly, is no longer enough by itself, and security leaders need to know how their teams and tooling perform under pressure during a live intrusion event. One of the greatest vulnerabilities facing security leaders across the enterprise is the vast gulf between traditional knowledge and training, and the unique threats facing individual organizations. Too many companies still see cybersecurity through the lens of periodic training, static instruction and conventional wisdom. Far fewer are putting their teams — and networks — to the test by engaging in realistic simulations of the most likely attack vectors facing their organizations. Worse, some companies are deploying untested agentic defenses to live production environments, which can further expand the potential attack surface and present unique vulnerabilities to opportunistic assailants. The Five Eyes security statement notes that cyber risk “can no longer be treated as a purely technical issue,” and that a “whole-of-organization and whole-of-society response” is necessary to combat the emergent threat of autonomous cyberattacks. This is why we urge many of the clients we work with to think of cybersecurity as a cultural value, not merely a technical problem. One of the most effective steps organizations can take to improve their defensive readiness is to move from periodic testing to cultures of constant training. To keep pace with emergent threats, security leaders must move toward continuous validation loops, not one-off exercises, and regularly test detection, response and AI-driven protocols. Organizations that test more frequently achieve measurably higher performance, while those that test less typically plateau. The performance metrics of yesterday are of little use in today’s asymmetrical threat environment. Rather than outdated indicators such as the volume of alerts detected, security leaders should measure outcome-based metrics including detection success, response accuracy and decision quality across both human and AI workflows. Without outcome-based metrics, organizations cannot determine whether AI is improving performance or introducing new risk. As the Five Eyes security statement notes, the rapid advancement of AI technologies means that risk assumptions about cyberdefense can become outdated in months, not years. This presents challenges in terms of ongoing training. Even the most capable security teams take time to adapt to novel workflows, and security leaders must factor in the inevitable friction when implementing and testing agentic defenses. SimSpace data shows that AI agents often introduce initial performance declines of approx. ~10–20%, followed by steady improvement with repeated testing. Organizations that anticipate this learning curve and conduct regular, iterative testing are far more likely to realize long-term gains. The most critical step in closing the agentic confidence gap is establishing an environment where AI cyberdefenses can be continuously tested and proven safely. This requires AI Proving Grounds, a realistic, controlled replica of production environments in which organizations can simulate realistic adversary behavior, exercise AI-driven detection and response workflows, test automated playbooks end-to-end, and evaluate how human analysts and AI agents perform together. As frontier labs and malicious threat actors alike push agentic technologies to their limits, novel threats will continue to emerge, and high-profile incidents will continue to make headlines because the most urgent threats are the ones that have never been seen before. With geopolitical tensions rising around the globe, the threats facing national institutions and critical infrastructure have never been higher. In the military, soldiers are taught to “train like you fight,” which means simulating combat scenarios as closely as possible to prepare troops for the realities of the battlefield. This includes how to respond under fire. Security leaders must assume that breach is inevitable, and trust their teams and tooling to handle emergent threats as they happen. The only way to cultivate that trust is to test them, which necessitates a safe, truly sandboxed environment in which teams, tools and agents can be evaluated alongside one another. Organizations that adopt this mentality will be better equipped to handle the emergent threats made possible by agentic AI. Even the highest-fidelity simulation of a real-time cyberattack can only go so far in preparing security professionals for the reality of an actual breach, but it’s a hell of a lot more effective than quarterly training.

Read full story at CSO Online →