TechNewsReel
Live

IBM's Mark Hughes: AI Compresses Cyberattack Timelines from Days to Minutes

The Global Managing Partner for Cybersecurity Services warns that AI-driven speed is rendering legacy defensive strategies obsolete.

TechNewsReel Newsroom · August 25, 2026

The window for detecting and neutralizing cyber threats is shrinking as artificial intelligence empowers attackers to operate at unprecedented speeds. Mark Hughes, IBM's Global Managing Partner for Cybersecurity Services, warns that the integration of AI into offensive toolkits has fundamentally altered the timeline of digital incursions.

Speaking in Cyber Magazine, Hughes noted that AI now allows attackers to execute complex attacks in a matter of minutes—a process that previously required days of manual effort. This acceleration removes the traditional "dwell time" that security teams once relied upon to spot anomalies and intercept breaches before they reached critical systems.

The Scale of the Threat

This shift in speed is already manifesting in real-world data. According to IBM's Cost of a Data Breach Report, the impact of these evolving tools is tangible, particularly in the UK. The research indicates that 22% of UK organisations experienced an AI-related security breach within the past year, signaling that AI-driven threats are no longer theoretical risks but active operational hazards.

Why Speed Changes the Game

For the cybersecurity industry, the transition from a "days-long" attack cycle to a "minutes-long" cycle renders many legacy defensive strategies obsolete. Traditional security operations centers (SOCs) that rely on human-led triage and manual verification cannot keep pace with automated, AI-driven exploits. When an attacker can probe, penetrate, and exfiltrate data in minutes, the only viable defense is a system that can respond with equal or greater speed.

This escalation forces a strategic pivot toward AI-driven defense. To counter the speed of AI-powered attacks, organizations must deploy autonomous security tools capable of real-time detection and automated remediation. The goal is to move from a reactive posture to one of proactive, machine-speed resilience.

The Path Forward

As AI continues to lower the barrier to entry for sophisticated attacks, the industry is watching for how these tools will be used to create more convincing social engineering and polymorphic malware. While IBM and other leaders are pushing for advanced defensive frameworks, the primary challenge remains the gap between the speed of the attacker and the speed of the defender. The focus now shifts to whether organizational infrastructure can be modernized fast enough to close that window.

Get a notification when a big story breaks. A few a day at most — no spam.