# In the AI Era, Cyber Defense Needs a New Playbook

> Source: <https://blogs.cisco.com/news/in-the-ai-era-cyber-defense-needs-a-new-playbook>
> Published: 2026-07-22 14:00:49+00:00

*AI is changing the speed of cyber risk. Cisco’s executive brief outlines how organizations need to move from current operating models to continuous defense.*

In nearly every customer and partner conversation I’ve had recently, one concern keeps coming up: AI is creating a new class of cyber threats that are outpacing traditional defense models.

Many organizations are still operating with security postures built for a different era, when vulnerabilities, patches, upgrades, and response cycles moved at human speed.

That era is over. Frontier AI models are accelerating the ability to find vulnerabilities, generate exploits, and chain them into attack paths. The time between disclosure and weaponization has been compressed from weeks to days or hours. At the same time, the enterprise can take [43 days to patch a critical vulnerability](https://blog.talosintelligence.com/2025yearinreview/). And in 2025, [40% of the most targeted vulnerabilities](https://blog.talosintelligence.com/2025yearinreview/) affected systems with limited patch options.

That gap is now a major cyber risk for technology leaders, and it requires a different operating model for defense.

**What we learned inside Cisco **

We’ve already seen what changes when defenders operate at the speed of AI. Through Cisco’s Security and Trust Organization, leveraging several AI models and early access to Anthropic’s [Project Glasswing](https://www.anthropic.com/glasswing) and OpenAI’s [Trusted Access for Cyber](https://openai.com/index/scaling-trusted-access-for-cyber-defense/), we [scanned 1.8 billion lines of code](https://blogs.cisco.com/news/8-years-of-security-research-in-8-weeks-transforming-cybersecurity-with-ai) across more than 25 languages in eight weeks. Before AI, that same work would have taken eight years.

The speed was significant. But the bigger lesson was what speed revealed about the operating model defenders now need. This wasn’t a faster scan. It was years of security research, engineering judgment, and threat intelligence applied across a complex environment in a way that could be repeated, measured, prioritized, and scaled.

That’s the opportunity AI creates for defenders: it accelerates the work and changes the operating model. Defense has to move from periodic discovery and reactive response to a continuous capability for finding risk earlier, prioritizing what matters most, and acting with greater consistency across the enterprise.

**From security projects to security posture **

For leaders, security posture has to become an ongoing operating discipline, not a set of periodic projects. That means predictable patch and upgrade cadences, unsupported assets retired rather than left past end-of-life, and exposure managed continuously through stronger visibility, segmentation, and containment.

Done right, this reduces the blast radius of an incident, strengthens business resilience, and helps organizations maintain trust with the customers, partners, and communities they serve.

## Three practical shifts

The teams making progress aren’t trying to solve everything at once. They’re focused on three practical shifts:

First, they’re making remediation continuous. Patching and upgrading can’t be treated as emergency motions. They need to become part of a predictable operating rhythm.

Second, they’re using modernization to retire risk. This isn’t a hardware refresh. Unsupported and end-of-life assets create exposure that security teams shouldn’t be asked to carry indefinitely.

Third, they’re raising their security posture to match the speed of the threat. That means segmenting environments, closing identity gaps, and giving SOC teams the tools to act with greater speed and confidence.

None of this requires a perfect program before you start. Each step reduces risk and makes the one after it easier.

**The path to continuous resilience **

We’re at an inflection point. AI is changing the threat landscape at unprecedented speed, and it’s giving defenders new ways to operate securely at scale. Moving from point-in-time security to continuous, AI-accelerated defense is no longer a nice-to-have. It is the new baseline for resilience, readiness, and trust.

Securing the enterprise in the AI era is complex, but it becomes more manageable with discipline and clear priorities. By focusing on continuous remediation, retiring legacy risk, and elevating security posture, organizations can reduce exposure and build the trust required for long-term innovation.

To help leaders take the next step, our teams across Cisco developed detailed guidance to help security and networking professionals strengthen AI-era cyber defense. This new executive brief summarizes five actions leaders can authorize in the next 90 days and the questions to ask their teams now.

## Read Cisco’s executive brief on cyber defense in the AI era:

[A new operating model for critical infrastructure].
