CFOtech US - Technology news for CFOs & financial decision-makers
United States
AI arms race forcing businesses to rethink cybersecurity

AI arms race forcing businesses to rethink cybersecurity

Wed, 22nd Jul 2026 (Today)
David Shilovsky
DAVID SHILOVSKY Interview Editor

Organisations are accelerating efforts to automate cyber hygiene and reduce their attack surface, as AI shortens the gap between the discovery of vulnerabilities and the consequential exploitation.

Businesses are starting to view rapidly evolving artificial intelligence-powered threats as a catalyst for overhauling long-standing security practices, instead of simply deploying more security products.

The change comes as security teams deal with an increasingly shrinking time-to-exploit window. Previously, organisations had a period between the public disclosure of a vulnerability and attackers developing working exploits - but AI is significantly reducing that timeline.

There is now very little, if any, response time, according to Harman Kaur, CTO at Tanium.

"Traditionally, we were very used to vulnerability - there was a lag," Kaur said. 

"Now that gap is effectively nothing."

Anticipation of the pendulum swinging further towards the advantage of bad actors has been fuelled by the spectre of Anthropic's much-hyped Claude Mythos.

Claiming it is currently unsafe for wide-scale use, the San Francisco-based AI firm has pulled back from publicly releasing Mythos, in favour of consultation with a select group of major technology firms, including Nvidia, Apple and Amazon Web Services.

"Our perspective right now, responding to a lot of our customers, they think (Mythos) is going to be very disruptive for them," Kaur said.

"We're really focused on how we can make sure that they're ready to respond to Mythos, in whatever form it actually takes."

In response to the looming paradigm shift, companies have been forced to rethink how they manage cyber risk. 

Businesses need to automate routine security operations, while also reducing the number of systems that could be targeted in the first place.

"Where you can patch more effectively, where you can patch faster, we should be doing that," Kaur explained. 

"We shouldn't rely on just a human pushing the button."

But patching alone will not be a sufficient solution.

Instead, organisations should remove unnecessary software, close unused network ports and gain greater visibility into where vulnerable applications exist across their environments, particularly on critical systems.

Customer conversations have increasingly shifted from whether they should prepare for AI-driven attacks, to how quickly they can do so.

Many boards are now mandating concrete response plans.

The rapid increase in threat actors' attacking capability is widely seen as an inflection point for security teams.

Thus, perhaps there has never been a better time to get the ear of executives who can make significant changes to their company's workflow.

"Never waste a crisis," Kaur said.

"Use this as an opportunity to actually change a lot of things about your business."

AI adoption important - but governance still an obstacle

Many businesses are racing to adopt generative and agentic AI, although governance concerns remain the biggest barrier to broader deployment.

Most organisations recognise AI's strategic importance, but are still waiting for governance frameworks, an increase in funding, or executive approval before implementing large-scale agentic rollouts.

There's no shortage of enthusiasm across security.

"For the most part, people are trying to take it seriously," she said.

"I've never seen this before with any other technology. The eagerness to actually leverage this and use it inside businesses, to drive processes, to create change, is everywhere."

While cost has attracted considerable industry attention, companies are willing to make the immediate expenditure if there is a good case for ROI.

Governance, however, remains a critical issue.

Kaur cited companies lacking confidence that autonomous systems will consistently make appropriate decisions without human oversight. Despite the advances in AI, its capability is inherently limited by the prompts being generated by humans.

It is not intrinsically capable of judgement or intuition like people are. It can't think for itself. 

"When you remove human judgment from a process, does that process still work?" she said. 

"Even if you can automate it on paper, typically, the answer is no."

As a result, organisations are focused on building mechanisms that enable autonomous agents to properly validate decisions before acting.

Another emerging challenge is workforce capability. While businesses are investing in automated tools, employees require significant retraining as AI changes the nature of day-to-day work.

Especially in larger enterprises, AI expertise can fluctuate considerably, requiring them to rethink workforce development alongside technology adoption.

Kaur has encouraged her own teams to continually reassess how they work, partly to ensure they are not falling behind the times.

"If you're doing the same job you were doing three to six months ago, you're missing something," she said.

Tanium is also applying AI within its own platform to simplify cybersecurity operations, enabling security teams to interact with systems using natural language prompts.

Vulnerability management, exposure management and remediation can now be performed through conversational interfaces, with AI also handling much of the underlying analysis traditionally undertaken by experienced security staff.

Despite growing interest in AI-powered defence, organisations should not view cyber resilience as simply responding faster after an attack occurs. The industry has historically overinvested in tools designed to detect attacks after multiple security failures have already occurred.