AI is shrinking attack windows, and it’s forcing a complete rethink of cyber resilience – here’s how organizations can prepare
Commvault has urged companies to improve their business continuity and resilience plans in the face of flaws spotted by AI
The rapid rise of flaw-spotting AI means companies need to bolster resilience plans to avoid becoming victims.
That's according to Commvault, which pointed to two key changes in security. Notably, advanced models are spotting a huge number of vulnerabilities — notably with the rise of frontier models like Anthropic Mythos and OpenAI's GPT-5.5 Cyber.
This increased level of automation is enabling threat actors to take advantage of exploits near-instantly, researchers warned. That collapse in the remediation window means resilience is no longer part of recovery, but an "operating requirement".
“AI models will continue to evolve that accelerate remediation timelines and require a new approach to readiness,” said Bill O’Connell, chief security officer (CSO) at Commvault.
O’Connell noted that resilience operations (ResOps) are now vital and an area that cannot be overlooked by IT leaders.
"ResOps gives organizations a way to continuously validate readiness, advance clean recoveries, restore systems with confidence, and build resilience into the way they operate."
CrowdStrike said earlier this year that AI is speeding up the pace of attacks, while Forescout said enterprises should be ready for an explosion in vulnerabilities. All of that means companies need to do more than simply patch in order to stay secure.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"Frontier models change the economics of vulnerability discovery. AI models will reveal exploitable vulnerabilities at such a fast pace, remediation programs must evolve,” said Nick Patience, VP and AI Practice Lead, Futurum Group.
"While a rigorous patching strategy remains critical, the key now is also making sure readiness, resilience, and clean recoveries are top priorities."
Cyber resilience in the AI era
To help enterprises stay ahead amid these challenges, Commvault recommended four key steps to set up a resilience operations framework, ensuring they can maintain business continuity through an attack, outage or AI driven disruption.
Risk evaluation
The first step is to evaluate the recovery risks, with IT and security assessing how well their current plans will hold up against faster flaw spotting and exploitation cycles caused by AI.
Commvault advised looking beyond backups and asking "harder questions", such as whether critical systems can be restored cleanly and if recovery environments are isolated from compromised production systems.
Similarly, IT and security teams are advised to ensure recovery plans have been mapped to key dependencies.
Isolation is key
After that audit, Commvault said the second step was to isolate recovery to ensure critical data remains secure and backed up to support remediation efforts.
"Maintain immutable, isolated copies of critical data and workloads, separated from production identity, network, and management planes," the company advised.
"These copies help provide a clean fallback when patching or when remediation cannot keep pace."
Beyond that, enterprises should assume that recovery time objectives set before the advent of AI will no longer hold true, and reconsider them against new attack scenarios.
Identify priorities
The third step is to prioritize any systems that are business critical, identifying those that are required for the business to function, be it identity platforms, billing systems, or cloud services.
Then, set out which order they should be recovered. Don't forget to include new dependencies such as data pipelines, model repositories, and agentic workflows.
Automation can bridge gaps
Lastly, organizations should automate where they can, according to Commvault. This could include automated threat scanning or recovery orchestration and restoration.
Regular testing of recovery plans is also critical, the company noted, which can be supported through automation. This is a vital area, researchers warned, largely due to the pace of change brought about by AI.
"Organizations that embrace this four-step process will be better suited to take advantage of rapidly evolving AI models while also mitigating the risks,” Patience added.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
‘The economics of vulnerability discovery have changed’: NIST wants to modernize the National Vulnerability Database amid AI advances – cyber experts say it needs to be redesigned with machine-speed in mindNews The National Vulnerability Database was designed for human-speed. Advances in AI mean it needs a much-needed overhaul
-
Anthropic’s Mythos AI tried to dupe devs in social engineering attack, collaborated with other agentsInter-agent collaboration is a serious cause for concern, says security expert
-
Anthropic joins OpenAI in admitting loss of control in cybersecurity testsThe company found Claude AI had escaped containment three times and targeted other organizations
-
'It delivers world-class performance at 50 percent of the cost of leading models': Microsoft unveils cut-price AI for security with latest in-house model launchNews Pairing the MAI security model with GPT-5.4 gives benchmark leading results at half the cost, according to the tech giant
-
The case for the channel in an AI-driven security marketIndustry Insights AI won't replace channel partners; SMB cybersecurity still relies on trust
-
Cisco just launched two cyber-focused small language models: Antares-350M and Antares-1B aim to supercharge codebase analysis – and they run at a “fraction of the compute expense” of popular frontier modelsNews The Antares models unveiled by Cisco aim to cut costs in codebase analysis
-
Businesses need to boost cyber resilience, here’s howIn depth The government’s recently released Cyber Security Breaches Survey shows gaps in firms’ cyber resilience. How can companies improve their approach?
-
Cyber professionals are flocking to AI tools, but they’re getting tired of fixing mistakes and reviewing outputsNews Cyber pros are spending significantly more time validating AI outputs and deciding when to trust AI-generated recommendations

