Blog Post

When the Adversary Is Running the AI Agents

October 5, 2026

Table of Contents

Agent governance content addresses an organization's own agents. The other direction is an adversary running them, and the published figures on that are specific enough to be modeled rather than gestured at.

‍

Average breakout time, meaning the interval from initial access to movement onto a second system, fell to twenty-nine minutes in 2025, down from forty-eight the year before. The fastest observed was twenty-seven seconds, and in one intrusion data began leaving within four minutes of initial access.

‍

Which Model Term Changes?

‍

Two of them, and the second is the one that gets missed because it hides inside a severity estimate.

‍

Frequency rises directly, with AI-enabled adversary operations up eighty-nine percent year over year. More attempts arrive, which moves the likelihood side of any scenario without touching what an event costs.

‍

The Containment Assumption Breaks

‍

Severity estimates carry an implicit assumption that response limits scope. A model calibrated on historical events inherited whatever containment happened at human speed in those events. Where attacker speed compressed sixty-five percent in a year and response time did not, containment contributes less than the calibration assumed, so the historical severity distribution understates rather than staying valid.

‍

Why Is the Ratio the Real Input?

‍

Because the attacker's speed is identical for every organization and the ratio is not.

‍

Activity stream showing a session paused within seconds of a volume anomaly, with the constituent signals from four sources each individually permitted
Where containment happens in seconds rather than hours, the scope reached before a session stops is a different quantity from the historical case.

Twenty-nine minutes matters only against a detection and response interval. An organization detecting in ten minutes with automated containment and one detecting in six hours face the same attacker and land in completely different places. So the modeling input is the ratio of attacker pace to defender pace, which is a property of your own environment.

‍

Which Makes One Metric Load-Bearing

‍

Mean time to detect stops being a performance indicator and becomes a severity input. A figure measured in hours against a breakout measured in minutes says the uncontained case is the realistic one, and the model should reflect that rather than the historical average.

‍

What Does Malware-Free Intrusion Change?

‍

Which controls contribute to the frequency reduction, which reorders an investment case.

‍

The same reporting puts a large majority of intrusions in the malware-free category, where adversaries authenticate with stolen credentials and use native administrative tooling. Signature-based detection has nothing to match against in those cases, so its contribution to reducing frequency is close to zero for the dominant pattern.

‍

What Does Contribute?

‍

Identity controls and cross-domain correlation, because the activity is legitimate-looking on any single source. An intrusion that authenticates properly and uses approved tools is visible in the relationship between events rather than in any one of them, and attack vectors ranked by exposure puts valid account abuse at the top for the same reason.

‍

What Is the New Vector With No Base Rate?

‍

Prompt injection against employees' own assistants, which arrived without appearing in any historical loss dataset.

‍

Portfolio view showing inherent and residual annual loss alongside annual likelihood and the reduction attributable to controls
A stated likelihood is the term a new access vector moves, and it is the term with no historical observations behind it.

The report documents adversaries injecting malicious prompts into legitimate generative AI tools at more than ninety organizations, generating commands to steal credentials. The injection is an initial access route through a sanctioned application rather than through a vulnerability or a phishing message.

‍

Which Leaves the Frequency Term Unanchored

‍

A vector with ninety documented organizations and no prior history has no base rate to estimate from. The honest treatment is a stated assumption rather than a derived figure, labeled as such, and carrying prompt injection as a priced condition sets out how to hold a scenario that cannot be patched.

‍

Does Magnitude Ever Stay Stable?

‍

For the fully completed event, largely yes, and separating that from the truncated case is what makes the model right.

‍

What a completed exfiltration or a completed encryption costs is determined by what was reached and what it was worth, and neither changed because the attacker moved faster. So the severity of the worst case is roughly stable while the probability of reaching that worst case has risen, because fewer events get interrupted partway.

‍

Which Reshapes the Distribution Rather Than Moving It

‍

Probability mass moves toward the upper end rather than the maximum increasing. More events run to completion, so the middle thins and the tail thickens, and reading a distribution at more than one point is what makes that visible where an average alone hides it.

‍

What Should Be Reassessed?

‍

Three inputs, and all three are already in the model under different names.

‍

The containment factor, meaning whatever proportion of scope the severity estimate assumes response prevents. The detection interval, since it now feeds severity rather than only reporting. Then the frequency for credential-based access, which the malware-free finding suggests is the dominant pattern rather than one of several.

‍

What Should Not Change?

‍

Asset values and the cost of a completed event. Compression is a speed and reach story, and treating it as a reason to inflate every term produces a figure nobody can defend, which the limits of a modeled figure covers.

‍

Does the Same Compression Help Defenders?

‍

In one place, and it is the only response that operates at the relevant speed.

‍

Nothing a person decides fits inside twenty-nine minutes once detection, triage and escalation are included. Automated containment does, and it is the only control on the response side that scales with the attacker rather than against them. Everything else shortens the human part of a process that was already too slow.

‍

What Makes Automated Containment Tolerable?

‍

A bounded action set and a reversible effect. Suspending a session or revoking a token is recoverable in minutes if wrong, while disabling an account or isolating a host during business hours is not, so the automation that gets deployed is the automation whose mistakes are cheap.

‍

Which Is a Modelable Trade

‍

The cost of a false containment against the severity reduction from acting inside the window. Both are estimable, the first from how often the detection fires wrongly and what an interrupted session costs, and stating what a control removes is the discipline that keeps the second from being asserted.

‍

What Should Be Established?

‍

Three figures, and the first two are the comparison that matters.

‍

Current mean time to detect and mean time to contain, measured rather than targeted. Whether containment is automated at any point or depends on a person deciding, since the second cannot operate inside twenty-nine minutes. Then what the severity estimate assumes about containment, which is frequently an unstated multiplier rather than a documented input. Cyber risk quantification that separates duration from magnitude is what allows the compression to be modeled without inflating the whole figure.

‍

Model the Ratio, Not the Attacker

‍

Average breakout time fell to twenty-nine minutes from forty-eight, with a fastest observed twenty-seven seconds and one case where exfiltration began four minutes after access. Frequency rises directly, since AI-enabled operations were up eighty-nine percent, and the second effect is less visible because it hides inside a severity estimate. A model calibrated on historical events inherited the containment those events happened to achieve at human speed, so where attacker pace compressed and response did not, the historical severity distribution understates rather than remaining valid. The attacker's speed is the same for everyone and the ratio to your own detection interval is not, which makes mean time to detect a severity input rather than a performance metric. Kovrr's cyber risk quantification separates duration from magnitude, which is what the change requires.

‍

To see exposure modeled with containment as a stated input rather than an assumption, book a demo mapped to your own estate.

Yakir Golan

CEO

Attack Compression FAQs

Speak to an Expert

What is the current average breakout time in a cyber attack?

Does AI-accelerated attack speed change frequency or severity?

Why is the attacker-to-defender ratio the right modeling input?

What does malware-free intrusion mean for control investment?

Is prompt injection an initial access vector?

Does the cost of a completed cyber event rise with attack speed?