Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

AI Transforms Cybersecurity: Attacks in Hours Instead of Months

Artificial intelligence is drastically changing the threat landscape. Where hackers once needed months, hours are now often enough. New challenges for businesses.

Dramatic shift in cyber threats driven by AI

The digital threat landscape is undergoing a fundamental upheaval. Artificial intelligence has revolutionised the pace of cyberattacks: where hackers once needed months of preparation to scout out and successfully infiltrate corporate networks, generative AI now handles these complex tasks in a matter of days or even hours.

This development confronts companies with entirely new challenges. The democratisation of hacking tools through AI has permanently changed the playing field and enables even inexperienced actors to launch highly complex attacks.

New attack methods and their speed

AI-supported attacks in real time

The main risk lies in the unprecedented speed of modern cyberattacks. AI-supported attacks run autonomously and adapt in real time to the defensive measures of the systems under attack. Even inexperienced actors can now orchestrate highly complex deepfakes and automated attacks that effortlessly bypass conventional security barriers.

This new reality means the end of the traditional cyber preparation window. Companies now have almost no opportunity to detect and repel slowly building attacks at an early stage.

Upgrading the defence

In response to these threats, companies are upgrading their own infrastructure. AI-driven security operations centres (SOCs) are increasingly taking over threat prediction in order to counteract automatically before damage occurs. In this digital arms race, transparency, control and the right response speed determine the survival of critical infrastructures.

Post-quantum cryptography becomes a present-day challenge

Shortened timelines to the breakthrough

A topic long regarded as a distant prospect is now reaching the boardroom: post-quantum security. The timeframe until quantum computers can break current encryption algorithms has shortened dramatically over the past twelve months.

Financial service providers, smart city operators and the public sector are particularly affected. For these areas, crypto agility is becoming the new survival factor.

Strategic adjustments required

Companies must adapt their strategies swiftly in order to prepare for post-quantum cryptography (PQC) and protect their sensitive data over the long term. It is no longer sufficient simply to encrypt data. Instead, organisations must be able to switch flexibly between different cryptographic algorithms in order to be prepared for future computing power.

Tighter regulation increases the pressure

DORA and the Cyber Resilience Act

It is not only technology that is increasing the pressure on companies - legislators are too. The practical application of DORA (the Digital Operational Resilience Act) for financial institutions is now firmly in focus. In parallel, the first deadlines under the EU Cyber Resilience Act (CRA) are taking effect.

By June, the notifying authorities must have established and published the procedures for assessing and designating conformity assessment bodies. From September, manufacturers of products with digital elements will be obliged to report actively exploited vulnerabilities as well as severe security incidents via a central platform.

Radical cyber hygiene required

This regulatory accountability is forcing companies into radical cyber hygiene. Anyone who does not have their incident playbooks and governance structures under control risks not only data loss but also significant sanctions.

Skills shortage as a critical obstacle

Skills gaps slow AI adoption

According to a PwC survey from the end of 2025, the biggest obstacles to using AI for cyber defence are knowledge and skills gaps. Across all sectors, companies lack the structures and expertise to securely manage increasingly connected operating systems.

Dramatic shortage of experts

There is not only a considerable shortage of qualified specialists, but also greater demand, driven by the rising number of companies that must comply with cybersecurity regulations. In the field of cyber defence alone, a shortfall of 10,000 to 20,000 specialists is currently forecast.

Universities are still investing too little in this area to equip students with the necessary skills. Higher investment could, however, close this gap.

Strategic realignment necessary

Resilience instead of pure defence

A protective wall and a few intelligent security tools are no longer enough. Cybersecurity needs a broader, more strategic approach. Companies must deploy their resources deliberately in order to concentrate on the most important priorities.

That also means examining the threat situation closely, identifying attackers and detecting vulnerabilities. The winners of digital transformation will be those companies that rely on continuous monitoring, automated response and a crypto-agile infrastructure.

Cybersecurity as a business foundation

Cybersecurity is no longer purely an IT task - it is the foundation of business sovereignty. Companies must recognise that security technologies today are an integral part of their business strategy, not merely downstream protection.

Outlook: continuous adaptation required

The rapid evolution of the AI-driven threat landscape requires companies to continuously adapt their security strategies. What is considered adequate today may already be obsolete tomorrow. Only through proactive investment in modern technologies, qualified staff and agile security concepts can companies hold their ground in this new era of cybersecurity.