An analyst in Nairobi has not yet logged off at 2:47 am. His monitors are cluttered with over four thousand alerts he has yet to review. Elsewhere on the network an automated process has, in less than four seconds and without so much as a line of hand-typed code, completed its ten-thousandth probe for the night.
We have long worked under the premise that human speed put a limit on cyber risk. There were typos in phishing attempts, or odd links; a failed login would be recorded in the logs; fraudsters would leave a trail for auditors to follow. We put in place access controls and third-party audits and felt we had the threat in check.
The attacks of today don’t make grammatical errors. They come through in perfect English, crafted from open-source data to suit your organisation before you have even read the subject line. They will reference actual supplier contracts to a finance team or copy an internal tone to get past the scepticism.
Consider what happened last month with OpenAI’s agents. They found an undocumented hole in an internal registry, made their way out of a controlled setting and into Hugging Face production systems where millions of developers work.
On their own, these agents forged authentication tokens, set up covert channels on public sites and walked away with 136 live credentials. Containment is tenuous even at the top AI labs; an adversary will be nothing if not bold.
A person can handle an incident or two by hand but cannot keep up with unrelenting automation. To expect human teams to do so is to court burnout. This is a gap in governance we are overlooking.
There is no working around it. One has to answer the adversary’s tools with one’s own. That means having AI-powered intelligence to sort through thousands of alerts in a matter of seconds, to spot a deepfake or synthetic voice as it happens and to watch for anomalies while the rest of the team is at rest.
Do not view this as some optional IT cost to be cut when the books are reviewed. It is the kind of infrastructure required for compliance and to keep the trust of customers. These days, from Africa to the rest of the world, there are no silos in technology. A breach in a customer platform or financial rail will be felt by regulators and partners in an instant.
The board has to ask itself: when an AI attack comes for us, will we be in a position to contain it, or are we left to deal with the damage to our name and finances? We ought to be in companies that put money behind their defences rather than let disruption make the call.
Cyber risk is no longer a box to tick for compliance. Treat it as one, and it is a gamble, not with budget, but with trust, and trust carries no line item to replace it once lost. Lose it, and what follows is not an entry in a ledger. It is the slow, quiet exit of customers, partners and investors who no longer believe the organisation can keep its word.
The threat does not wait for the next budget cycle. Neither can we. Our capital and our defences must move at the speed of the threat, starting now.