Readiness
Are you prepared for an AI-enabled cyberattack?
An AI-enabled attacker is not more inventive than a human one. It is cheaper, so it looks at everything and it looks constantly. Preparedness is therefore a question about cadence: whether your estate is examined as often as it changes, or once a year.
The honest answer
The asymmetry is the cost of attention
The industry sells this as a capability problem, which is why nobody believes it. The change that actually happened is an economic one, and it is easier to defend against precisely because it is unglamorous.
- Looking used to be the expensive part
- A thorough examination of an estate took a skilled tester weeks and tens of thousands of pounds. That price, not the difficulty, is why testing settled at once a year.
- It now costs a day and tens of pounds
- The same sweep runs on machines. The economics that made a small estate not worth examining have gone, for us and for anyone testing you without asking.
- The schedule never moved
- Most programmes still test on the cadence the old price set. The exposure is the distance between those two rates.
In practice
What an AI-enabled attack actually finds
Not zero-days. A year of ordinary change that nobody has looked at, which was survivable only while looking was expensive.
- Services that outlived their purpose
- Staging environments, test endpoints and integrations that were temporary when they were built and are still reachable now.
- Access granted for a deadline
- A permission loosened to ship something on time, never revoked, and never examined again because the engagement had already happened.
- Certificates and dependencies that aged
- Expiry and drift are quiet failures. They do not announce themselves between engagements, and nothing is watching for them.
- Weaknesses that only matter together
- Individually low-severity issues that chain into real access. This is the step a scanner cannot perform and the reason a queue of findings is not an answer.
The answer
Testing at the same cadence as the attacker
Preparedness answered with evidence rather than an opinion, which means running the engagement often enough that drift is caught rather than accumulated.
- Run as often as you deploy
- The estate is re-tested as it changes, so the answer describes now rather than March.
- Only what was demonstrated
- Findings arrive proven by exploitation, with the chain that produced them, so the report is evidence rather than a list of possibilities.
- Inside declared scope
- Targets are bounded before anything runs, and destructive actions are refused by the engine unless your scope permits them.
- Against a documented authorisation
- Every mission runs against a recorded Letter of Authorisation, which is what makes testing at this frequency defensible.
Boundaries
What this does not answer
Revelion is not accredited. Where a scheme, an insurer or a contract requires a CREST or CHECK engagement, Revelion does not satisfy that requirement, and we would rather say so here than in a procurement call.
Revelion is not a replacement for a human red team. A skilled tester will still out-think an agent on novel, deeply contextual attacks, and on anything involving social engineering or physical access. That work is worth commissioning and worth keeping.
What a scheduled human engagement cannot do is run every week against an estate that changes every week. Keep the accredited test. Use Revelion for the other fifty-one weeks, so the scheduled engagement starts from a cleaner baseline and spends its time on the hard problems instead of rediscovering drift.
Related
Worth reading next
Find out what a year of drift looks like on your estate.
Talk to us
