Cyberattacks Are Moving at AI Speed. Can Your Small Business Keep Up?

SofTouch Systems cybersecurity banner showing a fast-moving AI-driven cyberattack hitting a protected business network with monitoring and security controls.

Cyberattacks are moving at AI speed. That is no longer a prediction.

In September 2026, Palo Alto Networks Unit 42 described an intrusion where a human attacker used frontier AI models and agentic frameworks to move through an enterprise environment in less than 10 hours. Unit 42 estimated that comparable work could normally require about two weeks of coordinated human effort.

The attacker did not rely on one magical zero-day. Instead, AI agents helped execute familiar attack steps faster, in parallel, and with less waiting between decisions.

For a small Texas business, that changes the security question.

If an attacker can move from first access to deep compromise in hours, can your business still depend on someone noticing the problem tomorrow morning?

SofTouch Systems cybersecurity banner showing a fast-moving AI-driven cyberattack hitting a protected business network with monitoring and security controls.
AI is accelerating cyberattacks by compressing reconnaissance, credential theft, and system access into much shorter windows. Small businesses need monitoring and response that can keep pace.

Unit 42 reported that a human attacker used frontier AI models and attack-specific agentic AI frameworks during an intrusion into an enterprise environment.

The attack moved through more than 50 MITRE ATT&CK techniques in under 10 hours. The AI agents mapped systems, searched source repositories, identified exposed credentials, gained higher-level access, interacted with CI/CD systems, and reached cloud and AI infrastructure.

According to Unit 42, the significant change was not revolutionary hacking technique. It was operational speed.

The AI agents could monitor results, evaluate what happened, choose the next action, and keep working without waiting for a human operator to manually perform every step.


Traditional cyberattacks often include pauses.

An attacker scans a system, reviews the results, researches a vulnerability, tries credentials, waits for access, checks what worked, and then decides what to do next.

AI agents can compress many of those steps.

They can also work in parallel.

One agent can map systems while another reviews code. Another can search for credentials while a fourth checks cloud permissions.

The attacker still sets the objective, but the tactical work can happen much faster.

That means security controls designed around slow human response may become less effective.


The Unit 42 case did not depend on an exotic attack that small businesses could never defend against.

It involved familiar security problems such as exposed services, credentials, excessive permissions, secrets stored where they could be found, and connected systems that allowed access to spread.

That matters because AI does not need to invent a new weakness when businesses already leave ordinary weaknesses unresolved.

AI can simply find and use them faster.


A large enterprise may have a security operations center monitoring systems around the clock.

A five-person Texas business probably does not.

That gap becomes more important when attacks speed up.

If an employee clicks something suspicious at 4:30 p.m. on Friday, a business cannot assume the attacker will still be sitting on the same computer Monday morning.

They may have already tried:

  • Cloud email accounts
  • Saved browser credentials
  • Shared folders
  • Remote access
  • Administrator accounts
  • Backups
  • Business applications
  • Connected AI tools

The issue is not that every small business will face a frontier-AI attacker tomorrow.

The issue is that the economics of automated attacks are improving.


Endpoint protection remains essential.

However, antivirus usually watches one part of the environment: the device.

An AI-assisted attacker may move across identity, cloud systems, email, code repositories, remote access, and other applications.

That is why small-business security needs layers.

Those layers should include:

  • Managed endpoint protection
  • 24/7 monitoring
  • Strong identity controls
  • MFA or passkeys
  • Password management
  • Patch management
  • Backup monitoring
  • Restricted administrator access
  • Alert review and escalation

Continuous monitoring does not mean someone stares at a screen all night.

It means systems watch for suspicious behavior and generate alerts when activity crosses known risk thresholds.

The important part is what happens next.

A security alert that sits unread until Monday morning has very different value from an alert that triggers investigation and containment while the attack is still developing.

AI-speed attacks increase the importance of reducing that delay.


Passwords remain valuable to attackers because one account can unlock multiple services.

A reused password may reach email, cloud storage, accounting, CRM, or remote-access systems.

A stolen browser session may sometimes bypass the need to enter the password again.

That is why password-first security still matters.

Businesses should use unique passwords, a password manager such as 1Password, MFA or passkeys where available, and separate administrator accounts for higher-risk work.

Reducing account overlap limits how quickly one compromise can spread.


The Unit 42 case also reinforces a basic security principle: least privilege.

If every employee has broad access to files, cloud systems, backups, and administrative tools, an attacker using one compromised account inherits that reach.

Small businesses often grant broad access because it is convenient.

Convenience becomes a security problem when the account is stolen.

Employees should have the access they need to do their jobs, not permanent access to everything the company owns.


Faster attacks also reduce the time available to protect backups.

If an attacker reaches backup systems, they may try to delete recovery points, change retention settings, or steal backup credentials.

A business should know:

  • Whether backups completed successfully
  • Who can administer them
  • Whether backup credentials are separate
  • How many recovery points exist
  • Whether restores have been tested

A backup that cannot survive the incident is not a reliable recovery plan.


The right response is not to buy every new AI security product.

Start with the basics that reduce attacker speed and limit the blast radius.

  1. Patch systems quickly. Remove known weaknesses before automated tools find them.
  2. Use managed endpoint protection. Make sure security software is monitored, not merely installed.
  3. Strengthen identity. Use unique passwords, 1Password, MFA, and passkeys where appropriate.
  4. Limit administrator access. Do not give every daily-use account elevated permissions.
  5. Monitor cloud sign-ins. Suspicious identity activity can be as important as malware alerts.
  6. Protect backups. Separate credentials and verify restores.
  7. Know who responds to alerts. A security tool without an escalation path is only half a solution.

AI is not only an attacker advantage.

Security vendors increasingly use automation and AI to analyze alerts, identify unusual behavior, summarize events, and help defenders investigate faster.

That creates a new kind of race.

Attackers can automate.

Defenders can automate too.

For small businesses, the practical answer is not building a private security AI platform. It is choosing managed tools and support that can watch systems continuously and respond faster than a purely manual process.


Did AI perform the entire 10-hour cyberattack by itself?

No. Unit 42 described a human-directed attacker using frontier AI models and agentic frameworks. The human set the objective while AI agents accelerated and automated much of the tactical work.

Did the attacker use a new zero-day vulnerability?

Unit 42 emphasized that the incident did not depend on novel zero-day exploitation. The speed came from AI-assisted execution across familiar weaknesses and attack techniques.

Why does AI make cyberattacks faster?

AI agents can perform repetitive technical tasks, analyze results, plan next steps, and run multiple lines of work in parallel. That reduces the pauses normally created by human research and manual execution.

Does a small business need 24/7 cybersecurity monitoring?

Businesses that depend on email, cloud systems, customer data, remote access, or online operations benefit from continuous monitoring because security incidents do not follow business hours.

What is the most important defense against AI-powered attacks?

There is no single defense. Strong identity, patching, monitored endpoint protection, restricted permissions, reliable backups, and a clear response process work together to reduce risk.


The most important lesson from the Unit 42 incident is not that AI suddenly made cybersecurity impossible.

It is that attackers can compress familiar attack steps into much shorter windows.

Small businesses should respond by removing unnecessary weaknesses, limiting permissions, monitoring continuously, and making sure someone is responsible for acting when an alert appears.

SofTouch Systems helps small Texas businesses manage endpoint protection, patching, passwords, backups, monitoring, and practical incident response without enterprise complexity.

If you are not sure how quickly your business would detect and respond to a compromised device or account, start with a free 15-minute IT security check.

The attacker may be moving faster. Your security process should too.

SofTouch Systems Simplifying technology, maximizing results

Sources:


Home » 24/7 monitoring » Cyberattacks Are Moving at AI Speed. Can Your Small Business Keep Up?

Discover more from SofTouch Systems

Subscribe to get the latest posts sent to your email.

What do y'all think?

Discover more from SofTouch Systems

Subscribe now to keep reading and get access to the full archive.

Continue reading