Skip to main content

Most crisis playbooks were written for a human on the other end. Someone who wanted money, made demands, set deadlines, and - crucially - could be talked to. Buy time. Open a channel. Bring in a negotiator. The entire ransomware response industry is built on the assumption that the attacker is a counterparty.

That assumption is starting to fail, and the data is beginning to show why.

What the numbers actually say


IBM's 2026 Cost of a Data Breach Report found that AI-driven cyberattacks surged 56% globally over the past year. More than one in four organisations worldwide - and 22% in the UK - reported experiencing AI-generated attacks. The most common forms were deepfake impersonation (45%), AI-enabled malware (19%) and AI-assisted phishing (17%).

It's worth being precise about what those figures mean, because the honest reading is more useful than the alarming one. Most of what's counted today is AI as a force multiplier for human attackers: faster, more convincing, cheaper to run at scale. There is still, for now, a person behind most of it setting the objective.

But the trajectory is clear. As IBM's own cybersecurity lead put it, attacks that used to take days can now be executed in minutes - and the recommendation is a shift from reactive security toward continuous, autonomous defence. That single phrase - autonomous defence - is where the real story sits, and it deserves more scrutiny than it usually gets.

The genuinely new thing isn't the absence of a human. It's the speed.


Data theft with no negotiation counterparty is not new. Espionage and credential harvesting have always operated that way - nobody expects a hostile intelligence service to call and open talks. What's changed is not that there's no one to negotiate with. It's that the attack now moves at machine speed, adapts as it goes, and pursues a fixed objective - acquire everything held on this subject; find and exfiltrate this data set; move laterally until you can't - without pausing for human decision-making on the attacker's side.

You can't negotiate with a process that isn't waiting for your reply. You can't buy time from something that finishes before your incident bridge has even convened. And you can't appeal to the self-interest of code that has no interest beyond its objective function.

This breaks the crisis model at the root. The first hour of most cyber-crisis plans is built around assessment and containment while keeping options open. Machine-speed attacks collapse that window. By the time a human has confirmed the incident is real, the objective may already be met.

So does defence have to be automated too?


Partly - and this is the uncomfortable part.

If an attack completes in minutes, the containment loop has to run faster than a human can convene, deliberate and authorise. Detecting the anomaly, isolating the affected segment, revoking credentials, cutting a network path - for the fastest-moving attacks, these will increasingly be automated decisions, made by defensive systems without waiting for a person to say yes.

That is the "AI defending against AI" future, and for the containment loop specifically, yes: humans are too slow. The honest answer to "should we let machines pull the trigger" is that for a narrow class of fast, unambiguous threats, we already do, and we'll do more of it.

But - and this is where most of the commentary stops too early - automated containment is itself a new source of crisis.

The kill-switch problem no one wants to own


An automated kill switch that isolates a compromised system is only as good as its ability to tell a real attack from a false positive. Get it right, and it saves you. Get it wrong, and your own defences have just taken production offline, cut off a hospital ward, halted a trading desk, or disconnected a plant - with no attacker involved at all. You've done the adversary's job for them.

This creates a category of incident that barely exists in current playbooks: the self-inflicted outage. Operations that suddenly cease - not because an attacker broke something, but because your automation decided to. And the faster and more autonomous the defence, the higher the stakes of every false positive.

Three questions follow, and most organisations can't answer any of them:

  1. Who authorised the machine to end operations?
    If a kill switch can halt a revenue-generating system, someone has to have pre-agreed that it may — and pre-agreed the thresholds. That's not a technical decision. It's a board-level risk decision, and right now it's usually made implicitly by whoever configured the tool.

  2. What happens to the business when systems vanish with no warning?
    Staff, customers, regulators and partners all need to be told something, fast, when operations stop — and "our own security system did this deliberately" is a harder message to deliver than "we were attacked."

  3. How do you coordinate the humans when the systems they'd normally use are the ones that have just been isolated or wiped?
    If your defensive automation has cut off, quarantined or shut down your primary environment, your email, chat and collaboration tools may be inside the blast radius.

What crisis response has to become


The role of human crisis management doesn't disappear in the AI-versus-AI world. It moves. It stops being negotiation with the attacker and becomes governance of the automation and management of its consequences. Specifically:

Pre-authorised decision rights. Before an incident, the board decides which systems the automation may take offline, under what conditions, and who - if anyone - can override it in-flight. Waiting until the incident to decide this means it's decided by default settings.

Reverse business continuity. Continuity planning has always asked "what if an attacker takes this down?" It now has to ask "what if our own defences take this down?" - and plan for outages that arrive with no warning and no attacker to blame.

Communications infrastructure that survives its own containment. The channel used to coordinate the response cannot live inside the environment the automation might isolate, quarantine or wipe. If your defensive kill switch can cut off Microsoft 365, then the crisis team's ability to talk to each other cannot depend on Microsoft 365. Out-of-band, independently hosted communication stops being a nice-to-have and becomes the precondition for managing an automated response at all.

Rehearsal of the false positive. Teams should exercise not just "we've been breached" but "our automation just halted operations and we're not yet sure whether it was right." That's a genuinely different muscle.

The honest conclusion


Is the future AI defending against AI because humans are too slow? For the detect-and-contain loop, increasingly yes. Humans cannot out-run a machine-speed attack, and pretending otherwise is how you lose.

But automation buys speed at the price of judgement. It cannot decide whether it's worth halting a hospital's systems on a 70% confidence signal. It cannot manage the reputational fallout of a self-inflicted outage. It cannot reassure a regulator, hold a business together through an unexpected shutdown, or make the call that a false positive is more dangerous than the threat it's responding to.

That is the human layer - and it doesn't get faster. It gets better placed. Its job is no longer to negotiate with an adversary who isn't there. It's to govern the machines doing the fighting, and to keep the organisation running through decisions those machines make in milliseconds.

The organisations that come through this era well won't be the ones with the fastest kill switches. They'll be the ones who decided, in advance and with clear heads, who gets to pull them - and who made sure they could still talk to each other after they'd been pulled.

Richard Stephenson
Written byRichard Stephenson
05 Aug 2026
Richard is the CEO of crisis management software provider YUDU Sentinel. Richard has run public listed companies, mid-market private equity investments and tech start-ups. His professional skills include digital strategy, crisis management, risk and digital document publishing.