Pages

2026/09/04

The Tools Are Becoming Symmetrical. The Incentives Aren’t.


 

There is an interesting paradox developing in cybersecurity.

As increasingly capable AI systems become able to inspect software, identify vulnerabilities, analyze configurations, and potentially discover flaws humans have overlooked, much of the attention naturally goes toward the offensive possibilities.

What happens when malicious hackers have access to these tools?

It is a reasonable concern.

But something else is happening at exactly the same time.

The defenders have them too.

A security team can theoretically have AI crawling its own perimeter, examining source code, reviewing dependencies, inspecting configurations, detecting anomalies, and looking for weaknesses before someone outside the organization finds them.

There is a useful word for this: simultaneity.

Both things are happening at once.

The attacker is looking for the hole.

The defender is looking for the same hole.

And increasingly, both may be using machines capable of conducting that search at extraordinary speed.

At first glance, that sounds almost reassuring. Give both sides comparable tools and perhaps they cancel each other out.

Except they don't operate under comparable conditions.

The defender still has to ask permission

Imagine a defensive AI discovers a serious vulnerability.

It reports:

This service is vulnerable. Here is the likely attack path. Here is the remediation.

Technically, that's extraordinary.

Organizationally, what happens next might sound considerably less futuristic.

Submit a change request.

Determine the system owner.

Schedule testing.

Wait for application approval.

Present the change to the review board.

Coordinate with the vendor.

Find an acceptable maintenance window.

Confirm that the fix won't interrupt another department's workflow.

Meanwhile, the attacker has a substantially shorter process:

Does it work?

That may become one of the strangest contradictions of AI-era cybersecurity.

We could possess defensive systems capable of discovering vulnerabilities at machine speed while the organizations surrounding them continue operating at committee speed.

The bottleneck isn't necessarily intelligence anymore.

It may be institutional latency.

How quickly can an organization move from:

observation → decision → authorization → remediation

without abandoning the safeguards that change management exists to provide?

That question feels much less glamorous than talking about AI discovering zero-day vulnerabilities.

It may also matter more.

Then there is the incentive problem

There is another asymmetry that technology alone doesn't solve.

Consider the incentives on each side.

A salaried information-security analyst may spend day after day monitoring systems, reviewing logs, applying patches, checking alerts, documenting vulnerabilities, and keeping infrastructure healthy.

Success often looks like this:

Nothing happened.

No breach.

No ransomware.

No outage.

No angry executives.

No emergency conference call.

That is excellent security work.

It is also psychologically quiet.

The attacker's incentives can look very different.

There may be money.

Status.

Reputation.

Competition.

Novelty.

Ideology.

Curiosity.

And sometimes simply the adrenaline rush of getting somewhere you weren't supposed to get.

Probe.

Discover.

Exploit.

Escalate.

Each successful step provides another little reward.

Then there is the financial asymmetry.

The defender goes to work and earns the dollar that buys the lottery ticket.

The attacker is playing for the jackpot.

One successful intrusion might produce access to an entire enterprise, valuable data, extortion opportunities, cryptocurrency payments, credentials, intellectual property, or an underground reputation that opens the door to the next target.

Hundreds of unsuccessful attempts may mean very little if attempt number 301 works.

That leads to an uncomfortable equation:

Defense has to be consistently good. Attack only has to be occasionally right.

We reward explosions better than we reward prevention

Organizations have another problem.

We are often much better at recognizing incident response than prevention.

When something breaks, everyone notices.

Teams assemble.

Executives join calls.

Resources suddenly appear.

People work late.

There are status reports, postmortems, recovery plans, and eventually stories about the people who helped save the organization.

Quiet prevention rarely receives that kind of attention.

Nobody normally calls an all-hands meeting after six uneventful months and announces:

Congratulations. Nothing happened.

Yet "nothing happened" may represent thousands of good decisions.

A patch installed before an exploit existed.

A suspicious login investigated.

A configuration corrected.

A credential rotated.

A firewall rule questioned.

A server retired.

A user who reported an odd email instead of clicking it.

The absence of disaster is difficult to dramatize.

That makes cybersecurity an unusual profession: some of its greatest victories are events that never occur.

AI doesn't remove the human system around the technology

This may be the larger lesson.

When powerful new technology arrives, we naturally focus on what the tool can do.

But capability does not automatically become organizational capacity.

An AI may detect a vulnerability in seconds.

That does not mean an organization can remediate it in seconds.

An AI may recommend the correct action.

That does not mean anyone has authority to perform it.

An AI may continuously patrol the perimeter.

That does not mean the people responsible for the perimeter have the autonomy, staffing, incentives, or processes necessary to act on what it finds.

The technology may eventually expose weaknesses that have very little to do with technology.

Ownership.

Bureaucracy.

Communication.

Incentives.

Decision rights.

Risk tolerance.

Trust.

The vulnerability may be sitting in the software.

But sometimes the real weakness is the organization surrounding the software.

The next arms race may be organizational

This is why I suspect the cybersecurity competition created by advanced AI will not simply be:

AI attacker versus AI defender.

It may increasingly be:

AI-speed attackers versus organizations capable of operating at AI speed.

That doesn't mean eliminating oversight or allowing automated systems to make consequential changes without controls.

It means recognizing that our operating models were often designed for a world in which humans discovered problems, humans investigated them, humans proposed solutions, and humans executed each step.

Machine-speed discovery changes one part of that equation dramatically.

The rest of the organization eventually has to adapt.

And somewhere inside that transition is perhaps the most interesting paradox of all.

The offensive and defensive technology may increasingly resemble each other.

The motivations won't.

The permissions won't.

The economics won't.

The bureaucracies certainly won't.

The tools are becoming symmetrical faster than the incentives are.



Image by geralt from Pixabay


No comments: