AI Made Hackers Faster
That’s Why the Fundamentals Matter More Than Ever

By Ed Correia

CrowdStrike recorded a breakout time of just 51 seconds in 2024. Yet the attacks succeeding aren’t using sophisticated exploits. They’re walking through unlocked doors.

The Marks & Spencer ransomware attack that hit the headlines in 2025 didn’t begin with advanced malware or a zero-day vulnerability. It started with a phone call. An attacker impersonated an employee, called a third-party help desk, and asked for a password reset. That single call ultimately cost the major UK retailer £300 (~$410) million in lost profit, wiped over £750 million (~$1.02bn) off their market value, and kept their online ordering offline for 46 days. If you haven’t followed the story, M&S is roughly equivalent to a combination of Macy’s and Whole Foods: a household name with 65,000 employees and over 1,400 stores.

Meanwhile, AI has compressed attack timelines dramatically. Industry analyses show time from vulnerability disclosure to exploitation has shrunk from weeks to days, with some critical flaws exploited within hours of public disclosure (Verizon, 2025). Attackers aren’t getting smarter; they’re getting faster, and the outcome will likely favor those with security basics in place.

Here’s your quick read brief:

  • The average eCrime breakout time dropped to 48 minutes in 2024, with the fastest recorded at 51 seconds, and entry points remain unchanged: stolen credentials, unpatched systems, and social engineering (CrowdStrike, 2025).
  • 88% of SMB breaches involve ransomware, with most exploiting fundamental security failures (Verizon, 2025).
  • Organizations using security automation reduce breach costs by $2.22 million on average, not through sophisticated tools but through consistent execution of basics (IBM, 2025).

When Attackers Move Faster, Your Basics Become Your Best Defense

AI-powered attacks sound terrifying. But they’re exploiting the same weaknesses we’ve known about for years, just at speeds your traditional defenses can’t match.

Eighty-six percent of business leaders reported at least one AI-related security incident in the past year (Cisco, 2025). That statistic sounds alarming until you look at how those incidents unfolded. The entry points weren’t novel. They were the same vulnerabilities security professionals have warned about for decades: weak or stolen credentials, unpatched systems, misconfigured access controls, and employees tricked by convincing messages.

What AI changes is speed and scale. Where crafting a convincing phishing email once required language skills and cultural knowledge, AI now generates locally appropriate, grammatically perfect attacks in seconds. Where scanning for vulnerabilities once took days of manual work, automated tools now identify and exploit weaknesses before most organizations know they exist.

What that speed means for defenders is that the basics matter more, not less. If your credentials are strong and your multi-factor authentication (MFA) is everywhere, speed doesn’t help attackers get in. If your systems are patched within days instead of months, automated scanning finds nothing to exploit. If your backups are tested and immutable, ransomware encryption becomes an inconvenience instead of a catastrophe.

The M&S attack illustrates this perfectly. Despite the company’s significant investment in cybersecurity, the attackers bypassed technical controls entirely by exploiting a procedural weakness at a vendor. One verification failure, one password reset, but $410 million in consequences.

As Tenable’s Chief Security Officer noted in their 2025 year-end review, “Neglecting fundamental cyber hygiene allows malicious AI to execute massive-scale attacks with unprecedented speed and low skill.” The good news embedded in that warning is that AI-powered attacks can’t succeed if you’ve closed your most critical exposures.

The Five Fundamentals That Stop 90% of Attacks

Security vendors will happily sell you sophisticated tools. But research consistently shows that most breaches exploit failures in basic controls that cost little to implement correctly.

After reviewing hundreds of breach reports and working with businesses across manufacturing, construction, and professional services, I keep seeing the same five failures creating the same catastrophic outcomes. Address these, and you’ve eliminated the entry points that enable most attacks.

Identity and access controls come first

The M&S breach started with a compromised identity. Attackers didn’t hack their way in; they convinced someone to hand over the keys. Multi-factor authentication everywhere, no exceptions for executives or convenience, stops the vast majority of credential-based attacks. Microsoft’s data consistently shows MFA blocks 99.9% of account compromise attempts. Yet I regularly see businesses with MFA on email but not on their VPN, or on the VPN but not on administrative accounts. Partial implementation is barely better than none.

Patching speed has become survival speed

When vulnerabilities are exploited on the same day they’re disclosed, your patching cadence determines your exposure window. Industry data shows organizations took weeks or months to remediate critical vulnerabilities in 2025, while attackers exploited them within hours (Verizon, 2025). The goal should be 48 hours for critical patches on internet-facing systems. If that sounds aggressive, consider that the alternative is operating with known vulnerabilities that automated tools are actively scanning for.

Backup testing matters more than backup completion

This distinction catches many businesses off guard. They have backups running nightly. The logs show successful completion. But modern ransomware routinely targets backup systems directly, and only 39% of UK-based companies successfully restored from backups in 2025 (Covenco, 2025). Having backups and being able to recover from them are completely different things. Monthly restoration testing, using your actual recovery procedures and measuring real recovery time, separates businesses that survive ransomware from those that pay ransoms or close their doors.

Network segmentation limits blast radius

When attackers got into M&S’s systems, they were able to move laterally until they reached critical infrastructure. Flat networks, where any compromised system can reach any other system, turn single points of entry into total compromises. Segmentation doesn’t prevent initial access, but it contains the damage and gives defenders time to respond before ransomware encryption spreads everywhere.

Shadow AI visibility closes the newest gap

Your employees are using AI tools you don’t know about. Eighty-one percent of security teams have zero visibility into their organization’s AI usage (Cycode, 2025). Every unauthorized AI tool is a potential data leak, feeding your confidential information into systems you don’t control. Creating approved alternatives before enforcement gives employees productive options while giving you visibility.

For more on building AI governance, see my previous article on making AI work for your business.

My 90-Day Fundamentals Reset

You don’t need perfection. You need measurable progress on the basics that actually stop attacks. Here’s how to start without overwhelming your team or your budget.

The businesses I see deploying and managing effective security systems aren’t the ones with the largest budgets. They’re the ones executing consistently on fundamentals. The following approach works whether you have an internal IT team, work with a provider like Sagacent Technologies, or operate with a co-managed arrangement where you handle day-to-day operations while specialists handle security.

Start the first month by getting visibility into your current state. Audit all user accounts and identify any that are dormant, using default credentials, or lacking MFA. Most organizations discover accounts they’d forgotten about, including those belonging to former employees or contractors. While you’re auditing, inventory the AI tools in use across your organization. You’ll likely be surprised at what employees have adopted without IT awareness. Pick one critical system and test restoring from backup, documenting what works, what fails, and how long recovery actually takes.

Month two focuses on closing the gaps you discovered. Deploy MFA to any systems that lack it, prioritizing administrative accounts and internet-facing services. Establish a patch cadence that gets critical updates deployed within 48 hours, starting with edge devices like firewalls and VPNs that attackers target first. Create an AI acceptable use policy that acknowledges which employees need these tools while establishing boundaries around what data can be shared with external services.

The third month moves into ongoing maintenance that keeps fundamentals strong. Weekly backup verification catches problems before you need those backups. Monthly access reviews identify accounts that should be disabled. Quarterly phishing simulations reveal where training needs reinforcement. Continuous monitoring for unauthorized AI tools prevents new shadow applications from creating new exposures.

It doesn’t involve purchasing new tools or implementing cutting-edge technology. But it addresses the actual entry points attackers use. The M&S attack, with all its sophistication in execution, ultimately succeeded because basic verification procedures failed at a vendor. Similarly, the Asahi Group attack that halted six breweries in 2025 spread through connected systems that lacked segmentation. This pattern repeats across nearly every major incident: sophisticated outcomes from fundamental failures.

Getting the Fundamentals Right Matters

The threat landscape has genuinely changed. AI has accelerated attack timelines and expanded what’s possible for attackers with limited skills. But the defenses that matter haven’t changed nearly as much. Strong authentication, timely patching, tested backups, sensible segmentation, and visibility into what’s actually running in your environment: these fundamentals stopped attacks in 2015, and they stop AI-accelerated attacks in 2026.

The businesses that will thrive aren’t necessarily the ones spending the most on security. They’re the ones executing the basics consistently while their competitors hope sophisticated tools will compensate for weak foundations.

If you’re not sure where your fundamentals stand, that uncertainty itself is a signal. Businesses with solid basics know their patch cadence, know their backup recovery time, know which accounts have administrative access. If those questions give you pause, it might be time for an outside perspective.

Let Sagacent Check Your Fundamentals

Wondering if your fundamentals would survive a determined attacker? Sagacent Technologies regularly performs security assessments for businesses that believe they’re covered and consistently finds gaps that could be exploited. If you’d like a confidential conversation about your actual security posture, contact us at Sagacent.

Glossary of Terms

  • Cyber Kill Chain: The sequence of stages an attacker moves through to compromise your systems, from initial reconnaissance to final objective. Understanding this chain reveals why stopping attacks early, at the fundamentals level, is far easier than stopping them once attackers have established presence.
  • Attack Surface: Every potential entry point into your business: user accounts, internet-facing systems, software applications, cloud services, vendor connections, and employees who might click suspicious links. The larger your attack surface, the more doors attackers can try. Reducing attack surface through fundamentals like disabling unused accounts and patching known vulnerabilities shrinks the target you present.
  • Immutable Backup: A backup that literally cannot be modified or deleted once created, even by administrators with full system access. Modern ransomware routinely attempts to find and encrypt backup systems as part of the attack. Immutable copies remain safe for recovery because they can’t be altered. The “immutable” part is what makes them valuable; regular backups can be found and destroyed by attackers who’ve gained administrative access.

Extra Reading