A Coming Incident Crisis?
- phil7672
- 16 minutes ago
- 4 min read
We’re all talking about the tidal wave of vulnerabilities that is upon us, with repeated waves likely coming. As I’ve covered here, we can respond to this in various ways including ramping up speed across our entire defensive stack, which is as much about structural defense-in-depth than just faster patching. I’ve covered that here as well.
But, there’s a question as to whether the leading indicator of increasing vulnerabilities will in fact result in an increase in the lagging indicator of actual incidents. I think it will but it might be hard to measure especially if much of the increase doesn’t immediately show up in publicly reported numbers. Even amid this angst about a crisis of vulnerabilities we run the risk of neglecting various other factors that together could also contribute to a big increase in the number of incidents we have to more formally manage.
Even if just the vulnerabilities don't correlate to more incidents then the wider concern might really be the industrialization of attackers using AI capabilities, not just to find and chain vulnerabilities, but to transform how many attacks they can conduct in parallel. This applies across their entire "business" value chain from discovery to exploit to monetization. The fact is that attackers have been resource constrained. They can only perpetrate so many attacks at once. For example, one ransomware gang might only be able to execute 10 attacks a week and negotiate payments with 5 compromised organizations. This leaves plenty of other targets or, more likely, targets of opportunity sitting there with their accepted risks unrealized. But with the use of extensive AI driven automation we will see attackers being less resource constrained. That same gang might be able to do 100 attacks a week and negotiate ransoms with all of them at once.
So, incidents might correlate to the productivity of attackers not only the availability of vulnerabilities.
And, as with regular enterprises, the leading indicator of AI investment by attackers will take a while to show up as the lagging indicator of productivity (more successful attacks).
Our other impending source of incidents is also AI-fueled, and that is a crisis of authenticity. Many business processes are built on verification procedures that cannot survive AI driven fakery. Companies will have to respond to social media brand crises or other issues more and more. This will cause an increase in and of different types of incidents for security, and related teams, to handle.
At the same time, as if the other things weren’t enough, we have many operational risks associated with AI dropping into the lap of the security team and its incident response capability. For example, when the LLM-powered customer support chatbot does something stupid, or illegal, then who does the CEO call? In some organizations it’s a new trust and safety team, or an AI support team, but in many organizations the call goes to the CISO and their incident response apparatus. In the end, security teams might be dealing with more non-security incidents than classic security events.
So, we’re going to have more incidents, more types of incidents, happening with more frequency, concurrently. Most will also, irrespective of hazard, have high outrage, and so triage will be even more difficult. Remember, Risk = Hazard + Outrage.
Therefore, along with everything else on their plate, security teams are going to have to ramp up their incident response capability to cope with this. More incidents, everywhere, all at once.
But wait, it gets worse. Along with all of this, regulators and legislators of the world, in pretty much every industry, are trying to lower the threshold of significance of what is reportable in some way while also expecting that such disclosures happen faster. Of this larger number of incidents more will need to be scrutinized across security, legal, compliance, privacy, corporate communication, executive leadership and the Board, to determine what needs disclosure, when, and if so, in what way.

This is a depressingly perfect storm for many security teams whose current incident response processes aren’t built for this scale. The current incident or two per month is well handled by a home-grown process to coordinate with lawyers and others on disclosure decisions along with containment and recovery. But, in a world of many more incidents in parallel, which even if not significant, will nevertheless require more effort on disclosure and reporting decisions because of reduced thresholds for reporting.
It might not even be the security team that is the issue, your one privacy lawyer, or cyber outside counsel, might quickly become the bottleneck running up against reporting deadlines during multiple incidents of varying degrees of significance.
Ok, so it's not looking good. But there are ways through this, and that is to radically scale incident management including response, containment, recovery and possible disclosure and reporting. This isn’t to throw more bodies at this but instead to actually deploy a more sophisticated workflow to scale and improve coordination among all the teams involved in incident management.
Every organization will need world-class incident management, and tooling is the only way to achieve this without spending vast amounts on hiring more people. Gartner even has a nascent category for this called CIRM (Cyber Incident Response Management). As with other domains like red-teaming, insider threat detection, security operations and more we see massive utility in the deployment of AI to augment and scale humans in this process.

This is why I was so excited to join the board of BreachRx to help get this to even more organizations to help them scale. Other brands of CIRM are available :-)
And, in that context, I was happy to co-author this blog post with their CEO, Andy Lunsford that goes into more specifics on this challenge and what to do about it.
Bottom line: incident response management is yet another aspect of cybersecurity, and beyond, that will need increased automation to shift from the artisanal handling of a few incidents per quarter to the industrial response to dozens or more per month. Even if this doesn’t come from increased cybersecurity vulnerabilities it will be driven by the increased productivity of attackers, security teams responding to different types of non-security incidents, and more incidents needing disclosure coordination as thresholds for reporting decrease around the world.
Comments