The front door is already open: Rethinking security in the age of “affordable” AI

By Grace Chng

It starts, as most breaches now do, with something boring. An exposed remote access portal. A forgotten edge device, still listening on the Internet after years of neglect. Ten years ago, finding that door took a skilled intruder days, sometimes weeks. Today it takes an AI model minutes.

That is the uncomfortable premise at the centre of the recent Ensign 2026 Cyber Threat Landscape Report: the barrier to becoming a capable cyber attacker has effectively collapsed. Not because the technology has grown smarter but because it has grown cheap. And cheap changes everything about who shows up to the fight.

For years, security leaders assumed that only a limited pool of sophisticated actors, nation-states and organised crime syndicates, had the resources to run complex intrusion chains. That assumption no longer holds.

Ensign’s data shows open-source models can now run offensive operations at roughly a twentieth of the cost of top-tier frontier AI Western systems, while matching much of their capability. The economics of attack have inverted.

The findings, part of Ensign testing 10 frontier AI models, found that performance is converging across Eastern and Western AI models. Cost, rather than capability, may increasingly become the deciding factor for threat actors.

Multiply that cost decline across a threat landscape that already numbers in the tens of thousands of active groups, and the maths turns grim fast. Every group that once lacked the technical bench strength to breach a hardened network can now rent that capability by the token. The result is not a handful of elite attacks. It is a swarm.

The testing of the frontier AI models in a controlled cyber range found that gaining initial network access was a trivial task for every single one. It does not matter whether the models were built in San Francisco, Hangzhou or Beijing.

Once inside, the pace changes entirely. Attacks that used to unfold over days now complete in hours. Security teams who used to assume that cyber attackers were profiled by skill level operating at a certain rhythm are now facing a different enemy, one that does not sleep, does not hesitate and does not need to eat.

The regional numbers bear this out starkly. Ransomware activity has surged 600 per cent across Australasia and 400 per cent across East Asia, a spike the report tied directly to the falling cost of automated attack tooling.

Singapore, prized by attackers because of its digital maturity and dense financial infrastructure, has seen the resale value of a stolen identity package climb to USD$95, more than triple its 2023 price of US$30.

The fight is not lost. Ensign’s assessment surfaces a narrow advantage for defenders: AI models remain unreliable once they move past the perimeter. At least half the models tested in the cyber range stumbled on lateral movement, failing to consistently harvest and use the credentials needed to spread through a network.

For security leaders, that clumsiness is the only room left to manoeuvre.

Perimeter defence and patch cycles which served as the primary success metric to keep out attackers no longer work.
Ensign’s report states clearly that organisations have to be build their cybersecurity muscle around detecting and containing attacks instead.

That reframing – from prevention rate to time-to-containment is not a rhetorical flourish. It is a proposed change to how security performance gets measured, reported and funded at the executive level. A security operations centre (SOC) that stops 99 per cent of probes but takes three days to notice the one that succeeds is, under this framework, failing. A SOC that lets more through but catches the breach in twenty minutes is winning.

What can cybersecurity defenders do in the AI age?

The goal is not to stop the AI. It is to slow it down to something closer to human speed, buying time for a human analyst to intervene.

Getting there requires deliberately engineering friction into internal networks, suggests the Report. This would include network segmentation that forces an attacker to go through multiple inspection points, hardened trust boundaries at the domain controller level, and lateral movement restrictions tight enough to push automated tools into noisy, non-standard techniques.

A major finding that Board Directors must consider is the pace of obsolescence facing their own defences. Frontier AI capability is advancing on what Ensign describes as roughly a two-month development cycle.

A security control validated at the start of the year may already be outmatched by the version of the same model running in June. Instead the Report suggests that there should be a mandated 60-day cycle of continuous security validation, thus treating defensive posture as a perishable asset rather than a tick in the box.

For business leaders outside the security function, the temptation is to treat cybersecurity as a technical problem for the chief information security officer to solve quietly in the background.

Ensign’s findings argue otherwise. Budget cycles, board reporting cadences and risk appetite statements built around annual review no longer match the speed of the threat they are meant to govern.

Organisational discipline is needed – the willingness to validate security controls every two months instead of annually, to redraw internal boundaries that make lateral movement painful, and to change the idea of success from a clean prevention scorecard to a fast containment time.

The organisations most likely to come through intact, said the Report, will not be the ones with the highest walls, but the ones that assumed that the walls would be breached, and built everything else around what happens next.

Teo Xiang Zheng, Vice-President of Advisory at Ensign InfoSecurity said, “Organisations should strengthen their cybersecurity foundations by prioritising the scanning and patching of critical Internet-facing assets and continuously validating their defences against the latest AI models. Agility and dynamism in cyber defence defines the good cyber defender from the rest.”

That is the real shift business leaders have to absorb in the new era of AI-powered crime: strong internal defence and speedy, effective detection, are the only practical defence against AI-enabled cyberattacks.

Contributed by Grace Chng, veteran tech journalist.

Tagged with: