Cisco urges continuous AI defence as threats speed up
Wed, 22nd Jul 2026 (Today)
Cisco says organisations need to replace traditional cybersecurity operating models with continuous, AI-assisted defence as artificial intelligence shortens the time between vulnerability disclosure and cyber attacks.
The company argues that many enterprise security practices were designed for an environment where vulnerabilities, software updates and incident response progressed at a much slower pace. AI has changed that timeline by enabling attackers to identify weaknesses and develop exploits more quickly.
Cisco said the interval between vulnerability disclosure and weaponisation has fallen from weeks to days or even hours. It also noted that enterprises take an average of 43 days to patch a critical vulnerability, while 40% of the most targeted vulnerabilities during 2025 affected systems with limited patching options.
The company said this growing gap requires security teams to adopt a different approach that focuses on continuous identification, prioritisation and remediation of cyber risk.
Faster analysis
Cisco outlined its own experience using AI within its Security and Trust Organisation to demonstrate the potential impact of AI-assisted security operations.
The company said it used several AI models alongside early access to Anthropic's Project Glasswing and OpenAI's Trusted Access for Cyber to analyse 1.8 billion lines of code across more than 25 programming languages over eight weeks.
According to Cisco, completing the same task without AI would have taken around eight years.
Dave West, President, Cisco Asia Pacific, Japan and Greater China, said the exercise demonstrated more than faster code analysis.
"This wasn't a faster scan. It was years of security research, engineering judgment, and threat intelligence applied across a complex environment in a way that could be repeated, measured, prioritized, and scaled," said West.
He said AI changes how security teams operate by allowing them to move from periodic vulnerability assessments towards continuous detection and response.
"Defense has to move from periodic discovery and reactive response to a continuous capability for finding risk earlier, prioritizing what matters most, and acting with greater consistency across the enterprise," said West.
Continuous posture
Cisco said organisations should treat cybersecurity as an ongoing operational discipline instead of managing it through periodic projects.
The company said this includes maintaining predictable patching and upgrade schedules, retiring unsupported systems once they reach end of life, and continuously managing exposure through greater visibility, network segmentation and containment measures.
Cisco said these practices can reduce the potential impact of cyber incidents while improving operational resilience and maintaining trust with customers, partners and other stakeholders.
Three priorities
Cisco identified three operational changes that it believes can help organisations strengthen their cyber resilience.
The first is making remediation a continuous activity by integrating patching and upgrades into regular operational processes instead of treating them as emergency responses.
The second is reducing exposure by replacing unsupported and end-of-life assets rather than continuing to operate systems that can no longer receive security updates.
The third is strengthening overall security posture through network segmentation, closing identity-related security gaps and equipping security operations centre teams with tools that improve response speed and consistency.
Cisco said organisations do not need to complete a comprehensive transformation before improving their security posture.
"None of this requires a perfect program before you start. Each step reduces risk and makes the one after it easier," said West.
Executive guidance
Cisco said AI is reshaping both cyber threats and defensive capabilities, making continuous security operations an operational requirement for enterprise organisations.
The company has published an executive brief outlining five actions that business leaders can authorise over the next 90 days to strengthen cyber defence, together with questions that security and networking teams should consider as they adapt to AI-driven threats.
"We're at an inflection point. AI is changing the threat landscape at unprecedented speed, and it's giving defenders new ways to operate securely at scale. Moving from point-in-time security to continuous, AI-accelerated defense is no longer a nice-to-have. It is the new baseline for resilience, readiness, and trust," said West.