Palo Alto Networks reports that AI-assisted cyberattacks have compressed

What "attack compression" actually means

Attack compression describes the shrinking gap between an attacker's first foothold and the moment they achieve their objective — moving laterally, escalating privileges, and exfiltrating or encrypting data. Palo Alto Networks frames the concern in terms of time: when AI assists the intruder, the full sequence that used to unfold over hours or days can now run to completion in roughly 25 minutes.

The significance is not that any single technique is new. It is that the slow, manual steps between them — reconnaissance, figuring out which credential works where, writing a working payload for the environment in front of you — are the parts AI accelerates. Removing the human bottleneck from those steps is what collapses the timeline.

Why AI removes the delays defenders rely on

Most detection-and-response programs are built around an implicit assumption: there is dwell time. Analysts get minutes to hours to notice an alert, correlate it, and act before the attacker reaches anything important. AI-assisted operations attack that assumption directly by parallelizing and automating the reasoning an operator would otherwise do by hand.

Concretely, the compression tends to show up in a few places:

  • Reconnaissance that maps a network and identifies high-value targets without pausing to think.
  • On-the-fly generation of scripts and commands tailored to the exact systems discovered.
  • Rapid triage of stolen credentials and access to decide the shortest path to the goal.
  • Continuous adaptation when one route is blocked, instead of stopping to regroup.

What defenders should change

If the window from breach to impact can be measured in minutes, controls that depend on human review inside that window stop being reliable. The practical shift is toward prevention and automated containment: assume that once an attacker is inside, you may not have time to investigate before damage is done, so the priority is making the inside harder to move through and making containment automatic.

That points to a handful of concrete emphases. Enforce least privilege and network segmentation so a single foothold does not open the whole environment. Require phishing-resistant authentication so stolen passwords alone are not enough. Wire detections to automated response — isolating a host or revoking a session without waiting for an analyst. And rehearse the fast path: if your incident process assumes hours of lead time, test what actually happens when you have minutes.

Reading the 25-minute number honestly

A specific figure like 25 minutes is best treated as a directional signal rather than a fixed benchmark. Real intrusions vary with the target's maturity, the attacker's goal, and how much the environment resists lateral movement. The useful takeaway is the trend: the economics of an attack are being rewritten so that the tedious, time-consuming steps cost the attacker far less than they used to.

For most defenders, the honest response is to stop planning around comfortable dwell times. Measure your own mean time to detect and contain against a threat that finishes in under half an hour, find where your process still waits on a human, and decide in advance which of those steps can be automated or eliminated before an incident forces the question.

Automate Your Content with AI Video Generator

Try it Free →