Skip to main content

When AI Shortens the Cybersecurity Clock

Share

The cybersecurity response window is shrinking. AI can help defenders at financial institutions find vulnerabilities, suggest fixes, and draft new security-monitoring rules faster. It can also help attackers discover weaknesses, chain them together, and shrink the time banks have to respond. 

That puts new pressure on vulnerability management. Traditional programs were built around a slower rhythm: identify a weakness, scan for exposure, assign the work, and patch. During a ProSight GCOR cybersecurity panel, Derek Dahlen, deputy CISO at Regions Bank, said that approach made sense when exploitation took days, weeks, or months. “But now we’re dealing with hours,” he said. 

The panelists’ guidance points banks toward a more connected model: understand exposure, prioritize what can be exploited, and remove delays across the full path from detection to remediation. 

Manage exposure, not just vulnerabilities. Kenneth Robbins, executive director of cyber defense and response at Ally Financial, said “the current way that [financial services institutions] perform vulnerability management is dead.” He said separate programs for vulnerability management, configuration management, and end-of-life technology are too narrow for the current environment. Banks need to evaluate any abnormal condition that creates exposure. 

Look for the attack path. Ryan Reynolds, head of attack surface management at U.S. Bank, said frontier AI models can chain 10, 20, or 30 lower-risk vulnerabilities into a viable path to compromise an environment. That changes the remediation question. Banks may need to identify the two or three fixes that break the chain, rather than trying to fix every item at once. 

Find the delays before the incident. Automation cannot stop at scanning. Reynolds pointed to change control, testing cycles, validation, and environment spin-ups as parts of the process that may need to speed up. If those steps stay slow, continuous testing can still leave remediation stuck. 

Prioritize in real time. Dahlen said institutions need continuous, real-time information on  their attack surface, exposure, and remediation options. That includes business conversations before an incident about what levers cybersecurity teams may need to pull, “up to and including turning off a business application.” 

Put guardrails around AI. The panelists saw value in using AI to find vulnerabilities, suggest fixes, support penetration testing, and help security teams write rules that flag suspicious activity. Reynolds said institutions need to choose the right AI model for the job and define what it is allowed to do. “You can’t assume they’re going to use what we would call common sense,” he said. An AI model asked to scan code, for example, should not be able to change that code unless the institution has explicitly approved that role. 

Bring vendors into the response plan. Software-as-a-service providers and other critical third parties are part of the attack surface. Reynolds said institutions need to know what data is stored with each SaaS provider, how the provider connects to the institution, and what conditions might require a change in service. Dahlen said vendor criticality—who holds sensitive data and who supports critical business processes—should drive third-party risk management work in this realm. Robbins added that institutions should know their SaaS providers’ security contacts, control environment, exposure, and remediation plans before an incident, so response can start with action rather than introductions. 

The takeaway: AI-driven threats are pushing vulnerability management toward present-day exposure management. Banks need to know what they have, understand what matters most, reduce friction from detection to remediation, and make governance decisions before a fast-moving cyber event forces the issue. 

Related Articles

Login to View This Content

 

Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.