AI in Cyberattacks: Are Defenses Ready for 2028?

Listen to this article · 8 min listen

Key Takeaways

  • By 2028, autonomous agents will launch 70% of initial cyberattacks, so we have to move from reactive defense to anticipating threats.
  • AI-driven cyberattacks are on track to cost $30 billion a year by 2027, which means we must spend more on AI defenses and the people who can run them.
  • A serious skills gap is obvious when you see that only 15% of organizations have the AI security expertise to fight these agentic AI threats.
  • Agentic AI slashes compromise time from hours to minutes, so security teams absolutely need real-time detection and automated response.
  • Even now, 40% of companies are still using signature-based detection, which is completely useless against the polymorphic threats agentic AI creates.

The latest from CISA is a wake-up call: agentic AI can now find and hit zero-days with 40% more efficiency than our own security researchers. This isn’t just about faster scripts anymore. We’re talking about attacks that think for themselves. Our defenses have to be ready for an enemy that learns and adapts on the fly without a human pulling the strings.

70% of Initial Cyberattacks Projected to Be Executed by Autonomous Agents by 2028

Gartner’s forecast that 70% of initial cyberattacks will be fully autonomous by 2028 is a number you can’t ignore. These new attacks will adapt their tactics in the middle of an operation, find vulnerabilities we haven’t patched, and stay hidden without any human guidance. My take is simple: any organization still running a traditional, people-heavy security operations center (SOC) is going to get steamrolled. You just can’t have analysts manually clicking through alerts when the attacks come at machine speed and volume. Our defense has to become as autonomous as the offense. This means sinking real money into AI-powered threat intel platforms that can see attacks coming and shut them down just as fast. The people in your SOC won’t be first responders anymore. Instead, they’ll become the strategic architects who design and babysit these autonomous defense grids. It’s part of that bigger story about AI agents getting more powerful everywhere.

$30 Billion Annual Cost of AI-Driven Cyberattacks Estimated by 2027

The money side of this is just as grim. IBM Security X-Force is calling for $30 billion in annual costs from AI-driven attacks by 2027. That number includes the direct hit from a breach, plus the business downtime, stolen IP, regulatory penalties, and the hit to your reputation. Honestly, that $30 billion figure feels low. Most companies I see can’t even begin to calculate the real long-term cost of a major breach on customer trust or their market share. When your attacker is an AI that can do its own recon, write exploits, and sneak data out without leaving a trace, good luck with attribution and recovery. Your cybersecurity budget can’t just be for keeping the lights on anymore. It has to grow to fund real innovation. You’ll need to set aside money specifically for new AI defense tools and for advanced threat hunting, and then you have to spend on training your people to use it all. Doing nothing will end up costing a hell of a lot more than investing in proper AI-backed security. And this is all before we even start talking about the complications from things like quantum AI cyber war shocks.

Only 15% of Organizations Possess Necessary AI Security Expertise

Even with these threats piling up, most companies are nowhere near ready. The Ponemon Institute found that only 15% of organizations have people who actually understand AI security well enough to fight these attacks. That’s a huge hole in the boat. Just buying a bunch of AI security software won’t save you. You have to have people on staff who know how to tune the algorithms, make sense of the output, and spot when the AI is getting it wrong. I’ve personally watched companies buy expensive AI platforms that just sit on a shelf because their security teams don’t have a clue about machine learning or adversarial techniques, giving everyone a completely false sense of safety. We desperately need more upskilling programs for existing staff and more cybersecurity apprenticeships that focus on AI. We should also be working much more closely with universities to build that talent pool. Throwing this problem at your generalist IT team is just asking for a breach. The skills gap is a massive problem, which is why things like AI Bootcamps: 2026 Job Readiness for Professionals are becoming so important.

Average Time to Compromise Reduced from Hours to Minutes by Agentic AI

Everything gets faster when agentic AI is involved, and that changes all the rules for defenders. Mandiant reported that these agents can cut the time it takes to break into a system from hours down to just minutes. Your human incident response team can’t keep up with that. By the time an analyst even sees a weird log entry and starts poking around, the AI attacker is already in, has set up shop, and is probably moving on to the next server. This is exactly why real-time detection and automated response protocols are no longer optional. Properly tuned SOAR platforms tied into good AI threat intelligence are now a baseline requirement. You have to be able to spot and kill a threat in seconds, not hours, before it spreads. It forces you to completely re-engineer your security playbook, building in automation everywhere just to keep pace.

40% of Organizations Still Rely Predominantly on Signature-Based Detection

The old playbook is officially dead. It’s shocking, but a CyberRisk Alliance survey just showed that 40% of organizations are still depending on signature-based detection as their main defense. Signatures only work for attacks we’ve already seen and cataloged. Agentic AI creates brand-new attacks and evasion tactics every single time it runs, making your signature database obsolete before it can even be updated. Sticking with signatures now is like bringing a knife to a drone fight. It creates a dangerous illusion of safety while leaving the doors wide open for any half-decent AI attacker. In my view, the only way forward is to aggressively adopt behavioral analytics and AI-powered threat hunting. You need systems that look for weird behavior, not just known bad files. Believing a static list of virus definitions can stop an intelligent, adaptive attacker is a fantasy that will get you breached. The threat from agentic AI isn’t some sci-fi scenario anymore, it’s here, it’s real, and it means organizations have to completely change their approach by prioritizing AI on defense, building real expertise, and automating response now.

What is agentic AI in the context of cybersecurity?

In cybersecurity, agentic AI are systems that can think and act on their own. They can make decisions, plan a course of action, and carry out tasks without a human operator constantly giving commands. This means they can independently find weak spots, create their own attack tools, launch the attack, and change tactics if they run into trouble.

How do agentic AI threats differ from traditional cyberattacks?

The biggest difference is their autonomy and ability to learn. Traditional attacks follow a script or a human’s direct commands. Agentic AI threats can operate on their own, creating new ways to attack, getting better at hiding from your security tools, and running entire campaigns at a speed no human team can match.

What are the primary challenges in defending against agentic AI attacks?

The main challenges are their speed, their creativity, and their scale. They move too fast for human response. They can invent polymorphic attacks and even find zero-day exploits on their own. Because they’re autonomous, figuring out who is behind the attack is incredibly difficult. Your old signature-based antivirus is useless here, which is why we’re all moving to behavioral analysis and AI-driven defense.

What specific technologies can help mitigate agentic AI cybersecurity threats?

To fight back, you need a modern stack. That means using AI-powered IDPS to spot and block threats, SOAR platforms to automate your response in seconds, and behavioral analytics tools that can tell you when something on your network just doesn’t look right. Some teams are even using things like GANs to basically build a sparring partner, an AI that helps them model threats and test their defenses before a real attack happens.

How can organizations build internal expertise to combat agentic AI threats?

You have to invest in your people. This means sending your security team to get specialized training in machine learning and adversarial AI. You should also start apprenticeship programs focused on AI security, partner with local universities to find new talent, and make a point of hiring security pros who already have an AI or ML background. You can’t buy your way out of this. You have to build the skills internally.

Andrew Castillo

Principal Innovation Architect Certified Artificial Intelligence Practitioner (CAIP)

Andrew Castillo is a Principal Innovation Architect at NovaTech Solutions, where she leads the development of cutting-edge AI solutions. With over a decade of experience in the technology sector, Andrew specializes in bridging the gap between theoretical research and practical application. Her expertise spans machine learning, cloud computing, and cybersecurity. Prior to NovaTech, she honed her skills at the Global Institute for Digital Advancement. A notable achievement includes leading the team that developed a novel AI algorithm, resulting in a 30% increase in efficiency for NovaTech's core product line.