Skip to content

You can’t keep up, so prioritize better.

Attackers don't need to find every route in. They just need one. COO Luke Potter argues the fix isn't more scanning. It's vulnerability prioritization: focus research where an attacker would actually look, then build the signal to catch what slips through.

Long-exposure shot of a crowded station concourse, with a static, illuminated information booth at the center while blurred figures move past in every direction.

A question I’m hearing a lot from clients at the moment is: how on earth are we supposed to keep up with all of this?

More vulnerabilities, more disclosures, more zero-days, more attack tooling, more AI-assisted research, more autonomous capability, and a general sense that the pace of change is accelerating faster than most security teams can reasonably absorb.

My answer is probably not the comforting one: you can’t keep up with everything, and I think pretending otherwise is increasingly part of the problem.

We have spent years building security programs around the idea that if we can identify enough vulnerabilities, patch quickly enough, buy enough tooling and consume enough intelligence, we will stay ahead. The reality is that a capable attacker does not need to stay ahead of everything. They just need to find one route into your organization that works.

That route may be a newly disclosed vulnerability, but equally it may be something nobody has published yet. It may be unique to the way your environment is built. It may be a weakness in a product that has never been looked at properly, a strange trust relationship, an identity path, an exposed service, an AI agent with too much privilege, or simply several fairly mundane issues that become interesting when someone thinks creatively enough to connect them.

That is the bit I think matters most.

The real threat is not just the next CVE. It is the attacker asking: “What can I do here that nobody else has thought to try?”

James recently wrote about the vulnerability gap and the growing challenge of dealing with a world where AI is accelerating vulnerability discovery at a pace organizations can realistically triage and remediate. That is absolutely part of the problem.

But there is a broader implication too. AI is making good attackers better researchers.

It lowers the cost of exploring ideas. It can help navigate unfamiliar code, reverse engineer binaries, compare versions, analyze firmware, generate hypotheses, and dismiss dead ends much faster than before. The important point is not that AI suddenly replaces skilled security researchers. It is that a good researcher can now investigate more possibilities, more deeply, in less time.

That changes the economics of offensive security.

This is why we are starting to bring more focused and targeted research directly into Constant Cyber Attack. If we identify technology, architecture, or an attack path that genuinely matters to a customer, we want the ability to go deeper than simply asking whether a known vulnerability exists.

We can take source code, binaries, firmware, or version changes and use our agents to accelerate repetitive analysis, identify areas worth investigating, gather context, and test different hypotheses. We can then use adversarial validation to try to disprove those findings rather than simply accepting whatever the first model suggests. The researcher remains in control of the decision-making, the exploitation hypothesis, and ultimately whether something is real.

That is important because the answer to the next phase of security is not generating even more noise. James’ piece makes this point well: as AI makes it cheaper to generate security hypotheses, human attention becomes increasingly valuable.

So, if you cannot keep up with everything, the obvious question becomes: what do you do instead?

For me, the answer is better prioritization.

You need to spend more time thinking about the things an attacker would actually care about.

  • What protects your most valuable systems?
  • Where do you have unusual privilege?
  • What has changed recently?
  • Which technologies sit in particularly trusted positions?
  • Where are the odd dependencies and trust relationships?
  • What did an attacker nearly manage to exploit last time?
  • Which parts of the organization have never really been looked at from an adversarial perspective?

That is where I want our research effort going. Not trying to investigate every possible weakness equally, but focusing deeply on the things where a novel route to compromise could materially matter.

And even then, we need to be realistic: we will still miss things.

Which is why the second half of this problem is signal.

You cannot assume you will identify every novel attack before somebody attempts it. If attackers are increasingly using AI and agentic methods to move faster, explore more broadly, and chain activity together, then your ability to see abnormal behavior becomes even more important.

  • Can you identify when something is probing your environment in a way you have not seen before?
  • Can you spot odd authentication, unusual API behavior, unexpected enumeration, or legitimate-looking actions being combined in a way that does not make sense?
  • Can your SOC recognize that something is wrong even if it has never seen that exact attack before?

You cannot write a signature for something that has not been invented yet. But you can get much better at understanding what normal looks like, what meaningful deviation looks like, and whether your controls and people actually respond when something starts rattling the lock.

That is where this whole market needs to move.

There is a huge amount of attention right now on who can automate more tests, launch more attacks, scan more assets, and find more vulnerabilities. A lot of that capability is genuinely useful, but volume is not the end state.

The real challenge is whether you can continually think more like the attacker.

  • Can you identify where they would focus?
  • Can you research what is unique about your environment?
  • Can you discover the routes nobody has documented yet?
  • Can you adapt when an obvious route fails?
  • And if somebody else finds something before you do, can you see it and respond quickly enough?

That is increasingly how I think about Constant Cyber Attack.

It is not about pretending we can keep up with everything. Nobody can. It is about continually making better decisions about where to look, using AI and focused research to go deeper where it matters, and then attacking the organization as a genuine adversary would.

That last part is important because a real attack path is rarely linear. An attacker tries something, learns, changes direction, combines weaknesses, hits controls, finds another route, and keeps going. If we want to emulate the real threat, our offensive security has to be able to do the same.

But the value to the customer is not simply whether we eventually find a route to compromise.

It is the signal generated along the way.

  • What did we try?
  • What worked?
  • What failed?
  • Which controls stopped us?
  • Which did not?
  • What did the SOC see?
  • What should it have seen?
  • Which apparently insignificant weakness became useful when combined with something else?
  • Where did we change direction, and why?

That is information a conventional finding or an automated attack result rarely gives you in isolation. It allows defenders to understand an adversary’s behavior in their own environment and turn that knowledge into better detection, better controls, and better decisions.

This is where Constant Cyber Attack stands apart from a market increasingly focused on automating penetration tests, replaying attack scenarios or validating individual exposures. Those capabilities all have value, but the end goal cannot simply be more attacks executed or more vulnerabilities proven. It has to be a continuously improving understanding of how someone would actually try to compromise your organization, how your defenses react when they do, and what you need to change as a result.

For us, every attack plan should leave the customer harder to compromise and better able to recognize the next attempt.

And every attack makes the next one smarter.

That is how we outpace the real threat: not by claiming we can predict everything an attacker will do, but by continuously emulating them, learning from every route they might take, and giving defenders the signal they need to respond faster than the adversary can adapt.