Key Takeaways
- The president of S&J notes that AI is reducing the interval between vulnerability discovery and attack launch.
- Research from Palo Alto Networks' Unit 42 and ReliaQuest shows intrusion, lateral movement, and data theft can now unfold within minutes.
- Organizations may need faster patching, stronger segmentation, and incident plans that account for attacks outside normal working hours.
Cybercriminals are using artificial intelligence to move from vulnerability discovery to active exploitation at a pace that can overwhelm conventional security processes, according to the president of Tokyo-based information security service provider S&J.
“Attack programs can be created in the blink of an eye with AI,” the president said in a recent interview. He added that AI-driven attacks have increased in recent months, shortening the interval between identifying a weakness and launching an attack against it.
The warning follows cyberattacks affecting major Japanese businesses, including frozen food maker Nichirei, household goods supplier Askul, and beverage maker Asahi Group Holdings. System failures caused serious disruptions to corporate activities at the companies, illustrating how a security incident can quickly become an operational and supply-chain problem.
That distinction matters. Cyber risk is no longer confined to stolen files or unavailable email accounts. An intrusion can interrupt ordering, distribution, manufacturing, and customer service, particularly when tightly connected business systems allow an attacker to move across the environment.
The S&J president argued that Japanese companies can be attractive targets because many have historically experienced fewer attacks and may consequently have less mature defenses. The issue is not necessarily a complete absence of security products. It can also involve slow escalation procedures, limited visibility across older systems, or uncertainty about who has authority to isolate a critical application.
An approval process designed around an attack lasting several hours may not work when the decisive phase lasts only minutes.
Industry observations support this concern. Palo Alto Networks' Unit 42 reported that attackers were targeting vulnerabilities within 15 minutes of CVE disclosure. It also said the fastest data exfiltration it observed had fallen to about 72 minutes, while top-quartile intrusions were entering networks within 72 minutes.
ReliaQuest reported even shorter windows in some cases. Its fastest observed lateral movement fell to 4 minutes, down 85% from its fastest-observed 2024 case. Its fastest exfiltration time dropped from more than 4 hours to about 6 minutes.
These figures do not mean every attack will progress at that speed. They do show what defenders may encounter at the edge of current attacker capability. AI can help adversaries draft phishing messages, modify malicious code, examine disclosed vulnerabilities, and automate parts of reconnaissance. It can also let smaller criminal groups operate at a scale that once required more people.
Social engineering is another pressure point. Microsoft reported that AI-driven phishing emails achieved a 54% click-through rate, compared with 12% for non-AI phishing. More convincing language, rapid personalization, and automated translation can make malicious messages harder for employees to identify, especially when attackers imitate suppliers or senior executives.
Eliminating every entry point is difficult. Instead, organizations can identify likely attack routes in advance and introduce controls that reduce the damage after an initial compromise. “Countermeasures vary greatly depending on a company’s size and system configuration,” the executive noted.
That can mean mapping connections among identity services, ordering applications, production systems, and third-party access channels. Network segmentation and carefully tested isolation procedures may help prevent one compromised endpoint from becoming an enterprise-wide outage. Faster vulnerability triage also becomes more important when public disclosure can be followed by exploitation attempts within minutes.
Timing deserves attention, too. Ransomware attacks are often launched between late Sunday night and the early hours of Monday, with encryption typically completed by early Monday morning. Attackers may be counting on reduced staffing and slower decision-making. Security monitoring, escalation coverage, and authority to contain systems therefore need to extend beyond normal office hours.
“If there is a risk of a major system failure, it is also important to disconnect ordering systems,” the president said. That step can carry immediate business costs, but leaving a compromised system connected may create a wider and longer disruption.
External cybersecurity specialists can help fill monitoring and incident-response gaps, he added, although cost and responsibility remain difficult questions. Contracts should clarify who investigates alerts, who can authorize isolation, and how quickly each party is expected to act. In an attack cycle measured in minutes, ambiguity itself becomes a vulnerability.
⬇️