Cyber Security
AI-Powered Cyberattacks Are Here. Is Your Business Ready for Machine-Speed Attacks?
Attackers are beginning to automate reconnaissance, testing and decision-making. The practical answer is stronger fundamentals, applied consistently.
10 min read — Altitude IT Security Team
Cyberattacks have always been a race between attackers finding a weakness and defenders spotting what is happening.
AI is starting to change the speed of that race.
Recent reporting described a four-day campaign against Taiwanese government and critical-infrastructure systems in which suspected China-linked operators reportedly used multiple AI agents simultaneously. The important lesson for UK businesses is not the geopolitics. It is that attackers are increasingly able to automate reconnaissance, testing and decision-making that previously required more human effort.
What reportedly happened?
According to recent reporting, attackers used multiple AI agents during a campaign targeting government and critical-infrastructure systems in Taiwan. The reported system could:
- investigate systems;
- search for vulnerabilities;
- explore several attack routes;
- reassess priorities;
- change tactics when something failed;
- operate several tasks in parallel;
- compromise user accounts; and
- extract data.
Researchers reported that up to eight agents could operate simultaneously. The campaign reportedly affected more than 20 government systems and also targeted organisations linked to nuclear safety and energy. More than 85 accounts were reportedly compromised and over 2,500 personnel records extracted.
Attribution remains sensitive. This article therefore uses terms such as “suspected”, “reportedly”, “according to researchers” and “China-linked operators”. It does not present Chinese government responsibility as confirmed fact.
The real change is speed
AI does not need to discover a completely new vulnerability to change cybersecurity. If attackers can automate work that previously required people, they can potentially scan more systems, test more weaknesses, run several attack paths simultaneously, work continuously and reassess failed approaches faster.
That changes the economics of an attack. A weakness that might once have gone unnoticed can increasingly be found and tested automatically. For businesses, that reduces the value of relying on obscurity, a low profile or the assumption that “nobody would target us”.
This is not a reason to buy every new security product. It is a reason to make sure the controls you already depend on are actually configured, monitored and maintained.
Small businesses should not assume they are too small
Most SMEs are unlikely to be individually selected by a sophisticated state-backed attacker. But that does not mean the technology is irrelevant.
Automated attack techniques spread. As more offensive activity becomes automated, attackers do not need to personally choose every victim. They can scan large numbers of organisations and look for whichever ones have weak authentication, unsupported systems, exposed remote-access services, poorly secured Microsoft 365 accounts, missing patches, weak administrator controls or inadequate monitoring.
That makes basic cyber hygiene more important, not less. A business does not need to be famous to be exposed. It only needs to present a weakness that can be found and exploited at scale.
Identity becomes even more important
Most modern business attacks eventually involve identity. If an attacker gets access to a Microsoft 365 account, administrator account or remote-access credential, they may not need a sophisticated exploit at all.
Businesses should prioritise:
- multi-factor authentication;
- phishing-resistant authentication where available;
- passkeys for suitable users and services;
- strong administrator controls;
- separate administrator accounts;
- Conditional Access where appropriate;
- removal of unused accounts; and
- monitoring for unusual sign-ins.
A compromised password should not automatically mean a compromised business. Proper identity controls can make a stolen password less useful and can give defenders a better chance of detecting unusual activity. Altitude’s Microsoft 365 Security Baseline Review looks at the configuration behind the licence, including authentication, privileged access and endpoint compliance.
Patch faster
Known vulnerabilities are ideal for automation. If a vulnerability is documented publicly, attackers can build tooling that searches for systems still exposed to it.
Keep Windows, Microsoft 365 applications, browsers, firewalls, VPN appliances, remote-access tools, business applications and servers supported and patched. The longer a known vulnerability remains exposed, the more opportunity automated attackers have to find it.
Patch management is not just an IT administration task. It is part of exposure reduction. Cyber Essentials provides a useful baseline around security updates, supported software, access control, firewalls and malware protection. Certification alone is not a complete security programme, but the fundamentals remain directly relevant when attackers can search for gaps faster.
Know what your business exposes to the internet
Many businesses have services online that nobody actively remembers. Examples include old VPN portals, remote-management systems, firewall interfaces, development environments, legacy websites, unused cloud applications and old user accounts.
Attackers increasingly automate discovery. You need to know what is visible from outside your organisation before somebody else finds it first.
This is the practical purpose of exposure management: keeping an accurate view of internet-facing services, ownership, software versions, authentication routes and the action needed when something should not be there. It is not a promise that every risk can be removed. It is a way to replace assumptions with an evidence-based list of priorities. Altitude’s Security Assurance approach starts with that wider view of business risk.
Endpoint security still matters
AI-assisted attackers still need to interact with devices, accounts and services. Strong endpoint protection helps detect suspicious processes, credential theft, malware, unexpected scripts, lateral movement and unusual behaviour.
Modern endpoint detection should form part of a wider security approach rather than relying on traditional antivirus alone. Devices need to be supported, patched, encrypted where appropriate, managed consistently and connected to a process that someone can act on when an alert appears.
Endpoint security also helps with the part of an incident that happens after an account is compromised. Isolating a device, revoking sessions and investigating unexpected activity can prevent an initial foothold from becoming a wider business interruption.
Email security remains a practical control
Email is still one of the most useful routes into a business because it connects identity, communication, links, attachments and payment processes. Machine-speed attacks do not make email controls irrelevant; they make weak email controls easier to exploit repeatedly.
Review authentication records such as SPF, DKIM and DMARC, but do not stop at DNS. Consider mailbox forwarding rules, administrator access, external sharing, suspicious sign-ins, supplier impersonation and how staff report unexpected messages. Our Email Security page provides a free public check for domain authentication, while an Email Authentication and Sending Architecture Review can look at the wider sending and protection arrangement.
Backups are still your safety net
AI does not make backups obsolete. Quite the opposite. If attacks become faster, businesses need a reliable way to recover.
Backups should be automated, monitored, protected from the same credentials used by production systems, tested and available for critical Microsoft 365 data as well as servers and files where required. A backup you have never tested is only an assumption.
Recovery is also a security control. A business that can restore clean data has more options than one forced to negotiate with an attacker or rebuild under pressure. Altitude’s Microsoft 365 Backup service focuses on protecting cloud data and proving that recovery is possible.
Monitoring matters more when attacks move faster
If attackers can automate actions, the time between initial access and meaningful damage could shrink. Businesses should monitor for events such as:
- unusual sign-ins;
- repeated failed authentication;
- administrator privilege changes;
- new forwarding rules;
- unexpected mailbox access;
- large data downloads;
- security tools being disabled; and
- new remote-access software or changes to firewall settings.
The objective is not to watch everything manually. It is to have systems capable of highlighting behaviour that needs investigation, with a clear route from alert to action. Monitoring that nobody reviews is not the same as an operational response capability.
You need an incident response plan
Technology alone is not enough. If a user account or device is compromised, someone needs to know what happens next.
At minimum, define:
- who owns the response;
- who can disable accounts;
- who can isolate devices;
- who can reset credentials and revoke sessions;
- how backups are checked;
- when insurers need to be contacted;
- when customers or regulators may need notification; and
- how business operations continue during recovery.
A plan created during an attack is not a plan. It does not need to be a large document, but it does need named responsibilities, usable access and a process that has been discussed before people are under pressure. Altitude’s cyber security services help businesses bring identity, devices, email, backup, monitoring and response into a practical assurance picture.
Cyber Essentials still covers the right fundamentals
The rise of AI-assisted attacks does not make frameworks such as Cyber Essentials irrelevant. Its core principles remain directly applicable:
- secure configuration;
- firewalls;
- access control;
- malware protection; and
- security updates.
These are exactly the kinds of controls that make automated attacks harder to progress. AI increases the importance of doing the basics consistently. It does not remove the need for sensible priorities, evidence of work done and a plan for what happens when a control fails.
The Altitude IT view
AI is not making traditional cybersecurity obsolete. It is making weak cybersecurity easier to exploit at scale.
The businesses best placed to deal with this shift will not necessarily be the ones buying the most security products. They will be the ones that:
- know what systems they have;
- protect identities properly;
- keep systems updated;
- monitor unusual activity;
- protect endpoints;
- maintain tested backups; and
- know how to respond when something goes wrong.
The technology used by attackers is changing. The fundamentals of good defence are not.
Sources and Further Reading
This article responds to recent reporting and does not reproduce the source material. The supplied reporting for the campaign is:
- Security Affairs: China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan
- CNN Business: Hackers Used Autonomous AI Agents to Attack Taiwan
Attribution in the reporting remains sensitive, so the account above uses cautious language and focuses on the practical implications for business security.