Companies Have Six Months to Prepare for Automated Attacks
Cybersecurity experts are warning that companies need to drastically improve their defenses due to the rapidly advancing capabilities of frontier AI models, which can autonomously conduct end-to-end attacks. Booz Allen’s research, combined with other testing, indicates that these models are quickly approaching parity with Chinese AI models in attack capabilities. The key takeaway is that traditional human-speed cybersecurity operations will no longer be sufficient, and companies need to adopt asymmetric defenses and a ‘design to contain’ strategy to counter this evolving threat landscape. The rise of open-weight models is lowering the barrier to entry for automated attacks, making them a more accessible and cost-effective option for attackers.
Cybersecurity experts are warning that companies need to drastically improve their defenses due to the rapidly advancing capabilities of frontier AI models, which can autonomously conduct end-to-end attacks. Booz Allen’s research, combined with other testing, indicates that these models are quickly approaching parity with Chinese AI models in attack capabilities. The key takeaway is that traditional human-speed cybersecurity operations will no longer be sufficient, and companies need to adopt asymmetric defenses and a ‘design to contain’ strategy to counter this evolving threat landscape. The rise of open-weight models is lowering the barrier to entry for automated attacks, making them a more accessible and cost-effective option for attackers.
With multiple benchmarks confirming that at least one frontier model — Anthropic’s Mythos 5 — can act as a fully autonomous hacker and compromise a production-grade enterprise network, cybersecurity firms are urging companies to accelerate their security efforts. Booz Allen’s research, dubbed the Cyber Weapon Index (CWI), benchmarks a model’s ability to find and exploit vulnerabilities alongside its execution capabilities.
Mythos scored an 80 on the CWI, while SpaceXAI’s Grok-4.5 scored a 49, but experts predict this gap will narrow significantly within six months as open-weight models become more prevalent. These models are lowering the barrier to entry for automated attacks, making them a more accessible and cost-effective option for attackers.
Recent incidents, such as a four-day Chinese-speaking cyberattack on Taiwanese government servers, demonstrate the advantage of near-autonomous operations. The attackers chose which systems to map, which techniques to pull from public sources, and when to expand into new sectors, all without step-by-step human direction.
“Today’s models are extremely noisy,” says Nico Waisman, CISO at offensive cybersecurity vendor XBOW. “They weren’t built to be quiet, and in offensive operations noise means early detection. That’s what makes an attacker think twice before turning an agent loose on a real target.”
Companies should shift from patching vulnerabilities – a strategy that’s becoming increasingly ineffective – to ‘design to contain’ strategies, utilizing AI to automate every aspect of their defenses, from detection engineering through triage to incident response. Booz Allen’s approach, dubbed Guile, uses deception – presenting false leads and dead ends – which AI models are likely to fall for, while human attackers rarely do.
“The frontier model was not our differentiator – we did not have a special one,” Waisman says. “The harness and the people were the differentiator.”
