Ido Geffen, CEO and Co-founder, Novee Security.
For decades, enterprise security operated on the assumption that sophisticated cyberattacks were constrained by the time, expertise and resources required. Every additional target required more time and effort, and every sophisticated campaign demanded experienced operators. Those necessities naturally limited how often advanced techniques could be deployed and at what scale.
That is no longer the case. Human expertise is still essential, but AI is increasingly handling the repetitive work that once consumed that expertise, allowing sophisticated offensive capability to scale in ways it couldn’t before.
Rather than replacing skilled operators, AI is changing the economics of cyber offense by dramatically reducing the time, expertise and cost needed to execute attacks once reserved for elite teams. As those constraints disappear, organizations can no longer assume sophisticated attacks will remain relatively scarce. The limiting factors have changed. The problem is that many security programs haven’t changed with them.
AI Is Removing The Bottlenecks
In economics, when something becomes dramatically cheaper to produce, it becomes more abundant. The same principle applies to sophisticated offensive capability.
AI isn’t making expertise free or replacing skilled operators. Still, it is dramatically reducing the human effort required to apply that expertise at scale by removing many of the bottlenecks that historically limited what those operators could accomplish. As a result, the skill floor for offensive operations has fallen dramatically. In many cases, sophisticated AI capabilities are no longer built from scratch but accessed through readily available services and marketplaces, lowering the barrier to executing advanced attacks at scale.
This automation frees experienced operators to focus on the work that still requires human judgment: understanding how a business actually operates, identifying business logic flaws, reasoning through exploit chains and adapting attacks to a specific environment.
In other words, AI is lowering the floor while raising the ceiling. Less experienced attackers can now execute techniques that once required years of specialized expertise, while experienced operators can work at a scale that no human team could previously match.
The most significant consequence is that many of the assumptions organizations have relied on for years—how often systems need to be tested, how quickly vulnerabilities can be found and exploited and how much time defenders have to respond—are becoming less reliable because the underlying economics have changed.
Elite tradecraft, once bottlenecked by headcount, is becoming something that scales.
Defenders Are Still Organized For Yesterday’s Economics
Most security programs were designed for a world in which sophisticated offensive capabilities were expensive. When skilled operators, time and expertise were the limiting factors, annual testing, quarterly remediation cycles and severity-based prioritization were reasonable ways to manage risk. They reflected the pace at which attackers could realistically operate.
Those economics have changed. Today’s attackers can probe continuously, adapt as environments change and automate much of the repetitive work that once limited offensive campaigns. As the window between vulnerability discovery and exploitation continues to shrink, organizations have far less time to rely on periodic testing and delayed remediation. At the same time, the economics increasingly favor offense: The cost of continuously discovering and exploiting weaknesses is falling faster than the cost of continuously defending every possible attack path.
For defenders, however, this creates a different challenge. Responding to a cheaper offensive model with an equally expensive defensive one is unlikely to scale. The organizations that adapt most successfully will be those that rethink how security operates, using automation to continuously identify meaningful exposure, validate what is actually exploitable and focus human expertise where it delivers the greatest value.
The result is an operational mismatch: Defenders are still operating on episodic cycles against continuous adversaries.
What Leadership Looks Like When Offense Becomes Cheap
If sophisticated offensive capability is no longer scarce, resilience can no longer be treated as a milestone. It has to become an operating model that continuously adapts as environments change and verifies that risk has actually been reduced.
That starts by challenging assumptions that may no longer hold. Leaders should ask whether their security programs are still designed around periodic assessments and compliance milestones, or whether they continuously identify meaningful exposure, verify that remediation actually worked and adapt as quickly as their environments change. The goal isn’t to layer new technology onto existing workflows but to rethink the way those workflows operate.
Every major technological shift changes not only what is possible but what is economically viable. AI is doing both for cyber offense. The question is no longer whether AI will change cyber offense—it already has. The question is whether security programs will evolve just as quickly. Organizations that recognize this shift will rethink not only the tools they use but the assumptions their security programs were built on. They will understand that resilience is no longer something you achieve once; it has become a continuous state.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?







