SECURITY
SECURITY
SECURITY
Artificial intelligence is a double-edged sword when it comes to cybersecurity. It is giving defenders new ways to sift through vast amounts of telemetry, identify anomalous behavior and automate routine work. But it is also giving attackers the ability to discover vulnerabilities faster, build more convincing social engineering campaigns, and execute multistage intrusions at a scale that would have required large, well-resourced teams only a few years ago.
That shift is at the heart of “frontier AI,” a term that is increasingly important to security leaders. Frontier AI refers to the most capable, general-purpose AI models: systems able to reason through complex problems, analyze code and data, plan multistep tasks and, increasingly, invoke tools to act. Agentic AI is a particularly consequential evolution because it can plan, decide and act on a user’s behalf rather than simply generate an answer or summarize information.
For cybersecurity teams, the concern is not that every frontier model is inherently malicious. The issue is that these models can lower the cost, skill threshold and time required for adversaries to conduct sophisticated operations. Attackers can use AI to automate reconnaissance, identify exposed assets, analyze software for flaws, adapt phishing lures, write or refine exploit code, and coordinate activity across many targets simultaneously. Tasks that once unfolded serially and often required distinct specialists can now be compressed into a faster, more scalable workflow.
That compression changes the economics of defense. An organization that leaves a vulnerability unpatched for days or weeks has always carried risk. In a frontier AI environment, however, the window between vulnerability disclosure and exploit development with widespread targeting can be much shorter. The security challenge is no longer just finding weaknesses and responding to alerts. It is anticipating how a weakness, a misconfiguration, an identity control failure and a poorly segmented application environment can be combined into a viable attack path.
Many enterprise security architectures were designed for an era when attacks moved comparatively slowly. Security teams collect alerts from endpoint, identity, network, cloud and application tools. Analysts investigate those alerts, determine priority, coordinate with infrastructure teams, and eventually adjust policy or remediate the issue. That process can work well when threats are isolated, predictable and slow-moving. It is far less effective against adaptive attacks that change tactics based on the environment they encounter.
Frontier AI amplifies several security challenges:
The key point is that frontier AI does not eliminate the need for security fundamentals. It raises the cost of getting those fundamentals wrong. The U.K. National Cyber Security Centre notes that frontier AI makes it easier, faster and cheaper to discover and exploit weaknesses, while emphasizing that strong cybersecurity basics remain the most effective foundation for resilience.
Cato Networks Ltd. is addressing this problem with Cato Agentic Threat Prevention, a new capability built into its cloud-native secure access service edge platform. The company’s thesis is similar to mine. If attackers can use AI to move at machine speed, enterprises need defensive AI systems that can do more than detect threats after they begin to unfold. It’s a matter of fighting fire with fire.
Cato Agentic Threat Prevention uses autonomous agents to predict likely attack paths within a specific customer environment and generate protections to stop attacks before they escalate. It combines network and security telemetry with customer activity and threat intelligence to model risk across users, applications, traffic patterns, assets and exposures.
This is an important distinction from conventional exposure-management or attack-path analysis products. Those tools can identify vulnerabilities, prioritize risks, or show potential paths through an environment. Cato is extending the concept from analysis to action. It aims to determine how an attacker could chain techniques, exploit control gaps or evade existing defenses, then enforce preventive controls tailored to that environment.
The company benefits from operating a converged network and security cloud. Because Cato’s platform unifies networking, security and access, it has visibility into more of the context needed to make a useful prediction. More importantly, Cato says protections can be enforced globally through its points of presence, avoiding the service chaining and enforcement gaps that can slow response times in a collection of disconnected tools.
Cato is pairing this prevention capability with its Agentic CVE Mitigation technology, which it says can autonomously assess and apply protection for newly disclosed vulnerabilities in as little as 45 minutes. The two capabilities address different but closely related problems: Common vulnerabilities and exposures mitigation narrows the exposure window after a new vulnerability is disclosed, while Agentic Threat Prevention focuses on predicting how an adversary may exploit a broader set of weaknesses.
The strategy reflects a broader shift in security operations. Detection and response will remain necessary, but they cannot be the sole line of defense against AI-assisted attacks. Security teams must increasingly use context-aware automation to reduce exposure and disrupt the likely path of an attack before the adversary reaches critical systems.
Security professionals should view agentic defense as an enhancement to, not a substitute for, cybersecurity discipline. Five actions should be priorities:
Frontier AI is making cyberattacks faster, more adaptive and more accessible. The response cannot be to add another dashboard or generate more alerts. The security industry needs systems that can understand context, predict how attacks will progress and enforce defenses before an attack becomes a breach.
Cato’s Agentic Threat Prevention exemplifies that emerging model. Whether enterprises use Cato or another platform, the strategic lesson is that, in the age of AI-assisted attacks, prediction must be a core component of prevention.
Zeus Kerravala is a principal analyst at ZK Research, a division of Kerravala Consulting. He wrote this article for SiliconANGLE.
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.