When both sides have AI: Rethinking incident response management
By Andy Mura
Ask any incident responder about their worst night on call, and you will hear a story about time. The minutes lost confirming whether an alert was real. The hours spent paging the right people. The days between the first foothold and the moment someone finally said the word “breach” out loud.
Time has always been the currency of incident response. What has changed is that attackers now have tools that spend that currency faster than most defenders can count it.
We have crossed into a period where AI sits on both sides of the table. Defenders use it to triage alerts and correlate signals. Attackers use it to write convincing phishing lures, clone voices, and move through networks at machine speed. If your incident response plan still assumes a human adversary typing commands one at a time, it is already out of date.
The numbers are not subtle
The 2026 IBM Cost of a Data Breach Report, conducted by the Ponemon Institute across 602 organizations, gives us a clear picture:
- The global average cost of a breach reached $4.99 million, up 12% year over year.
- One in four malicious breaches were AI-enabled, a 56% jump from the prior year.
- Those AI-enabled breaches cost around $6 million on average, roughly a million dollars above the global mean.
- The mean time to identify and contain a breach was 247 days, six days longer than the year before.
Read that last figure again. With all our tooling, dashboards, and threat intelligence feeds, organizations still took the better part of a year to find and shut down intrusions. The attackers did not slow down to wait for us.
There is a hopeful counterweight, though. Organizations that folded AI and automation into their security operations cut breach costs by nearly $2 million on average. The technology that raises the ceiling on attacker capability also raises the floor on defender speed. The catch is that one in four organizations have not adopted these tools at all.
What actually changes in the response lifecycle
The classic phases still hold: preparation, detection and analysis, containment, eradication, recovery, and lessons learned. AI does not erase them. It compresses them and stresses them in specific ways.
- Detection gets noisier before it gets faster. AI-generated phishing now accounts for a large share of malicious email, and the tells we used to teach staff (odd grammar, clumsy formatting) are mostly gone. Your detection logic has to lean on behavior and context rather than surface cues.
- Analysis demands provenance. When a “CFO” appears on a video call asking for a wire transfer, your responders need a fast, rehearsed way to verify identity out of band. Deepfake impersonation is no longer a novelty.
- Containment races the clock. Exfiltration speeds for the fastest attacks have climbed sharply. A containment playbook that assumes you have hours may only have minutes.
- Lessons learned must feed the machine. Every incident is training data. If your post-incident review does not update detection rules and automation logic, you are relearning the same lesson at full price.
The regulatory clock is tightening too
For organizations operating in the European Union, the NIS2 Directive turns this speed problem into a legal obligation. Covered entities must submit an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month.
When an AI-driven attack can move from initial access to exfiltration in minutes, that 24-hour window puts real pressure on your ability to detect, classify, and escalate quickly. Regulators are effectively asking a question the threat landscape already forced on us: can you recognize a serious incident fast enough to report it before the damage is done? Teams that have not mapped their internal escalation paths to these deadlines will feel the strain during their first real event.
A real-world pattern worth studying
Consider the voice-cloning fraud cases that made headlines over the past two years. An employee receives a call that sounds exactly like a senior executive, complete with the right accent and speech rhythm, authorizing an urgent payment. In several reported cases, the money moved before anyone questioned it. The technical controls were fine. The breakdown was in process: there was no rehearsed verification step, and no one felt empowered to pause an “urgent” request from leadership.
That is the uncomfortable lesson. Most AI-era incidents still succeed through very human pressure points. Urgency, authority, and trust remain the soft targets.
Practical steps for teams starting this week
You do not need a nine-figure security budget to make real progress. A few moves pay off quickly:
- Rewrite your verification procedures for financial and access requests and require an out-of-band confirmation that a cloned voice or video cannot satisfy.
- Instrument your mean time to detect and respond as a tracked metric, then set a target and review it monthly.
- Run tabletop exercises with AI-flavored scenarios, such as a deepfake vendor call or an AI-written spear-phishing campaign against your finance team.
- Automate the boring first mile of triage, so your analysts spend their attention on judgment calls, not copy-paste enrichment.
- Govern your own AI usage. Shadow AI tools handling sensitive data create new incident classes. Know what your teams are running.
Collaboration makes us stronger
Here is the question I ask every CISO, compliance officer, and IT lead I get to talk to: if an AI-enabled intrusion started in your environment tonight, how many of those 247 days would you actually need?
I genuinely like to hear how your teams are adapting and whether they are tracking detection speed as a hard metric or started adding deepfake scenarios to their tabletop exercises.
The people who share what worked, and what failed, are the ones moving this whole field forward. The attackers are already collaborating with their machines. The defenders who treat incident response as a living, measured, AI-aware discipline are the ones who will keep their worst nights short.
About the author
Andy Mura is the head of marketing at Kertos, where he leads growth strategy for the company’s compliance automation platform. A marketer and growth strategist by trade, he has spent years working in highly regulated industries such as payments, which is where his interest in compliance, data privacy, and information security first took root. That foundation has since been sharpened by extensive field research and by ongoing conversations with the CISOs and IT security leaders Kertos serves as customers. He writes about the practical realities of building and running security and compliance programs, drawing on what practitioners tell him works and what does not.