Cisco says AI is shrinking the threat window between vulnerability disclosure and cyberattack from weeks to hours.
Cisco has highlighted a shift in the cybersecurity landscape: the rapid acceleration of cyber threats driven by AI. As AI models accelerate the ability to find vulnerabilities and generate exploits, the time between disclosure and weaponization has, in some instances, shrunk from weeks to days or hours.
The company says, many organizations remain vulnerable by relying on outdated infrastructure and security postures built for human response speeds. According to Cisco Talos’ 2025 Year in Review, enterprises can take 43 days to patch critical vulnerabilities, and 40% of the most targeted flaws affect systems with limited patching options.
To address this growing exposure gap, Cisco is urging technology leaders to adopt a new operating model for resilient infrastructure, transitioning from periodic discovery and reactive response to a continuous, AI-accelerated defense model.
Join the Techitup Executive Network
Join the Middle East’s inner circle of C-Suite Tech Leaders. Exclusive access to closed-door regional roundtables, priority VIP seating at our annual awards, and strategic industry briefings.
“As AI reshapes the threat landscape, organizations across the Middle East cannot afford to rely on legacy cyber defense models,” said Fady Younes, Managing Director for Cybersecurity at Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia (METAC). “With the region advancing its digital economy and smart infrastructure, defenders must use AI to outpace attackers. By adopting a continuous defense strategy, Middle Eastern enterprises can reduce exposure, strengthen business resilience and build the trust required for lasting innovation.”
Cisco’s Security and Trust Organization recently used several frontier AI models to scan 1.8 billion lines of code across more than 25 languages in just eight weeks, a task Cisco estimates would have taken eight years without AI.
Building on these insights, Cisco outlines three practical shifts organizations can make to achieve continuous resilience:
- Making remediation continuous: Patching and upgrading must become part of a predictable, continuous operating rhythm.
- Using modernization to reduce risk: Unsupported and end-of-life assets create unnecessary exposure that IT and security teams should not have to carry indefinitely. Organizations should use modernization to remove risks that cannot be addressed through patching.
- Elevating security posture: Defenders must match the speed of modern threats by segmenting environments to contain attack impact, closing identity gaps and equipping security operations center teams with the tools to act rapidly and confidently.
The full executive brief is available on Cisco’s website.
Disclaimer: This article is based on research and analysis published by Cisco.

