Detecting Threats Got Faster. Responding to Them Didn’t.
Cybersecurity solved visibility faster than it solved action. AI may widen that gap before it closes it.
Detecting Threats Got Faster. Responding to Them Didn’t.
Cybersecurity solved visibility faster than it solved action. AI may widen that gap before it closes it.

Cybersecurity has made real progress on detection. The bottleneck quietly moved — from finding threats to converting detection into action before the attacker moves again. And AI may be making that gap more expensive to close, not less.
What the progress reports leave out
Security teams have gotten meaningfully better at detection. Threat intelligence improved. SIEM tools matured. Behavioral analytics narrowed dwell time from months to days in many environments.
The SANS State of ICS/OT Security 2025 Survey confirmed the progress: nearly 50% of incidents are now detected within 24 hours. That’s a genuine improvement.
Then comes the part that didn’t follow.
Almost one in five incidents still takes more than a month to remediate — and some stretch on for many months longer.
Detection in 24 hours. Remediation in 30 days. That isn’t a detection problem. The bottleneck quietly moved from finding threats to converting detection into action before the attacker moves again.
The window that determines actual damage
Cybersecurity investment concentrated on visibility for a long time. Find threats earlier. See more of the attack surface. Reduce dwell time. The industry built extraordinary capability around one question: is something happening that shouldn’t be?
Modern detection capabilities have improved dramatically. For many organizations, finding threats is no longer the primary constraint.
The harder question — what do you do about it, and how fast can you do it? — never received the same investment. Detection and response were treated as a sequence: find it, then handle it. The assumption was that once you found the threat, the response would follow.
That assumption is breaking. An organization might detect ransomware in 15 minutes but take 18 hours to contain it, isolate affected systems, apply patches, and verify the threat is eliminated. The 15-minute detection window gets headlines. The 18-hour remediation window determines actual business impact.
Attackers understood this gap long before defenders did. Finding a foothold isn’t the objective. Establishing persistence, moving laterally, and reaching the data or systems that matter — that happens in the window between detection and action. The bottleneck is no longer finding threats. It’s converting detection into action before the attacker moves again.
Why the operating model breaks before the technology does
The traditional security operations model has a straightforward economic logic: more attacks require more analysts, more tooling, more MDR spend, larger SOC teams.
That logic held when attack volume scaled slowly enough for headcount to keep pace.
It doesn’t hold anymore.
Mandiant’s M-Trends 2025 report places median attacker dwell time at 11 days globally — but individual incidents range from hours to months depending on attack type and detection maturity. Attack volume is no longer scaling linearly with security headcount. The operating model built for linear volume breaks under non-linear attack pressure.
The result is a security industry that has been asked to do more with less while the attack surface expanded and adversary speed increased. More alerts, same team. More complexity, same playbooks. The architecture held together when humans could keep pace. It shows strain when they can’t.

The bottleneck moved from finding threats to converting detection into action before the attacker moves again.
The cost nobody budgeted for
The industry’s response to machine-speed attacks has been machine-speed defense — agentic AI that can investigate, triage, and remediate without waiting for analyst review. That’s the right direction.
But it introduces an economic problem that almost nobody in the category is addressing directly.
Consider how AI investigations actually work at enterprise scale. A basic alert classification might consume around 1,000 tokens. A guided investigation runs 20,000 to 50,000 tokens per incident. A fully autonomous agentic investigation loop can burn millions of tokens on a single complex incident — and real-world cases are beginning to confirm the explosive rising costs.
Now multiply that by the number of alerts generated daily at enterprise scale.

The organizations that need autonomous defense the most are also the ones most likely to generate the highest AI consumption during an attack.
Many AI security platforms introduce consumption-based economics — fractions of a cent per token, at massive volume, with no natural ceiling. IBM’s 2025 Cost of Data Breach Report places the average breach lifecycle at 241 days, with costs averaging $4.44M globally and $10.22M in the US. The financial exposure from a breach is well understood. What isn’t yet priced into security budgets is the cost of the AI investigation running in real time to stop it.
This creates a structural problem that has no equivalent in traditional security operations: the more serious the attack, the more expensive the autonomous response becomes. The organizations that need autonomous defense the most are also the ones most likely to generate the highest AI consumption during an attack.
A coordinated enterprise-wide intrusion — the scenario where autonomous response matters most — is also the scenario where token consumption spikes highest. Organizations that rely on consumption-based AI security face an impossible question during the worst possible moment: optimize for stopping the adversary, or control AI costs.
What the next generation of security operations requires
The shift from detection to action as the primary bottleneck isn’t just an operational problem. It changes what security architecture needs to solve.
Detection-first architectures assume that finding threats is the hard part and response follows naturally. When detection improves but remediation stays slow, the architecture reveals its assumption: that human review is fast enough to be part of the critical path.
It isn’t anymore. Not at machine speed.
The gap between detection and remediation is where advanced persistent threats establish persistence — using the investigation window as cover while defenders work through the process of triage, escalation, and approval before action.
Closing that gap doesn’t mean removing human judgment from security operations. It means being precise about which decisions require human judgment and which ones can be resolved before a human ever sees the alert. Most threats have known signatures, known remediation paths, and known risk profiles. Reserving autonomous action for the threats that are well-understood, and human judgment for the ones that aren’t, is a different operating model than asking analysts to process everything first.
The economics question compounds this. Autonomous defense that runs on consumption-based AI becomes a variable expense with no ceiling — predictable when attacks are light, potentially catastrophic when attacks are sustained. Sustainable autonomous defense isn’t just about capability. It’s about whether the economics allow that capability to run at full depth when it matters most.
The future question isn’t whether humans disappear from security operations. It’s whether human attention remains reserved for the decisions where it creates the most value.
The equation that’s still catching up
The cybersecurity industry has been talking about AI for years. What it hasn’t fully confronted is that AI changes the economics of defense as much as the capability.
Every generation of security tooling eventually runs into the same structural tension: the tools that help most are also the ones most expensive to run at scale. SIEM vendors learned this when organizations started limiting data ingestion to control costs — creating blind spots attackers could count on. The risk with consumption-based AI security is the same dynamic at larger scale and faster pace.
Detection used to be cybersecurity’s limiting factor. It isn’t anymore. Action is.
The next generation of security platforms won’t be judged by how quickly they recognize an attack. They’ll be judged by how reliably they convert recognition into action — and whether they can afford to keep doing it when attackers force them to operate at scale.
메타데이터
- post_id
- bb1bb68ee1e0
- slug
- detecting-threats-got-faster-responding-to-them-didnt-bb1bb68ee1e0
- url
- https://medium.com/@sonuarticles74/detecting-threats-got-faster-responding-to-them-didnt-bb1bb68ee1e0
- canonical_url
- https://medium.com/@sonuarticles74/detecting-threats-got-faster-responding-to-them-didnt-bb1bb68ee1e0
- author_url
- https://medium.com/@sonuarticles74
- status
- ok
- fetched_at
- 2026-07-25 20:51:28