Blogs>AI Is Making Cybersecurity Easier, and More Dangerous

AI Is Making Cybersecurity Easier, and More Dangerous

Simulations Labs
📅September 13, 2026
AI Is Making Cybersecurity Easier, and More Dangerous

One report tells both halves of this story at once. IBM's 2025 Cost of a Data Breach Report found the global average cost of a breach dropped to $4.44 million the first decline in five years driven largely by AI-powered detection and containment. The same report found that 1 in 6 breaches now involve attackers using AI, most commonly for phishing and deepfake impersonation. Same technology, same year, pulling defenders and attackers forward at the same time.

This isn't really a contradiction. It's the actual shape of what AI has done to cybersecurity: it hasn't picked a side. It's made everyone faster.

Split visual contrasting a defensive security dashboard with an automated attacker interface

  1. How AI Is Genuinely Making Cybersecurity Easier

The defender-side numbers are real and worth taking seriously, not just as marketing for security AI vendors.

Breach costs are falling for the first time in years. IBM's report found organizations using AI and automation extensively paid $3.62 million per breach on average, compared to $5.52 million for organizations that didn't, a gap of nearly $1.9 million, driven mostly by detection and containment speed rather than any single silver-bullet tool.

Detection and containment are meaningfully faster. The same research found breach lifecycles at a nine-year low, with AI-heavy security operations cutting the time to identify and contain a breach by roughly 80 days compared to organizations without extensive AI adoption. Eighty days is a long time to have an active intruder in your environment; closing that gap has genuine, measurable value.

Junior analysts can do more, faster. AI-assisted triage tools reduce alert volume and surface likely-relevant signals from noise that used to require years of pattern recognition to sort through manually. This doesn't replace experienced analysts, but it does compress the ramp-up time for less experienced ones, which matters given how understaffed most security teams already are.

None of this is hypothetical. It's showing up in the same breach-cost data that also tells the more uncomfortable half of the story.

  1. How the Same Technology Is Making Attacks More Dangerous

Phishing has gotten dramatically faster to produce. IBM's data shows generative AI has cut the time to craft a convincing phishing email from roughly 16 hours to about 5 minutes. That's not a marginal efficiency gain for attackers; it's a fundamentally different economics of attack, where personalized, well-written phishing at scale no longer requires the time investment it used to.

The volume reflects it. Hoxhunt's phishing trends research found AI-generated phishing campaigns surged 14x since December 2025, and now account for roughly half of all phishing attacks reported by users. Projected losses from phishing are expected to exceed $25 billion in 2026, with AI-personalized messages boosting click-through rates by as much as 54% compared to generic templates.

The barrier to technically sophisticated attacks has genuinely collapsed. Sonatype's tracking of malicious open-source packages found the count in public repositories grew from about 55,000 in 2022 to 454,600 in 2025, an eightfold jump that tracks closely with the rise of AI coding tools capable of generating convincing malicious packages at scale. Security researchers have been blunt about the implication: attacks that used to require an organized, skilled team can increasingly be carried out by a single, less technical actor.

  1. The Nuance Most Coverage Skips

It would be easy to read the above as a straightforward story of attackers pulling ahead. The actual picture is messier, and more useful, than that.

Unit 42's analysis of AI-enabled malware samples found something worth sitting with: AI clearly lowers the barrier to creating malware. Researchers found a large and growing volume of AI-generated malware samples in public repositories. But creating a sample and successfully deploying it against a properly defended environment turned out to be different problems, and the AI-enabled samples that did reach production environments were caught by the same detection mechanisms that already catch conventional malware. None of them required a novel detection approach.

That's an important qualifier. AI is lowering the barrier to attempting more sophisticated attacks, dramatically, across the board. It is not automatically lowering the barrier to succeeding against an organization that has kept its defensive fundamentals current. The gap between those two things is exactly where an organization's actual security posture, not just its AI adoption, decides the outcome.

  1. What This Means in Practice

The paradox in the framing isn't a reason for fatalism; "AI helps everyone equally so nothing changes" is the wrong conclusion. The more accurate read is that the gap is widening between organizations that adopt AI defensively and keep their human skill sharp, and organizations that either ignore AI entirely or treat buying an AI security tool as a finished task rather than a starting point.

The IBM data backs this distinction directly: the cost savings went to organizations using AI and automation extensively, integrated across their security operations, not to organizations that had simply purchased a tool. And the Unit 42 finding on malware deployment makes the same point from the attacker side: a well-defended environment absorbs AI-enabled attacks about as well as it absorbs conventional ones. Defense-in-depth doesn't stop mattering because the attacker's tooling got faster.

  1. Building the Muscle, Not Just Buying the Tool

Closing the gap on both sides of this paradox comes down to the same underlying need: teams that have actually practiced against fast-moving, AI-relevant attack patterns, not just teams that read about them. Simulations Labs' Cyber Range is built around exactly these live-fire, production-safe exercises that let analysts practice incident response and threat detection under realistic, time-pressured conditions- the same conditions IBM's data shows now define both sides of this fight. For teams looking to close the skills gap at scale rather than one hire at a time, security team upskilling programs built around scenario libraries covering SOC, cloud, and incident response give organizations a way to keep pace with attacker tooling that isn't slowing down.

Security analyst monitoring a live incident response simulation on a dashboard

Want to see how your team performs against a realistic, AI-relevant attack scenario? Explore the Simulations Labs Cyber Range and put your defenses to an actual test instead of a policy assumption.

  1. FAQ

Is AI making cybersecurity better or worse overall? Both, in ways that don't cancel out. IBM's 2025 data shows AI-driven defense has cut breach costs and detection times to multi-year lows, while the same report shows AI is now involved in roughly 1 in 6 breaches on the attacker side. The honest answer is that AI has raised the ceiling for both defenders and attackers simultaneously, which means organizations that don't actively adopt it defensively fall behind on both fronts.

How much has AI actually sped up phishing attacks? Substantially. IBM's research found generative AI has reduced the time to write a convincing phishing email from around 16 hours to about 5 minutes, and separate research from Hoxhunt found AI-generated phishing campaigns surged 14x in a matter of months, now representing roughly half of reported phishing attacks.

Does AI make it easier for unsophisticated attackers to succeed, not just to try? Not automatically. Research from Unit 42 found that while AI clearly lowers the barrier to creating malware, AI-generated samples that reached production environments were caught by the same detection methods used against conventional malware meaning a well-defended organization's fundamentals still matter as much as they did before.

What's the most effective way for a security team to keep up with AI-enabled attacks? The IBM data points to extensive, integrated use of AI and automation across security operations, not a single tool purchase, combined with regularly practiced, hands-on incident response skills. Teams that only buy AI tooling without building the underlying human judgment to use it well don't see the same cost or speed improvements as teams that do both.

Are AI-enabled attacks harder to detect than traditional ones? Not inherently, based on current evidence. Unit 42's research specifically found that AI-enabled malware samples reaching production didn't require any novel detection approach; they were caught by existing mechanisms. The bigger risk is volume and speed rather than a fundamentally new detection challenge, at least so far.