How Breach and Attack Simulation Must Evolve in the AI Era

www.news4hackers.com-how-breach-and-attack-simulation-must-evolve-in-the-ai-era-how-breach-and-attack-simulation-must-evolve-in-the-ai-era

What breach and attack simulation needs to become in the AI era

Breach and attack simulation (BAS) has long relied on a human-driven process to translate threat intelligence into actionable tests. This workflow involves analyzing reports, extracting techniques, and deploying them against security controls. Historically, converting a significant threat into operational simulations within 24 hours was considered rapid. However, the emergence of frontier AI models has disrupted this balance. The post-Mythos era has compressed the timeline from public vulnerability disclosure to weaponized exploits to approximately ten hours, with over 130 new CVEs identified daily. Compounding the challenge, less than 0.5% of disclosed vulnerabilities receive upstream patches. A growing portion of production environments incorporates the same AI models used by defenders, creating an asymmetry in threat execution speed. When only one side of the security pipeline automates, the gap between defense and attack accelerates. This underscores the need to modernize BAS rather than simply increasing its frequency.

Key findings from 338 million attack simulations

The Picus Blue Report 2026 analyzed 338 million BAS tests conducted in customer production environments during the first half of 2026. The study revealed that detection failures primarily stem from two factors. Performance issues accounted for 49% of failures, doubling from 24% in the previous year. Log collection gaps contributed another 41% and posed greater risks, as they often go undetected, preventing any rule from triggering. Both issues reflect configuration and operational shortcomings rather than product deficiencies. The industry’s tendency to address machine-speed threats with additional purchases—such as AI-powered security operations centers (SOCs)—fails to resolve underlying systemic issues.

Limitations of current BAS frameworks

Most enterprises deploying BAS use architectures designed before the rise of machine-speed adversaries. These systems face three critical constraints. First, they rely on scheduled triggers, producing point-in-time results that expire between runs. Security controls like firewalls or endpoint detection and response (EDR) updates can invalidate prior assessments, leading to undetected drift. The report highlights the rapid decay of effectiveness, with average performance metrics declining sharply. Second, traditional BAS struggles to address the CVE lifecycle. While the KEV (Known Exploited Vulnerabilities) list is updated nightly, manually verifying detection capabilities for each entry requires four to six hours per CVE. This process prioritizes only the most critical vulnerabilities, leaving the majority untested. Third, the reliance on human intervention for validation creates bottlenecks. After identifying a gap, engineers must translate findings into deployable rules for next-generation firewalls (NGFWs) or security information and event management (SIEM) systems, a process that consumes significant resources.

The evolution of BAS in the AI era

Agentic BAS represents a paradigm shift, operating as a closed-loop system where agents autonomously execute tests, deploy fixes, and revalidate results. This approach eliminates human involvement in the loop, with personnel only intervening at decision points. The process follows a consistent cycle: simulate, validate, fix, verify. However, the inputs, triggers, and execution mechanisms differ significantly. AI-driven tools like Threat Builder rapidly construct attack campaigns using enterprise-specific threat intelligence (CTI) feeds and open-source data. Simulations launch automatically against live production environments, ensuring silent failures are detected immediately. Fixes are delivered to teams, with detections deployed to security stacks and revalidated. This model achieves machine-speed response while maintaining human oversight, proving alerts and deploying rules when necessary.

Behavioral simulation and threat validation

The Picus approach ingests threat intelligence in formats analysts typically receive, such as CISA alerts, blog URLs, PDFs, or threat actor names like Scattered Spider. Instead of keyword matching, the system analyzes sources to reconstruct attack chains, generating ATT&CK-mapped simulations in about nine minutes. Exploitation is tested behaviorally, eliminating the need for working exploits. For example, a KEV entry becomes testable the day it is published, enabling comprehensive coverage beyond critical CVEs. Each vulnerability is assessed for blocking, detection, or residual risk, with compensating rules applied when patching is delayed. Threat groups receive similar treatment, with their exact tactics, techniques, and procedures (TTPs) tested against live controls. Every gap triggers a vendor-specific fix, which is approved by humans, deployed automatically, and revalidated.

Integration with autonomous security workflows

BAS must evolve from a standalone tool to a foundational component of broader security strategies. The same closed-loop system can integrate with autonomous penetration testing and exposure validation, enabling continuous control validation without requiring new tools. Only content verified in the Picus Threat Library is executed in production, ensuring safety. The system operates under Anthropic’s Cyber Verification Program, with enterprise agents capable of driving workflows via the MCP API.

The imperative for AI-enabled defense

The next wave of attacks will leverage AI capabilities, necessitating defenses that match this speed and sophistication. The distinction between traditional BAS and AI-era solutions lies in five core attributes, none of which involve increased frequency. Tests are triggered by signals, not schedules, allowing immediate validation of new CVEs without exploits. Missed detections are diagnosed as root causes, not triage items, and every gap receives a vendor-specific fix. Continuous validation no longer depends on human labor, and vendors must demonstrate these capabilities live, not through presentations. A contained pilot can resolve readiness questions within a week, providing measurable results rather than opinions. Organizations seeking to transition from calendar-driven to signal-driven security must address how teams shift workflows without rebuilding infrastructure. The benefits of an upgraded BAS system include measurable trends, validated results, and a proactive defense posture against AI-enabled threats.

Conclusion

The benefits of an upgraded BAS system include measurable trends, validated results, and a proactive defense posture against AI-enabled threats.

About Author

en_USEnglish