Artificial intelligence has cut the average time attackers need to move through a compromised network to 29 minutes, with the fastest recorded breach taking just 27 seconds, as cybersecurity experts warned UAE businesses at an annual security conference that the window for defending against intrusions is closing fast.
The warning came at the third edition of FutureSec, held in Dubai, during a panel discussion titled ‘Cyber Resilience and Compliance Across the Digital Supply Chain’. Michel Tannous, manager of sales engineering at CrowdStrike, moderated the session.
Panellists included Ali Khalid, head of data quality and enterprise analytics at a major airline; Phil Lea, vice president for privacy and cybersecurity at Landmark Group; Siham Benhamidouche, VP for cybersecurity and data risk at Schneider Electric; and Sreedhar Suragouni, group chief operations and technology officer at Sukoon Insurance.
AI cyberattack breakout time collapses to under half an hour
The 29-minute average breakout figure, drawn from CrowdStrike’s 2026 Global Threat Report, covers 2025 activity and measures eCrime breakout time: how quickly an attacker pivots from an initial foothold to other systems on a network. In 2025, AI-enabled adversaries drove an 89% increase in attacks, while 82% of all detections were malware-free, meaning attackers relied on legitimate tools and stolen credentials rather than traditional viruses.
The report also found that adversaries exploited legitimate generative AI tools at more than 90 organisations, injecting malicious prompts to generate commands for stealing credentials and cryptocurrency.
Separately, CrowdStrike’s 2026 Threat Hunting Report found that AI agent-triggered detection leads occurred at 2.5 times the rate of human-triggered leads. During one recorded LLMJacking campaign, attackers sent 200,000 API requests in two minutes, exploiting the victim’s AI infrastructure at scale.
Panellists push for security built in from the start
The FutureSec panellists agreed that cybersecurity can no longer function as a protective layer applied after systems are built. It must be embedded into business practices and corporate culture from the outset, they said.
The group raised particular concern about AI agents being granted access to corporate systems, data, and credentials. Giving an AI agent unchecked access could significantly increase an organisation’s exposure, the panellists warned, especially where existing security practices are already weak.
They called on companies to strengthen security controls based on established regulations and international benchmarks, and stressed that a vulnerability at one point in a supply chain can create risks across the whole network.
The panellists also pressed for responsible AI use when sensitive customer data is involved. Transparency, they said, is increasingly important when AI-driven decisions could directly affect customers.
The threat hunting data reinforces the urgency. According to CrowdStrike’s 2025 Threat Hunting Report, interactive intrusions increased 27% year on year, with eCrime accounting for 73% of all hands-on-keyboard attacks. Voice phishing was on track to double its prior year’s volume by the end of 2025.
State-sponsored activity is also rising. CrowdStrike’s 2026 Global Threat Report recorded a 38% increase in China-nexus activity in 2025, with the logistics sector seeing an 85% jump in targeting. Incidents linked to North Korean actors rose more than 130%.
The next edition of the conference, FutureSec 2026, is already being promoted under the theme ‘The Age of Intelligent Defence’, with a subtitle referencing ‘Securing Nations and Enterprises in the Agentic AI Era’.
