Articles - 3 numbers show human-in-the-loop cyber defence is outdated


How do you defend against AI attack speed? As cyberattacks become increasingly AI-driven, human-in-the-loop cyber defence is leaving organisations vulnerable. This article looks at the weaknesses of human-in-the-loop cyber defence against AI-enabled attacks, as well as the implications for cyber insurance. Waiting for human approval used to be prudent. Now it might be too little, too late. Nobody wants an algorithm accidentally pulling the plug on production. But against AI-enabled attacks, waiting for human approval becomes the greater risk.

By Shay Simkin, Chair, Howden Cyber & AI Lab
 
These three numbers explain why. 
 
27
In 2025, CrowdStrike recorded a record breakout speed of 27 seconds. The average across electronic crime intrusions was 29 minutes, 65% faster than the year before. In one case, data was already leaving the company four minutes after initial access.
 
60
60 seconds to detect, 10 minutes to investigate and an hour to remediate. That's the old gold standard, the “1-10-60” rule. But as AI-enabled attacks compress breakout times, this once-ambitious benchmark may not be enough. 
And for many organisations, the approval process can take much longer than an hour, especially at three o’clock in the morning. An AI-enabled attacker may get into your systems and steal your data before the first human has even noticed the breach. 
 
56
AI-enabled cyberattacks increased by 56% between March 2025 and February 2026, according to IBM’s 2026 Cost of a Data Breach Report. In total, one in four malicious breaches were AI-enabled, reflecting a growing trend towards automation among cybercriminals. When your attacker is backed by AI, relying on humans alone to direct your defence is an unfair fight. So, how can you level the playing field? 
 
From ‘in the loop’ to ‘on the loop’
To put up an effective defence against AI-enabled cyberattacks, organisations must adopt AI and automation in their security measures. Human oversight still has a vital role to play as part of an automated cyber defence. But it must shift from ‘in the loop’ to ‘on the loop’. 
 
It’s up to human cyber experts to set the policy in advance. This includes deciding which actions to take in response to a threat. For example, whether to isolate the host, revoke the credential, kill the session or block the egress. But instead of waiting on a lengthy approval chain, the defensive AI agent can execute actions in seconds. 
 
Importantly, AI agents should only be allowed to run freely when acting on your cyber defence. Access to sensitive business and customer information should still be tightly controlled. 
 
How this affects cyber insurance underwriting
Cyber insurance must respond to the evolving risk landscape. Here’s how I see things playing out within underwriting and insurance policy terms. 
 
Response speed could become a key cyber hygiene metric
Cyber insurers insist organisations demonstrate robust security measures: backups, multi-factor authentication and the like. But incident response speed is often overlooked. When attacks are increasingly AI-enabled, time-to-contain is poised to become a key rating factor for underwriters. Insurers may reward organisations that can demonstrate a fast detection and containment strategy that doesn’t require a human signature.
 
Cover for autonomous shutdowns is crucial
When responding to a genuine intrusion, an automated defence may shut down the wrong server. The loss is therefore caused by the defence itself, rather than an attacker. Without voluntary shutdown cover, many current cyber wordings won’t cover losses caused by autonomous defensive actions. No unauthorised access by an attacker means no trigger. 
 
Organisations shouldn’t be punished for automating their defence. To tackle this, cyber insurance should provide affirmative cover for autonomous defensive action.
 
The risk of systemic events will increase
As organisations turn to AI cyber defence tools to protect against AI-enabled attacks, the risk of a systemic event grows. For example, a flaw in a popular AI tool could affect thousands of insureds simultaneously. 
 
Insurers must adapt accumulation models to reflect AI technology dependencies. This includes identifying the concentration of exposure to specific AI security providers, as well as stress-testing model failures and platform-wide outages. 
 
Are you ready?
Debating whether we’re ready to take the human out of the loop is beside the point. Attackers are increasingly bypassing humans already. 
 
The real question is this: are your cyber defences and insurance policies designed to protect against an adversary that moves faster than any human defender?
 
 

 

Back to Index


Similar News to this Story

3 numbers show human-in-the-loop cyber defence is outdated
How do you defend against AI attack speed? As cyberattacks become increasingly AI-driven, human-in-the-loop cyber defence is leaving organisations vul
Stewardship reporting under the new LGPS regime
"If the pool is a Stewardship Code signatory, do funds still need to report?" The recent pooling reforms change how investment strategy is implemented
Redefining Health Insurance by innovation and analytics
From ageing populations and rising chronic disease to the growth of personalised digital health solutions, Jessica Plewes and Lisa Balboa explore how

Site Search

Exact   Any  

Latest Actuarial Jobs

Actuarial Login

Email
Password
 Jobseeker    Client
Reminder Logon

APA Sponsors

Actuarial Jobs & News Feeds

Jobs RSS News RSS

WikiActuary

Be the first to contribute to our definitive actuarial reference forum. Built by actuaries for actuaries.