ENISA, the EU cybersecurity agency, warns of the increasing speed at which cyberattacks are occurring. Instead of relying on continuous vulnerability scans, defenders must make SecOps virtually real-time, with a human always involved within 24 hours.
The recommended approach for defenders is no joke. ENISA states that organizations must treat every environment as potentially compromised. Continuous threat modeling and dynamic incident response maintain the security posture, but that’s easier said than done. AI assistance is required, as is a role for human intervention within 24 hours.
Time-to-detect reduced to under 10 minutes
For a long time, extremely fast cyberattackers have primarily been cited as prime examples in cybersecurity reports. A highly sophisticated and targeted attack campaign can progress from compromise to exploitation within 10 minutes. The reality is that such speed has been rare until now. Today, automated systems are taking over a large part of this “task” from human attackers, with the now-popular term “machine speed” used to emphasize that human responses are anything but fast enough to counter the threats.
ENISA therefore recommends aiming for a mean time to detect (MTTD) of less than 10 minutes and a measured mean time to response (MTTR) to further refine this. In addition, well-known recommendations are reviewed, such as zero-trust segmentation and a layered detection shell. The basic assumption should be that attackers are constantly changing their behavior.
European AI is desperately needed
The cyber agency is well aware of the limitations faced by defenders. After months of negotiations, ENISA finally gained access not to Mythos 5.1, Anthropic’s latest cyber model, but to the three-month-old Mythos 5. This allows the EU agency to contribute to the same type of hardening that has taken place under the names Project Glasswing (Anthropic) and Daybreak (OpenAI), using cyber-capable models that only a select few are permitted to deploy.
For ENISA, this leads to the logical conclusion that Europe must also pursue sovereignty when it comes to cybersecurity. Specifically, AI systems are needed that can utilize reports, disclosures, telemetry, malware samples, and threat intelligence. The agency is positive about the legislation; in that area, the EU is indeed ahead of the curve.
Member states, for their part, must primarily carry out a mix of direct and indirect defense measures surrounding critical infrastructure. In addition to inspections based on the national implementation of NIS2 legislation, it is particularly important to emphasize practically effective measures such as zero-trust and to evaluate potentially useful systems, such as AI-based detection.