Home Business News Building a Security-First Culture for an Accelerating Threat Landscape

Building a Security-First Culture for an Accelerating Threat Landscape

7

Shrinking exploit windows and AI-driven automation make everyday security behavior critical

By Derek Manky, Chief Security Strategist & Global VP Threat Intelligence, Board Advisor, Threat Alliances at FortiGuard Labs

The basics of cybercrime rarely change: An adversary identifies an exposed asset or a valid credential, establishes access, expands that foothold, and ultimately converts the intrusion into financial or operational impact. What is changing, however, is how quickly, at what scale, and how efficiently attackers can now move through that sequence.

To start, threat actors no longer need to build everything from scratch. The 2026 Fortinet Global Threat Landscape Report shows that modern cybercrime increasingly operates as an industrial system, with credentials, infrastructure, malware or malware services, access to compromised networks, and specialized services all available through an established and thriving criminal supply chain. And now, automation and AI are making that entire ecosystem even faster and easier.

These advances have significant implications for security teams. They also underscore why basic cyber hygiene matters more than ever. A strong password, a properly handled multifactor authentication request, a timely software update, or a promptly reported phishing email can interrupt an attack before it advances to the next stage.

Cybersecurity Awareness Month is a useful reminder that often-rudimentary tasks like patching devices or updating passwords cannot be seen as separate from your organization’s technical defenses. They are part of the control environment. Building a security-first culture means embedding those behaviors into your normal business operations.

AI Is Compressing the Attack Lifecycle:

In the report, FortiGuard Labs data shows that the time-to-exploit window for critical vulnerabilities has shrunk from nearly 5 days to less than 48 hours. In some cases, thanks to AI integration into threat tools, exploitation activity began within hours of public disclosure.

While global exploitation attempts increased by over 25% year over year, attack volume doesn’t tell the whole story. For example, last year FortiGate IPS telemetry recorded nearly 68 billion brute-force events in 2025, or about 185 million attempts per day. However, that figure represents a 22% year-over-year decline. That’s because cybercriminals are trading their traditional, indiscriminate attack methods for greater precision. Stolen credential datasets, automation, and AI-assisted analysis help them identify more promising accounts and services, refine credential testing, and focus on the attack paths most likely to yield access.

AI accelerates reconnaissance, generates and refines social engineering content, analyzes exposed infrastructure, identifies software vulnerabilities, and automates elements of the attack and exploitation. Soon, agentic capabilities will coordinate multiple steps with less direct operator involvement. This further reduces the time and expertise required to execute an attack while increasing the number of operations an adversary can run simultaneously.

Because attackers continue to compress their timelines, it is critical that defenders reduce latency across their entire security program. Yes, that includes detection and response, but it also includes identity management, patching, employee reporting, and the decisions required to contain an attack.

Establish a Practical Cyber-Hygiene Baseline

Cyber hygiene is not a separate, entry-level security layer. It is the routine maintenance that keeps identities, endpoints, applications, and network infrastructure from becoming easy entry points. The objective is not to turn every employee into a security engineer. It is to apply a small set of critical protective actions consistently across your organization.

For users, this starts with:

  • Performing scheduled password updates
  • Storing credentials in a trusted password manager
  • Reviewing, recognizing, and replacing weak, reused, or exposed passwords
  • Using MFA wherever available, especially for email, remote access, and cloud services
  • Reporting unexpected MFA prompts
  • Installing all approved patches and updates promptly
  • Avoiding the use of unapproved applications, shadow IT, and shadow AI
  • Reporting suspicious messages or requests or unusual device behavior to IT
  • Completing all security training required for their level of access and responsibility

Administrators need to apply the same discipline to the infrastructure users rarely see.

  • Remove factory-default and shared credentials from firewalls, routers, switches, wireless access points, cameras, printers, and other connected devices
  • Separate privileged accounts from ordinary user accounts, protected by MFA, and limited according to least privilege
  • Implement ZTNA across the environment, especially in OT networks
  • Consider network-wide deception technology to create intruder tripwires and alarms
  • Maintain an accurate asset inventory, disable dormant accounts and unnecessary services, and restrict access to management interfaces
  • Subscribe to a threat intelligence service to prioritize patching based on active exploitation and business risk
  • Provide employees with a reporting process for suspicious activity or insider threat that is visible, fast, and easy to use
  • Ensure that cybersecurity training is continuous, role-specific, and informed by the techniques employees are likely to encounter.
  • Make sure information and trust go both ways (phishing simulations, for example, are most useful when they identify gaps and reinforce reporting behavior, not when they are treated as punitive exercises)

Make Security Part of Normal Operations

On their own, these may seem like small things. The value of employing these practices as part of an integrated threat and control strategy, however, lies in their combined effect. A password manager reduces credential reuse. MFA can prevent a stolen password from being used to establish an authenticated session. Patching removes an available exploit path. Reliable threat intelligence gives defenders additional context and time to respond. None of these is sufficient on its own, but together they create multiple points along the attack chain at which an intrusion can be detected or stopped.

Today’s threat landscape requires developing a security-first culture. It shows up in how quickly an organization can act on those controls: how soon an exposed credential is replaced, how rapidly a critical vulnerability is remediated, and whether an employee reports something that does not look right. As AI increases the speed and precision of attacks, reducing the time between a warning signal and a defensive action becomes a measurable source of resilience.

AI and automation play critical roles for defenders as well. First, they can eliminate many menial tasks performed by users and administrators, reducing procrastination and human error. They can analyze large volumes of data to detect and respond to threats in real time, write and test patches, dynamically update devices, and centralize and simplify SOC management.

Like all security, cyber resilience starts with consistent habits. Cybersecurity Awareness Month is a welcome opportunity to examine whether critical habits are embedded across your organization and strengthen them where gaps remain.