Authored by Ravindra Baviskar, Director - Sales Engineer, Sophos India and SAARC
Security teams have been talking about attackers "moving faster than defenders" for years. That gap, which used to be measured in weeks, but now with AI in the mix is now measured in days.
This shift has become an official policy concern in India. The Reserve Bank of India's (RBI) Financial Stability Report for June 2026 surveyed 33 scheduled commercial banks and 10 upper-layer Non-Banking Financial Companys, and found that for the first time, AI-enabled cyber threats topped the list of risks institutions expect to face over the next year. This is ahead of ransomware, phishing, and third-party supply chain exposure.
It's a striking reversal: for more than a decade, ransomware held that top spot in nearly every risk survey I've seen.
What "agentic" actually changes
Most of the AI and cybersecurity conversations over the past two years have focused on AI writing better phishing emails or cloning a voice for a fraud call. That's real, but it understates what's happening now. What's different about agentic AI is autonomy. An attacker can hand an AI agent a goal rather than a script, and the agent will scan for exposed services, adapt when a defense blocks it, and chain together multiple stages of an intrusion with very little human input in between.
A threat intelligence disclosure in June 2026 gave the industry a concrete look at this, when researchers uncovered a fully operational threat-actor lab built specifically to develop malware capable of defeating endpoint detection tools. The setup used an AI system as a coordinating "manager" directing several agents through code generation, testing, and revision, running each build against live security products before shipping it. It wasn't theoretical red-teaming, it was a working pipeline, industrializing what used to be slow, manual malware development.
The bigger structural story sits in Sophosโ most recent Active Adversary Report - composed from 661 incident response and MDR cases. Here we found that median attacker dwell time has decreased to three days, with identity-based attacks, stolen credentials, weak MFA, poorly protected accounts, now the dominant ways attackers get in, ahead of software exploitation. AI isn't inventing new ways to get through the door. Instead it's collapsing the time between getting in and doing damage, which is arguably the more dangerous problem for defenders operating on human-paced response cycles.
Why this as a governance problem, not just a tooling one
RBI's report is useful precisely because it doesn't stop at naming the threat - it also quietly diagnoses the gap. Despite rising security budgets (cybersecurity spend as a share of IT budgets rose for 71% of surveyed institutions over the last three financial years, and two-thirds increased security staffing over the past year), the regulator flagged employee awareness and training, and forensic readiness for incident investigation, as areas that still lag. The human gap is the weakness machine-speed attacks are built to exploit.
There's also a quieter warning worth sitting with: 42% of surveyed institutions believe geopolitical tension is already increasing their likelihood of being attacked, and global regulators such as the Financial Stability Board, International Organization of Securities Commissions and the Organisation for Economic Co-operation and Development are moving from general AI principles toward specific supervisory frameworks. India's own Financial Sector Cybersecurity Strategy, under development by the Financial Stability and Development Council, is reportedly at an advanced stage. Expect it to formalize AI-specific risk assessment as a compliance expectation, not just as a best practice.
So what this means in practice?
None of this argues for panic, and it doesn't mean the fundamentals have changed. It means the fundamentals matter more. A few things worth prioritizing:
Identity first. With identity compromise now the leading entry point across incident response caseloads, phishing-resistant MFA and tight management of both human and machine ("non-human") identities deserve to sit above most other line items on a 2026 security roadmap.
Assume compressed timelines. Three-day median dwell time means detection, containment, and response can no longer be planned as sequential steps with review gates in between. They need to run in parallel, which usually means 24/7 monitoring through MDR or an equivalent always-on capability, not a business-hours SOC.
Match machine speed with machine speed. Signature-based detection was designed for a world where new threats appeared occasionally. When an AI-assisted pipeline can generate and test dozens of evasion variants in an afternoon, detection needs to work off attacker techniques and behaviors, not just known signatures because the specific payload may genuinely be new every time.
Close the human gap. Investment in tools without investment in people and forensic readiness leaves the weakness that RBI's report describes. Tabletop exercises and incident response drills matter more, not less, as AI compresses response windows.
Agentic AI hasn't replaced the attackerโs human intent, and often human error on the defending side, still drives most incidents. What it has done is remove the friction that slowed down attacks and gave defenders a little breathing room. That breathing room is what needs to be re-engineered back into enterprise defense through identity controls, always-on monitoring, and detection built for techniques rather than signatures before it disappears for good.
๐๐ญ๐๐ฒ ๐ข๐ง๐๐จ๐ซ๐ฆ๐๐ ๐ฐ๐ข๐ญ๐ก ๐จ๐ฎ๐ซ ๐ฅ๐๐ญ๐๐ฌ๐ญ ๐ฎ๐ฉ๐๐๐ญ๐๐ฌ ๐๐ฒ ๐ฃ๐จ๐ข๐ง๐ข๐ง๐ ๐ญ๐ก๐ WhatsApp Channel now! ๐๐ฒ
๐ญ๐๐๐๐๐ ๐ถ๐๐ ๐บ๐๐๐๐๐ ๐ด๐๐ ๐๐ ๐ท๐๐๐๐ฌ ๐ Facebook, LinkedIn, Twitter, Instagram