Cisco has warned that artificial intelligence is compressing the time between a vulnerability being disclosed and being weaponised from weeks to days or hours, leaving enterprises that still run periodic patching cycles badly exposed.
The company said frontier AI models are accelerating the ability to find flaws, generate exploits and chain them into attack paths, while most security postures remain built for human response speeds.
Cisco is urging technology leaders to move to a continuous, AI-accelerated defence model and has published an executive brief setting out five actions leaders can authorise within 90 days.
The exposure gap is measurable; according to Cisco Talos’ 2025 Year in Review, enterprises can take 43 days to patch a critical vulnerability, and 40% of the most targeted flaws in 2025 affected systems with limited patching options.
“As AI reshapes the threat landscape, organisations across the Middle East cannot afford to rely on legacy cyber defence models,” said Fady Younes, Managing Director for Cybersecurity at Cisco Middle East, Türkiye, Africa, Caucasus and Central Asia.
“With the region advancing its digital economy and smart infrastructure, defenders must use AI to outpace attackers. By adopting a continuous defence strategy, Middle Eastern enterprises can reduce exposure, strengthen business resilience and build the trust required for lasting innovation.”
Eight years of code review in eight weeks
Cisco pointed to its own security operations as evidence of what AI changes for defenders. Its Security and Trust Organisation used several frontier AI models, including early access to Anthropic’s Project Glasswing and OpenAI’s Trusted Access for Cyber, to scan 1.8 billion lines of code across more than 25 languages in eight weeks. Cisco estimates the same work would have taken eight years without AI.
Writing in the company blog, Dave West, Senior Vice President, Global Specialists at Cisco, said the significance was not the speed of the scan but what it showed about how defence now has to operate. The exercise applied security research, engineering judgement and threat intelligence across a complex environment in a way that could be repeated, measured, prioritised and scaled.
The executive brief sets out three changes for organisations pursuing continuous resilience. The first is making remediation continuous. Cisco said patching and upgrading can no longer be run as emergency drills and must become part of a predictable operating rhythm.
The second is using modernisation to retire risk rather than treating it as a hardware refresh. Unsupported and end-of-life assets create exposure that cannot be closed through patching, and Cisco argues security teams should not be asked to carry it indefinitely.
The third is raising security posture to match the speed of the threat. That means segmenting environments to limit the blast radius of an incident, closing identity gaps, and equipping security operations centre teams to act quickly.
West said none of this requires a complete programme before an organisation starts, and that each step makes the next one easier. Gulf governments are pushing large-scale digital infrastructure and smart city programmes, expanding the attack surface that regional security teams have to defend.
Cisco argues that point-in-time security has stopped being adequate as a baseline for resilience, readiness and trust, and that the same AI capability driving faster attacks is available to defenders.





