AI Is Accelerating Cyber Crimes: Here Is What Companies Need to Do
30th July 2026
Apax Cyber security has always been an arms race. What has changed in the last year is the pace at which that race is now run. Artificial intelligence has become, inCyber security has always been an arms race. What has changed in the last year is the pace at which that race is now run. Artificial intelligence has become, in equal measure, the most powerful tool available to defenders and the sharpest weapon in the hands of attacker, and for portfolio companies across every sector, it can feel like attackers are often one step ahead.
This was the theme that opened Apax’ most recent annual Cyber Security Summit, bringing together security leaders from across the portfolio to confront a simple but uncomfortable truth: the foundations of good cyber security that got businesses this far will not be enough to get them to where they need to go next. Three distinct shifts are converging on portfolio companies simultaneously, and AI runs through all of them. The pace of change means that "Companies need to operate at attacker tempo, not typical business tempo,” says John Nugent, who leads on portfolio cyber security at Apax.
Three Shifts Linked by AI
The first is speed. Research shows that the window between an attacker gaining initial access and moving laterally inside a network, the so-called "breakout time”, has almost halved in the space of a year, while AI-augmented attacks have nearly doubled in volume year-on-year and that trend is showing no sign of slowing. Attackers are using legitimate AI tooling to scan for vulnerable systems at a scale and speed that would have been unimaginable eighteen months ago.
The second is the pace of AI adoption inside businesses themselves and the implications of that. Companies are deploying AI tools faster than their security teams can secure them. A meaningful share of the AI "agent skills" now being installed across corporate environments carry known vulnerabilities yet are frequently run with a level of implicit trust that would never be extended to unvetted code in any other context.
The third orients around stakeholder expectations. Boards, investors and regulators all demand that businesses demonstrate they are secure. Regulatory frameworks in both the UK and the U.S. have begun formally incorporating frontier AI cyber risk into existing operational resilience requirements, and further regulatory milestones are expected before the end of the summer. Witness for example how Anthropic’s new Mythos model was suspended for weeks by the U.S. government.
Identity Is the New Front Door
One research finding stands out above the rest. Threat actors overwhelmingly no longer need to hack their way in. They simply log in as what they need is already available or can often be accessed without huge amounts of difficulty. The vast majority of ransomware insurance claims now originate from compromised remote access credentials rather than a sophisticated technical exploit.
Multi-factor authentication remains a genuinely effective control, but it is only the first of several locks needed on the front door, says Nugent.
Protecting the credentials themselves through secrets management and restricting what a compromised credential can actually do through privileged access management, both lag well behind in terms of common adoption.
At the same time, a newer category of identity has been growing just as fast: the "non-human" identities, such as service accounts and API keys, that increasingly authenticate AI agents without any person at a keyboard at all.
“It is more crucial than ever that we look to lockdown the full span of identity-related exposures, not least those which allow privileged activity or which are the currency of the AI agents that we are likely to become ever more dependent upon,” says Nugent.
From Finding Problems to Finishing the Fix
Encouragingly, an increasing number of companies are starting to leverage AI effectively in their defensive efforts. becoming highly effective at finding vulnerabilities. Apax fund-backed TradeMe has built an autonomous code-reviewer that runs an AI-driven model inside isolated, sandboxed environments, and is triggered instantly whenever developers push code, ensuring security reviews scale with the pace of development.
Equally, Bonterra has woven AI through its defensive stack, embedding behavioural analysis that detects email threats by intent rather than known signatures, alongside continuous AI-driven detection of cloud misconfigurations across its environment.
Lastly, RapidSOS, which provides critical infrastructure services to first responders, has responded to the security challenges posed by AI by developing a comprehensive CISO-owned programme that maps to an array of recognised external standards and which spans legal, engineering, product and compliance, bringing business-wide ownership and execution.
“You can't secure what you can't see and so the first thing we stress is that people need to have a grip of what is being used and what is happening in their environment,” says Nugent. “There are tools that will allow you to have that depth of visibility, but it's also having the right governance in place within the organisation.”
Interestingly, while AI allows us (and attackers) to find ever more security exposures at a far greater speed, the harder challenge is remediating those at pace and scale. Enforced, risk-based service-level agreements for fixing what is found remain far less common than rapid identification, meaning known issues can sit unresolved for longer than they should.
“In essence, anything reachable from the internet with a known exploit path needs immediate action,” says Nugent. The priority has to become developing a security capability that is geared on the one hand around continuous testing, and on the other, around fixing at AI-speed, wherever a vulnerability may arise within the organisation. This is an incredibly complex undertaking.
The same pattern holds for resilience. Detection capability, tested incident response plans, and critically, offline, immutable backups that are actually tested through restoration exercises, rather than deemed to be effective through service provider guarantees, are the controls that determine whether a business can recover from an incident without paying a ransom.
Apax continues to work hand-in-hand with its portfolio companies on each of these fronts through direct engagement and partnership, shared threat intelligence, and a security programme built to keep pace with the businesses it protects.