Benjamin Klein and his McKinsey colleagues open their latest Risk & Resilience piece, The speed problem: How frontier AI exposes weakness in enterprise cybersecurity1, with a deliberately unsettling premise. The important shift in enterprise security, they write, is not smarter malware. "It is the collapse of time." Everything that follows is an unpacking of that single sentence.
How Fast Is Fast?
The numbers set the stakes. The authors cite industry tracking data suggesting the average gap between disclosure of a critical vulnerability and its active exploitation has fallen to a matter of hours, down from roughly three weeks as recently as 2025. Frontier models such as Anthropic's Mythos/Fable, OpenAI's GPT-Cyber and Google's Gemini are credited with closing that gap, not by accelerating existing attack workflows but by making discovery and exploitation accessible to a far larger pool of attackers. McKinsey's own analysis suggests critical novel vulnerabilities with no available patch now make up most active exposures.
To be clear, the authors do not frame this as a technology race. Their central claim is that frontier AI enables attacks faster than enterprise decision-making, which makes it an operating-model problem rather than a technology problem.
Where Does the Latency Live?
This is the section that should give boards pause. When security leaders are asked what stops them responding faster, they seldom blame the tools; most already have robust detection, patch management and playbooks. The bottleneck is decision-making, governance and coordination.
Klein and colleagues walk through the typical chain: security identifies and assesses a vulnerability, which can take a day or more given poorly inventoried assets; escalation to IT leadership and application owners managing release schedules and change freezes; weeks of validation for custom or legacy code; negotiation of patch windows with the business; sign-off from a change advisory board that often meets weekly; and third-party systems on timelines nobody internal controls.
To be fair, the authors are explicit that none of this is dysfunction. These processes exist to protect uptime, compliance and service quality. But because vulnerabilities that once sat exposed for weeks must now be closed within hours, organizational architecture has itself become a direct security liability. The root cause is that nobody owns decision speed: IT owns patching, the business owns downtime, legal owns disclosure, procurement owns vendors, security owns risk assessment, and no single function has the authority and mandate to move the enterprise at the pace the threat requires.
What Does the Fix Look Like?
The authors' answer is a model they call governed autonomy: AI handles high-volume, time-sensitive monitoring and routine remediation, while human judgment governs novel threats, strategic risk and anything material to the business. It rests on three imperatives, each organizational before it is technical.
First, continuous visibility, but scoped. Enterprise-wide real-time visibility consistently fails; leading firms instead define a "minimum viable organization," the irreducible core whose disruption would be existential, and concentrate scanning and attack-surface reduction there. One global financial institution found that prioritizing large language model scanning on its minimum viable bank cut exposure around its highest-value assets faster and at lower cost than prior approaches.
Second, defensive AI as foundational architecture, spanning continuous attack-path discovery that prioritizes by real exploitability rather than generic severity scores, AI-assisted remediation across the software development lifecycle, and incident response where agents are preauthorized to isolate systems, revoke credentials and apply compensating controls within defined guardrails, with human review following low-risk actions.
Third, and in the authors' view most underestimated, redesigning decision rights. The prescription is a small cross-functional response cell with a single decision-maker holding CSO-delegated authority to override standard change management for confirmed active threats, preauthorized playbooks, and an executive liaison reporting to the board every 24 hours. The case evidence is pointed: one financial institution restructured governance after a critical vulnerability sat unpatched for 11 days because no team could override a production change freeze; a pharmaceutical company gave security standing authority to override R&D schedules during active threats.
Why the CEO, Not the CSO?
The most important divergence from conventional wisdom is where accountability sits. Organizations that treat governed autonomy as a security program stall in phase one, because the bottlenecks are business decisions on downtime, change authority, development priorities and vendor obligations that security cannot resolve unilaterally. The authors also flag a second wave: agentic AI introduces new requirements around data boundaries, identity and behavioral guardrails; the per-query cost of running large models continuously is a budget category legacy security spending was never built to absorb; and the CSO role itself is being redefined as an architect of governed autonomy at scale.
The conclusion is blunt: the security budget will matter far less than the clarity of the operating model.
Five Takeaways for Advisors and Investors
- Security spend is no longer the signal. Ask portfolio companies who owns decision speed, not how much they budget for tools.
- Legacy code is a repricing risk. Banks, industrials and technology-intensive manufacturers face the longest validation lags, and the authors say so explicitly.
- Governance is the moat. A named response cell with delegated override authority is a due-diligence question, not a technical detail.
- Watch the cost line. Continuous large-model inference is a new, structural expense in security operations.
- The lesson generalizes. AI is compressing management timelines everywhere; cyber is simply where it bites first and hardest.
Footnote:
1 Klein, Benjamin, et al. "The Speed Problem: How Frontier AI Exposes Weakness in Enterprise Cybersecurity." McKinsey & Company, 11 Sept. 2026, https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/the-speed-problem-how-frontier-ai-exposes-weakness-in-enterprise-cybersecurity. Accessed 15 Sept. 2026.