When Outages Become Normal

Vulnerabilities Are Getting Cheaper, but Downtime Remains Expensive

Vulnerabilities, Downtime, cyber resilience, vulnerability research, how AI is changing vulnerability research, why EDR failure creates a cybersecurity blind spot, how to detect attacks after security tools are disabled, vulnerability
Facebook
X
LinkedIn
Reddit
WhatsApp

AI is accelerating the search for security vulnerabilities, while attackers are increasingly disabling the very tools designed to stop them. What can still detect an attack when EDR and other security controls have already been taken offline?

For years, cyber defense relied on a relatively simple assumption: Attackers try to evade security tools, while defenders try to detect them as early as possible. That division is beginning to shift.

Ad

Professional attackers are increasingly targeting the systems that could expose their activity. Vulnerable signed drivers and legitimate remote management tools have made defense evasion an established part of modern attack chains. At the same time, AI is changing the economics of vulnerability research. The offensive side is becoming faster and cheaper, while patch cycles and maintenance windows are barely changing. The cost of launching an attack is falling faster than organizations can adapt their defenses.

The Defense Fails First

Marc Elias of the Symantec Threat Hunter Team attributes this shift, in part, to the success of behavior based detection:

“Attackers have largely stopped trying to make their ransomware undetectable and are instead simply trying to disable the security mechanisms.”

Ad

Marc Elias, Symantec Threat Hunter Team

As a result, it is no longer enough to know how effectively an EDR system can detect an attack. Organizations also need to ask what happens when that system is switched off. The more detection and response capabilities are concentrated on a small number of platforms, the more attractive those platforms become as attack targets themselves.

The question is no longer just: What can our sensor detect? It is also: What can still detect the attack when that sensor is gone?

OT Reveals the Problem in Its Most Extreme Form

Conventional EDR typically does not run on industrial controllers. That often leaves engineering workstations, HMI servers, and jump hosts among the few systems where endpoint detection is possible.

If the agent disappears from those systems, network visibility becomes an independent observation layer. It can be supplemented with process data, historian records, controller diagnostics, and remote access logs. A network sensor also cannot simply be removed from an engineering workstation with a signed driver.

The goal is not to build the perfect sensor. The goal is to ensure that no single sensor becomes a single point of failure for the entire defense.

AI Widens the Speed Gap

Ta Lun Yen of TXOne Networks demonstrated an LLM powered workflow for finding vulnerabilities in firmware binaries without debug information. The model helps focus limited reverse engineering resources on the most promising areas. AI does not make vulnerability research trivial. But it can make the scarcest resource more efficient: expert time.

On the defensive side, maintenance windows remain limited, update paths are determined by vendors, and changes must be tested. In OT environments, patch cycles can take months or even years. Simply telling organizations to “patch faster” therefore misses the point. Segmentation, controlled transitions between environments, access restrictions, and network monitoring are becoming increasingly important.

The Attack Path Does Not Have to Start on the Internet

USB drives, service laptops used by external contractors, and firmware files are all legitimate entry points into segmented environments. That is precisely what makes them problematic.

Benny Czarny, CEO of OPSWAT, puts it this way:

“You don’t have to break into the network remotely. You only have to compromise a file, a device, a service provider, or one step in the maintenance and supply chain.”

According to the ICS/OT Cybersecurity Budget Report 2025, 27.3 percent of respondents who were able to identify an initial attack vector cited transient cyber assets such as contractor laptops. Another 15.2 percent pointed to compromised removable media. This is also a governance issue. Who is allowed to use such assets? How are they inspected? Which zone are they permitted to access? And what evidence and records are retained?

Transparency Becomes a Regulatory Requirement

The Cyber Resilience Act gives transparency new regulatory weight. Initial reporting obligations will take effect on September 11, 2026. Manufacturers will have to submit an early warning within 24 hours after becoming aware of an actively exploited vulnerability in a product.

Matt Wyckhouse, CEO of Finite State, identifies visibility as the biggest challenge:

“The biggest gap is transparency. If you don’t know exactly what software is in your products and whether a newly discovered vulnerability affects you, it is extremely difficult to meet a 24 hour reporting requirement.”

An SBOM is useful only if it is kept current and connected to ongoing vulnerability management. It must be treated “as a living asset rather than a static document.” An audit export alone does not create operational transparency.

Cyber Defense Must Survive Its Own Failure

Security controls need to be designed on the assumption that individual components may fail during an attack. If endpoint detection goes down, the organization still needs network and log visibility. A compromised remote access system must not create an uncontrolled path to critical systems. Removable media and temporary devices require dedicated controls. Commitments around updates, vulnerability handling, and end of support dates also need to be built into supplier requirements and contracts from the outset.

As vulnerability research becomes faster and attacks become cheaper, defenders cannot rely on patching at the same pace. They need to become more resilient at the moment when the first line of defense has already fallen.

The key question is therefore no longer simply: Can our security tools detect an attack? It is: What can still detect the attack when the first security tool has already been disabled?

Sabine Frömling

Sabine

Frömling

Cybersecurity- und GRC-Consultant

Sabine Frömling is a cybersecurity and GRC consultant specializing in ISMS, NIS2, and OT security, and regularly writes about these topics.
Ad

Artikel zu diesem Thema

Weitere Artikel