Blog

Cybersecurity in the Age of Acceleration: Can Your Organization Keep Up With the New Tempo?

For years, time has been a form of invisible protection in cybersecurity. Discovering a complex vulnerability could require weeks or months of research. Analyzing a new cryptographic algorithm demanded extremely specialized knowledge. Developing an exploitation method required skilled personnel, infrastructure, money, and a great deal of patience. Organizations likewise had a certain amount of time to analyze threats, prioritize fixes, and progressively adapt their protection mechanisms.

This reality is beginning to change with the acceleration of artificial intelligence capabilities. In the summer of 2026, researchers at Anthropic demonstrated that a frontier AI model could contribute significantly to cryptanalysis work that would traditionally have required considerable human effort. Claude Mythos Preview notably made it possible to substantially improve the best known attack against HAWK, a candidate for post-quantum digital signature standardization, after roughly 60 hours of work. In another experiment, the model largely autonomously discovered a significant improvement to an attack against a deliberately reduced version of AES. This work in no way means that currently deployed cryptographic systems are suddenly compromised: HAWK remains a standardization candidate and full AES has not been broken.

The importance of these experiments lies elsewhere. They give a glimpse of what can happen when artificial intelligence begins to radically compress the time needed to accomplish certain highly specialized intellectual tasks. This phenomenon extends far beyond cryptography and already touches programming, vulnerability research, data analysis, scientific research, and various forms of automation. For executives, one question then becomes unavoidable: what happens when technologies and threats begin to evolve faster than the organizations responsible for governing them?

The experiment conducted by Anthropic provides a particularly interesting illustration of this compression of time. HAWK had already been through two years of expert examination as part of the NIST post-quantum standardization process. Claude Mythos Preview nonetheless helped discover, in roughly 60 hours, a significant improvement to the best known attack against the scheme. For AES, a model operating largely autonomously found, in about a week, a method considerably improving on certain earlier attacks against a deliberately reduced version of the cipher.

These results obviously do not mean that an artificial intelligence can now break the cryptographic mechanisms that protect the Internet. Anthropic itself stresses this distinction. They do, however, show that AI systems are beginning to become capable of participating seriously in an extremely specialized scientific activity that traditionally required a great deal of time and rare expertise. This development is directly relevant to cybersecurity because time is one of the fundamental variables in any confrontation between attackers and defenders.

A vulnerability has a different value depending on whether it takes six months or six hours to understand how to exploit it. A weakness becomes more dangerous when its discovery can be automated, and an attack becomes economically accessible to more actors when the intellectual cost of developing it decreases. An organization also has less room to maneuver when the period between the discovery of a weakness and its potential exploitation contracts. An attacker's real advantage could therefore increasingly come from their speed of analysis and execution.

Canada's Office of the Superintendent of Financial Institutions recently took an interest in this transformation and in the shortening of reaction times driven by advances in frontier AI. This development is beginning to call into question certain traditional practices in patch management and incident response. The problem becomes organizational as much as technological, since many cybersecurity processes were designed to operate at human speed while some analysis and automation capabilities are progressively beginning to operate at machine speed.

In a traditional organization, a vulnerability is detected, documented, passed to the relevant people, analyzed, classified by risk level, submitted for a decision, tested, scheduled, and then remediated. Each of these steps has a reason to exist. Operational caution remains essential, since a patch applied too quickly can itself cause an outage or disrupt critical operations. The problem arises when this full decision chain requires several weeks while the analysis and exploitation capability on the other side is moving toward a few hours or a few days.

This difference in tempo could become one of the major cybersecurity challenges of the coming years. It does not concern malicious actors alone. The same systems capable of analyzing code, searching for vulnerabilities, and rapidly exploring different hypotheses can help researchers, software vendors, and cybersecurity teams discover weaknesses before they are exploited.

The International AI Safety Report 2026, chaired by Yoshua Bengio and produced with contributions from more than a hundred international experts, likewise notes the advancing cyber capabilities of artificial intelligence systems, particularly in programming and vulnerability discovery. The net effect of this development nonetheless remains uncertain. An AI capable of quickly finding a weakness can help an attacker, while the same capability can allow the defender to discover it, understand it, and fix it first. We are therefore entering an environment where artificial intelligence can accelerate both sides simultaneously.

For organizations, the decisive question then becomes their capacity for integration. A company may have extremely high-performing artificial intelligence tools and continue to operate with decision processes designed twenty years earlier. It may detect an anomaly in seconds and need three days to determine who has the authority to intervene. It may automatically discover a vulnerability and wait several weeks before a maintenance window allows it to be fixed. It may also generate thousands of additional alerts without proportionally increasing its capacity to determine which ones genuinely require intervention.

Technological acceleration therefore does not automatically produce a faster organization. Adding more automation to a company unable to prioritize its risks quickly can simply produce more information to process. Adding artificial intelligence to an excessively complex process can speed up its execution without correcting the reasons it became complex. The challenge is instead to intelligently accelerate understanding, decision-making, and adaptation while retaining the controls necessary for decision quality.

This distinction brings back to the forefront several organizational capabilities that may seem less spectacular than the latest artificial intelligence models. An organization that knows its assets precisely can quickly determine whether a new vulnerability concerns it. One that knows its software dependencies can more easily identify the affected systems. A properly segmented architecture makes it possible to limit exposure quickly. Rigorous identity management reduces the opportunities for movement when a compromise occurs. Clear governance ultimately makes it possible to know who has the authority to make an urgent decision. These capabilities often determine the real speed of response.

Organizational knowledge thus becomes a fundamental component of cyber resilience. When a company does not know exactly which systems it owns, which libraries they use, which suppliers are involved, which data flows through them, or which identities hold which privileges, every new event triggers an investigation before the real response can even begin. A significant part of the time lost then comes not from the sophistication of the attack, but from the difficulty of understanding one's own organization quickly enough.

This reality connects directly with the challenge of cybervigilance. In an environment where technological capabilities advance quickly, an annual security assessment essentially provides a snapshot of an environment that starts changing again the next day. Applications are updated, new services are connected, suppliers modify their architectures, vulnerabilities are discovered, and new attack techniques appear. Cybervigilance progressively turns that snapshot into a continuous capacity for observation and reassessment, so as to know what is changing early enough to decide before the change becomes an incident.

This logic takes on particular importance in cryptography. Organizations are already facing the transition to post-quantum mechanisms because a future quantum computer powerful enough could make certain widely used algorithms vulnerable today. The experiment conducted with HAWK adds another dimension to this thinking: even new algorithms must be continually examined, attacked, tested, and improved. A durable cryptographic strategy therefore cannot rest solely on the choice of the next algorithm. It must also make it possible to change algorithms as knowledge and standards evolve.

That is precisely why crypto-agility is becoming a strategic capability. An organization must know the cryptographic mechanisms it uses, where they are located, which systems depend on them, and how difficult they would really be to replace. When a weakness is discovered or a standard evolves, it can then quickly determine its exposure and organize a transition. In an accelerating technological environment, the ability to change sometimes becomes more important than the ability to perfectly predict what comes next.

This idea extends far beyond cryptography. It applies to artificial intelligence models, cloud providers, software, libraries, APIs, mobile devices, and connected equipment. The shorter technology cycles become, the faster a rigid architecture accumulates strategic debt. The resilient organization progressively becomes the one that retains enough knowledge, modularity, and control to evolve without having to constantly rebuild its environment.

The work chaired by Yoshua Bengio remains cautious about the exact trajectory of the coming years. Technical, energy, or economic constraints could slow some progress, while feedback loops in which artificial intelligence itself contributes to AI research could, on the contrary, accelerate certain advances. There is no scientific consensus allowing us to state precisely which trajectory will prevail, and that uncertainty is itself important information for executives.

An organization does not need to correctly predict the exact speed of progress in order to prepare. Above all, it must avoid building its processes on the implicit assumption that the current pace will remain stable. The concerns expressed by some researchers directly involved in developing frontier systems illustrate this tension. Conclusions about future risks remain debated, but one observation deserves attention: the speed at which capabilities evolve is itself becoming a variable that organizations must learn to govern.

For companies and government organizations, this question has a far more immediate dimension than debates about the distant future of artificial intelligence. Cybersecurity teams must already continuously absorb new vulnerabilities, technologies, regulations, architectures, and attack techniques. They must protect hybrid environments made up of internal systems, cloud, SaaS applications, mobile devices, connected objects, and now artificial intelligence agents. They must simultaneously maintain operations and prevent the pursuit of speed from itself introducing new risks.

No team can indefinitely multiply its resources at the same pace as this complexity. External expertise can then add specialized capacity temporarily or on an ongoing basis, bring an independent perspective, and help internal teams examine areas they do not necessarily have time to explore in depth while maintaining their daily operational responsibilities.

It is from this perspective that Quantum Beyond can support organizations. Our role consists of working alongside existing teams to increase their capacity to understand, anticipate, and absorb change. Security architecture makes it possible to identify dependencies and critical paths. IAM, Zero Trust, and Continuous Trust help limit the consequences of a compromise. Cyber resilience prepares the organization to keep operating when preventive measures are no longer enough. Artificial intelligence governance helps frame systems whose capabilities evolve quickly, while the Qb Knowledge Standard helps make organizational knowledge more structured and usable. Post-quantum readiness finally makes it possible to build the cryptographic inventory, the dependency mapping, and the crypto-agility needed to manage a transition that will span several years.

These disciplines ultimately share a single objective: reducing the time needed to understand what is happening and increasing the organization's capacity to act correctly. This is also where the thinking can evolve from cybersecurity toward Hypersecurity. Cybersecurity controls remain essential, but they must operate in an environment where identities, data, applications, suppliers, artificial intelligence, Edge infrastructures, and cryptographic mechanisms are continually evolving. Hypersecurity seeks to connect these different dimensions to the organization's resilience, governance, sovereignty, and capacity for adaptation so that protection too can keep up with the new tempo.

For decades, we have mainly sought to make our systems harder to attack. That ambition remains fundamental, but it must now be accompanied by another capability: making organizations faster at understanding, deciding, and adapting. This acceleration does not mean that every decision must be made more quickly. Some still require perspective, validation, and deep human expertise.

Anthropic's experiment provides an excellent illustration of this. The model was able to produce certain cryptographic results quickly, while their human verification required far more time. In the case of the improvement concerning the reduced version of AES, Anthropic reports that the model found its method in about a week, whereas two researchers then spent nearly a month gaining sufficient confidence in the validity of the result. The machine can therefore considerably accelerate discovery, while the organization must accelerate its capacity to understand that discovery without sacrificing the rigor needed to decide correctly.

The transformation ahead therefore comes down neither to a competition between humans and machines nor to a simple race between attackers and defenders. It will increasingly distinguish organizations capable of learning, deciding, and adapting quickly enough from those whose technologies accelerate far faster than their governance processes. The advantage will not come only from the speed of machines, but from the human and organizational capacity to turn that speed into reliable decisions.

The results obtained by Anthropic in cryptanalysis do not mean that the cryptographic mechanisms protecting our information today have suddenly become obsolete. They do, however, offer executives a particularly interesting glimpse of what happens when artificial intelligence begins to radically reduce the time needed to accomplish certain complex intellectual tasks.

This phenomenon can simultaneously affect research, software development, vulnerability discovery, defensive activities, and malicious activities. The response therefore cannot be limited to acquiring ever faster technologies. Organizations must develop their own capacity for acceleration by knowing their assets and dependencies better, structuring their knowledge, reducing unnecessary privileges, improving segmentation, clarifying responsibilities, intelligently automating certain analyses, and building architectures agile enough to evolve as knowledge changes.

Cybervigilance then becomes a permanent capacity for learning and adaptation, while Hypersecurity makes it possible to connect that vigilance to the whole of the architecture, identities, data, artificial intelligence, cryptography, resilience, and sovereignty. The objective is to create organizations capable of continuing to protect their operations while technologies, dependencies, and threats evolve.

Quantum Beyond can add a further layer to this capability by working with internal teams on architecture, cyber resilience, Zero Trust and Continuous Trust, IAM, AI governance, organizational knowledge, cybervigilance, and post-quantum readiness. This contribution aims to strengthen the professionals already responsible for these environments by bringing them the complementary expertise, perspective, and capacity needed when the pace of change exceeds what an operational team can reasonably absorb on its own.

We do not know precisely how fast artificial intelligence capabilities will advance in the coming years, and researchers themselves acknowledge the uncertainty surrounding that trajectory. For organizations, however, that uncertainty is no obstacle to action. When the time needed to discover a weakness can drop from several months to a few days, the main risk is no longer the weakness alone. It also lies in continuing to manage it with an organization designed for yesterday's tempo.