The Age of Perpetual Breach: Why Resilience Has Replaced Patching as the Measure of a Defensible Institution

By Andrew Horton  ·  21 September 2026

When machines discover weaknesses faster than humans can fix them, perpetual breach becomes the normal condition of every network and resilience becomes the decisive strategic advantage.

Microsoft’s September security release fixed 966 vulnerabilities in a single day, the largest security update in the company’s history. More than one hundred were rated critical, and attackers were already exploiting two of them. The significance lies in what the number reveals about the changing character of cyber conflict. For more than three decades, cybersecurity rested on a simple assumption that discovering vulnerabilities was difficult and fixing them was largely a matter of process and discipline. Artificial intelligence has overturned that equation. Machines now analyse software at a scale and speed beyond any human team, so discovery has become abundant while remediation remains finite.

Microsoft’s own trajectory shows how quickly the ground has moved. The company patched 887 vulnerabilities across all of 2021, then 917 in 2022 and 909 in 2023, before climbing to 1,009 in 2024 and 1,130 in 2025. By September 2026 it had already fixed more than 2,600 for the year, more than double its previous annual record of 1,245, with a quarter still to run. We are entering the Age of Perpetual Breach, a condition in which machines expose flaws faster than institutions can close them, so that compromise becomes the standing state of every network.

That discovery should be welcomed. Microsoft has turned an agentic AI system on its own code and warned customers that “as AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release”. Every flaw a vendor discovers and fixes is one fewer opportunity for an adversary, and Microsoft deserves credit for interrogating its own products at machine speed. The difficulty is that the same capability is spreading. Hostile intelligence services and ransomware syndicates can turn machine-scale discovery against the software that runs governments and critical infrastructure, and they will find weaknesses faster than institutions can remove them.

Many boards and policymakers still treat cybersecurity as a compliance problem, in which vulnerabilities are counted and progress is recorded in audit reports. Those activities remain necessary, and they have stopped being sufficient. Once machine discovery reaches industrial scale, every organisation accumulates a backlog it can never clear, because security teams cannot test and deploy fixes as fast as new flaws appear. Human attention becomes the binding constraint, and the contest shifts from discovering vulnerabilities to deciding which of them matter.

Compliance regimes designed for an earlier era strain under that load. Australia’s Essential Eight asks organisations to patch internet-facing systems within 48 hours where a working exploit exists and within two weeks otherwise. Those clocks assume remediation can keep pace with discovery, an assumption calibrated for a major vendor shipping under a hundred fixes a month. Applied to a thousand, they become a test few security teams can pass honestly and a box many will tick regardless.

A compliance regime that measures the speed of patching measures the one variable an adversary has already outrun.

 

The adversary, meanwhile, is accelerating. Mandiant’s M-Trends 2026 estimates the mean time to exploit at minus seven days, meaning attackers routinely weaponise vulnerabilities before vendors release patches, and exploitation has been the leading avenue of intrusion for six consecutive years. Attackers now operate inside the defender’s decision cycle.

Vulnerabilities differ enormously in danger, and the sceptics deserve a hearing. VulnCheck’s analysis of the first half of 2026 found that of 1,061 vulnerabilities attributed to AI discovery, only 14 were confirmed as exploited, and Tenable’s Satnam Narang argues that AI is “creating larger haystacks, but it isn’t finding more needles”. That observation strengthens the argument. The same VulnCheck data shows almost a quarter of exploited flaws were attacked on or before the day they were published. The real task is finding the few flaws that matter before an adversary does, and in a flood of technical discoveries, judgement becomes the most valuable defensive capability.

The closest parallel sits on the battlefields of Ukraine. In May the Ukrainian Air Force recorded close to 1,500 Russian drones and missiles launched across a single day, the heaviest barrage of the war. Kyiv’s planners accepted that some weapons would get through and concentrated on preserving what mattered most. Engineers ringed critical substations with concrete and sandbags, and in August the grid operator Ukrenergo began moving parts of the network underground ahead of a fourth winter of strikes. Ukraine recognised a reality many cybersecurity strategies still resist: success depends on ensuring that the assets which matter most survive the attacks that inevitably get through.

Cybersecurity has entered the same strategic phase. The Australian Signals Directorate advises organisations to operate with a mindset of “assume compromise”, an acknowledgement that breach has become a normal condition of digital life, and its latest threat report records the average cost of an incident to a large Australian business rising 219 per cent in a single year. The question has moved from whether intrusions will occur to whether organisations can keep operating when they do. Most boards can describe their patching programs. Far fewer can name the specific datasets whose theft or corruption would threaten the future of the enterprise.

Information is increasingly the true centre of gravity. Defence intellectual property, critical infrastructure designs, scientific research and sensitive government data carry enduring strategic value. Networks can be rebuilt and servers replaced, while lost information is often gone for good. Nations that field AI-enabled discovery at scale will accumulate unprecedented insight into the weaknesses embedded across the digital ecosystem, and the advantage will pass to those who know precisely what must be protected at all costs. Authoritarian states have long treated data as a strategic harvest, gathered now and exploited later. Democracies must answer with equal clarity, drawing on trusted institutions and alliances able to coordinate the defence of critical information across governments and industry.

For policymakers, this means moving cyber regulation from measuring activity towards measuring resilience. Knowing precisely where critical data resides, isolating it from routine systems, and regularly rehearsing its recovery should carry the same regulatory weight as the speed with which organisations apply patches. For boards, the central question shifts from whether the organisation is patched to what an adversary could reach once inside. The first question measures diligence. The second measures survival.

Ukraine’s engineers learned under relentless attack that resilience begins with deciding which parts of a system must never fail. The Age of Perpetual Breach will reward the nations and companies that make that decision about their information before the intruder arrives, and history will judge them by what survived the breach.

Next
Next

The Compounding Error: Why the Next AI Contest Will Be Fought Over Verification