The Firewall Is Dead: Welcome to the Age of Relentless AI-Enabled Hacking

August 26, 2026  |  Mark Hillary

Play Audio Version

How much does it cost a business to recover from a data breach? It could be a malicious attack by hackers, or ransomware, or just negligence – either way it very quickly gets very expensive.

The latest IBM estimate is $4.99 million as the average cost – up 12% on last year. This will vary with each company as the type of attack will define how difficult it is to recover – where it involves the loss of customer’s personal data it may also involve compensation and damage to the reputation of the business.

What I find interesting though is that IBM has been publishing their annual ‘Cost of a Data Breach’ report for 21 years now. Even back in 2005, the cost ran into millions of dollars, so the risk is not new, but it is being increased through the use of AI for attacks.

Security company Sysdig has recently reported LLM-powered hackers able to break into networks in seconds. They can be let loose on targets and they automatically try different tactics and search for weaknesses that can be targeted. This is automated hacking.

This creates a new era for network security. Traditional firewalls need to be replaced by dynamic and intelligent security systems that are actively looking for unauthorized access. One problem is that malware can easily be generated using AI – so you don’t need to be highly skilled to be involved in hacking today. Security analysts have suggested that even “relatively unspectacular” malware creates a new dynamic where attacks can be automated and relentless.

Research published recently in Time magazine outlined how iPhone users who don’t regularly update their operating system could become the victim of malware that targets phones that have not been updated. The issue of security is becoming both a problem for our personal use of technology as well as the enterprise use – even more so when customer information is also at stake.

Last year, the British retailer Marks & Spencer was targeted by a cyber-attack that entirely knocked out their ability to sell anything online. It affected their in-store payment systems and in-store stock controls – even after stores had recovered the ability to take payment the shelves were empty.

This was a tough time for M&S as analysts had predicted record profits in 2025. Instead, 99% of their profit for the year was wiped out by the disruption of the cyber-attack. This cost the business hundreds of millions of pounds. A smaller retailer would have been finished.

IT security has become more complex in 2026. The M&S attack was blamed on a third-party contractor, although every company involved has denied any responsibility for the hacking incident.

Whatever really happened, the end result was clear. Profits for an entire year entirely wiped out. A record year destroyed.

Security today requires a vision that goes beyond traditional on-premise systems. Now the cloud needs to be secure. Connections to suppliers need to be secure. All employees need to be aware of social engineering and how calls from the IT help desk may actually be hacking attempts. Many companies now support work from home employees. There are so many more potential attack vectors compared to a decade ago.

CI/CD security is required to protect software development workflows. A complete strategy for identity management needs to be developed for all users at all levels of the business. Security Information and Event Management (SIEM) provides real-time monitoring and automated detection systems that can flag up unusual network activity.

Penetration testing is also becoming an important tool in the fight against hackers because it encourages a cultural change. Security is no longer just the responsibility of the CIO or CTO. The technology managers can secure networks and build automated event detection, but if authorized user accounts are used to access restricted data – as happened during the M&S hacking – then these alerts will not be triggered until it is too late.

Security today requires an holistic approach that embraces all these strategies and uses tools like penetration testing to create a culture of security within the business.

It is impossible to ignore the real-life experience of companies such as M&S. A cyberattack can wipe out a year’s profit, disrupt every part of the business, and damage customer trust in a matter of hours. It can take years to recover. Many never recover, and are just forced into bankruptcy.

As AI makes attacks faster, cheaper, and easier to automate, companies can no longer treat security as an annual compliance exercise or something owned only by the CIO and IT team.

Every employee, third-party supplier, cloud service, software update, and user account is now part of your defense against attack. A businesses that acts now will build and test their resilience – before it is needed. Those that wait may discover – far too late – that the cost of prevention was insignificant compared with the cost of business recovery.

For more information on IT security operations with IBA Group please click here.

    Access full story Leave your corporate email to get a file.
    Yes

      Subscribe A bank transforms the way they work and reach
      Yes