SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

Attacks in as little as 51 seconds—CrowdStrike CEO says, 'You must fight AI with AI'

As AI agents integrate into corporate operations, the attack surface expands, and CrowdStrike founder and CEO George Kurtz sounded the alarm in a Yahoo Finance interview, stating, 'If you don't fight AI attacks with AI, you won't be able to defend in time.'


1. What does it mean to 'fight AI with AI'?—The premise of 'automated attacks'


Kurtz's message is simple. Since attackers are also using AI, and the speed and scale have become 'mechanized,' the defense side cannot keep up unless they counter with AI.
In the interview, he described AI agents as 'superhuman.' They have 'IDs' just like humans and can access data, computing resources, and workflows. And, 'what a human does in a day, an agent does in a second.' This gap translates directly into risk.

The point is that AI is transforming from a 'convenient tool' into an autonomous workforce (a new entity) operating within the company. As the number of entities increases, so does the scope of what needs to be protected (monitoring, permissions, and auditing).

2. The 'attack surface' expanded by AI—Prompts and agents become new entry points


2-1. Prompt layer: Inputs become direct pathways for information leakage

Kurtz cited the risk of employees pasting confidential information into public LLMs as an example. Even if the individual intends it as a 'consultation,' accidents happen if the destination, reuse, and log management of the data are ambiguous. What is needed here is the concept of placing guardrails on inputs and outputs (what can be entered/what can be returned/what can be sent externally).

2-2. Prompt injection: Extracting 'answers that should not be revealed' through questioning techniques

'If you ask a travel booking site's AI a certain way, it will return other customers' information'—this type of story is typical of prompt injection (direct/indirect). In short, as AI operates as 'part of an application,' not only traditional vulnerabilities (DBs and APIs) but the conversation (commands) itself becomes an attack surface.

2-3. Agents: Convenient automation creates 'rogue permissions'

Kurtz compared agents to 'releasing a drunk intern onto the network.' It's a funny expression, but the essence is sharp.

  • What data they touched

  • Which tools they called

  • What judgments they made and what they output
    —agents that cannot be tracked are 'free-range' in terms of both compliance and security.

3. After EDR comes AIDR—Moving to a defense that 'measures, audits, and stops AI'


CrowdStrike has launched this trend as 'AIDR (AI Detection and Response)' and announced the acquisition of AI security company Pangea. The goal is to visualize and control all layers of AI usage, development, and operation, using the same mindset as traditional EDR (endpoints).

Broadly speaking, the core of AIDR consists of the following three points:

  1. Visualization: Who is using which AI, and what prompts/responses are flowing

  2. Enforcement: 'Stopping' dangerous inputs, dangerous outputs, and dangerous tool calls

  3. Audit trail: Recording each step for audit and regulatory compliance

It is not 'don't use AI,' but rather 'defend with the assumption that you are using it.' This is the turning point.

4. The enemy of defense is 'speed'—from intrusion to lateral movement in as little as 51 seconds


What makes the AI era troublesome is not just the sophistication of attacks, but the fact that time disappears. According to CrowdStrike's threat report, the 'breakout time' from intrusion to lateral movement has reached an average of 48 minutes, with a minimum of 51 seconds. In other words, the grace period left for the defense side is not 'detect and respond,' but rather 'stop it almost simultaneously.'

Furthermore, as a real-world confirmation, Anthropic announced in September 2025 that an attacker, believed to be Chinese, abused the 'agentic capabilities' of AI to have the AI execute much of the intrusion process. The industrialization of attacks is already becoming a 'matter of observation' rather than 'prediction'.

5. Where should companies start? Designing 'AI adoption' and 'AI governance' simultaneously


Finally, I have compiled a checklist of priorities in the field from an editor's perspective.

  • Treat AI agents like 'new employees': Prepare everything from ID assignment, least privilege, and segregation of duties to termination (suspension) procedures

  • Guardrails at the prompt entrance: Establish policies for classification of confidential information, prohibition of data exfiltration, and blocking/permitting external LLMs

  • If an AI doesn't produce audit logs, 'don't put it into production': This is a lifeline, especially for regulated industries (finance, etc.)

  • Operations based on speed: Automated isolation and blocking that doesn't wait for human approval (keeping up with AI using AI)

  • Purchasing and contracts should also be 'platform-based': CrowdStrike is promoting module deployment with flexible licensing (Falcon Flex), which can also be called a commercial design to keep up with the 'fast-changing attack surface'.

AI increases productivity. At the same time, it also increases the productivity of attackers. That is why the conclusion converges on Kurtz's words: 'If you are going to introduce AI, you must also introduce a mechanism to protect that AI at the same time'—and we are entering a phase where, if it isn't AI, you won't make it in time.

Recommended Articles


Next Big Wave (Growth Stocks, Seeds of Ideas, Deep Dives into Trends)




いいなと思ったら応援しよう!