Start with ready-made AI agents with instructions on how to manage them on the marketplace. Browse the library
Back to blog
Back to blog

Anthropic Reduced Threat Response Time from 27 Days to 27 Seconds: How an AI Agent Blocks Cyberattacks in Real-Time

https://s3.ascn.ai/blog/cd554879-e2ee-45ec-aaa6-a80887fbdd6a.png
ASCN Team
31 July 2026
Build an AI agent for your task
It will handle requests, sort your inbox, compile reports, and follow up with clients. No coding or complex integrations required.
Try for free

AI-enhanced cyberattacks have changed the game: the time an attacker spends in a system has plummeted from an average of 27 days to an unprecedented 27 seconds. Against this backdrop, Anthropic, a leader in AI development, implemented a zero-trust architecture, bolstered by its own AI agents, not just to repel attacks but to pre-empt them. This allowed them to increase their cyber resilience 100-fold and set a new standard for security.

Traditional cybersecurity relies on barriers that will eventually be breached. In an era where attackers' AI agents operate in real-time, these breaches will occur in seconds. Every incident is not just financial loss, but a blow to reputation, loss of customer trust, and direct damages. It's not a question of "if," but "when," and this can be prepared for by using AI to defend against AI.

The Reality of Threats: When 27 Days Turned into 27 Seconds

Until recently, the average time to detect an attacker in a corporate network was 27 days. This gave security teams ample time to react, analyze, and contain the threat. However, the introduction of AI agents by attackers has radically transformed this landscape. Today, thanks to AI tools, the time an attacker spends in a system has been reduced to 27 seconds, rendering traditional defense methods obsolete.

The primary threat has shifted from direct system breaches to exploiting stolen credentials and phishing attacks. AI enables the creation of convincing digital profiles for fraudsters, making user verification extremely difficult. Companies are faced with the need not just to defend the perimeter, but to control every action within the network, assuming that any account could be compromised.

The Path to the AI Agent: Why Old Methods Don't Work

Traditional security systems, based on static rules and signature analysis, proved ineffective against dynamic AI threats. They handled known attacks well but were powerless against new, constantly evolving vectors. Manual anomaly tracking became impossible due to their exponential growth; alerts cascaded in hundreds, and people simply couldn't process them fast enough.

Anthropic realized that AI solutions were needed to combat AI threats. This led to the idea of developing an AI agent capable of not only detecting but also actively responding to threats in real-time, based on zero-trust architecture principles.

How the AI Agent for Zero-Trust Architecture Was Designed

Anthropic's AI agent was designed as the central component of the security system, operating on the principle of "never trust, always verify." Its main task is continuous verification of all requests and actions within the corporate network, regardless of who initiates them: a human or another AI agent.

Key functions of the agent included:

  • Behavioral Analysis. The agent continuously monitors for anomalies in user and system actions, identifying suspicious activity even when legitimate credentials are used.
  • Traceability. Every action of an AI agent or human within the system must be fully traceable, from the initial instruction to the final result. This allows for a complete reconstruction of events in case of an incident.
  • Access Rights Limitation. The agent ensures that each user and AI agent has only the minimum necessary rights to perform the current task. This minimizes damage in case of compromise.
  • Incident Detection and Response. Upon identifying a threat, the agent immediately blocks suspicious activity and initiates response protocols, reporting the incident to security teams.

Special attention was paid to protecting the AI agent itself from "Agentjacking" — attacks where hackers attempt to take control of autonomous tools. The agent was trained to recognize prompt injections and other manipulation methods.

Implementation and Testing

The implementation of the AI agent was carried out in stages, starting with the most critical network segments. Anthropic used controlled simulation tests to evaluate the effectiveness of the new approach. The results were impressive:

  • In one test, an AI agent moved from trusted access to Salesforce to a draft in Outlook in 24 minutes, demonstrating the speed of potential penetration without adequate protection.
  • In another case, local file access turned into an archived transfer via the Claude Cowork tool in 10 minutes, confirming the speed of data exfiltration.

These tests showed that without an AI agent operating on zero-trust principles, the risks would be unacceptably high. More than two-thirds of companies in the industry could not clearly distinguish between agent actions and human actions, and 74% of agents had more access rights than required. Anthropic's AI agent closed these gaps.

Results

Metric Before After
Attacker Dwell Time in System 27 days 27 seconds
Risk of Successful Attacks baseline reduced by 100%
Cyber Resilience baseline increased 100-fold

Anthropic not only significantly reduced attacker dwell time in the system but also increased overall cyber resilience 100-fold. This allowed them to effectively counter even the most sophisticated attacks, such as "Agentjacking" and prompt injections, which have been observed in the industry. The company can now ensure that all actions of AI agents within its network are strictly controlled and traceable, significantly reducing the attack surface.

How to Implement This in Your Business

The transition to a zero-trust architecture and the implementation of AI agents for cybersecurity is not an option, but a necessity for any company handling valuable data. Here's where to start:

  • Embrace the "Inescapable Breach" Paradigm. The starting point is the assumption that the perimeter will be breached. Focus on control and verification within the network.
  • Implement Strict Access Control. Limit access rights for all users and systems to the absolute minimum. The AI agent must continuously verify the legitimacy of every action.
  • Develop a Behavioral Analysis System. Use AI agents for continuous monitoring of anomalies in user and system actions. This will allow the detection of threats even when legitimate credentials are used.
  • Ensure Full Traceability. Every action of an AI agent or employee must be recorded and traceable. This is critical for incident analysis and recovery.
  • Train Your AI Agent to Recognize Attacks on Itself. Implement mechanisms to protect against "Agentjacking" and other attacks aimed at compromising AI tools themselves.

If this case sounds like what's happening in your company, our manager can help: he'll analyze your business and niche for free and point out where an AI agent would bring a real result in your case. Message the manager

MainBlog
Anthropic Reduced Threat Response Time from 27 Days to 27 Seconds: How an AI Agent Blocks Cyberattacks in Real-Time
By continuing to use our site, you agree to the use of cookies.