Attacks at machine speed demand defense at machine speed

Rodrigo Jorge · Published October 9, 2026, at 12:05 a.m. (Brasília time, UTC-3).

When an attack keeps moving while defense waits for approval, the queue becomes part of the risk. IA×IA was created to explore how to close that gap.

An alert can arrive in seconds while the response takes hours. In between, someone has to gather information, assess the impact, find the person responsible, and get approval to act. Each step may make sense. The problem is how much time they take together.

The attacker does not have to wait for that process to finish.

Scripts, bots, and exploitation tools have automated attacks for years. AI agents can add the ability to interpret context, test hypotheses, and adjust their approach as they run. That does not make every attack autonomous or every attacker capable. It does, however, expand the work a single person can set in motion.

As a CISO, the question I care about is operational: when an attack can advance between two of our decisions, what needs to change on defense?

The response window matters

Cloudflare reported a 31.4 Tbps DDoS attack that lasted 35 seconds in 2025. Detection and mitigation were automated. Within that window, a team could not investigate every event, open a ticket, and approve the response.

The case shows why some actions need to happen automatically. It does not show that the mitigation used language model agents. That distinction matters: the technology should fit the task, the time available, and the risk of an error.

A rule can block a known pattern. A specialized system can absorb a DDoS attack. An agent can investigate scattered signals when a decision requires context. The challenge is to identify where each approach works and verify the result.

Authorize in advance, monitor in real time

For an automated response to work, some decisions need to be made before the incident: which signals justify action, which targets are protected, what scope is permitted, and when to stop or ask for help.

Temporarily blocking an IP address and disabling a privileged account require different levels of authority. Even a reversible action can cause harm before it is undone. Speed therefore needs limits and a path to recovery.

People remain responsible for those choices and for exceptions. Case-by-case approval belongs where the impact or uncertainty warrants it. For delegated actions, the team needs to monitor errors, review evidence, and be able to reduce autonomy.

Cyberbot illustrates a concrete workflow. It analyzes traffic that has passed through the WAF and can block at the edge after filters and deterministic controls. The case reports less than a minute from log entry to block. It is an implementation worth studying, with its own limits, not a promise of performance in every environment.

View the diagram: authorize first, respond as events unfold. A conceptual workflow, not measured timings.

Why IA×IA exists

The project began as a talk. Someone attended, put the idea into practice, and built Cyberbot. That feedback prompted me to turn the talk into a guide: document the design, the controls, and the open questions so other teams can assess what is worth adapting.

I want IA×IA to be useful to people making decisions while running a real operation. It should help them identify a task, understand the data it requires, define the action's scope, and measure whether the change improved the response. It should also help them conclude that a simple rule is enough, or that there is not yet enough evidence to delegate.

That is why the guide is public, free, and has no commercial affiliation with a solution vendor. The cases describe reported implementations; the playbooks offer proposals to test. Their labels preserve that distinction.

The name IA×IA expresses the question behind the project: how can we use AI in defense against the capabilities it brings to an attack? The answer needs to show up in operations: less waiting where delay increases risk, decisions we can verify, and the ability to restore service when something goes wrong.

References

Open this article in your AIChatGPTClaudePerplexityCopilotGrok
Want to see this applied?

Explore reported production implementations in the success stories, or adapt a proposed architecture from the defense playbooks.