Open, right now if you can, your company firewall's log of rejected connections for the past 24 hours. If it is empty, or if nobody knows where to look to find it, you already have the first answer to the question in the title: not if, but when. Somebody is already trying to get in, non-stop, automatically. The only thing that matters is whether you find out.
What "scanned" actually means
Scanning attempts and successful breaches are not the same phenomenon — the press often conflates them. Scanning is automated and universal: thousands of systems knock non-stop at every public IP address. A successful breach requires something else: a real, unpatched vulnerability, and the absence of detection that would stop it in time.
On 3 October 2025, GreyNoise reported a roughly 500% single-day increase in addresses scanning Palo Alto login portals — from under 200 to around 1,300, with 93% classified as "suspicious" and infrastructure created within the previous 48 hours. A similar pattern appeared against F5 BIG-IP devices on the very day F5 announced its own incident, 15 October 2025.
Romania's DNSC recorded approximately 27.08 million security events in 2024 — computer fraud up 40.2%, malware up 286.8%, but defacement down 45.8% and DDoS down 38.5%. The data does not show a single upward trend. It shows that some threats grow fast and others do not; what matters for a company remains whether its infrastructure can be found and used from the outside.
Vulnerability exploitation, the main entry point
Three major reports converge on the same direction, though they cannot be compared directly — they measure different data populations. The Verizon DBIR 2026 (May 2026, over 22,000 confirmed breaches, data from November 2024 to October 2025) puts vulnerability exploitation at 31% of initial access vectors, up from 20% — a 55% increase. It is the first time in the report's 19 years that exploitation overtakes stolen credentials as the main entry point.
Credential abuse fell to 13% at initial access, down from 22% — and the report explains why: it separated "pretexting" (directly manipulating a person) into a distinct vector, which pulled the figure down artificially. Counted at any point in a breach, credential abuse remains in first place, at 39%.
Mandiant M-Trends 2025, covering 2024 incidents, puts vulnerability exploitation at 33% — the fifth consecutive year as the dominant vector. IBM X-Force 2026, on 2025 data, puts it at 40%, a 44% increase over the previous year. The 31%, 33% and 40% figures are different samples — confirmed breaches, incidents investigated by one firm, telemetry from another vendor — telling the same qualitative story: exploiting an unpatched vulnerability has become an increasingly common route into a network.
The 2025 edition of the same Verizon report already showed where exploitation concentrates: the share of perimeter devices rose from 3% to 22% in a single year, more than sevenfold. Mandiant confirms the pattern with a concrete example — CVE-2023-46805 and CVE-2024-21887 (Ivanti Connect Secure), exploited as zero-days, that is, before a public fix existed. Adding access via stolen credentials (16%) and access bought from a broker (8%), Mandiant arrives at 57% of incidents starting from an unpatched vulnerability, a compromised credential, or ready-made purchased access.
The race against the clock: the defender's clock has slowed down
The 2025 DBIR measured, for critical perimeter vulnerabilities in the CISA KEV catalogue, a median time of zero days from publication to mass exploitation — practically simultaneous with the announcement. Across all KEV vulnerabilities, the median was 5 days; defenders took a median of 32 days to apply the fix.
The 2026 edition shows that this clock has not accelerated — it has slowed. Only 26% of KEV vulnerabilities are fully remediated, down from 38%. Median remediation time rose to 43 days, from 32; the median number of vulnerabilities to patch per organisation grew to 16, from 11.
How long before a new vulnerability is actively exploited? Sources disagree — Flashpoint calculates 44 days, Cybermindr around 5 — but they all show the same thing: exploitation outpaces the rate at which companies manage to apply a fix that is already available.
What AI changes on the attacker's side
The public story about AI and security has fixed itself on flawlessly written phishing — the visible part, but the less important one. On 13 November 2025, Anthropic disclosed GTG-1002, a cyber-espionage campaign attributed with high confidence to a Chinese state-sponsored group and detected in September 2025. It targeted around 30 organisations in technology, finance, chemicals and public administration — of which only a few were actually compromised.
The Claude Code model, orchestrated through MCP servers (a protocol through which AI directly commands other tools, with no human operator), executed 80-90% of the tactical activity — reconnaissance, vulnerability testing, lateral movement — with human intervention at only 4-6 critical moments. Anthropic acknowledges the limits: the model sometimes hallucinated credentials or data that, once verified, turned out to be public.
The scepticism deserves mentioning. Anthropic published no technical indicators of compromise, and BleepingComputer received no response to its requests for details. Yann LeCun, then at Meta, wrote on X that such studies pursue "regulatory capture" — regulating the market in favour of the large players. The publication coincided with a 13 billion dollar funding round. The event was reported, that much is certain; the actual autonomy of the AI component remains contested.
CrowdStrike reports, in its Global Threat Report 2026 — its own telemetry — a "breakout" time (from initial access to lateral movement) of 29 minutes in 2025, with a record of 27 seconds, and an 89% increase in the activity of "AI-enabled" adversaries, among them FANCY BEAR. IBM X-Force suggests a link between the 44% rise in exploitation and AI-accelerated vulnerability discovery — a correlation, not a demonstrated causality.
The central argument is not about the quality of a phishing email but about the economics of attack. Choosing a target used to be a costly human decision — and that cost was, in practice, your implicit defence. The available data shows a direction, not a complete certainty: when reconnaissance and exploitation become parts of an automated pipeline, the cost of being chosen as a target falls.
Your company is no longer chosen by a person. It is just a row in an automatically generated list, re-checked every few minutes.
AI can work for you too
The same technology does not work only for attackers. According to the IBM Cost of a Data Breach Report 2025, companies that extensively use AI and automation in security had an average breach cost of 3.62 million dollars; those that do not, 5.52 million — a difference of 1.9 million. The average time to identify and contain fell to 241 days, the best result in nine years; extensive AI users cut a further 80 days off it.
The same source warns about "shadow AI" — unauthorised AI tools used by employees without the IT department's knowledge — which adds an average of 670,000 dollars to the cost of a breach. AI reduces risk only when it is deployed deliberately, not when it creeps in unnoticed.
Size no longer protects you operationally — and protects you less and less contractually
The figures above come largely from reporting dominated by large organisations. The DBIR 2026 answers directly whether they also apply to a mid-sized company: among ransomware cases where the organisation's size is known, roughly 96% of victims were "small business" — under 1,000 employees in Verizon's definition, broader than what we mean by "SME" in Romania. In opportunistic ransomware, victims were compromised through credentials (38%) or unpatched perimeter vulnerabilities (29%).
ENISA Threat Landscape 2025 (July 2024 – June 2025) puts ransomware at 81.1% of EU cybercrime incidents, with Akira, SafePay and Qilin leading among the 82 active variants. Crime has industrialised through Ransomware-as-a-Service — SMEs are targets with value of their own, not collateral victims (European DIGITAL SME Alliance). A 2025 Sophos survey shows, for companies of 100-250 employees, an average recovery cost of 638,536 dollars, excluding any ransom. DNSC publishes no comparable breakdown for Romania.
Since 2025, a stricter legal framework has settled over this picture. NIS2 was transposed in Romania through OUG 155/2024, with DNSC as the authority: initial warning within 24 hours, interim report at 72, final report at 30 days. Micro-enterprises under 50 employees are generally exempt in law — but remain under contractual pressure if they supply services to larger clients. The DORA regulation, in force since January 2025, directly binds IT service providers to EU financial institutions, regardless of size. GDPR remains applicable in parallel — the obligations stack.
What to do concretely, starting Monday morning
The list below covers the points where the two races described above are won or lost: applying fixes, and detecting an intrusion, now measured in minutes.
- 1Build the real exposure inventory — what actually answers a query from outside, not what someone remembers. The Shadowserver Foundation provides free daily reports for your own IP range (shadowserver.org); CISA has a similar service, but reserved for the US.
- 2Close everything that has no business reason to be public, then treat the perimeter — firewall, VPN, gateway — as the priority. Their share of exploitation rose more than sevenfold in a single year.
- 3Enable multi-factor authentication (MFA) on all exposed access points — one of the cheapest barriers against stolen credentials.
- 4Segment the network — separate IT from production systems, isolate public services into their own zone. Limit what an attacker can do after a first intrusion.
- 5Invest in detection, outsourced to a cybersecurity partner if you have no team of your own. With a breakout time under 30 minutes, a manual reaction rarely arrives in time any more.
- 6Apply the 3-2-1-1-0 backup rule — three copies, two different media, one offsite, one immutable or offline, zero errors in quarterly restore tests. Today's ransomware actively targets backups.
- 7Write and test an incident response plan — who decides to isolate a system, who informs management and clients, and within what timeframe.
Conclusion
Nothing you have read here is a reason to panic — it is a reason for proportion. Automated scanning is universal and has nothing to do with how interesting your company is; all that matters is what part of it can be found and used from the outside. AI appears to have lowered the cost of choosing a target, even if the exact degree of autonomy remains contested. The same technology lowers, on firmer data, the cost of early detection for those who use it deliberately. The difference between a managed incident and a crisis remains, almost always, the same: how small your exposed surface is and how quickly you find out. The first step costs nothing: by Monday morning, ask your IT team for the complete list of everything that currently answers a request coming from the internet. If you want to go through it together, let us talk for 30 minutes.
Sources
- GreyNoise — analysis of scanning against Palo Alto portals and F5 BIG-IP devices, October 2025 (greynoise.io)
- National Cyber Security Directorate of Romania (DNSC) — Romania cybersecurity statistics 2024 (dnsc.ro)
- Verizon — Data Breach Investigations Report (DBIR) 2026, May 2026, and the 2025 edition (verizon.com/business/resources/reports/dbir)
- Mandiant (Google Cloud) — M-Trends 2025 (cloud.google.com/security/resources/m-trends)
- IBM — X-Force Threat Intelligence Index 2026 and Cost of a Data Breach Report 2025 (ibm.com/reports)
- CISA — Known Exploited Vulnerabilities (KEV) Catalog (cisa.gov/known-exploited-vulnerabilities-catalog)
- Anthropic — "Disrupting the first reported AI-orchestrated cyber espionage campaign", 13 November 2025 (anthropic.com)
- CrowdStrike — 2026 Global Threat Report, 24 February 2026 (crowdstrike.com/global-threat-report)
- ENISA — Threat Landscape 2025, October 2025 (enisa.europa.eu); European DIGITAL SME Alliance (digitalsme.eu)
- Sophos — State of Ransomware 2025 (sophos.com); Flashpoint (flashpoint.io) and Cybermindr (cybermindr.com) — average time to exploitation
- Shadowserver Foundation — free exposure scanning and reports (shadowserver.org)
- OUG 155/2024 (NIS2 transposition in Romania); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR)