The narrowing window

Hamish Friedlander | RUSH HoE headshot

Hamish Friedlander

Chief Information Security Officer

August 27, 2026

5 mins

I was at CIO Summit this year on a panel about how organisations scale capability with AI without losing control of it, and a lot of that comes down to data. You're the custodian of your business data, but a good chunk of it is actually your customers' data. The moment you feed it into an AI system, you need to know whether you actually have permission to do that, and what the provider does with it once it's theirs. Some AI vendors have genuinely good governance. Some are fly by night, and your data ends up wherever it feels like going. That's the boring but necessary part of scaling responsibly with AI. Your data governance needs to be mature enough to survive contact with it.

Outside of the panel, cybersecurity was also a large focus of the summit. This is something I've been living daily since taking over as CISO at RUSH. In 2024, an organisation had roughly 30 days between a vulnerability being disclosed and someone attempting to exploit it. That window is now significantly under 48 hours. My forecast is for it to shrink to under an hour within a couple of years, because at that point you're not up against a person acting on a disclosure, you're up against an agent watching the feed and moving the moment something appears.

Part of why the window is closing so fast is that AI not only finds vulnerabilities faster, but chains them. A flaw that would have sat harmless in a system a year ago can now get stitched together with nine or ten others into something serious. A human analyst might link two or three but AI doesn't have a limit.

That shift is why RUSH is making moves away from the standard model of responding to vulnerabilities after they're disclosed. Waiting for the disclosure, assessing the impact, patching on a cycle or pushing an emergency fix if it's critical is no longer fast enough given how quickly disclosure turns into exploitation. Our response is to keep every dependency current before a vulnerability is ever announced, so the fix is already shipped by the time anyone needs it.  Fortunately AI can enable the defenders as well - a combination of AI agents and specialist humans in the loop make this approach practical where it wasn’t before, at the same time as the old approach has become impractical.

Another place where  businesses are newly vulnerable is developer machines. Supply chain attacks have become common enough that what looked like a one-off incident a year or two ago is now understood as a standing weakness with no easy fix. Point solutions exist (RUSH works with Aikido on some of this), but closing the gap properly means changing developer workflow, and that has to be weighed against developer efficiency. Getting that balance right is a real focus for RUSH.

Every individual taking responsibility for security is the single habit that prevents more incidents than any tool. Security controls trade protection for friction, and the safest possible setting is also the most useless one. So organisations end up relying on people to make good calls, which means security training has to be more than something staff quickly click through to get to other work.

That matters more now because phishing has moved a long way past the obviously fake email. The progression from generic spam, then targeted requests that impersonate a CEO asking for a transfer, and now AI-generated video and voice built from a leadership team's public media appearances, asking for information only an insider should know is wild. The technical controls haven't gone anywhere. What's changed is how much they now depend on a person recognising that something's off.

[Watch the interview here.]

Arrow right