October 9, 2026
AI lets attackers move from an idea to a working attack faster than a business that waits on approvals can respond. The fix is not a bigger security budget. It is removing the delays inside your own business: deciding in advance who can act, knowing what you own, and keeping a fast lane for urgent fixes.
Security writer Daniel Miessler made this point last month in Attacker vs. Defender AI Advantage. His core observation:
"Attackers can be sloppy and fast, and defenders have to be a lot slower and more careful."
He places the blame squarely on how organizations work, not on the tools:
"This is not a fair fight in the slightest, and the root cause is beaurocratic friction, not technology."
We agree, and we think the point lands even harder for a 20-person firm in Metairie or Covington than for a large enterprise. Here is what it means for you and what to do about it.
Why speed now decides who wins
An attacker does not need a meeting, a budget line or a sign-off. With AI tools, one person can write a convincing phishing email, adapt it for your industry and test it against your staff in an afternoon. If the attempt fails, they change it and try again.
Your side of that exchange runs on a different clock. A security update needs someone to notice it, someone to approve the downtime, and someone to install it. A suspicious login needs someone to see the alert and someone with the authority to lock the account. Every handoff is a delay, and the attacker uses every delay.
Large companies slow down because of committees. Small businesses slow down for simpler reasons: the owner is the only one who can approve anything, nobody is sure who manages the firewall, or the person who knows the Microsoft 365 admin password is on vacation.
Where small businesses lose time
- Nobody owns the decision. An alert arrives and everyone assumes someone else will act.
- Nobody knows what is running. You cannot patch a laptop, server or cloud app you have forgotten about.
- Every change waits for the owner. Routine security fixes sit in an inbox until the busiest person in the company has a free minute.
- The vendor is the bottleneck. The line-of-business software vendor has to approve an update, and nobody has asked them.
- The plan lives in one head. When that person is out, the response stops.
Ener Systems' practical plan: close the gap with decisions, not tools
1. Pre-approve the urgent changes
Write down, once, which security actions your IT team or provider may take without asking first: installing critical security updates, disabling a compromised account, blocking a malicious sender, isolating an infected computer. A one-page list signed by the owner removes the wait for one busy person's approval.
2. Keep an inventory you trust
List every computer, server, network device and cloud service, with who owns it and who can administer it. An inventory turns "we think we are covered" into "we know we are covered." Our cybersecurity checklist is a good place to start.
3. Run two patch lanes
Keep your normal, scheduled maintenance window for routine updates. Add a separate fast lane for updates that fix flaws attackers are already using. The fast lane is where pre-approval from step 1 pays off.
4. Make stolen passwords worthless
AI makes phishing emails more convincing, so assume some passwords will leak. Phishing-resistant multi-factor authentication, alerts on unusual sign-ins and fast account lockout limit what a stolen password can do. We covered why attackers now log in rather than break in in an earlier post.
5. Rehearse before you need it
Gulf Coast businesses already know this habit from hurricane season: you decide the plan before the storm, not during it. Do the same for a cyber incident. Walk through one realistic scenario a year, such as "the bookkeeper's email is taken over," and time how long each step takes. The slow steps are your real risk.
6. Put your own AI use on a short leash
Your staff are almost certainly using AI tools already. Decide which tools are approved, what data may never be pasted into them, and who to ask when unsure. Our AI strategy and enablement service helps businesses set those rules without slowing people down.
The takeaway for New Orleans and Northshore business owners
Attackers have gained speed. You can get faster too, mostly by deciding things in advance. The businesses that fare best are not the ones that buy the most security products. They are the ones where the right person can act the moment something goes wrong.
If you are not sure how long your business takes to act on a security alert, that is the first thing worth finding out. A free network assessment from Ener Systems shows where the delays are, and our managed IT services are built to remove them.
Frequently asked questions
Does AI really help attackers more than defenders?
Right now, yes, in speed. Attackers can try, fail and retry without approvals. Defenders gain the same tools, but they still have to get changes through their own organization, and that is where time is lost.
Do I need new security software to close the gap?
Usually not first. Start with decisions: who may act without waiting, what you own, and a fast lane for urgent updates. Those cost little and remove the slowest steps.
What is a "fast lane" for patches?
A pre-approved path for installing updates that fix flaws attackers are already using, outside the normal maintenance schedule, without waiting for a meeting or the owner's sign-off.
Is it safe for my employees to use AI tools?
It can be, with rules: approved tools only, no client or financial data pasted into public AI services, and a named person to ask when in doubt.