Driven by the rapid adoption of Artificial Intelligence (AI) in the cybersecurity industry, the speed and scale of cyberattacks continue to escalate, enabling cybercriminals to execute more sophisticated threats or scams in just a short amount of time.
This was according to Simon Green, president, Asia Pacific and Japan at Palo Alto Networks, who also disclosed that the development of ransomware, which took approximately 12 hours in 2022, has now dropped to only three hours, and by 2026, it was predicted that attacks could be launched in just 15 minutes.
Green cited a US health insurer which became a target and infected with ransomware in 2024, rendering the platform inaccessible and cost them $2-billion.
The compromise and data exfiltration time has also reduced, indicating that attackers are now able to steal data faster than before. From nine days in 2022, cybercriminals can now exfiltrate data in just one day and only 20 minutes by 2026, implying that data theft can now be done in shorter amount of time.
Related to this was the case mentioned by Green where 15-milion users’ personally identifiable information (PII) and confidential data were exfiltrated in 2024.
The speed of exploiting vulnerabilities has also reduced in time. In 2022, nine weeks were needed to exploit vulnerabilities. Now, attackers can exploit vulnerabilities in just one week, and in less than 60 minutes by 2026, which means cybercriminals are becoming effective in exploiting vulnerabilities.
Green cited the MOVEit vulnerability, a major cybersecurity accident, which led to a massive data breach affecting more than 500 organizations and over 35-million individuals globally.
Now that attacks can be done in a much shorter amount of time than before, organizations would require a robust detection and response capabilities to stay ahead of potential threats.
The cybersecurity industry is now being transformed as attackers are leveraging on AI. The number of threats or scams using AI-generated technology is increasing. Bernadette Nacario, country director at Palo Alto Networks Philippines, warned that “although the digitalization happening around us has a lot of opportunities to open, let’s also be mindful that it also brings and opens new risks and vulnerabilities.”
“In fact, there is a growing number of sophisticated threats going around. There is a need for a robust zero trust framework and it is also worth mentioning that there is a critical shortage of skills and cybersecurity professionals,” noted Nacario.
In the Philippines, only 7% of the workforce is dedicated to cybersecurity. Of these, only 13% are trained cybersecurity professionals, implying that there is so much room to be looked at to a new set of professionals who can really focus on cybersecurity.
Nacario also relayed that in the Philippines, only 10% or less than 20% of investments in most companies is being allotted on cybersecurity projects which according to her, “is very alarming.” “I don’t think that would be enough for companies to set aside as investments,” she said.
Nacario also mentioned that cybercriminals are very collaborative and are highly organized. “For us in the cybersecurity community, it is important to be equally collaborative as well, and to be organized in making sure that we know how to position ourselves. It is important that we share information, share best practices and understand the different perspectives of customers, shared Nacario.






















































































