Opinion: The New Economics of Cyber Offense
What happens to cyber weapons companies, offensive research, and attack forces when the scarcity the market was built on begins to shift?
The Central Claim
Thesis
The offensive advantage is gradually shifting from an arsenal of tools to a continuous capability to produce a path to the desired effect.
Introduction
What will a cyber weapons company sell ten years from now?
At first glance this sounds like a question about technology. To me, it is first and foremost a question about economics.
For years, a significant part of the economy of offensive cyber has rested on scarcity. Quality vulnerability research demanded excellent researchers, time, money, and experience. A reliable exploit was hard to develop. A useful zero-day was an asset you could hold, deploy, and sometimes reuse across a meaningful window of time.
Around that scarcity, entire structures were built: research teams, brokers, commercial surveillance companies, state capabilities, and a whole market.
But what happens when the cost of part of the discovery process drops, the pace of research rises, and the side that builds and defends the product gains exactly the same leverage? What happens if a capability that was once rare becomes partly industrialized, while the vulnerabilities that truly remain out of reach of automation become rarer still?
I do not think we are heading toward a world without vulnerabilities. The data does not support that. Nor do I think we are heading toward a simple world of “AI versus AI”, where humans exit the game and offensive cyber comes to an end. I think something less dramatic in the headline, but far deeper strategically, is taking place: the economics of attack are changing.
The Zero-Day Is Not Dead
It is worth starting precisely with what is not happening. Zero-days are not disappearing. Google’s Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in the wild during 2025, compared to 78 in 2024. Google describes the last few years as a range that has roughly stabilized between 60 and 100 exploited vulnerabilities per year. Almost half of the zero-days observed in 2025 hit enterprise technologies, a record both in absolute number and as a share of all observed vulnerabilities. 1
The claim that “soon there will be no vulnerabilities” simply does not match reality on the ground. Systems grow more complex, attack surfaces shift, new code is written all the time, and components, identities, infrastructure, and trust relationships keep creating opportunities.
What does change is where the adversary looks for value. Google points to a significant drop in browser exploitation and a rising focus on enterprise technologies, edge devices, and security and network products. When mitigations make a given path harder, the adversary does not stop being an adversary. It changes target, extends the chain, or looks for a different attack surface. 1
What Actually Breaks in the Equation?
The scarcity that was tied to research is starting to shift. Not all research, and not in every domain, but enough to change the economic question.
In DARPA’s AI Cyber Challenge, autonomous systems analyzed more than 54 million lines of code. In the final, they identified 86% of the synthetic vulnerabilities, patched 68% of the vulnerabilities they found, and additionally discovered 18 real vulnerabilities that had not been planted in the competition. The average cost per competition task was about $152, and patches were submitted within 45 minutes on average. 2
These are not numbers that prove a machine can replace vulnerability research. They do prove that part of the work once identified with expensive human expertise can be carried out at a completely different pace and cost.
And it happens on both sides of the equation. The same capability families can serve an attacker to accelerate reconnaissance, vulnerability discovery, and exploit development, but also a vendor to find and fix vulnerabilities earlier, including before the code ever reaches customers. Google already describes this shift explicitly as a race in which the times to discovery, exploitation, and remediation keep shrinking. 3
The question, then, is not whether there will be vulnerabilities. The question is what happens to the economic value of a vulnerability when the cost of searching for it drops for both sides, and when the ability to produce and to close capabilities can operate at a pace that was not possible before.
"AI Only Finds What It Was Trained On" - Not Exactly
In the discussions I have had around this topic, one claim kept recurring: a model can only find vulnerabilities of the kind it was trained on. It is an intuitive claim, but in the sense in which it is usually stated, it is no longer true.
The public record already shows otherwise:
- Project Zero and Google DeepMind reported in 2024 on Big Sleep, an agent that found a new, previously unknown memory-safety vulnerability in SQLite. 4
- DARPA reported 18 real, non-synthetic vulnerabilities discovered during AIxCC, none of them planted for the competition. 2
- Anthropic reported in February 2026 on finding high-severity vulnerabilities at meaningful scale. Its Coordinated Vulnerability Disclosure dashboard recorded about 2,300 vulnerabilities disclosed across 392 open-source projects, as of August 26, 2026. 5
Novel discovery does not mean general vulnerability research. The fact that a model can find a new vulnerability does not mean it can find every vulnerability, understand every system, produce every primitive, or build an operational exploit chain. In fact, Anthropic itself showed in early 2026 that the gap between finding a vulnerability and reliable exploitation is still large: in an experiment on Firefox, Claude managed to turn a vulnerability into a working exploit in only two cases out of hundreds of attempts, and even then in a test environment where some of the protections of a modern browser had been removed. 6
The important point is a different one: “the model only reproduces vulnerabilities it saw in training” is no longer an adequate description of the capability. There is public proof of novel vulnerability discovery. At the same time, there are very significant limits to what these systems can do. Both facts can be true at the same time.
Maybe Research Does Not Disappear. Maybe It Polarizes.
This is where the discussion gets more interesting. If part of vulnerability discovery becomes cheaper, faster, and more industrial, it does not necessarily follow that the human researcher loses value.
The opposite may happen at the top end of the market.
Heard in a discussion
"If I find a zero-day that even these systems did not find, why would I share it?"
This is not yet a measurable fact, but an economic thesis. Still, it is worth thinking about. Imagine a vulnerability that survived a secure SDLC, fuzzing, static analysis, code review, human researchers, and automated systems capable of scanning code at enormous scale. If a researcher still manages to find it, they may not be holding “another zero-day”. They are holding an asset that passed through a far denser filter.
So I think research may polarize. On one side, a growing layer of vulnerability discovery turns into a commodity. On the other, frontier research, the ability to find what remains after automation, may become rarer, more secret, and more expensive.
This is also the place not to write off specialists. Quite the opposite. An extreme specialist who can solve a problem that the tools, the models, and most researchers cannot may become an even more significant strategic asset. The erosion is likely to happen precisely in the middle: in the work, a growing share of which can be accelerated, replicated, or automated.
So What Happens to a Cyber Weapons Company's Business Model?
Google already describes a commercial surveillance industry that does not sell just a single exploit. These commercial solutions can bundle an exploit chain, spyware, and the infrastructure needed to reach the desired information. Google calls these turnkey espionage solutions. 7
And that matters, because the evolution has already moved from bug to capability.
In the activity documented around Intellexa and Predator, too, you can see the importance of delivery, infrastructure, and shifting infection vectors. Amnesty International reported on the development and use of vectors based on the advertising ecosystem, and assessed that such methodologies may grow as genuine zero-click becomes more expensive and harder to obtain. 8
The market is already teaching us that the customer does not buy a CVE. They buy a capability.
But I think the next stage may run deeper.
From Product to Effect
If a rare capability becomes more expensive to maintain, if shelf life is no longer a given, and if part of the basic research becomes cheaper, then perhaps it is no longer as worthwhile for the weapons company to hand the asset over to the customer at all.
Perhaps the customer of the future will not buy “the next Pegasus”. Perhaps they will not even want to know which exploit was used, which implant, which delivery vector, or which researcher.
They will arrive with a question: “I need to know X”. Or with a need: “I need to reach Y”.
And the supplier will be responsible for everything in between.
I present Adversary as a Service as a strategic hypothesis, not as a description of an existing business model or a regulatory recommendation. Moving from selling a product to operating a capability on a customer’s behalf raises heavy questions of sovereignty, accountability, oversight, attribution, defense export, and international law.
But that is exactly what makes it interesting: economically, it solves a real problem. The supplier can:
- keep the rare IP in house,
- reuse capabilities without handing them over,
- and assemble, for each mission, the right set of research, intelligence, infrastructure, access, and experts.
This model is not entirely imaginary in terms of market structure, either. Google has previously distinguished between commercial surveillance vendors that sell customers a capability to operate, and hack-for-hire firms that carry out the attacks themselves as a service. 9 The hypothesis here is that the line between these worlds may become more strategic as the economics of the exploit change.
This Is Not Only About Commercial Companies
The same question should occupy militaries, intelligence organizations, and state cyber forces.
If in the past an advantage could be measured largely through the number of researchers, the quality of the research, and the size of the arsenal, then in a world where part of the technical capability becomes more available and cheaper, that metric alone becomes less sufficient.
A state has something that most pentest companies do not: a combination of cyber, intelligence, HUMINT, SIGINT, physical access, infrastructure, authorities, time, and the ability to build an operation around a target. As the basic technical layer becomes more accessible, it is precisely the integration of all these capabilities that may become the strategic differentiator.
The advantage is not necessarily “I have the best RCE”. The advantage is the ability to take a target, understand the constraints, choose the right combination of capabilities, and keep producing a path even when the first path closes.
Google already describes this kind of adaptation at the threat level: improved mitigations on mobile and in browsers push attackers to extend chains, change techniques, and turn to other targets. 1 This does not prove how a future military will be built, but it illustrates a basic principle of an adversary: it is not loyal to a tool. It is loyal to the goal.
What About Pentest?
Here I prefer to leave a question mark.
Pentesters already use models routinely. There is enormous investment in agents, autonomous pentesting, and cyber reasoning systems. Part of the work that used to be manual is becoming faster, and another part will probably undergo deep automation.
But there is still a distance between a system that can carry out a sequence of technical actions and something you can hand a complex scope and tell: “really try to break this thing, work out for yourself what matters, change strategy when needed, and come back with meaning”.
So I do not know whether the job called pentester will look the same a decade from now. It may shrink, split, or change character entirely. What I do think is that as the techniques themselves become more accessible, the value moves from the ability to perform a technique to the ability to choose, combine, and invent a way.
But something is easy to miss in the noise: as of now, the market is not behaving as if the role is dying. CyberSeek data published in mid-2025 showed 514,359 open cybersecurity positions in the United States, a 12% increase over the prior period, with penetration tester among the most frequently listed roles. 11 That does not mean the number stays. But it is a data point that deserves weight.
And here lies a nuance that does not get enough attention: the main near-term risk to offensive roles may not be AI itself. It may be decision-makers who do not understand how it is built. An executive who watches a demo of an AI agent running a scan and concludes that pentesting is solved is not making a technical judgment. They are making a budget decision based on a misunderstanding. Only 12% of security professionals believe their role will be completely replaced by AI. And organizations that adopted AI automation in security reported spending more time on additional cyber projects, not less. 76% of them, according to EY. 12 The tool changes the work. It does not erase it.
The risk is not that AI replaces the pentester. The risk is that someone with budget authority believes it already has.
The Generalist and the Specialist Are Not Fighting Over the Same Spot
This leads to a professional question that interests me in particular: which kind of offensive person will hold the highest value?
I do not think the answer is “only a generalist”. Nor is it “only a specialist”.
We may see two ends growing stronger. At one end, a deep specialist capable of frontier research where automation stops. At the other, a generalist capable of taking a target, constraints, and a vast range of capabilities - web, cloud, identity, mobile, infrastructure, social, research, intelligence, and automated tools - and combining them into a route that produces an effect.
The middle, then, may erode while the two ends grow stronger.
From Assessment to Adversary: Why I Am Leading the Move to EAF
This shift also connects to a strategic move I have been leading recently: a transition from a point-in-time view of offensive activity to an Enterprise Adversary Force (EAF) model.
To me, EAF is not “a stronger red team”, and it is not an attempt to add another tool to the box. The change is in the unit of thinking: from the ability to run an assessment to the ability to sustain an adversary.
An assessment usually starts with a scope, a methodology, and a defined deliverable. An adversary starts with a goal. It is not committed to a particular technique, tool, or exploit:
- If one path closes, it looks for another.
- If the existing capability is not enough, it develops capability.
- If information is missing, it collects it.
The test is not whether a given technique was executed, but whether the adversary managed to produce its effect under the constraints that reality imposed.
In a world where tools and techniques change faster, this is, to my mind, a more important organizational capability than maintaining a particular toolset. The point is not to build a force around what it can run today, but around its ability to keep being an adversary tomorrow.
This is why I struggle with the popular prediction that the future is simply “AI versus AI”.
It reduces an attack to a technical problem. But a real attack is not just finding a vulnerability and running a payload. There is a target, an intent, intelligence, risk, time, limits, people, decisions, and an effect you are trying to achieve. Even if autonomous systems carry out a growing share of the technical actions, someone still defines what matters, what price is acceptable, when to change path, and what even counts as success.
AI is an enormous change in the toolbox. It is not the whole story.
And it is certainly not proof that we are approaching a world without hackers. It may actually force us back to a more basic definition of a hacker.
Definition
A hacker is not someone who knows how to use an exploit. A hacker is someone who can produce impact under constraints.
The New Economics of Cyber Offense
I have no way to know whether, a decade from now, weapons companies will actually move to Adversary as a Service, whether the zero-day will become an uneconomical product in every market, or whether pentesting will disappear. None of that is settled.
But there are enough signs to ask the questions now:
- The cost of part of the research is changing.
- Automated discovery of new vulnerabilities is no longer a theoretical scenario.
- Vendors are gaining a better ability to find and fix.
- Exploit development, too, is starting to enter the range of what models can do, even if it is still far from full autonomy.
And in parallel, attackers keep adapting, shifting attack surfaces, and combining more components to reach a target. 1236
But there is a real possibility that some of this shifts back. The Gartner Hype Cycle for Security Operations 2026 already places AI SOC Agents at the Peak of Inflated Expectations with only 1-5% market penetration, while Cybersecurity AI Assistants, which were at the peak just a year earlier, have already slid into the Trough of Disillusionment. The same report warns about “AI washing” four times and advises buyers to demand independent benchmarks before signing contracts. 13
Hype cycles do not predict the future. But they remind us that markets overshoot before they correct. It is entirely possible that in a few years the noise settles, the capabilities that actually work are absorbed into standard workflows, and the industry reaches a new equilibrium that looks more like evolution than revolution. Maybe some assumptions that are currently treated as inevitable turn out to be premature. Maybe some things that have not surfaced yet change the picture entirely. That, too, is part of the economics.
So the question that interests me is not whether offensive cyber will die.
The question is what the offensive asset will be when the tools themselves become more available.
Perhaps, a decade from now, the most important weapons company will not be the one holding the most zero-days. And perhaps the strongest state force will not be the one holding the most researchers.
The advantage may belong to whoever you can hand a target, constraints, and a desired effect - and who will still find a way.
What This Means for the Other Side
This article has been about offensive economics. But you cannot talk about economic shifts on the offensive side without asking what it means for the other side. When the cost of attack drops, the attack surface expands, and capabilities become more accessible - a defense built for a different world will not hold.
The numbers already tell this story. The average SOC generates 4,330 alerts per day. Analysts investigate only 37% of them - meaning two out of three alerts disappear without anyone even looking at them. 46% of all alerts turn out to be false positives. And 71% of SOC analysts report burnout caused directly by alert overload. 15
On the other side of the equation: the average damage to a breached organization in 2024 reached $4.88 million, an all-time high. A phishing kit on the dark web costs as little as $25. A basic RaaS program - under $100. The gap between what an attack costs to launch and the damage it can cause spans orders of magnitude. And the number that should worry the most: 241 days on average from breach to identification and containment. 14
And there is a deeper structural problem: a global shortage of 4.76 million cybersecurity professionals, with demand at 10.2 million against a workforce of only 5.5 million. 16 Even if there were enough tools - there are not enough people to operate them.
AI in Defense: The Promise, the Reality, and the Trap
AI does help on the defensive side, and there are numbers to back it up: organizations that adopted AI and automation in defense save an average of $1.88 million per breach, identify and respond roughly 100 days faster, and pay $3.84 million per breach compared to $5.72 million in organizations without AI. 14
But as I wrote above, Gartner already places AI SOC Agents at the Peak of Inflated Expectations with only 1-5% market penetration, while Cybersecurity AI Assistants have already slid into the Trough of Disillusionment. 13 And this is not just a hype problem.
Earlier I wrote that I struggle with the prediction that “AI versus AI” is the future, because it reduces an attack to a technical problem. The same argument applies to the defensive side, but for an additional reason: “AI versus AI” is not a symmetrical game.
The offense is growing faster than the defense. Phishing attack volume rose 1,000% between 2022 and 2024, with 82.6% of phishing emails already using language models and achieving a 54% click-through rate, compared to 12% for traditional phishing. But it is not just emails. AI-powered voice phishing attacks surged 442% in 2024. 85% of organizations reported deepfake incidents in the past year - from voice impersonation of a CEO to real-time video manipulation in live calls. And attackers are already generating custom malware built specifically to evade an organization’s defensive models. AI lowers the barrier to entry for attacks and raises the bar for detection, and both of those things are happening at the same time. 19
Beyond volume, there are structural problems that AI in defense does not solve.
First, adversarial ML: defensive models can be bypassed. An attacker who understands how a model works can make nearly invisible changes to input that cause it to miss. The defense you built today is tomorrow’s attack surface.
Then there is a problem I keep running into in the field: detecting is still not responding. AI can identify. Someone still has to decide what to do about what was identified. And when there are thousands of alerts a day, most of them false positives, more detection does not necessarily mean more security.
And underneath all of this sits an asymmetry that no technology changes: the attacker needs to succeed once. The defender needs to succeed every time. AI accelerates both sides, but the side that needs to be perfect still needs to be perfect.
Insight
Adding AI to the defensive side does not solve the problem. It accelerates the race. And if you are running in the wrong direction, running faster does not help.
Prioritization as a Core Defensive Capability
If you cannot defend everything at the same depth, you have to choose what to defend. And that does not mean giving up - it means stopping the waste of energy on things that do not actually matter.
Gartner predicts that organizations adopting Continuous Threat Exposure Management (CTEM) - a framework that prioritizes exposures by business impact rather than technical coverage - will achieve a two-thirds reduction in breaches. 17 NIST added “Govern” as a new foundational function in Cybersecurity Framework 2.0, anchoring risk management in organizational context and requiring prioritization before coverage. 18
The idea is not new, but most organizations still fail at executing it: identify the crown jewels - the assets that are truly critical to the organization - concentrate the bulk of defensive pressure there, and accept that not everything gets the same level of protection. Red teams already build exercises around crown jewels and analyze specific attack paths to those assets, instead of testing for general coverage.
This requires a shift in the question the CISO asks themselves. Not “how much coverage do we have?” but “are the assets that actually matter protected enough?”. It echoes what I described on the offensive side - the move from performing an action to producing an effect. Same principle, other side of the fence.
In the end, the organizations that will make it through this period are not the ones that bought the most tools or deployed the most AI. They are the ones that sat down, did the unglamorous work of asset mapping and prioritization, and figured out what is actually worth defending - and where they can afford to take a risk.
The bottom line
Tools change. Exploits die. Paths close. The adversary remains.