Jim McGann is CMO at Index Engines.gettyIn early July, researchers disclosed an attack unlike anything security teams had seen before. An AI agent carried out an entire ransomware operation without a human at the keyboard. Humans played a role in acquiring the credentials to hack into the database and directing the attack. However, the agent, later named JadePuffer, autonomously gained entry through an exposed server, harvested credentials and moved into a production database, where it encrypted more than 1,300 records. Along the way, it showed a level of autonomy that set it apart from earlier automated tools. When one exploit attempt failed, the agent corrected itself within 31 seconds and tried again, eventually repeating variations of the attack more than 600 times in a single session. What made this incident notable was not the ransom demand itself, but the fact that it could never have been fulfilled. The encryption key was generated randomly, used once and never stored or transmitted anywhere. There was no way for the attacker, or anyone else, to unlock the data. Payment would not have changed the outcome. For most of the past two decades, cybersecurity strategy has rested on a fairly simple premise: If an organization becomes effective enough at prevention, the incident never occurs. JadePuffer is a useful reminder of why that premise is incomplete, and why the gap it leaves is becoming more consequential. How AI Speeds Up Cyberattacks​Attackers have relied on trust relationships, vendor access, remote connections and partner integrations for as long as those relationships have existed. That part of the equation has not changed. What has changed is the speed at which the vulnerable pathways can be found and exploited. A skilled analyst might need days to identify and exploit a misconfigured system. An autonomous agent can attempt, fail, adjust and try again within seconds, without fatigue or hesitation. Mythos, an Anthropic model that maps and tests an environment's exposure, could help to close that gap by giving defenders faster access to finding these same vulnerabilities before an attacker does. JadePuffer went a step further, though. Beyond surfacing the vulnerabilities, it automated the majority of the attack chain. No organization, regardless of maturity, can close every point of exposure in an environment built on interconnected trust. That residual risk has always existed. AI simply narrows the time it takes to find it. This raises a more useful question for security leaders than whether every attack can be prevented. If some level of exposure is unavoidable, the more relevant measure becomes how quickly, and how confidently, an organization can recover once an incident occurs. That is not an argument for deprioritizing prevention. It is an acknowledgment that prevention alone was never going to be sufficient on its own. Data Protection In The Age Of AI Attacks​When an attack occurs, most organizations focus on a single objective: getting operations back online and minimizing the impact. Effective recovery, however, actually requires two distinct steps. The first is restoring clean data. The second is returning to operations. Too often, organizations focus on the second step and simply assume the first has already been handled by the data protection team. That assumption is where real risk hides. Most organizations maintain backups, replicas and immutable snapshots, so having a copy of the data is rarely the issue. The harder problem is data validation. Snapshots and other "protected" data are high-value targets for attackers—so in the middle of an incident, how does a team know whether a given recovery point is clean, rather than already compromised? If compromised or corrupted data is restored, the attack can be reintroduced into the environment, leading to repeat incidents, prolonged outages and greater business impact. Restoring data that hasn't been validated doesn't resolve an incident. It defers it, often resurfacing days later with less confidence and more downtime. This is the problem data integrity validation needs to solve. Through years of evaluating recovery architectures, I've found that the most effective approaches examine data at the byte level, trained continuously on real-world ransomware variants, to identify corruption and confirm which recovery point is genuinely clean before any restoration begins. Solving this requires moving that validation further upstream, into production storage itself, scanning snapshots as soon as they are created. This ensures the most recent data is also the most trustworthy, and it allows recovery to begin in seconds rather than hours.A New Measure Of Data Security ​None of this diminishes the importance of prevention. Firewalls, identity controls, and endpoint protection remain necessary investments. But prevention is fundamentally a bet against an adversary's evolving capability, and that bet becomes harder to win as AI systems continue to advance. Recovery confidence represents a different kind of investment, one grounded in an organization's own preparation rather than its ability to consistently outpace an attacker. Security teams have long measured their performance by how quickly they detect an incident and how quickly they respond to one. It may be time to add a third measure, one that captures how confident the organization is, at any given moment, that its most recent recovery point is clean. JadePuffer shows that this is no longer a theoretical concern. The organizations that can answer that question before an incident occurs, rather than during one, will be the ones best positioned to weather what comes next.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?