The moment an organisation's board starts asking how to prepare for autonomous AI attacks, the conversation has already shifted. What used to be a theoretical briefing topic is now a line item in risk registers and a direct question landing on CISOs' desks from the C-suite.
Shachar Hirshberg and Dan Shiebler, co-founders of Artemis Security, an AI-Native Protection Platform for security operations, in production at Mercury, Lemonade, Wix, Upwork, and some of the largest enterprises in the world, have that conversation daily.
Artemis raised $70M in series A, led by Felicis with First Round Capital and Brightmind Partners doubling down, alongside top VCs including Theory Ventures, Lockstep, Two Sigma Ventures, and prominent cybersecurity industry leaders, including the founders of Abnormal AI and Demisto, the former CEO and CTO of Splunk, and senior executives from CrowdStrike, Palo Alto Networks, Microsoft, and Okta.
In a recent episode of the Security Strategist Podcast with host Richard Stiennon, Hirshberg and Shiebler laid out the strategic reality with unusual clarity, not as a product pitch, but as a candid assessment of where the threat environment stands and what it demands from security leadership.
The Economics of Attack Have Changed
The foundation of legacy security architecture rests on an assumption that no longer holds: that launching a sophisticated, targeted attack is expensive. Acquiring intelligence on a specific organisation, crafting adaptive exploits, and manually steering a multi-stage breach required time, skill, and resources. Defenders could lean on that cost. Understand attacker behaviour, get ahead of their patterns, and you impose meaningful friction.
Shiebler identifies this as the core structural failure of traditional approaches today.
"AI really changes that. It's so much easier for attackers to craft new attacks, to explore different strategies, and make it much cheaper to send out radically different, really sophisticated attacks, which really means that trying to rely on approaches that involve just understanding attackers and trying to stay ahead of that is very, very challenging."
The consequence is not simply faster attacks. It's the collapse of the distinction between opportunistic, broad-based threats and sophisticated targeted campaigns. What previously required nation-state resources or advanced persistent threat infrastructure can now be approximated by an attacker with limited technical knowledge and access to capable agentic tooling.
The MTTR Calculation
Hirshberg frames the urgency in operational terms. The industry benchmark for mean time to respond sits at roughly four hours. The top 0.1 per cent of security operations globally measure in minutes. The frontier measures in seconds and adversaries are already in seconds.
"We are still talking in hours and need to bridge that gap because we will live in an era where it will have a hundred real zero days every single day in every organisation. If you're measuring your MTTR in hours and you have a hundred real attacks per day, you are fully overwhelmed with traditional tooling."
The arithmetic is unambiguous, and no staffing model resolves it. No incremental tooling investment closes it. It requires a categorical shift in how detection, investigation, and response are architected, moving from human-executed to human-guided autonomous response.
The Defender’s Unused Advantage
Underneath the operational urgency Hirshberg and Shiebler describe, sits an architectural premise about how Artemis is built. In an AI era, both sides draw on the same technology. Whatever edge the defender once held in raw capability is gone. What remains, and what the attacker cannot acquire from outside, is knowledge of the defender's own environment. Who works where. What is normal for this user? Which systems matter to the business? Whether a 3 a.m. login is routine or the first in this person's history. That knowledge has always existed. What has never existed is a security platform that could assemble it, keep it continuously current, and detect against it at machine speed.
Artemis is built around that advantage. The company calls it Environment Intelligence, and the practical effect for the security team is a qualitatively different output. Where most platforms produce alerts that an analyst then has to investigate, Artemis produces decision-grade cases: findings that arrive ready to act on.
The Strategic Cybersecurity Imperative
Hirshberg and Shiebler are blunt on timing, and it is the part that leaders miss. Deploying the technology is the fast part: Artemis connects in under an hour and produces real cases within 48 hours. The slow part is organisational: governance, and process maturity for a human-supervised AI to act at machine speed. That work compounds in months, not weeks. Organisations starting now will be operating in the new model when the threat tilts.
For more information on this, visit https://artemissecurity.com/ or connect with the guests:
Shachar Hirshberg | LinkedIn | Co-Founder and CEO Artemis
Dan Shiebler | | Linkedln | Co-Founder and CTO Artemis
Takeaways
- AI transforming cyber operations
- AI-driven attacks and defense
- Limitations of traditional security architectures
- How Artemis Is Shaping Autonomous Cyber Defence
Comments ( 0 )