Shifting the Balance: How Frontier LLMs Transform Risk
Download resourcesAbout this session
Sean Flynn, Akamai's Director of Security Strategy, argues frontier AI attack agents (citing Anthropic's Claude/Mythos and OpenAI's GPT-5.5 Cyber) have crossed an 'event horizon': in cited tests they found a 27-year-old OpenBSD bug and an FFmpeg flaw that five million fuzzing runs missed, chain low-severity issues into working exploits, and, per a UK AI Security Institute test, breached a mature environment 72.4% of the time versus 14.4% for the prior model generation, while blending into normal user traffic and credentials. Because manual patching (about 168 days) and even AI-assisted patching (about 24 hours) cannot outrun exploit generation measured in minutes, and because likelihood of breach can no longer be driven toward zero, he argues security must shift from perimeter prevention to controlling impact: application-layer micro-segmentation that contains blast radius, ship-bulkhead style, rather than legacy network-level VLAN segmentation. He details virtual patching (temporary ring-fencing of a vulnerable service), dependency and traffic-history mapping, human-in-the-loop AI policy recommendations, and ring-fencing MCP servers and AI agents with unique identities against 'tool chaining'. Audience questions cover the AI attack-defense arms race, Canadian cyber-insurance premiums tied to micro-segmentation, and attackers increasingly mimicking human behavior and targeting organizations' own AI agents.
As AI accelerates the pace of both business and breaches, the security landscape has hit a critical 'Event Horizon' where traditional defenses are failing. Attackers now move at machine speed, using AI to compress the time-to-exploit from months to just hours, a pace that human-led patching simply cannot survive. Because perimeter defenses can no longer stop every unknown vulnerability, the focus must shift from pure prevention to controlling the outcome. In this talk, we explore how to move beyond the fear of 'Shadow AI' and lateral movement by adopting a strategy of resilience. By implementing micro-segmentation and AI-driven protection, organizations can visualize their true blast radius and instantly contain threats at the source, ensuring that an initial breach doesn't disrupt the entire business.
What the Audience Can Expect to Hear
• The Collapse of Time: How AI-driven attacks have shrunk the window for reactive patching from years to a matter of hours.
• Smarter Lateral Movement: Insights into how attackers now chain 'low-risk' issues to move undetected through a network.
• The Shift to Containment: Why CISOs must prioritize measuring exposure and 'blast radius' over traditional entry-point protection.
• Automated Resilience: How to use AI-driven policies to create 'digital moats' and implement virtual patching for instant quarantine.
• Protecting the New Crown Jewels: Strategies to secure AI workloads and APIs that have become the primary targets for modern exploits.
Key takeaways
- Stop treating low-severity findings as low priority: frontier AI attack agents chain multiple 'low' issues into a working exploit chain, so triage has to account for combinations, not just individual severity scores.
- Assume the likelihood of an initial breach can no longer be pushed toward zero against AI-driven attackers; shift investment from pure perimeter prevention to controlling the impact (blast radius) of a breach that does get through.
- Move from legacy network-level (VLAN/firewall) segmentation to application-layer, host-based micro-segmentation so policies stay identity- and process-aware and travel with workloads into the cloud.
- Use virtual patching, temporary ring-fencing of a known-vulnerable service or process, to buy time when you cannot patch every affected server immediately (the speaker's example: a MOVEit-style vulnerability across many servers).
- Give AI agents and MCP servers their own unique identities and ring-fenced policies so an attacker who compromises one approved tool cannot use 'tool chaining' to reach others it was never meant to talk to.
Speakers

Sean Flynn is a seasoned cybersecurity strategist, serving as Director of Security Strategy and Technology at Akamai Technologies. With over 16 years of IT security experience, Sean leverages his expertise to ensure Akamai’s security vision aligns… Read moreRead less
Sean Flynn is a seasoned cybersecurity strategist, serving as Director of Security Strategy and Technology at Akamai Technologies. With over 16 years of IT security experience, Sean leverages his expertise to ensure Akamai’s security vision aligns with industry trends and customer needs. Since joining Akamai in 2012, Sean has been at the forefront of implementing solutions to defend enterprises against state-sponsored actors, hacktivists, and cybercriminals. He has consulted with leading organizations in finance, commerce, and healthcare, offering tailored application, network, and enterprise security strategies. Sean is also a passionate educator, training internal teams on advanced web and enterprise security practices.

