Tuesday, July 28, 2026

News

AI Cuts Hacker Dwell Time in Corporate Networks by 80 Days, WEF and KPMG Report Finds

ResearchPatryk Raba
AI Cuts Hacker Dwell Time in Corporate Networks by 80 Days, WEF and KPMG Report Finds
Fot. Tima Miroshnichenko, Pexels (Pexels License)

Companies that heavily use artificial intelligence in cyber defense detect breaches an average of 80 days faster and cut breach costs by $1.9 million, according to a World Economic Forum and KPMG report based on 20 case studies.

Contents
  1. What the report shows
  2. Concrete deployments
  3. Scale of the study and caveats
  4. What this means for Poland

Organizations that have broadly deployed artificial intelligence in their cybersecurity operations are cutting the time an attacker spends undetected inside their infrastructure by an average of 80 days. That is the finding of a World Economic Forum and KPMG report published in May 2026, now referenced by KPMG in a statement cited by the Polish outlet aboutmarketing.pl.

What the report shows

The document, titled Empowering Defenders: AI for Cybersecurity, was produced jointly by the World Economic Forum and KPMG. The authors gathered twenty concrete AI deployments in the security departments of large companies to show not declarations, but measurable effects of automating cyberattack defense.

The key metric is dwell time, the length of time an attacker remains undetected inside a compromised network. At organizations that have deployed AI at scale across security operations, that time fell by an average of 80 days compared with companies that don't use automation. Alongside faster detection, costs drop too, by $1.9 million per breach.

Concrete deployments

The report describes what this looks like in practice. IBM's system, called the Autonomous Threat Operations Machine, handles about 95 percent of daily security investigations and automates more than 850 hours of analyst work a month, cutting end-to-end investigation time by 37 percent. Accenture's Oliver agent analyzes more than 100,000 internet-facing websites, cutting the time to analyze a single site from 15 minutes to under a minute.

Check Point, with its Universe platform, cut investigation cycles from three weeks to one hour. ING, using machine-learning mechanisms to detect data leaks, processed 5 million alerts and raised detection precision by 20 percent among more than 60,000 employees. KPMG itself reports a 25 percent increase in operational efficiency in threat analysis.

Scale of the study and caveats

The findings are based on one-on-one interviews and workshops with 105 representatives from 84 organizations across 15 industries, conducted as part of the World Economic Forum's Cyber Frontiers: AI and Cyber initiative. The authors caution, however, that the metrics in individual case studies are self-reported by the organizations rather than independently verified - this is not an audited benchmark, but a collection of self-reported results.

The report also warns against over-reliance on automation. The authors recommend combining AI with human judgment, testing for failures in AI systems, and designing fallback safeguards for outages, because the same attackers AI is meant to defend against are increasingly using it themselves, increasing the speed, scale and sophistication of attacks.

AI has the potential to tip the scales in favor of defenders - Akshay Joshi, Head of the Centre for Cybersecurity, World Economic Forum

What this means for Poland

KPMG in Poland publishes its own Cybersecurity Barometer, which found that 83 percent of surveyed companies had experienced at least one cyberattack attempt. Referencing the global WEF and KPMG report fits that same line - the Polish arm of the firm is signaling to domestic clients that defense automation is no longer a pilot project, but is becoming a measurable factor in reducing risk and cost.

For Polish companies, especially in the financial and energy sectors, which have spent months testing resilience against hybrid-warfare scenarios, the report's numbers give them an argument for budget discussions on security operations center (SOC) automation. 88 percent of security teams covered by the study reported reduced workloads and better proactive defense capabilities thanks to AI, but the authors stress this still requires human oversight rather than full system autonomy.

The report also fits into a broader regulatory context - its findings are being weighed against GDPR requirements, the EU's Digital Operational Resilience Act, and the US requirement to report breaches within four business days (SEC Item 1.05). In Europe, where rules on labeling AI-generated content have applied since August 2, and the AI Act is entering further implementation phases, data on the real benefits of defense automation could speed up investment decisions at companies that have so far treated AI in cybersecurity as an experiment rather than a standard.

Share: