James Blake at Cohesity considers how the recent rogue AI breaches show a vital need for more focus on rapid secure system recovery and the Minimum Viable Company

The July 2026 incident involving Hugging Face and OpenAI is likely to become one of the defining cyber-events of the decade. Not because an AI agent successfully compromised another organisation, but because it clearly exposed how differently autonomous attackers behave than their human counterparts had done previously.
This was not a story about a more sophisticated attacker. It was about exponentially more of the same attacks, executed faster. AI-driven attacks can test, adapt and execute in parallel, keeping pressure on weak points until one breaks. Once inside, an autonomous agent may not stop at the first breach. It can continue hunting for privilege escalation, new routes and deeper compromise at machine speed. Therefore, the danger is not just that AI can break in faster. It is that it can keep breaking in, everywhere, all at once.
That makes this a cyber-resiliency warning, not just an AI security headline. Prevention still matters, but it is no longer enough. Boards need to know whether the organisation can keep operating when compromise unfolds faster than people can respond.
New attack methods require new defences
Too much cyber-defence still assumes attackers follow recognisable patterns, based on historic knowledge of previous incidents. That thinking becomes brittle when the adversary can adapt continuously, abandon failed paths and generate new routes inside the environment.
The fixation on known tactics, techniques and procedures is useful, but incomplete. Autonomous attackers will execute so many different attacks, so quickly, that success paths will almost certainly be different every time. In an AI-enabled attack, the playbook matters less than the objective. Defenders must protect against outcomes, not just behaviours they recognise.
Minimum Viable Company planning becomes essential
If AI can contaminate more systems more quickly, leaders must be certain in advance which services, identities, data and dependencies keep the business alive. This is the very definition of Minimum Viable Company (MVC) planning, which has now moved from good practice to critical board-level necessity.
Without that clarity, recovery becomes an argument under pressure. Teams lose time debating priorities while the attacker may still be active. MVC is not a recovery exercise. It is a survival plan, and MVC capability turns recovery into a pre-authorised business process: restore what matters first, not everything at once.
System recovery protocols are now primary targets
Recovery begins with trusted identity, not restored infrastructure. If privileged accounts, secrets, tokens and identity platforms cannot be trusted, bringing systems back online may simply bring the attacker back with them.
The recovery process is now a primary target. Backups, clean rooms, orchestration, automation tooling, monitoring platforms and administrative consoles are the tools that recover the systems. If they are compromised, recovery credibility collapses, and the worst time to discover your recovery systems are untrusted is when you need them most.
Recovery must move at machine speed
When attackers move at machine speed, recovery shouldn’t move at spreadsheet speed. Manual approvals, undocumented tribal knowledge and improvised decision-making are resilience failures. It is vital not to jump the gun, recovering areas of an organisation based on guess work. Availability is not recovery. Recovery means proving the business is safe to restart.
A true MVC and ongoing business resilience depends on rehearsed, automated and evidence-driven recovery. This means being able to quickly understand what happened and assess the damage, having an immutable backup of critical data, and having clean-room recovery capabilities that allow organisations to safely restore systems to a trusted state.
The bigger question for boards
The Hugging Face incident has triggered a debate about AI safety, governance and containment. And while that debate is important, C-level execs must ask a more practical question. ‘How could the organisation continue operating if an autonomous attacker moved across the estate faster than our internal processes can accurately investigate?’
That is the cyber-resiliency test AI has brought forward. Agentic AI cyber-threats expand the attack surfaces, change attacker behaviour and compress decision time.
The answer is not to abandon prevention. It is to assume prevention may fail and build the capability to recover the minimum viable company quickly, cleanly and with confidence as an absolute and immediate business priority.
James Blake is VP Global Cyber Resiliency Strategy at Cohesity
Main image courtesy of iStockPhoto.com and Devrimb
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543