JPMorgan talked about AI and cyber risk and they don’t tend to sound the alarm without reason. So when one of the world’s biggest banks says AI-driven cyber threats could become the industry’s biggest risk, worth more attention than credit shocks, it’s worth pausing on.
The detail that should get your attention isn’t the size of the bank saying it. It’s the timeline.
The AI and Cyber Risk statement
According to JPMorgan analyst Kian Abouhossein, modern AI models are compressing the time it takes to find an unknown software vulnerability, a “zero-day”, from “months and years to hours.” Read that again. A gap that used to give IT teams weeks or months to patch and prepare is shrinking to an afternoon.
If that’s true for the banks with billion-pound security budgets, ask yourself what it means for everyone else.
Most small and mid-sized firms, law practices, accountancies, and financial services businesses included, don’t operate on JPMorgan’s timeline to begin with. Patches get queued. Updates get postponed until “a quieter week.” Legacy software keeps running because replacing it is disruptive. That approach was already a gamble. If the window between a vulnerability existing and it being actively exploited is now measured in hours rather than months, “we’ll get to it next sprint” isn’t a strategy anymore. It’s an open door.
Cyber Risk Is A Question Of Operational Resilience
JPMorgan’s report also made a point that applies well beyond banking: it argued that regulators and firms should stop viewing cyber risk purely through a capital or compliance lens, and start treating it as a question of operational resilience. In plain terms, the real question isn’t just “are we compliant?” It’s “if something breaks through today, can we keep operating tomorrow?” That’s exactly the mindset shift we’ve been encouraging clients towards. Compliance is the foundation, not the finish line.
Social Media’s Role In AI and Cyber Risk
There’s also a knock-on effect worth noting. JPMorgan flagged how social media can amplify a cyber incident into a genuine trust crisis, pointing to the kind of rapid, public unravelling seen with Credit Suisse. For any business built on client trust, and law firms and accountants absolutely are, reputational damage can spread faster than the technical fix. A breach isn’t just an IT problem for a day. It’s a trust problem that can outlast the outage by months.
None of this means panic. It means treating patch management, vulnerability scanning, and incident response as continuous disciplines rather than occasional admin.
Ask the following AI and Cyber Risk questions:
1. How quickly do you deploy a critical patch if one is released today?
2. Do you know which of your systems are most exposed right now?
3. If a cybercriminal found a gap in hours, would you notice before they used it?
AI is changing the maths on both sides of this fight, for attackers and defenders alike. The firms that treat that shift seriously now will be the ones still standing, and still trusted, when it counts.
If you’re not confident in how quickly your business could respond to a fast-moving threat, talk to Jason Chaplin
Why does JPMorgan think AI is the biggest cyber risk?
JPMorgan believes AI has the potential to dramatically accelerate how quickly cybercriminals discover and exploit software vulnerabilities. According to analyst Kian Abouhossein, AI models could reduce the time needed to identify unknown “zero-day” vulnerabilities from months or years to just hours.
This matters because organisations traditionally rely on having time to detect, test and deploy security patches after vulnerabilities are discovered. If attackers can find and exploit weaknesses within hours, that window almost disappears. Cybersecurity becomes less about preventing every attack and more about responding fast enough to minimise disruption.
For businesses, the implication is clear: delayed patching, outdated software and reactive security practices become much higher risks in an AI-driven threat landscape.
Can AI discover software vulnerabilities automatically?
Yes. Modern AI systems can assist security researchers—and potentially attackers—by analysing large amounts of source code, identifying programming errors and highlighting patterns that may indicate vulnerabilities.
AI does not magically “hack” systems on its own, but it can:
- Analyse millions of lines of code far faster than humans.
- Detect coding patterns associated with known vulnerabilities.
- Generate exploit suggestions for identified weaknesses.
- Automate repetitive security testing.
- Help prioritise which vulnerabilities are most likely to be exploitable.
Cybersecurity professionals are also using AI defensively to improve vulnerability scanning, threat detection and incident response. The technology benefits both defenders and attackers, making speed of response increasingly important.
How does AI cyber risk affect small businesses?
Small and medium-sized businesses (SMBs) often have fewer cybersecurity resources than large enterprises, making them particularly vulnerable as AI accelerates attacks.
Common challenges include:
- Delayed software updates due to limited IT resources.
- Legacy systems that are difficult or expensive to replace.
- Limited visibility of vulnerable devices.
- Smaller security teams with less capacity for continuous monitoring.
- Greater reliance on third-party software and cloud services.
AI enables attackers to automate reconnaissance, identify vulnerable organisations more quickly and launch more convincing phishing campaigns. As a result, businesses that previously had days or weeks to respond may now have only hours.
For many SMBs, improving cyber resilience means investing in continuous monitoring, vulnerability management, rapid patching processes, employee awareness training and tested incident response plans.
Is being Cyber Essentials certified enough?
Cyber Essentials is an excellent starting point, but it is not sufficient on its own to defend against today’s evolving cyber threats.
Cyber Essentials helps organisations implement essential security controls such as:
- Secure configuration.
- Access controls.
- Malware protection.
- Firewalls.
- Patch management.
However, certification represents a baseline rather than comprehensive protection.
Businesses should also have:
- Continuous vulnerability scanning.
- Security monitoring and alerting.
- Multi-factor authentication across critical systems.
- Regular backup testing.
- Incident response planning.
- Employee cybersecurity awareness training.
- Regular security reviews and risk assessments.
Think of Cyber Essentials as building strong locks on your doors. It significantly reduces risk, but you still need alarms, CCTV, maintenance and a plan for what happens if someone gets inside.

