Skip to content
Governance & Risk

The $25 Attacker: Find Your Weakest Door Before an AI Agent Does

AI cut the cost of an attack to about $25 a target, and the cheap attack goes in through the systems nobody watches. The playbook for CISOs, General Counsel and AI leaders: find every door you expose, rank each by how easily it opens, set patch clocks in days, watch what leaves, and give the board five numbers before an incident gives them one.

Satori Canton / October 7, 2026 / 31 pages / v1.0

FreeAlways public

Executive summary

In September 2026 an attacker pasted a list of 301 online stores into an AI agent. The agents it directed compromised at least 27 companies in under a week, and the operator's own records put the average cost of a completed scan at $25.46. In the same month a small, freely downloadable model wrote a working browser exploit in a lab for $20.40. Microsoft measured the time from a flaw's discovery to a working attack in hours. In June, CISA rewrote the federal government's patching rules because AI may further narrow the time defenders have to react, and set a three-day deadline for the most serious flaws on internet-facing systems.

Those numbers retire an assumption that has quietly shaped most security budgets: that a mid-size or even a large company is not worth a skilled attacker's time. At $25 a target, every company is worth a look, and the look is automated.

The cheap attack does not go after the crown jewels. In October, seven South Korean financial firms, including Shinhan Bank, KB Kookmin Bank and Hana Bank, were breached by a human operator using an open source AI penetration-testing agent. Every attack went in through a system built for employees or partners: a loan-agent inquiry service, an employee mobile work app, an employee sales tool. The three largest banks had spent about $92 million on security the year before. The money protected what it was pointed at. Third parties were involved in 48% of breaches in Verizon's 2026 report, and organizations took a median of 43 days to fix vulnerabilities already being exploited.

This paper is a playbook for the systems an attacker now reaches first. It describes six kinds of side door that recur across 2026's incidents, from contractor portals to public web forms read by internal AI agents. It then sets out five steps. Build an exposure register of every system reachable from outside, including the ones partners run for you. Rank each system with a door score that weighs how easily its login opens against what sits behind it, using NIST's 2025 assurance levels. Set patch clocks by exposure, adopting the deadlines in CISA's BOD 26-04. Watch outbound traffic, including AI service calls, against an AI egress register, because the first reported AI-driven implant takes its orders from commercial AI services. And measure, by test rather than assumption, how long an intrusion on a low-tier system would run before anyone noticed.

It closes with seven clauses for contractor and partner agreements, the SEC disclosure rules that already put this in front of public-company boards, the five numbers a board should see every quarter, and a ninety day plan for the CISO, the chief AI officer and General Counsel. The exposure register, the door ranking rubric and the board's one page are included as templates that can be adopted as written.

The argument in one line: you are worth hacking now, so find your weakest door before an agent does.

What’s inside

  1. 01Why "not worth targeting" stopped being true
  2. 02Where the cheap attack goes in: six kinds of side door
  3. 03Step one: the exposure register
  4. 04Step two: rank every door by how easily it opens
  5. 05Step three: patch clocks keyed to exposure
  6. 06Step four: watch what leaves
  7. 07Step five: measure the detection clock on low-tier systems
  8. 08Contractors, partners and the portals you do not run
  9. 09Briefing the board: five numbers
  10. 10A ninety day plan, by owner
  11. 11Appendices: the exposure register, the door ranking rubric, the board's one page, and sources

Who this is for

  • CISOs responsible for externally reachable systems
  • General Counsel negotiating contractor and partner agreements
  • Chief AI Officers accountable for AI tools and AI traffic

Author

Satori Canton

Founder & Principal

Satori Canton is the founder and principal of ROAI, an advisory practice focused on measuring and improving the return on enterprise AI investment.

Want the numbers behind your own AI investment?

Book a focused session to see where AI creates real economic value in your organization.