Framework · AI Security
Zero Day to Zero Sec
Why context, not speed, is the defender's binding constraint
Zero Day to Zero Sec names what happened to the window that gave "zero-day" its meaning. A zero-day was never really about the vulnerability; it was about time — the interval between an exploit becoming usable and a defense existing, historically measured in days or weeks. Autonomous attack compresses that interval toward zero. The common conclusion is that defenders must therefore respond at machine speed themselves. That conclusion is incomplete. Speed is not the defender's binding constraint; context is. Reaction time only matters if the reacting party — human analyst now, automated system later — already understands what it is looking at: what AI systems exist, what each can reach, and what normal behavior looks like. That understanding cannot be acquired during an incident that outruns you. Whatever ends up defending your systems is capped by the picture you captured before the attack began. A faster defender without that picture is not a defense. It is the same blindness, arriving sooner.
The window that gave the term its name
"Zero-day" was always a measurement of time. Not a class of bug — a countdown. It described the gap between the moment an exploit became usable and the moment a fix existed, and the whole discipline of incident response was built inside that gap. Days to notice. Days to triage. Days to patch. Unpleasant, but survivable, because the attacker was also working at human pace.
Autonomous attack removes the attacker's half of that assumption. One documented intrusion needed nothing clever — one unpatched flaw and enough time to work alone — and produced 1,342 encrypted production records, self-correcting from a failed login in 31 seconds. Independent findings show AI already running full attack chains with minimal human steering. The precedent is on record: a single model instance ran the large majority of a state-linked espionage operation across roughly thirty organizations, largely on its own.
That is the shift the name marks. Zero day to zero sec. The interval defenders were built to operate inside has closed.
Where the industry's answer stops short
The near-universal conclusion is that defenders must match the speed — autonomous detection, autonomous response, fight AI with AI. It is not wrong. It is just not the constraint.
Speed only converts into defense when the thing moving fast already understands what it is looking at. An autonomous responder that does not know which AI systems you run, what each one can reach, or what ordinary behavior looks like for them does not defend you quickly. It reaches the wrong conclusion quickly, or no conclusion at all.
This matters most against the failure mode that speed alone cannot see: several agents dividing an attack so that each individual action looks harmless, and only the full pattern across all of them tells the story. Catching that requires reasoning across a string of separately unremarkable events. No amount of reaction speed substitutes for knowing what the events mean.
Context is acquired before, or not at all
Here is the asymmetry that actually decides the outcome. The attacker arrives having already mapped what matters — that is what the intrusion is for. The defender is expected to assemble the same understanding while the incident is running, at a speed the incident does not allow.
That is not a resourcing problem you can solve under pressure. Context is inventory, reachability, and behavioral baseline, and all three take time to establish precisely because they describe a steady state. You cannot observe a steady state during an emergency.
So the picture you will have at the moment of attack is the picture you captured before it. Everything else — detection, triage, containment, automation — operates on top of that, and inherits its gaps.
How to apply it
Stop treating readiness as a response-time metric. Mean time to respond measures the wrong half once the attacker is autonomous; it flatters teams that react quickly to things they were already equipped to understand and says nothing about the case where they aren't.
Measure completeness of context instead, and measure it today: can you enumerate every AI system and agent you run, what each can reach, what identities and data are within its blast radius, and what normal looks like for it? Whatever is missing from that answer is missing from your defense, and cannot be recovered mid-incident.
Then decide about autonomy second, not first. Automated response is a genuine amplifier — of whatever context it is given. Deploy it on top of a complete picture and it compounds; deploy it on top of an incomplete one and it compounds that instead.
Zero Day to Zero Sec was introduced by Asaf Nakash, Principal Product Manager for AI Security at Microsoft Defender and host of the Context Window podcast, in Context Window Edition #24 (July 20, 2026).