Closing Bell Overtime

Theresa Payton on machine-speed cyberattacks

Theresa Payton· CEO at Fortalice Solutions
·~6 min·English·CNBC
AI SafetyAgentsPolicyAI Infrastructure
TL;DR

Cybersecurity CEO and former White House CIO Theresa Payton argues AI has pushed cyberattacks from human-driven hacker speed to autonomous machine speed, and that safety has to be built into these systems by design rather than bolted on after release.

01Core Mental Model

Machine Speed, Not Hacker Speed

The change that matters is pace and autonomy: an attack program now spins up its own agents and runs without a human orchestrating each step.

we are seeing the hacks happen at machine speed whereas before it was at hacker speed.

— Theresa Payton, Closing Bell Overtime
Key Insight
The interviewer raises the dramatic image of agents 'going rogue'; Payton redirects to something more mundane and more scalable. When the attack program can spin up its own agents to carry out a task, a single operator no longer has to drive each move by hand, and that is what lets the attacks run at machine speed.

02Why It Is Worse

Old Problems, Now Multiplied

Machine-speed attacks do not replace the old weaknesses; they sit on top of a base of vulnerabilities the industry never finished fixing.

We haven't fixed all of those and now we've layered on something new, different, novel, and working at machine speed.

— Theresa Payton, Closing Bell Overtime
Key Insight
The danger is compounding, not substitution. A faster attacker is most dangerous against systems that were already exposed, so the same unpatched software and weak access controls that were a slow-burning risk become far more dangerous once an attacker can probe and exploit them at machine speed.

03What To Do

You Can't Bolt On Safety

Payton argues safety and security have to be engineered into these models from the start, the way a car is built with seat belts and brakes rather than having them added later.

We don't add on seat belts. We don't add on brakes. They're put on when it's designed in the factory.

— Theresa Payton, Closing Bell Overtime
Key Insight
The metaphor carries a claim about sequence. Payton's point is that security bolted on after release tends to be partial, because the system was not shaped around it; her preferred path puts governance and guardrails in during development so the protection is part of the design rather than a patch.

04Accountability

The Laws Already Apply

Payton's view is that much of the needed regulation already exists: if a program breaks into another network, the responsibility does not disappear just because no human typed the commands.

just because a software program did it doesn't mean the laws on the books don't apply.

— Theresa Payton, Closing Bell Overtime
Key Insight
This resists the idea that AI is a legal vacuum. By drawing the parallel to an employee who hacks another company from a work computer, who along with their employer would be hauled in for questioning, Payton suggests the first move is to ask who is responsible under existing law, rather than assuming AI is a blank space the books cannot reach.

05Defense

One of Many Solutions

No single product solves this; Payton frames containment tools like sequestering rogue agents as one layer among many, alongside authentication, monitoring, and governance.

it'll be one of many solutions.

— Theresa Payton, Closing Bell Overtime
Key Insight
Payton treats AI defense the way mature security already works: as layers rather than a silver bullet. Catching and quarantining a rogue agent is useful, but she places it next to multi-factor authentication, anomaly monitoring, and built-in governance, which implies that a vendor promising one tool as the answer is overselling it.

06The Stakes

Critical Infrastructure Is the Target

Asked what worries her most, Payton points to critical infrastructure, the energy, water, transportation, healthcare, and banking systems that were already under attack before AI.

Incredibly worried about critical infrastructure. There's a lot of very smart, hardworking people thinking about energy, water, transportation, healthcare, and banking.

— Theresa Payton, Closing Bell Overtime
Key Insight
Payton locates the risk where failure is physical, not abstract. These sectors were already targets by older methods, so her concern is less a new door than the same doors being tried far faster, which raises the question of whether defenders can see an attack coming in time to respond.