This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

Overview
Can you stop an attack before it exists? This CISO guide argues yes. AI now compresses reconnaissance, setup, and launch into minutes, with a single AI agent able to register, test, and deploy thousands of domains before most defenders notice. Waiting for the first alert means the attack is already in motion.
The guide introduces Pre-Attack Prevention, a discipline that detects and dismantles attacker infrastructure while it is still being built, during the reconnaissance and resource development phases long assumed untouchable. It closes the readiness gap, the window between adversary setup and defender action, where exposure grows.
Readers get a five-stage framework, a new readiness metric in Mean Time to Preempt (MTTP), guidance on embedding validated Indicators of Pre-Attack (IoPAs) into SOC, SIEM, and SOAR workflows, and a real-world case from the Israel National Cyber Directorate. Download the full e-book for the complete playbook.
Key findings
- AI merges setup, launch, and execution into one process, and a single AI agent can register, test, and deploy thousands of domains within minutes.
- The readiness gap, the time between attacker setup and defender action, now defines risk; closing it means fewer attacks reach operational systems.
- Traditional workflows depend on Indicators of Compromise that appear only after an attack begins, leaving no entry point against automated reconnaissance and resource development.
- The Pre-Attack Prevention framework runs five stages: Collect, Validate, Correlate, Enrich, and Prevent, dismantling adversary infrastructure before launch.
- Mean Time to Preempt (MTTP) measures the time between spotting adversary setup and shutting it down, and supports governance under NIST AI RMF and the EU AI Act.
- Using Malanta IoPAs, the Israel National Cyber Directorate identified and dismantled real adversary infrastructure targeting hundreds of Israeli companies across multiple sectors.
What is inside
- Executive Summary
- Introduction: The New Battleground
- The AI-Accelerated Threat Landscape
- The Limits of Detection and Visibility
- The Pre-Attack Prevention Framework
- Introducing a New Metric: Mean Time to Preempt (MTTP)
- Embedding Prevention into Security Operations
- Lessons from the Field
- The Takeaways
Frequently asked questions
What is Pre-Attack Prevention?
Pre-Attack Prevention is the operational category built on Pre-Attack Intelligence. It uses validated evidence to block, disrupt, or otherwise neutralize adversary infrastructure during preparation, before execution begins.
What is an IoPA?
An IoPA, Indicator of Pre-Attack, is a validated signal that adversary infrastructure is being prepared before use. It is not a lower-confidence IOC. It answers a different question at an earlier point in the attack timeline.
What is MTTP?
MTTP means Mean Time to Preempt. It measures the interval between observing adversary preparation and taking defensive action against it. The shorter the MTTP, the less opportunity attackers have to turn preparation into action.
How does AI change the attack timeline?
AI compresses reconnaissance, setup, and launch into minutes, with a single agent able to register, test, and deploy thousands of domains before defenders notice. This widens the readiness gap, the time between adversary setup and defender awareness.
How is Pre-Attack Prevention different from detection-based defense?
Detection-based workflows depend on Indicators of Compromise that appear after an attack begins. Pre-Attack Prevention acts during TA0042, Resource Development, identifying and dismantling attacker infrastructure while it is still being built.
Has Pre-Attack Prevention worked in practice?
Yes. Using Malanta IoPAs, the Israel National Cyber Directorate identified and dismantled adversary infrastructure targeting hundreds of Israeli companies before it became operational. Intervening at the setup stage limited exposure across multiple sectors.
Download the full Redefining Readiness: The CISO Guide to Preventing AI Attacks (PDF)









