SDA Bocconi Insight Logo
Knowledge

Like in an aerial dogfight: the OODA loop of cybersecurity

cybersicurezza

“Operate inside adversary’s observation-orientation-decision-action loops to enmesh adversary in a world of uncertainty, doubt, mistrust, confusion, disorder, fear, panic chaos and/or fold adversary back inside himself so that he cannot cope with events/efforts as they unfold.” This is how John Boyd , fighter pilot and military strategist, summarized his most famous idea: the OODA loop — Observe, Orient, Decide, Act — and the belief that in conflict victory does not go to the strongest, but to whoever completes this loop fastest. Boyd was thinking about aerial dogfights, but no image better describes what is happening, in these months, to corporate cybersecurity.

In the first part of this series , we saw that, thanks to the latest developments in AI, the speed and ease with which security vulnerabilities can be found within a corporate perimeter have increased enormously. In the second , that the playing field is becoming increasingly geopolitical. The most concrete question remains: how do you fight a battle in which both attack and defense operate at the speed of Artificial Intelligence? The answer does not lie in a list of tools to buy, but in a change to the model itself: the processes, the roles, the way an organization observes, orients, decides and acts.

The old security model was, in essence, the following: scan periodically, open a ticket, plan a fix, apply the patch. A rhythm measured in weeks and sometimes months, tolerable as long as attackers moved at the same frequency. That assumption has now collapsed. When an AI model identifies thousands of flaws in a few weeks and an attacker can move from discovery to exploitation in a few hours, any process that operates on a weekly timescale risk becoming effectively obsolete.

From a periodic cycle to a continuous cycle

The first change, therefore, is temporal in nature. Historically, improvements in defense were limited by the speed with which new vulnerabilities could be discovered. Today, the bottleneck lies elsewhere: in how quickly organizations can verify, disclose, and remediate the vast number of vulnerabilities that AI is already uncovering and will continue to uncover. Every flaw identified but left unresolved becomes a known open door, precisely the kind attackers are best positioned to exploit. If AI discovers a thousand of them a week and the organization manages to close one hundred, the other nine hundred do not disappear: they remain there, a backlog of open doors accumulating faster than they can be shut. Paradoxically, a company that identifies only one hundred but closes all of them may be more secure than one that finds ten thousand and fixes half (with non-trivial implications for cyber insurance as well).

This requires rethinking some classic metrics: no longer “how many vulnerabilities have we found”, but the average time and productive capacity of remediation: how many do we close, how fast, and with what residual backlog. And this brings us to the most uncomfortable point, the one that machine speed makes explosive. The same AI tool that found a vulnerability in the system could, in theory, fix it by generating an associated patch. But applying a patch often means touching production systems: restarting them, modifying them, sometimes stopping them altogether. When remediation was a slow, human process, that risk was diluted over time: one patch at a time, tested calmly, within an agreed maintenance window. But automating remediation to keep pace with the attacker means pushing changes into the company's vital systems at the same speed at which they are generated.

A mistaken fix, or one applied at the wrong moment, can throw production into chaos with the same speed with which it would have closed the flaw. Thousands of patches per week imply a tempo that traditional patch-management cycles simply cannot withstand, not to mention the open-source context, where updates depend on volunteer maintainers. And in reality, not all patches can be automatically generated — in fact, that is a very rare occurrence. In most cases, it is the provider of a given solution who must supply them, according to the respective contractual terms.

The risk, in short, is no longer only “how long do we leave the door open”, but “how much operational damage can we cause by closing it quickly”.

Roles and boundaries that dissolve

The second change, by contrast, is organizational in nature. In the new model, security stops being a series of periodic events and becomes a continuous flow: an OODA loop that never stops. And if the loop runs at machine speed, the human being can no longer sit inside every single decision, otherwise they become the bottleneck of the entire process.

The model that is emerging is therefore that of the human “on” the loop rather than “in” the loop: no longer the executor of every single action, but the supervisor who sets the rules of the game. The analyst no longer examines every alert; they define the limits and autonomy thresholds within which AI agents can observe, decide and act on their own, and they intervene on exceptions. It is a profound cultural reversal: the value of the person shifts from execution to judgment, from reacting to a single event to designing the system that reacts. The security operations center (SOC, Security Operations Center) becomes a control room that orchestrates fleets of agents, rather than a room full of people reading logs.

As a consequence, it is reasonable to expect the future IT and cybersecurity organization chart to change as well. The boundary between security and software engineering will become increasingly thin: if AI can propose fixes, rewrite components and verify code before release, security will tend to move “upstream”, into the development process, instead of remaining a control applied at the end. New skills and roles will therefore emerge, such as that of the AI agent trainer: a figure that will necessarily have to incorporate solid cybersecurity expertise. And, above all, the Chief Information Security Officer will cease to be primarily a buyer of technological tools and will become the director of hybrid teams made up of people and agents.

Resilience, not (only) prevention

The new model must therefore hold together at least three elements: gradual release capability, automated validation, and the ability to restore immediately to the previous version (rollback). All three require establishing in advance when cyber criticality takes precedence over business continuity, instead of improvising the decision during an incident, under pressure. This is a governance choice, not a technology choice.

And all of this converges on a principle that overturns decades of defensive posture: the objective is no longer to prevent every breach, but to survive without systemic damage. If one assumes — as one must — the presence of an adversary operating at the speed of Artificial Intelligence, the game is played on containment: limiting the scope of an attack, isolating fast and, above all, restoring quickly. Resilience becomes the true measure of success.

To do this, the defending company must make the most of its main advantage, small but not insignificant: knowing its own systems better than anyone else. And it must keep in mind that this advantage lasts only as long as it can turn it into an OODA loop faster than the attacker's.

And this, in the end, is the thread that ties the three parts together. Breach is inevitable; the terrain is geopolitical; the state of alert is permanent. But “permanent” does not mean “ungovernable”. The organizations that emerge as winners from this phase will not be those with the most powerful tools. They will be those that have redesigned their way of observing, orienting, deciding and acting, turning a scenario that looks like chaos back into a condition of operational normality.

The opinions and reflections presented in these articles draw on a series of discussions held over recent months within the Corporate Information Security Roundtable , an initiative involving European and American Chief Information Security Officers, as well as on the research activities of DEVO Lab , SDA Bocconi’s laboratory dedicated to studying innovation and the adoption of new technologies in companies.