Security as a Subscription You Can't Cancel
Somewhere in Tempo's public repositories, a bot named Cyclops is trying to break their code right now. At 3am. On a Sunday. While the engineers sleep.
It never stops. That's the point.
Tempo is the payments blockchain Stripe and Paradigm are building — the kind of infrastructure that can't afford a single unpatched vulnerability. So their engineers did something that would have seemed paranoid five years ago and seems inevitable today: they pointed a 24/7 AI agent at their own code and left it running. Attacking. Probing. Hunting for the exploit before someone else does.
Because in crypto, someone else always does.
The Floodlight Audit
I've been watching this pattern emerge for months now across blockchain projects. It's not that crypto companies are more paranoid than traditional enterprises — it's that they never had the luxury of obscurity. Open source code. Immutable smart contracts. Systems reachable by anyone with a laptop and bad intentions. You can't quietly patch a smart contract at 2am like you can push an emergency fix to your private codebase.
The serious teams figured this out early. They've been running bots against themselves — either their own or hired red-teamers doing it for them — not as a one-time audit, but as a permanent stance. The code is always live. The money is always at risk. The attacks never stop coming.
What crypto learned the hard way is about to become everyone's problem.
Nobody Gets Fired the Day the Attacker Arrives
Here's the uncomfortable parallel: remember when cybersecurity was that compliance checkbox you handled once a year? Annual pen test. Quarterly vulnerability scan. Box checked, budget approved, everyone moves on.
That worked when attackers were human. When breaches required expertise, coordination, time. When the economics of an attack meant someone had to decide you were worth the effort.
The moment your software is worth attacking, someone — something — points an agent at it. Not a person anymore. An agent. Cheap, tireless, multiplying. Running 24/7 because compute is cheap and the bot doesn't need sleep.
The only thing that answers a 24/7 attacker is a 24/7 defender.
This isn't speculation. I'm seeing this with clients right now. Not in crypto — in regular enterprise software. Financial systems. Healthcare platforms. Anywhere the value of a successful exploit justifies the cost of renting cloud compute and letting an AI agent run.
The town doesn't empty the day the railroad bypasses it. But six months later, the pattern is obvious.
The New Cost Structure of Shipping Code
Let me put this in terms that make finance leaders uncomfortable: security is becoming a subscription cost, not a project cost.
Not "we ran a pen test in Q2." Not "we hired a security firm for the audit." A standing spend. A meter that runs as long as your software is live. Call it a defense budget — the number below which you don't get to call it production.
I had a conversation last month with a CISO who got this immediately. His board had approved a security assessment. One-time engagement. Nice report. He looked at me and said, "That report expires the moment we ship the next feature. What I actually need is a recurring line item that scales with our attack surface."
He's right. And his CFO isn't going to like it.
Because this isn't just about adding headcount. The humans can't keep up either. This is about matching AI-driven offense with AI-driven defense. Which means new tooling. New vendors. New contracts that look more like AWS bills than consulting engagements — usage-based, always-on, cost tied to your threat profile, not your fiscal calendar.
What This Looks Like in Practice
Here's what I'm telling clients to budget for:
Continuous automated testing that runs against every commit, not every quarter. Not a nice-to-have. Table stakes. If you're shipping code weekly, you need security analysis running at the same cadence.
AI-assisted threat modeling that updates as your architecture changes. The old threat model documentation that lives in Confluence and gets reviewed annually? Worthless in a world where your attack surface changes with every sprint.
Persistent red teaming — either your own bots or hired ones — that probe for weaknesses on the same timeline attackers operate: constantly. This is the Cyclops model. It feels excessive until you remember that the alternative is waiting for a real attacker to find it first.
But what do I know — I've only watched three technology waves force industries to rebuild their cost models from scratch.
The Question Nobody Wants to Answer
Security went from a project to a posture once already. We stopped treating it as a one-time fix and started building security teams, security practices, security culture. That transition took a decade and most organizations are still mid-journey.
This is the next step: Security as a subscription you can't cancel.
And here's the part that should make every CFO and audit committee sit with some tension: What's your number?
Not "what should we spend on security" in the abstract. Your specific number. The recurring monthly cost below which your production systems are effectively undefended against automated, AI-driven attacks. The threshold where you're cosplaying security instead of practicing it.
Most organizations don't know their number yet. They're still budgeting like it's 2019, when attacks required human attention and security could be episodic.
I don't have a clean answer for what that number should be. It's going to vary wildly by industry, by attack surface, by risk tolerance. A payment processor's number is different from a marketing site's number.
But I do know this: the number isn't zero. And it isn't static. And waiting to find out what it is — because you got breached and now you're doing the forensics to understand what you should have spent — is the most expensive way to learn.
What to Do Monday Morning
If you're a technology leader, ask your security team: "Are we defending at the same cadence we're being attacked?" If the answer involves quarterly assessments and annual pen tests, you have your answer.
If you're a finance leader, ask: "What would continuous security posture cost us, and what does our current gap risk?" Model it like insurance, because that's effectively what it is — ongoing spend to reduce the probability of a catastrophic loss.
If you're on an audit committee, the question is simpler: "Show me how we know our defenses are keeping pace with automated attacks."
The teams that figure this out early will have a competitive advantage. Not because they'll be unhackable — nobody is. But because they'll know their number. They'll have budgeted for reality instead of hoping the threat landscape freezes in place.
The rest will learn the same lesson crypto learned: the floodlight finds everyone eventually.
The only question is whether you turn it on yourself first.
Want to talk through what this looks like for your organization? I work with finance and technology leaders navigating exactly this transition — from episodic security to continuous defense. Let's talk.
Frequently asked questions
- What is Cyclops and why does Tempo run it against their own code?
- Cyclops is a 24/7 AI agent that Tempo (the payments blockchain built by Stripe and Paradigm) runs against its own codebase to find exploits before attackers do. In crypto, where code is open source and immutable, proactive attack automation is essential because threats come from anywhere with internet access.
- How does AI-powered security differ from traditional penetration testing?
- Traditional pen tests are periodic projects (e.g., "Q2 security audit"). AI-powered attackers operate continuously, tirlessly, and cheaply—requiring organizations to shift from project-based security to a standing defense budget that runs as long as software is live.
- Why is this security model coming to regulated industries beyond crypto?
- The moment software becomes valuable enough to attack, bad actors will deploy AI agents against it. Regulated industries can no longer rely on obscurity or periodic testing; they must adopt the 24/7 defense posture already standard in crypto, treating security as an ongoing subscription rather than a one-time expense.
- What should organizations do to prepare for continuous AI-powered threats?
- The post suggests organizations need to define their "defense budget"—the standing spend required to run continuous security automation as long as software is in production. This is a baseline cost below which software should not be called production-ready.
More Ai Posts
The AI Pricing Time Bomb: Your Strategy
You're paying 2% of true AI costs. Learn what happens when OpenAI and Anthropic reprice subscriptions and how to future-...
Why Solo AI Builders Are Your Market Canaries
Solo developers using AI are discovering pricing models and tools enterprises will demand in 2-3 years. Watch them to pr...
Stop Waiting for AI: Your Competition Already Started
AI disruption isn't coming tomorrow—it's happening now. While most companies debate, competitors are shipping. Here's wh...
