GoFirm
Back to Blog
Threat Landscape·3 min read

Europol's Velocity Gap Is Real. Faster Detection Is Not the Answer.

By GoFirm

Europol published its annual Internet Organised Crime Threat Assessment in April 2026. The report is titled How Encryption, Proxies, and AI Are Expanding Cybercrime. Its central concept is the velocity gap: cybercriminals are pulling ahead of defenders at an unprecedented pace, and traditional approaches cannot bridge it.¹

The report documents what is driving that gap. More than 120 active ransomware variants were identified in 2025 alone. AI is making fraud, deception, and social engineering more scalable and more convincing. Criminal networks have professionalised into cybercrime-as-a-service ecosystems, and the extortion model has shifted: attackers are moving away from encrypting data toward pure data theft, using the threat of exposure to force payment.

That last shift matters more than it might appear. Encryption-based ransomware is damaging and disruptive, but organisations can potentially recover from it. Backups can be restored. Systems can be rebuilt. Pure data theft combined with extortion cannot be recovered from in the same way. Once sensitive data is in the hands of an attacker, no recovery plan undoes that. The threat of exposure is permanent. The reputational, regulatory, and legal consequences persist long after the incident is closed.

Europol also identifies something that most security vendors do not say clearly: traditional approaches that assume attackers will maintain presence for weeks or months become ineffective against AI-accelerated attacks that complete their objectives in hours.¹ That is not a refinement of the existing model, it is a statement that the existing model has a structural problem.

The structural problem is this. Detection and response is a downstream model. It assumes the attack is in progress or has already succeeded, and the goal is to identify it, contain it, and recover. That model worked when attacks took weeks and defenders had time to catch them mid-operation. When AI compresses the attack timeline to hours, the detection and response window collapses. By the time the anomaly is flagged and the analyst reviews it, the data is already gone.

The Europol report calls for enhanced law enforcement capabilities and international cooperation. Both are necessary. Neither addresses the execution boundary problem at the organisational level.

The velocity gap cannot be closed by moving faster downstream. It can only be closed by moving upstream, to the point before the consequential action executes. That is where GoFirm operates. Before a bulk data export proceeds, before a privileged access change takes effect, before an AI agent executes a high-consequence instruction, GoFirm routes a confirmation request to the named human authority on their registered personal device through a channel separate from the operational environment. The authority confirms with their biometric. The action proceeds or it stops.

An AI-accelerated attack completing its objectives in hours is not slowed by faster detection. It is stopped by a control that requires confirmed human authority before the consequential action executes. The attacker can move at machine speed through every phase of the attack chain. At the execution boundary they need something they cannot produce: a biometric confirmation from the named authority on a physically separate device.

The shift from encryption to pure data theft makes the execution boundary argument more urgent, not less. When the irreversible action is data leaving the organisation rather than systems being locked, the window for recovery-based remediation closes entirely. The only meaningful control is one that stops the exfiltration before it executes.

Europol has correctly identified the velocity gap. The answer is not running faster in the same direction. It is standing at the point where the damage occurs and requiring confirmed human authority before it does.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Europol, Internet Organised Crime Threat Assessment (IOCTA) 2026: How Encryption, Proxies, and AI Are Expanding Cybercrime, April 2026, https://www.europol.europa.eu/media-press/newsroom/news/new-2026-iocta-highlights-sophisticated-tactics-and-emerging-challenges-in-digital-landscape

Share this article