The challenge
Almost everything around us now runs on software: medical devices, power grids, financial systems, military hardware. That dependence has created an expanding risk. When a system is compromised, the harm can outlast the breach by years, because fixes are often too complex, too risky or too slow to deploy safely. Conventional cyber defence also assumes a human in the loop. Analysts detect an intrusion, assess it, write a patch and roll it out, a process that can take weeks or months. In healthcare or defence, where a paused or corrupted system can endanger lives, that gap between attack and repair is where the real danger lies.
The initiative
URSA Inc., a small business funded through DARPA’s Small Business Innovation Research programme, is pursuing a different model of defence: systems that diagnose and repair themselves while an attack is still under way. The aim is to narrow the window between compromise and recovery to the point where an intrusion does little lasting harm.
The team’s tool, Cyber First Aid, was tested on a pacemaker simulator. In the demonstration, it detected a vulnerability, used a large language model to generate a software fix, verified that fix in a safe sandboxed environment before deploying it to the running system. The whole sequence took under 16 seconds and needed no human intervention at any step. Bernard McShea, DARPA's programme manager for Cyber First Aid, describes the ambition simply: "We're moving away from years of patching to seconds."
The design borrows from biology. URSA describes the approach as a digital immune system: with each attack it absorbs, the software learns and hardens itself against similar threats. Over time, the intention is for protection to accumulate, so a system grows harder to exploit the longer it runs and the more attacks it has weathered.
Early results and transformative potential
The headline result so far is a single controlled demonstration: a self-healing cycle completed in under 16 seconds on a pacemaker simulator. That is a proof of concept, and URSA is clear that significant technical hurdles remain before the approach could be trusted in live critical systems. The long-term target is faster still, with the team aiming for millisecond response times.
If the method proves robust and generalises beyond a controlled test, the implications are significant. Governments spend heavily defending the infrastructure citizens rely on, from hospital equipment to defence networks, and most of that spending buys faster detection and quicker manual recovery. Software that mends itself in seconds would change what resilience means, and would force fresh questions about how such systems are certified and trusted.
If government funding enabled a small business to develop a system that heals itself in seconds, what could governments do to find and fund more of these bets before the next crisis hits?