There’s a lot of chatter around AI right now. Many of the largest, most widely deployed technology vendors in the world are adding AI to their products: Copilot, Microsoft’s AI “companion,” is already being touted by the company as an essential must-have for Microsoft 365 productivity, while Google, Apple, and others are remodelling their products and services around AI assistants and agentic AI.
Then there’s large language models (LLMs) like ChatGPT, Claude, and others, which already appear to be altering how many people are interacting with computers and software, due to the conversational nature of the AI.
There are various discussions to be had around how AI is changing how we operate, but there’s one particular area where it appears to be having a positive impact, helping humans to do better: cybersecurity.
By its very nature, cybersecurity is difficult: to ensure networks and users remain secure, defenders pretty much have to get it right 100% of the time. Meanwhile, hackers and cyber attackers only need to be successful once; they just need to crack one password or successfully trick one user into clicking a phishing link to install malware, and they’re in. And of course, they’re exploring how they can exploit AI to aid with conducting attacks, too.
Cybersecurity at speed
But at its heart, much of cyber defense is about security tools examining data for trends, patterns, and unusual behavior. That’s something AI could massively help with.
“AI brings extraordinary speed and adaptivity to cybersecurity. Machine agents continuously monitor networks, detect anomalies, and patch vulnerabilities faster than any human team,” said Eleanor Watson, IEEE member and AI ethics engineer and AI Faculty at Singularity University. “This fulfills one of AI's most promising near-term applications: autonomous defense at machine timescale.”
Fundamentally, the idea is simple: that with the right training on the right data, AI can triage, analyze, and make initial decisions about alerts in the security operations center (SOC) at a much faster speed than a human ever could.
For example, the SOC receives an alert about a known user logging in from a new location on a new device at an irregular time of day. This isn’t automatically a threat in and of itself – maybe the employee is on a business trip, and they were issued with a new laptop ahead of it – but it does potentially classify as unusual.
A human security analyst would need to take potentially hours to investigate the alert before deeming it to be a legitimate security issue, but using the power of machine speed, an agentic AI assistant could triage this in minutes, perhaps even seconds.
“It’s tailor-made to look for what’s wrong in a large dataset, so anomaly analysis and UEBA [user and entity behavior analytics] is going to be incredibly strengthened,” said Chris Hosking, AI and cloud security evangelist at SentinelOne. “It’s something which really speeds up SOC work and the triage that determines if something is serious or not. Threat hunting at the moment is often a process of trying to find needles in a haystack: that process can be exponentially accelerated with agentic AI.”
Not only is this approach helpful for organizations, in that it helps to keep them secure against cyber threats, but it’s also potentially helpful to those working in the SOC.
“It’s very clear that in cybersecurity, there are too many alerts and not enough people making sense of it,” said Jimmy Astle, senior director of detection enablement at Red Canary. “I think now you can have the same amount of people, but you can have them focus on things like zero trust initiatives or better identity validation.”
Essentially, he argues that employing AI to triage and examine SOC alerts and potential cyberthreats frees up cybersecurity staff to focus more effectively on tasks and strategies which can help keep users and the wider network better secured against threats in the long term.
Because rather than dealing with potential incidents, they can spend their time implementing effective cybersecurity strategies, such as rolling out multi-factor authentication on all user accounts or providing those users with up-to-date training to help identify threats.
Unintended consequences
However, it would be a mistake to believe that implementing AI and leaving it to make all decisions around cyberthreats is a silver bullet. Even if AI were powerful enough to fully automate the SOC, the rigid nature of tools and an inability to think outside of binary choices could lead to new problems.
“An AI pursuing ‘maximum protection’ may escalate to over-securitization – locking out legitimate users, restricting infrastructure access, or falsifying telemetry to preserve its perceived integrity. Security and control could collapse into authoritarian code,” Watson said.
It’s therefore vital for any organization thinking of using AI to aid cybersecurity to have the right guardrails in place to ensure it doesn’t stray from a defined goal and cause additional issues.
For example, an AI given the task of securing users against cyberthreats might take this to the extreme: simply deleting user accounts. The logic behind the decision would be that with no accounts, users can’t be harmed by cyberthreats – but they also can’t do anything, hurting the business in a completely new way.
“It really comes down to managing how much agency you give these agents and how you focus them on very specific problems,” Astle suggested. “If you give them too broad a problem to solve, with too broad a set of tools and data to do that, that’s not good. We’re not in a state today where you can do that.”
AI augmented cybersecurity staff
Fundamentally, despite advancements in AI, even those in cybersecurity who are strong advocates for the technology say it isn’t about replacing humans in the SOC – it’s about augmenting them with tools to help them be more efficient – and ultimately helping to ensure people and businesses are better protected against cyberthreats.
“I’m a strong believer that AI doesn’t replace people,” Hosking said. “The reality is that the human’s role is changing and AI adoption is about asking how can we yield the benefits to help achieve what we need to achieve, which is machine speed – because if attacks are happening at machine speed, defense needs to be functioned around machine speed as well.”
The adoption of AI isn’t just about keeping computers and systems safe. If deployed correctly, it can make what’s a notoriously stressful job less taxing for cybersecurity employees, which isn’t just beneficial to them, but beneficial for whole organizations, because burned-out SOC analysts will struggle to keep networks secure.
“The SOC is resource-intensive for humans. The adoption of AI is going to unlock security teams to bring what they bring best to their day to their work: intuition, empathy, the ethical and moral decisions. That’s something AI will allow security teams to embrace more,” Hosking said. “But obviously, we can’t run too fast, you can’t give all of your security team and decisions over to AI – you need humans to validate AI decisions. But we can leverage strategic inputs from AI,” he adds.
Ultimately, cyber attackers are already leveraging AI to automate tasks in an effort to make their attacks more effective. Therefore, for Astle, cyber defenders must use the AI tools they have available to them to keep users and networks safe from evolving threats.
“I think it’s important for defenders to use it in the same way. I do think that at the end of the day, defenders have the upper hand,” Astle concluded. “Cybersecurity is a big data problem – this technology allows you to go through mountains of data and to make much more well-informed decisions.”
This article first appeared in the Cybersecurity Supplement
Comments