Your SOC cannot outrun AI
If attackers can automate the attack, defenders need to automate the response, says Kurt Goodall, technical director of Troye.
Cybersecurity professionals are facing a growing challenge as artificial intelligence becomes a double-edged sword in the realm of digital defense. Attackers are leveraging AI to streamline their malicious activities, while security teams grapple with a deluge of alerts and struggle to keep pace. The critical question now is not merely whether organizations possess adequate security tools, but rather if their security operations can match the speed of AI-driven threats.
According to Check Point Research's 2026 AI Security Report, evidence suggests AI is no longer a mere aid for cybercriminals but actively participates in live attacks, from generating commands to crafting sophisticated malware. This shift marks a transformation from AI serving as a force multiplier to AI functioning as an operator. For defenders, this paradigm change necessitates a reevaluation of traditional security measures.
While traditional controls remain essential, they are no longer sufficient on their own. Attackers can traverse multiple vectors, including identity, email, endpoints, cloud applications, and networks, leaving behind seemingly insignificant events that, when combined, pose a significant threat. The ability to swiftly connect these dots has become as crucial as blocking individual threats.
This challenge is where managed detection and response (MDR) services come into play. A robust security operation requires continuous monitoring, threat hunting, investigation, and rapid response, capable of tracing events across the entire environment and taking immediate action.
A recent Arctic Wolf 2026 survey reveals that 94% of organizations now utilize large language models, and 94% consider AI capabilities when making cybersecurity purchasing decisions. However, this rapid adoption of AI also presents new vulnerabilities. Check Point's latest research indicates that, on average, organizations employ ten different AI applications monthly, with high-risk Generative AI (GenAI) prompts doubling from 2% to 4% in the past year.
Furthermore, between 87% and 93% of organizations experience at least one high-risk GenAI interaction each month. Visibility into these activities is paramount, as it enables security teams to discern the broader context of events beyond individual product reports. For instance, if an employee's credentials are compromised, the crucial inquiry is not just the unusual login but what transpired subsequently—such as data access, communication with other endpoints, involvement of cloud applications, and resemblance to existing attack patterns.
This evolving landscape underscores the need for cyber resilience that extends beyond mere disaster recovery. Resilience entails detecting attacks, comprehending their scope, containing them, and recovering swiftly before the business impact becomes overwhelming. It demands security operations that can respond at machine speed while still relying on human judgment for decisions with significant consequences.
For South African Chief Information Security Officers (CISOs), the message is clear: as attackers automate their attacks, defenders must automate their responses to prevent perpetual catch-up scenarios. AI adoption is inevitable, but it must be judiciously governed to prevent the exposure of corporate data, creation of new attack surfaces, and acceleration of attacks.
The solution lies not in adding more security tools but in cultivating a security operation that integrates prevention, detection, intelligence, and response seamlessly.
Written by urgent.news from ITWeb's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.