{
  "id": 3676000,
  "title": "ITWeb TV Biz: The architecture of AI-native cyber defence",
  "url": "https://urgent.news/2026/08/25/itweb-tv-biz-the-architecture-of-ai-native-cyber-defence",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-25T12:35:30.000Z",
  "source": {
    "name": "ITWeb",
    "slug": "itweb",
    "url": "https://www.itweb.co.za/article/itweb-tv-biz-the-architecture-of-ai-native-cyber-defence/GxwQDq1DPOoMlPVo"
  },
  "original_language": "en",
  "account": "Snode Technologies, a cyber defence company based in Centurion, has been utilizing AI for an extended period before it became a buzzword in the industry. Based in South Africa, the company safeguards approximately 8 million devices spread across six continents. Co-founder and CEO Nithen Naidoo explains that their focus on AI stemmed from addressing a specific problem rather than a fascination with the technology itself. As Naidoo recounts, \"We weren't looking to leverage AI in a cyber security product. We were looking for a solution to a problem.\" It was in 2017 that Snode transitioned from Bayesian mathematics into machine learning and deep neural networks, with AI now playing a pivotal role in shaping both their products and development processes.\n\nNaidoo highlights that Snode's approach involves machining code rather than relying on a human process. Writing code has traditionally been a significant part of the development cycle, but now, the team dedicates its time to design, quality assurance, security testing, and AI red teaming. Naidoo emphasizes that Snode does not believe AI will replace humans, comparing the integration of AI to intelligence amplification, where technology enhances human cognitive capabilities instead of replacing them. He explains, \"You're looking at the synergy of humans doing what humans are good at and AI doing what AI is good at.\"\n\nBecause AI is integral to the platform rather than an afterthought, Snode focuses on behaviors rather than isolated indicators, such as IP addresses and file hashes. The analytical engine correlates activities from various sources into a unified, contextualized view of the attacker's kill chain. Building upon this foundation, Snode's digital twin simulates how active threat actors would move through an organization's real environment, enabling threat actors to be anticipated in real-time.\n\nRather than inundating security teams with reports listing a thousand vulnerabilities, Snode provides them with a precise understanding of the critical exposures that require immediate attention. Rather than relying on public large language models, Snode trains its own small language models, derived from a decade of analyst and client data expanded through data synthesis. These models are hyper-specific, lightweight, and portable enough to run at the edge on IoT sensors, phones, and even satellites. Naidoo stresses that Snode avoids using ChatGPT if it cannot pick up anti-virus signatures. Smaller models are also more trustworthy, as he explains, \"Too much of AI is like a black box, and it needs to be more of a glass box. You need to understand how the AI works in order to understand how it can be manipulated or misused.\"\n\nIn an interconnected and hyper-connected world, Snode understands that AI-native cyber defence is only as effective as its ability to surface understanding during an unfolding threat. Naidoo advises, \"Knowing about an attack five minutes after it happens is five minutes too late. You have to move at machine speed because you've been attacked at machine speed.\"",
  "summary": "How intelligent detection, digital twins and purpose-built models are reshaping what cyber defence looks like.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}