7 ways AI can be used to enhance security operations
BreachAI has an almost unlimited number of applications, yet none may be more important than its ability to strengthen enterprise security. AI marks a new era of business transformation in which AI autonomy and innovation converge to redefine how people, processes, and technology interact, says Sheetal Mehta, global head of cybersecurity at NTT DATA. “The development of agentic AI — systems that can learn, make informed decisions, act autonomously, and even adapt their reasoning in pursuit of goals — will take us into a new revolution of cybersecurity.” Is your organization doing everything it can to take advantage of AI’s formidable security power? Here’s a look at seven ways AI can strengthen your enterprise’s attack resilience. 1. Enhancing network and user monitoring AI can continuously monitor network and user activity while automating routine security tasks, says Leslie Daigle, CTO at the Global Cyber Alliance, a nonprofit organization of cybersecurity professionals. “Whether through behavioral analytics, machine learning models, or newer generative AI capabilities, AI can identify suspicious patterns and flag the most critical threats, so security teams can focus on the incidents that matter most,” she explains. AI works best when it’s integrated into your existing security program, not treated as a standalone tool, Daigle says. “Success requires close collaboration between cybersecurity, IT, and AI teams to ensure models that are accurate, reliable, and aligned with your organization’s specific threat model and risk tolerance,” she notes. That alignment isn’t a one-time setup, however. “Models need ongoing validation, since they can drift, miss novel attack patterns outside their training data, or be manipulated through adversarial inputs,” Daigle says. 2. Providing deeper visibility into your security posture Most security teams drown in data collected by dozens of tools, yet can’t see how well their program is performing, says Sivan Tehila, a professor at Yeshiva University’s Katz School and CEO of cybersecurity platform provider Onyxia Cyber. “An AI agent lets them ask a plain-language question — such as ‘which users are registered without MFA?’ — and get an immediate, prioritized answer instead of a week of manual work,” she says. AI removes the real bottleneck — analysis time, Tehila says. “It also shifts the posture from ‘prove nothing is broken’ to ‘prove the program is improving.’” 3. Streamlining the SOC One of the most impactful uses for enterprise security is applying AI to security operations center (SOC) activities, particularly threat detection, alert triage, investigation, and response, says Marc Vael, director of global digital trust at graphics art design packaging firm Esko. Millions of security events are generated every day, making it virtually impossible for any enterprise to handle them manually or even automated without proper insights into normal company behavior, Vael states. Fortunately, AI can be used to correlate signals, identify suspicious patterns, prioritize high-risk events, and provide security analysts with insights much faster than traditional rule-based solutions. “AI can also quickly detect a potential account compromise, insider threats, data exfiltration attempts, and emerging attack techniques that may not match known attack signatures,” he says. This approach’s effectiveness comes from AI’s ability to process and correlate vast amounts of data at high speed, Vael says. Security and IT teams are routinely overwhelmed by false positives and often suffer alert fatigue. “AI helps reduce the noise by identifying the events which most likely represent genuine cyberthreats,” he says. “AI can also shorten the time required to investigate security events by automatically gathering evidence, summarizing findings, and recommending response actions.” 4. Connecting the dots on otherwise unsuspicious activities Traditional cybersecurity focuses on suspicious activities. “With AI, organizations can check whether this activity makes sense,” says Neil Sahota, chief AI officer at financial services firm Consolidated Analytics. Sahota states that most successful attacks no longer rely on sophisticated malware: “They exploit normal behavior — individual events that often appear perfectly acceptable.” Danger emerges when such events — which may look completely normal until you connect the dots — causes a breach. “Unfortunately, people can’t synthesize millions of relationships across identity systems, network telemetry, financial transactions, HR records, cloud infrastructure, and third-party intelligence in real-time. AI, however, can handle the assignment with ease,” he says. Sahota suggests deploying AI as a decision-making partner before allowing it to take autonomous action. “Let analysts observe recommendations, measure performance, build trust, and gradually automate well-understood decisions once confidence is established,” he advises. “Security AI should earn authority the same way employees do.” 5. Reducing data loss and management protection AI is better positioned than humans to distinguish routine business activity from genuine risk by evaluating context — such as a user’s role, the data’s destination, and the timing of the activity — rather than relying solely on static rules that often produce excessive false positives, says Swathi Joshi, senior vice president of cyber defense at credit reporting service TransUnion. Joshi adds that AI can also establish behavioral baselines for employees and service accounts over time, then identify meaningful deviations that may indicate emerging risk. “This helps uncover slow-moving or subtle patterns that point-in-time controls frequently miss.” 6. Providing security team relief The biggest gift AI gives security teams is allowing them to speed through boring, high-volume work, by sorting signal from noise across logs, access patterns, and endpoint alerts faster than any analyst can, says Andrew Citro, CISO at Reltio, an SAP company that offers a cloud-native SaaS platform for real-time data unification and multidomain master data management. “This is where I would focus first.” To test this approach, Citro suggests selecting one narrow, painful use case, such as alert triage, phishing detection, or whatever is currently burning the most analyst hours, and then prove AI’s activities with a human reviewing every decision. “Resist the urge to automate broadly on day one.” 7. Uniting signals with intelligence Use AI to create an intelligent investigation layer that continuously brings together signals across the enterprise, understands their context, and helps security teams make faster, better decisions, says Kuldeep Thakur, CISO at data analytics and technology services firm Incedo. That’s a fundamentally different role for AI, Thakur says. “It shifts security from simply generating alerts to continuously producing insights and taking actions,” he explains. For over a decade, security spending added more sensors, more dashboards, and more alerts, leaving a thin layer of exhausted humans to make sense of it all, Thakur says. “Most analysts today will tell you that their real fear isn’t a threat they can’t detect — it’s a real incident that’s buried deep in the noise.” AI essentially takes an alert and does what a Tier-1 analyst would do, which is to pull context across identity, endpoint, cloud, and network functions, correlates the signals, and assembles the threat story in minutes instead of hours. “The human only steps in where judgment actually matters,” Thakur concludes.
Read full story at CSO Online →