SOC Teams Are Running Out of Road Without AI, Manchester Panel Warns

Security practitioners gathered at DTX Manchester to debate machine-versus-machine warfare, alert fatigue, and why the fundamentals still matter before any AI switch gets flipped.

ThreatVectr Newsdesk· 3 min read
SOC Teams Are Running Out of Road Without AI, Manchester Panel Warns
Share

Security operations centres that have not started integrating AI tools are already behind, according to panellists at the DTX conference in Manchester, who spoke during a session titled "Bot vs Bot: Surviving the Era of Autonomous Cyber Warfare." The consensus was direct: attackers are using AI to accelerate reconnaissance, phishing, and malware development, and defenders who rely on purely human-paced responses are being outflanked.

But the panel was not a sales pitch for any particular platform. Darren Kimuli, information security lead at reinsurance firm Canopius Group, told delegates that AI adoption must be shaped by what fits a business's operating model and regulatory obligations, not by vendor enthusiasm. "I'm more concerned about what AI fits rather than what it replaces," Kimuli said. That framing set the tone for a session that was, on balance, cautious.

Divine Uzodinma, cybersecurity analyst at managed services and telecom provider Radius, said AI tools are already helping analysts correlate and triage security logs, work that has historically consumed enormous amounts of human time. "AI can analyse and correlate logs and triage alerts while analysts continue with their investigation," Uzodinma said. Muhammad Khan, head of cybersecurity at Bridgewater Finance Group, added that reducing alert fatigue (a problem that has contributed to measurable staff burnout across the industry for years) is one of the more immediate returns AI delivers to stretched security teams.

Predictably, the panel also argued that AI is no substitute for security basics. System hardening, patching, access controls, and monitoring remain the ground layer. Without those in place, bolting on AI creates new risk rather than reducing it. Secarma senior cybersecurity consultant George Rees noted that enterprises need to test AI-based security systems against realistic attack paths, including application-layer attacks, cloud misconfigurations, and supplier access abuse, before trusting them in production.

Kelly Bissell, former corporate VP of product abuse and risk at Microsoft, opened the conference with a keynote on AI and cyber resilience. He was direct about the asymmetry: attackers can ignore privacy regulations and other legal constraints that defenders must observe, which gives them a degree of operational freedom. But scale, said Bissell, can close that gap. At Microsoft, machine learning applied to behavioural data allowed the team to build a neural network capable of detecting typosquatted domains being registered ahead of impersonation campaigns, with low false positive rates. "Our mission was to apply pressure to bot gangs," Bissell said.

Bissell also offered a taxonomy of CISOs: compliance-orientated, package-focused, or elite practitioners. The last group, he argued, will use AI to sharpen operations, but only after subjecting new tooling to something resembling a software development life cycle, including extensive penetration testing and guardrails before any production deployment. So the advice is essentially the same advice security professionals have been giving for decades, applied to a newer class of tool.

Rees added that skills such as prompt engineering and risk analysis are growing in importance, and that AI is creating demand for more governance, risk, and compliance hires. The analogy Rees reached for was the shift from typewriters to computers in the 1970s and 1980s: disorienting in the moment, and not something organisations could simply opt out of.

The debate has moved on from whether to adopt AI in security. The question now is how to do it without handing oversight to a system nobody fully understands.

© 2026 Threat Vectr