Seven Ways AI Is Changing How Companies Defend Themselves

Security experts say artificial intelligence is giving overstretched security teams a fighting chance, but only if organisations deploy it carefully and with realistic expectations.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
A security operations center with multiple analysts working at stations surrounded by large displays showing AI-powered threat detection dashboards and threat m
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Security teams receive millions of alerts every day, far more than any human team can review without help.
  • AI can sort genuine threats from harmless noise in minutes, a task that takes analysts hours or days by hand.
  • Practical guidance here comes from NTT DATA, TransUnion, and university researchers, first reported by CSO Online.
  • Getting AI right requires ongoing human oversight; left unchecked, models can drift or be tricked by attackers.
  • How ordinary employees use company systems shapes the data AI learns from, which makes their habits a security variable.

Picture a hospital control room where alarms go off constantly. Most are false. A handful matter. The nurses can only check so many. That, roughly, is what corporate security teams live with every day: the alarms are millions of digital warnings called alerts, and missing the real ones can mean a serious data breach.

Artificial intelligence is increasingly being used to manage that flood. Here is what it can actually do, and where the limits are. Our 19 August story "AI is already in your attacker's toolkit. Is it in your defences?" found a sharp gap between how confident security teams feel about AI-powered defences and how well those defences hold up under pressure, which makes the practical guidance below worth taking seriously.

What can AI do that humans simply cannot?

Process scale, plainly. A skilled analyst might review hundreds of events in a shift. AI systems can review millions simultaneously, connecting patterns across a company's email logs, login records, cloud traffic, and endpoint alerts at the same time.

Neil Sahota, chief AI officer at Consolidated Analytics, points out that most successful attacks today do not rely on dramatic, movie-style hacking. "They exploit normal behaviour, individual events that often appear perfectly acceptable." A single login from an unusual location looks fine. Paired with a large file download at 3 a.m. And a password reset the day before, it tells a different story. Humans struggle to hold millions of such relationships in mind at once. AI does not.

Sivan Tehila, a professor at Yeshiva University's Katz School and CEO of cybersecurity platform provider Onyxia Cyber, adds a practical example. A security manager can ask the AI system, in plain English, "which users are registered without MFA?" (MFA, or multi-factor authentication, means requiring a second proof of identity beyond a password, like a code sent to a phone.) Instead of a week of manual database work, an answer comes back in seconds.

Should ordinary employees care?

Yes, in a practical sense. AI security systems learn what "normal" looks like by watching how real employees use company systems every day. Swathi Joshi, senior vice president of cyber defense at credit reporting firm TransUnion, explains that this lets AI spot meaningful changes: a contractor downloading far more files than usual, or a service account (an automated system login) suddenly accessing sensitive records it has never touched.

For regular staff, the implication is direct. Unusual requests, whether by email or internal message, asking you to log in somewhere new, hand over a password, or move files, deserve a second look before you act.

Kuldeep Thakur, chief information security officer at data analytics firm Incedo, puts the broader problem plainly: "Most analysts today will tell you that their real fear isn't a threat they can't detect, it's a real incident that's buried deep in the noise." AI's job is to dig that incident out before it causes damage.

What are the risks of relying on AI for security?

AI is not a switch you flip and forget. Leslie Daigle, chief technology officer at the Global Cyber Alliance (a nonprofit network of cybersecurity professionals), warns that models can drift over time, gradually becoming less accurate as attack methods change. They can also miss entirely new attack patterns absent from their original training data, or be deliberately confused by sophisticated attackers feeding them misleading signals.

Andrew Citro, chief information security officer at Reltio, offers grounded advice: start with one narrow problem, say filtering phishing emails (fake messages designed to steal passwords), and have a human review every decision the AI makes before trusting it to act alone. "Resist the urge to automate broadly on day one."

Sahota agrees. "Security AI should earn authority the same way employees do."

The honest watch-point here is deployment pace. Every story on this beat eventually circles back to the same failure mode: teams buy the capability and skip the calibration. The technology is rarely the problem.

© 2026 Threat Vectr