Seven Ways AI Is Changing How Companies Defend Themselves
Security experts say artificial intelligence is giving overstretched security teams a fighting chance, but only if organisations deploy it carefully and with realistic expectations.

Key points
- Security teams today receive millions of alerts every day, far more than any human team can review without help.
- AI can sort genuine threats from harmless noise in minutes, a task that can take analysts hours or days by hand.
- Experts from NTT DATA, TransUnion, and several universities contributed practical guidance, first reported by CSO Online.
- Getting AI right requires ongoing human oversight; left unchecked, the models can drift or be tricked by attackers.
- Ordinary employees play a role too: how they use company systems shapes the data AI learns from.
Picture a hospital control room where alarms go off constantly. Most are false. A handful matter. The nurses can only check so many. That, roughly, is what corporate security teams live with every day, only the alarms are millions of digital warnings called alerts, and missing the real ones can mean a serious data breach.
Artificial intelligence is increasingly being used to manage that flood. Here is what the experts say it can actually do, and where the limits are.
What can AI do that humans simply cannot?
The honest answer: process scale. A skilled analyst might review hundreds of events in a shift. AI systems can review millions at the same time, connecting patterns across a company's email logs, login records, cloud files, and network traffic simultaneously.
Neil Sahota, chief AI officer at Consolidated Analytics, points out that most successful attacks today do not rely on dramatic, movie-style hacking. "They exploit normal behaviour, individual events that often appear perfectly acceptable." A single login from an unusual location looks fine. Paired with a large file download at 3 a.m. and a password reset the day before, it tells a different story. Humans struggle to hold millions of such relationships in mind at once. AI does not.
Sivan Tehila, a professor at Yeshiva University's Katz School and CEO of cybersecurity platform provider Onyxia Cyber, adds a more practical example. A security manager can simply ask the AI system, in plain English, "which users are registered without MFA?" (MFA, or multi-factor authentication, means requiring a second proof of identity beyond a password, like a code sent to a phone.) Instead of a week of manual database work, an answer comes back in seconds.
Should ordinary employees care?
Yes, in a practical sense. AI security systems learn what "normal" looks like by watching how real employees use company systems every day. Swathi Joshi, senior vice president of cyber defense at credit reporting firm TransUnion, explains that this lets AI spot meaningful changes: a contractor downloading far more files than usual, or a service account (an automated system login) suddenly accessing sensitive records it has never touched.
The takeaway for regular staff is simple. Unusual requests, whether by email, phone, or internal message, asking you to log in somewhere new, hand over a password, or move files, deserve a second look before you act.
Kuldeep Thakur, chief information security officer at data analytics firm Incedo, puts the broader problem plainly: "Most analysts today will tell you that their real fear isn't a threat they can't detect, it's a real incident that's buried deep in the noise." AI's job is to dig that incident out before it causes damage.
What are the risks of relying on AI for security?
AI is not a switch you flip and forget. Leslie Daigle, chief technology officer at the Global Cyber Alliance (a nonprofit network of cybersecurity professionals), warns that models can drift over time, gradually becoming less accurate as attack methods change. They can also miss entirely new attack patterns that were not in their original training data, or be deliberately confused by sophisticated attackers feeding them misleading signals.
Andrew Citro, chief information security officer at Reltio, offers grounded advice: start with one narrow problem, say filtering phishing emails (fake messages designed to steal passwords), and have a human review every decision the AI makes before trusting it to act alone. "Resist the urge to automate broadly on day one."
Sahota agrees. "Security AI should earn authority the same way employees do."



