Enterprise security teams face a widening gap between the volume of threats and their capacity to respond. AI is emerging as the primary tool for closing it, with applications ranging from continuous network monitoring to automated threat investigation. Seven security executives and researchers outlined how AI can strengthen attack resilience, and their advice centers on a common theme: AI works best when it augments human judgment rather than replacing it.
"The development of agentic AI - systems that can learn, make informed decisions, act autonomously, and even adapt their reasoning in pursuit of goals - will take us into a new revolution of cybersecurity," said Sheetal Mehta, global head of cybersecurity at NTT DATA.
Monitoring and visibility
AI can continuously monitor network and user activity while automating routine security tasks, said Leslie Daigle, CTO at the Global Cyber Alliance. "Whether through behavioral analytics, machine learning models, or newer generative AI capabilities, AI can identify suspicious patterns and flag the most critical threats, so security teams can focus on the incidents that matter most."
Daigle cautioned that AI works best when integrated into an existing security program, not treated as a standalone tool. "Success requires close collaboration between cybersecurity, IT, and AI teams to ensure models that are accurate, reliable, and aligned with your organization's specific threat model and risk tolerance." That alignment requires ongoing validation, she said, since models "can drift, miss novel attack patterns outside their training data, or be manipulated through adversarial inputs."
Most security teams drown in data collected by dozens of tools yet can't see how well their program is performing, said Sivan Tehila, a professor at Yeshiva University's Katz School and CEO of cybersecurity platform provider Onyxia Cyber. "An AI agent lets them ask a plain-language question - such as 'which users are registered without MFA?' - and get an immediate, prioritized answer instead of a week of manual work." AI removes the real bottleneck, analysis time, she said, and "shifts the posture from 'prove nothing is broken' to 'prove the program is improving.'"
Streamlining security operations
One of the most impactful uses for enterprise security is applying AI to security operations center (SOC) activities, particularly threat detection, alert triage, investigation, and response, said Marc Vael, director of global digital trust at graphics design firm Esko. Millions of security events are generated daily, making manual handling impossible. AI can correlate signals, identify suspicious patterns, prioritize high-risk events, and provide analysts with insights faster than traditional rule-based systems.
"AI can also quickly detect a potential account compromise, insider threats, data exfiltration attempts, and emerging attack techniques that may not match known attack signatures," Vael said. Its effectiveness comes from processing vast amounts of data at high speed, he added. "AI helps reduce the noise by identifying the events which most likely represent genuine cyberthreats. AI can also shorten the time required to investigate security events by automatically gathering evidence, summarizing findings, and recommending response actions."
Traditional cybersecurity focuses on suspicious activities. "With AI, organizations can check whether this activity makes sense," said Neil Sahota, chief AI officer at financial services firm Consolidated Analytics. Most successful attacks no longer rely on sophisticated malware, he said - "they exploit normal behavior, individual events that often appear perfectly acceptable." Danger emerges when such events, which may look normal until connected, cause a breach.
"People can't synthesize millions of relationships across identity systems, network telemetry, financial transactions, HR records, cloud infrastructure, and third-party intelligence in real-time. AI, however, can handle the assignment with ease," Sahota said. He recommends deploying AI as a decision-making partner before allowing autonomous action. "Let analysts observe recommendations, measure performance, build trust, and gradually automate well-understood decisions once confidence is established. Security AI should earn authority the same way employees do."
Data protection and team relief
AI is better positioned than humans to distinguish routine business activity from genuine risk by evaluating context - such as a user's role, the data's destination, and the timing of the activity - rather than relying on static rules that often produce excessive false positives, said Swathi Joshi, senior vice president of cyber defense at credit reporting service TransUnion. AI can also establish behavioral baselines for employees and service accounts over time, then identify meaningful deviations that may indicate emerging risk. "This helps uncover slow-moving or subtle patterns that point-in-time controls frequently miss," she said.
The biggest gift AI gives security teams is speed through high-volume work, sorting signal from noise across logs, access patterns, and endpoint alerts faster than any analyst can, said Andrew Citro, CISO at Reltio, an SAP company. "This is where I would focus first." He suggests selecting one narrow, painful use case - such as alert triage or phishing detection - and proving AI's value with a human reviewing every decision. "Resist the urge to automate broadly on day one."
For professionals looking to build these skills, AI for Cybersecurity Analysts covers threat detection and SOC optimization. Operations-focused teams can also explore AI for Operations for workflow improvement approaches that apply to security workflows.
Uniting signals with intelligence
AI can create an intelligent investigation layer that continuously brings together signals across the enterprise, understands their context, and helps security teams make faster decisions, said Kuldeep Thakur, CISO at data analytics firm Incedo. "It shifts security from simply generating alerts to continuously producing insights and taking actions."
For over a decade, security spending added more sensors, more dashboards, and more alerts, leaving a thin layer of exhausted humans to make sense of it all, Thakur said. "Most analysts today will tell you that their real fear isn't a threat they can't detect - it's a real incident that's buried deep in the noise." AI takes an alert and does what a Tier-1 analyst would do: pull context across identity, endpoint, cloud, and network functions, correlate the signals, and assemble the threat story in minutes instead of hours. "The human only steps in where judgment actually matters."
Why this matters for operations professionals
For operations leaders, the practical takeaway is to pick one narrow, high-volume security task - alert triage, phishing detection, or user access reviews - and pilot AI there with human oversight before scaling. The executives interviewed converge on the same sequence: prove accuracy on a defined use case, build trust with analysts, then expand automation gradually. Teams that skip that step risk deploying AI that generates more noise than it removes.
Your membership also unlocks: