{"id":9216,"date":"2026-08-24T08:25:00","date_gmt":"2026-08-24T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9216"},"modified":"2026-08-24T08:25:00","modified_gmt":"2026-08-24T08:25:00","slug":"7-ways-ai-can-be-used-to-enhance-security-operations","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9216","title":{"rendered":"7 ways AI can be used to enhance security operations"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">AI has an almost unlimited number of applications, yet none may be more important than its ability to strengthen enterprise security.<\/p>\n<p class=\"wp-block-paragraph\">AI marks a new era of business transformation in which AI autonomy and innovation converge to redefine how people, processes, and technology interact, says Sheetal Mehta, global head of cybersecurity at NTT DATA. \u201cThe development of agentic AI \u2014 systems that can learn, make informed decisions, act autonomously, and even adapt their reasoning in pursuit of goals \u2014 will take us into a new revolution of cybersecurity.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Is your organization doing everything it can to take advantage of AI\u2019s formidable security power? Here\u2019s a look at seven ways AI can strengthen your enterprise\u2019s attack resilience.<\/p>\n<h2 class=\"wp-block-heading\">1. Enhancing network and user monitoring<\/h2>\n<p class=\"wp-block-paragraph\">AI can continuously monitor network and user activity while automating routine security tasks, says Leslie Daigle, CTO at the Global Cyber Alliance, a nonprofit organization of cybersecurity professionals. \u201cWhether through behavioral analytics, machine learning models, or newer generative AI capabilities, AI can identify suspicious patterns and flag the most critical threats, so security teams can focus on the incidents that matter most,\u201d she explains.<\/p>\n<p class=\"wp-block-paragraph\">AI works best when it\u2019s integrated into your existing security program, not treated as a standalone tool, Daigle says. \u201cSuccess requires close collaboration between cybersecurity, IT, and AI teams to ensure models that are accurate, reliable, and aligned with your organization\u2019s specific threat model and risk tolerance,\u201d she notes.<\/p>\n<p class=\"wp-block-paragraph\">That alignment isn\u2019t a one-time setup, however. \u201cModels need ongoing validation, since they can drift, miss novel attack patterns outside their training data, or be manipulated through adversarial inputs,\u201d Daigle says.<\/p>\n<h2 class=\"wp-block-heading\">2. Providing deeper visibility into your security posture<\/h2>\n<p class=\"wp-block-paragraph\">Most security teams drown in data collected by dozens of tools, yet can\u2019t see how well their program is performing, says Sivan Tehila, a professor at Yeshiva University\u2019s Katz School and CEO of cybersecurity platform provider Onyxia Cyber.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAn AI agent lets them ask a plain-language question \u2014 such as \u2018which users are registered without MFA?\u2019 \u2014 and get an immediate, prioritized answer instead of a week of manual work,\u201d she says.<\/p>\n<p class=\"wp-block-paragraph\">AI removes the real bottleneck \u2014 analysis time, Tehila says. \u201cIt also shifts the posture from \u2018prove nothing is broken\u2019 to \u2018prove the program is improving.\u2019\u201d<\/p>\n<h2 class=\"wp-block-heading\">3. Streamlining the SOC<\/h2>\n<p class=\"wp-block-paragraph\">One of the most impactful uses for enterprise security is <a href=\"https:\/\/www.csoonline.com\/article\/4175349\/ai-becoming-an-soc-imperative-for-curtailing-emerging-cyber-threats.html\">applying AI to security operations center (SOC) activities<\/a>, particularly threat detection, alert triage, investigation, and response, says Marc Vael, director of global digital trust at graphics art design packaging firm Esko.<\/p>\n<p class=\"wp-block-paragraph\">Millions of security events are generated every day, making it virtually impossible for any enterprise to handle them manually or even automated without proper insights into normal company behavior, Vael states. Fortunately, AI can be used to correlate signals, identify suspicious patterns, prioritize high-risk events, and provide security analysts with insights much faster than traditional rule-based solutions.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAI can also quickly detect a potential account compromise, insider threats, data exfiltration attempts, and emerging attack techniques that may not match known attack signatures,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">This approach\u2019s effectiveness comes from AI\u2019s ability to process and correlate vast amounts of data at high speed, Vael says. Security and IT teams are routinely overwhelmed by false positives and often suffer alert fatigue.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAI helps reduce the noise by identifying the events which most likely represent genuine cyberthreats,\u201d he says. \u201cAI can also shorten the time required to investigate security events by automatically gathering evidence, summarizing findings, and recommending response actions.\u201d<\/p>\n<h2 class=\"wp-block-heading\">4. Connecting the dots on otherwise unsuspicious activities<\/h2>\n<p class=\"wp-block-paragraph\">Traditional cybersecurity focuses on suspicious activities. \u201cWith AI, organizations can check whether this activity makes sense,\u201d says Neil Sahota, chief AI officer at financial services firm Consolidated Analytics.<\/p>\n<p class=\"wp-block-paragraph\">Sahota states that most successful attacks no longer rely on sophisticated malware: \u201cThey exploit normal behavior \u2014 individual events that often appear perfectly acceptable.\u201d Danger emerges when such events \u2014 which may look completely normal until you connect the dots \u2014 causes a breach.<\/p>\n<p class=\"wp-block-paragraph\">\u201cUnfortunately, people can\u2019t synthesize millions of relationships across identity systems, network telemetry, financial transactions, HR records, cloud infrastructure, and third-party intelligence in real-time. AI, however, can handle the assignment with ease,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Sahota suggests deploying AI as a decision-making partner before allowing it to take autonomous action. \u201cLet analysts observe recommendations, measure performance, build trust, and gradually automate well-understood decisions once confidence is established,\u201d he advises. \u201cSecurity AI should earn authority the same way employees do.\u201d<\/p>\n<h2 class=\"wp-block-heading\">5. Reducing data loss and management protection<\/h2>\n<p class=\"wp-block-paragraph\">AI is better positioned than humans to distinguish routine business activity from genuine risk by evaluating context \u2014 such as a user\u2019s role, the data\u2019s destination, and the timing of the activity \u2014 rather than relying solely on static rules that often produce excessive false positives, says Swathi Joshi, senior vice president of cyber defense at credit reporting service TransUnion.<\/p>\n<p class=\"wp-block-paragraph\">Joshi adds that AI can also establish behavioral baselines for employees and service accounts over time, then <a href=\"https:\/\/www.csoonline.com\/article\/3822459\/what-is-anomaly-detection-behavior-based-analysis-for-cyber-threats.html\">identify meaningful deviations<\/a> that may indicate emerging risk. \u201cThis helps uncover slow-moving or subtle patterns that point-in-time controls frequently miss.\u201d<\/p>\n<h2 class=\"wp-block-heading\">6. Providing security team relief<\/h2>\n<p class=\"wp-block-paragraph\">The biggest gift AI gives security teams is allowing them to speed through boring, high-volume work, by sorting signal from noise across logs, access patterns, and endpoint alerts faster than any analyst can, says Andrew Citro, CISO at Reltio, an SAP company that offers a cloud-native SaaS platform for real-time data unification and multidomain master data management. \u201cThis is where I would focus first.\u201d<\/p>\n<p class=\"wp-block-paragraph\">To test this approach, Citro suggests selecting one narrow, painful use case, such as alert triage, phishing detection, or whatever is currently burning the most analyst hours, and then prove AI\u2019s activities with a human reviewing every decision. \u201cResist the urge to automate broadly on day one.\u201d<\/p>\n<h2 class=\"wp-block-heading\">7. Uniting signals with intelligence<\/h2>\n<p class=\"wp-block-paragraph\">Use AI to create an intelligent investigation layer that continuously brings together signals across the enterprise, understands their context, and helps security teams make faster, better decisions, says Kuldeep Thakur, CISO at data analytics and technology services firm Incedo.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s a fundamentally different role for AI, Thakur says. \u201cIt shifts security from simply generating alerts to continuously producing insights and taking actions,\u201d he explains.<\/p>\n<p class=\"wp-block-paragraph\">For over a decade, security spending added more sensors, more dashboards, and more alerts, leaving a thin layer of exhausted humans to make sense of it all, Thakur says. \u201cMost analysts today will tell you that their real fear isn\u2019t a threat they can\u2019t detect \u2014 it\u2019s a real incident that\u2019s buried deep in the noise.\u201d<\/p>\n<p class=\"wp-block-paragraph\">AI essentially takes an alert and does what a Tier-1 analyst would do, which is to pull context across identity, endpoint, cloud, and network functions, correlates the signals, and assembles the threat story in minutes instead of hours. \u201cThe human only steps in where judgment actually matters,\u201d Thakur concludes.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>AI has an almost unlimited number of applications, yet none may be more important than its ability to strengthen enterprise security. AI marks a new era of business transformation in which AI autonomy and innovation converge to redefine how people, processes, and technology interact, says Sheetal Mehta, global head of cybersecurity at NTT DATA. \u201cThe [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9217,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9216","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9216"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9216"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9216\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9217"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}