AI Transforms Security Operations To Fight Growing Threats

AI Transforms Security Operations To Fight Growing Threats

Malik Haidar is a seasoned veteran in the high-stakes world of cybersecurity operations, having spent years defending some of the world’s largest multinational corporations from increasingly sophisticated digital threats. His career has been defined by a unique ability to bridge the gap between complex technical analytics and high-level business strategy, a skill set that is more critical than ever as organizations navigate the current surge of artificial intelligence. Malik’s expertise lies in transforming overwhelmed security centers into agile, intelligence-driven units that don’t just react to alerts but anticipate the moves of global adversaries.

The discussion centers on the radical transformation of security operations as AI moves from a testing phase into a daily operational necessity for nearly half of the industry. We explore the mounting pressure of alert fatigue, where massive volumes of data are stretching skeleton crews to their breaking point, and the dangerous trend of organizations silencing security sensors just to keep up. Malik provides insights into why internal AI development projects often falter compared to specialized platforms and how the time saved through automation is being redirected into proactive threat hunting. The conversation also highlights the evolving role of the human analyst, who is shifting from a data processor to a high-level investigator, even as privacy and explainability remain the final hurdles to full autonomy.

With many security teams now receiving upwards of 1,000 alerts daily, how is the sheer volume of data fundamentally changing the way analysts approach their work in 2026?

The sheer weight of 1,000 daily alerts creates a suffocating environment where analysts feel like they are perpetually running behind a clock that never stops. When you consider that it takes an average of 75 minutes to thoroughly investigate just one alert, the math simply doesn’t work for a team of ten people. We are seeing a dangerous gap where alerts sit untouched for nearly an hour, which is a lifetime in a world where attackers can achieve a breakout and move through a network in just 29 minutes. This sensory overload forces teams to make impossible choices about what to ignore, leading to a state of chronic exhaustion and a reactive posture that favors the attacker.

We are seeing reports that some organizations are actually turning off security alerts because they lack the manpower to check them; what are the long-term risks of narrowing coverage in this way?

Turning off alerts is essentially flying a plane and deciding to ignore the engine warning lights because there are too many of them to read. While tuning a noisy rule is good engineering, roughly 40% of organizations are silencing sensors simply because they are overwhelmed, which creates massive “dark zones” in their defense architecture. The data shows that 60% of respondents have seen a missed or ignored alert turn into a full-blown data breach or major system downtime, often multiple times in a single year. By narrowing their field of vision, these teams aren’t just missing noise; they are missing the subtle footprints of an intrusion that could cost the company millions in the long run.

As hackers increasingly adopt AI for phishing and deepfake scams, how does the defensive strategy need to evolve to counter these machine-speed threats?

Defensive strategies can no longer rely on human reflexes alone because the 56% increase in AI-driven attacks, particularly in finance and healthcare, happens at a speed that humans cannot match. We are seeing AI-generated malware and deepfake audio scams that are so convincing they bypass traditional behavioral training, making the old “check the sender’s email address” advice obsolete. To counter this, security operations must deploy their own AI to monitor for patterns that are invisible to the naked eye, such as massive credential-stuffing attacks or subtle anomalies in network traffic. The goal is to move from a “detect and respond” model to one of “continuous validation,” where the system itself identifies and neutralizes the threat before a human analyst even has to look at a screen.

Given that over 70% of teams tried to build their own internal AI tools but nearly half of those projects were abandoned, why is it so difficult for companies to create durable in-house security AI?

Building a custom AI for security is a monumental task that requires not just coding skill, but a deep understanding of the rapidly shifting threat landscape. While 72% of users initially thought they could build an autonomous SOC in-house, they quickly realized that maintaining the durability of these tools is nearly impossible without a dedicated platform. Almost 46% of these DIY projects never reached production because they couldn’t keep up with the speed of new attack vectors or they lacked the sophisticated integration needed for different tools like EDR and identity management. Companies eventually find that it is far more efficient to use a commercial product that is already battle-tested, allowing their internal teams to focus on strategy rather than constant software maintenance.

Why does a majority of security professionals still insist on having a human review every AI decision, even when the AI’s conclusions are largely accurate?

Trust in cybersecurity is earned in inches and lost in miles, so it is no surprise that 57% of teams still require a human to sign off on every AI-driven action before closing an alert. Even though AI has cut investigation times by 25 minutes per alert for the vast majority of users, there is a lingering fear of “black box” logic where a machine might take an action that disrupts critical business operations. Currently, AI acts primarily as a senior assistant, recommending actions for the 44% of teams that prefer to execute the final step themselves. This human-in-the-loop requirement is a safety mechanism to ensure that the AI’s logic aligns with the specific nuances and risk tolerance of that particular business.

How is the time saved by AI—roughly 25% of the typical investigation cycle—being redirected to improve the overall security posture of these organizations?

The time we are getting back is being funneled into the most critical and underfunded part of security: proactive threat hunting. When analysts aren’t drowning in basic triage, they can actually look for the hidden threats that automated tools might miss, which has already led to a 38% discovery rate of malicious activity that was otherwise invisible. We see a dramatic difference in results here, where teams that hunt weekly have a 49% hit rate compared to a dismal 8% for those who never have the time to look. This shift allows the SOC to move from being a “cost center” that manages alerts to an “intelligence center” that actively hardens the organization’s defenses.

With team sizes remaining largely static despite the introduction of AI, what does the career path of a Tier 1 or Tier 2 analyst look like now?

The traditional Tier 1 role of “alert monkey” is rapidly disappearing, but it’s being replaced by something far more engaging and intellectually demanding. Instead of firing staff, 57% of companies are keeping their team sizes the same but elevating their people into roles focused on incident response, defense testing, and advanced hunting. Analysts are becoming “orchestrators” who oversee the AI’s work, fine-tuning the detection engines and handling the complex, high-stakes investigations that require human intuition. It’s an exciting time because it removes the burnout-inducing repetitive tasks and allows security pros to actually use the advanced skills they’ve spent years developing.

What are the primary hurdles currently preventing organizations from granting AI full autonomy in their security operations?

The two biggest roadblocks are data privacy and the “explainability” of the AI’s decision-making process. About 44% of security leaders are deeply concerned about how their sensitive data is used to train AI models and whether that information could leak or be exploited. Additionally, 41% of teams need to know exactly why an AI reached a conclusion; they won’t accept a simple “risk score” without a complete audit trail of every query and piece of evidence retrieved. Until vendors can provide single-tenant deployments that run within a customer’s own cloud and offer transparent, evidence-backed determinations, full unsupervised autonomy will remain out of reach for most.

Can you share a specific instance where an agentic AI platform like Prophet Security has significantly impacted a company’s operational efficiency?

One of the most striking examples is our work with JB Poindexter, where the implementation of an agentic AI platform fundamentally changed their defensive timeline. By automating the investigation of every alert across their entire stack, they managed to bring the mean time to investigate down to under four minutes. Over the course of their operations, this avoided a staggering 1,469 analyst hours that would have otherwise been spent on manual, repetitive triage. This wasn’t just about speed; it was about the depth of the investigation, providing a full audit trail that allowed their human team to verify every step and redirect their energy toward higher-level security architecture.

What is your forecast for the evolution of the autonomous SOC over the next two years?

By 2028, I expect the “human-in-the-loop” model to evolve into “human-on-the-loop,” where the AI handles the vast majority of remediations autonomously and humans only step in for the most extreme edge cases. We will see the total disappearance of the “missed alert” phenomenon as agentic AI becomes capable of investigating 100% of signals, regardless of severity, at a depth that matches a senior analyst. Privacy concerns will likely be solved through localized, on-premise model execution, and the primary role of the CISO will shift from managing headcount to managing the “trust parameters” of their AI workforce. Ultimately, the winners will be the organizations that stop trying to out-hire the problem and start using AI to out-think the adversary.

subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address
subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address