Security's AI dilemma: Moving faster while risking more

Presented by Splunk, a Cisco Company


As artificial intelligence (AI) continues to advance, the role of Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs) becomes increasingly challenging. They must harness the power of AI while maintaining human oversight and strategic thinking in cybersecurity. The emergence of AI in security operations is transforming the industry, but finding the right balance between automation and accountability is crucial.

The Efficiency Paradox: Balancing Automation and Human Involvement

There is immense pressure on organizations to adopt AI to streamline processes and enhance productivity. However, it’s essential to understand that while AI can automate tasks and accelerate workflows, human judgment is still irreplaceable, especially in critical decision-making processes. Security analysts should focus on higher-value tasks while leveraging AI for routine activities.

The Trust Deficit: Transparency in AI-Driven Decisions

While AI can improve efficiency, there is a lingering skepticism around the quality of AI-driven decisions. Security teams need transparency into how AI reaches its conclusions to build trust and validate its logic. Maintaining a human-in-the-loop approach is essential for complex judgment calls.

The Adversarial Advantage: Using AI Defensively

AI presents both opportunities and risks in cybersecurity. Defenders must be cautious in implementing AI to prevent vulnerabilities, while attackers can exploit AI tools to their advantage. It’s crucial to learn from attackers’ techniques and use AI defensively with appropriate safeguards.

The Skills Dilemma: Balancing AI Adoption with Skill Development

As AI takes on routine tasks, there is a concern about security professionals’ skills becoming obsolete. Organizations must invest in skill development programs to ensure that employees evolve alongside AI technologies. Employees must also embrace continuous learning to collaborate effectively with AI.

The Identity Crisis: Managing Identity and Access in an AI-Powered World

Identity and access management become increasingly complex in a world with numerous AI agents. Proper governance and access control measures are essential to mitigate risks associated with AI agents. Organizations must implement governance frameworks that prevent unauthorized access and maintain security.

The Data Foundation: Essential for AI-Powered Security Operations

Successful AI implementation in security operations relies on a solid data foundation. Security Operations Center (SOC) teams must address data challenges, such as siloed data and disparate tools, to enable AI to function effectively. Accessible, quality data enriched with metadata is crucial for AI-powered security operations.

The Path Forward: Embracing AI with Intentionality

The future of security operations involves a collaborative approach between humans and AI. By embracing AI’s efficiency gains while maintaining human judgment and oversight, organizations can achieve optimal cybersecurity outcomes. The key is to view AI as a collaborative partner rather than a replacement for critical thinking.


Tanya Faddoul, VP Product, Customer Strategy and Chief of Staff for Splunk, a Cisco Company. Michael Fanning is Chief Information Security Officer for Splunk, a Cisco Company.

Cisco Data Fabric provides the needed data architecture powered by Splunk Platform — unified data fabric, federated search capabilities, comprehensive metadata management — to unlock AI and SOC’s full potential. Learn more about Cisco Data Fabric.


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.