With cybersecurity threats on the rise, security operations centers (SOCs) are drowning in a sea of alerts, making it difficult to weed out real danger from the noise. Under pressure to ward off attacks before they impact the business, security teams are desperate for relief.

Help comes in the form of AI and GenAI-enabled solutions that can quickly zero in on patterns in the data to pinpoint attacks, automate time-consuming and repetitive tasks, and most importantly, drive faster incident response.

Foundry reached out to the CIO Experts Network, a community of IT professionals and technology influencers, to explore how enterprises can harness the power of AI and GenAI to up their security game.

At a high level, AI algorithms parse through and analyze historical and real-time data to identify unusual patterns in asset behavior and alert security teams to potential intrusion, security breaches, or unauthorized access, says Robert Siciliano, CEO at Protect Now LLC.

Machine learning (ML) is playing a key role in analyzing all operational and security data to find correlations while AI/GenAI facilitates improved threat detection, response, and prevention, according to Issac Sacolick (@nyike), president of StarCIO and author of Digital Trailblazer. “One key advantage of AI over humans is that it can analyze vast amounts of data in real-time to identify anomalies and detect sophisticated attacks like zero-day malware and possible phishing attempts,” Sacolick says.

The respite couldn’t come at a better time. More than half of security operation center (SOC) practitioners worry they can’t keep pace with the growing number of security threats. At the same time, 71% fear they will miss a real attack buried in a flood of alerts, according to Vectra’s 2024 State of Threat Detection survey. There is real cause for concern: Vectra found SOC teams managing an average of 3,832 alerts daily, and the average cost of a data breach is now pegged at $4.88 million.

Vectra research confirmed companies are jumping on the AI/GenAI bandwagon to solve security challenges. Nearly all SOC practitioners (97%) have embraced AI tools and 85% confirmed an increased level of investment this year. Not only are the AI-powered tools facilitating threat detection and response, they are also helping security professionals work smarter, reduce workloads, and address burnout issues, the Vectra survey found.

Getting the job done

One key role for AI/GenAI technologies is facilitating user and asset identification. Specifically, organizations can tap AI and machine learning to determine user risk before granting access to systems and data, notes Jim Taylor, chief product and technology officer at RSA.

“By evaluating every user’s context—including their device, IP address, time of day, and the systems they are trying to access—and comparing it with prior behavior and organizational norms, organizations can make smarter, faster, and safer access decisions,” Taylor says. “Even better, organizations can use AI to automate step-up authentications and challenge users when their behavior becomes too risky.”

GenAI can assist in security training, letting employees experiment with real-world incidents and problem solving through simulation of various attack scenarios. This approach helps to bolster incident response and strengthen an organization against emerging threats.

On the hacking front, GenAI traction has both good and bad ramifications. Not surprisingly, the technology is increasingly being used by hackers to automate the creation of sophisticated phishing attacks, generate malicious code, and impersonate individuals with alarming accuracy. “This raises the stakes in the cybersecurity arms race as defenders must contend with an ever-evolving threat landscape fueled by the rapid advancements in AI,” says Chris Selland, partner at TechCXO.

At the same time, though, GenAI serves up powerful capabilities to counter GenAI-enabled threat vectors. Because the technology can diagnose environments and snuff out vulnerabilities on a 24X7 basis, GenAI can function as an “ethical hacker,” called on to explore the perimeter and shore up its defenses. “This enables organizations to patch weaknesses before they can be exploited and stay one step ahead of malicious actors,” Selland says.

While GenAI goes a long way in addressing cybersecurity pain points, the new genre of tools should complement, not replace human security professionals, cautions Scott Schober (@ScottBVS), president and CEO at Berkeley Varitronics Systems Inc. Humans in the loop will be an essential component to GenAI initiatives, including cybersecurity functions, Schober says.

“People often feel threatened or resentful towards AI as it marches closer to displacing them right out of a job, but these technologies actually support and complement human security teams,” he says. “They automate the repetitive tasks that we humans do not excel at. The results are actionable threat intelligence.”

Learn more about Lenovo’s AI advancements here.

Share
Share
Advertisement