Cybersecurity is accelerating, and acceleration changes how risk behaves. For a long time, attackers and defenders operated under similar constraints.
Investigations took time.
Decisions moved through people.
Controls relied on coordination and manual execution.
Well, that shared pace no longer exists.
Attackers now operate at machine speed. They develop exploits in record time, at lower cost, and use malware that can adapt continuously.
This then begs the question: If threats move at machine speed, what happens to a security program still designed around human tempo?
This question now sits at the center of cyber strategy. AI is already reshaping cybersecurity. The real issue is whether security programs can absorb that speed without losing governance, traceability and/or clear human authority. Or whether they will spiral out of control simply trying to keep up with the growing momentum.
Start with your cyber strategy, not an AI tool
The starting point should not be an AI tool. It should be your cyber strategy because adding AI features to the cyber stack is not enough. The real test is whether AI changes how context, decisions, and governed actions move through the program.
Leaders need to identify where the program is already under pressure: controls that are too slow, too manual, too inconsistent, or too dependent on scarce expertise. They should also look at where risk is accelerating faster than governance can respond across threats, identities, cloud, third parties, data, and regulatory expectations.
Those pressure points, not the availability of AI features, should determine where AI belongs. AI creates value when it improves control performance, not when it simply adds another layer to the security stack.
Here are some questions leaders need to ask:
Which part of the program is too slow for the risk?
Where are teams repeating the same analysis?
Where does evidence exist, but not flow?
Where would faster containment reduce exposure?
Where can AI safely support action, and where must a human remain in command?
AI beyond SOC
For many organizations, SOC was the first place AI entered the security program. That made sense. Security operations had visible pressure points: alert volume, manual enrichment, repetitive investigations and slow response. However, it is a different story today. Most organizations now have some return on experience from AI in SOC. They have tested copilots, alert summaries, investigation support, detection engineering assistance, case enrichment, or response recommendations.
The next SOC transformation phase is already underway with the implementation of agentic AI. Success will depend on how well organizations optimize mean time to detect, respond, and contain (MTTD, MTTR, and MTTC), so they can match pace with AI-speed attackers.
But the opportunity cannot stop at SOC. AI is especially valuable in high-volume, decision-heavy controls where context is fragmented and speed matters:
- Identity governance: Moving from quarterly access reviews to continuous certification, real-time risk-based provisioning, and behavioral detection across users, machines, service accounts, and privileged access
- Vulnerability and exposure management: Shifting from long severity queues to risk-based prioritization that combines exploitability, asset criticality, business impact and remediation ownership
- Cloud security: Correlating misconfigurations, permissions, identities, and workloads to recommend remediation paths that technical and risk teams can act on
- GRC and audit: Reducing the manual burden of regulatory mapping, evidence collection, and control narratives while improving consistency and traceability
These are the kinds of controls where AI can make a visible difference, leading to less waiting, better context, faster decisions and stronger evidence.
AI-painted security: Optical illusions?
The spread of AI across cybersecurity creates a real risk: mistaking AI features for cyber transformation. AI-painted security usually looks good at first. Dashboards feel smarter. Summaries arrive faster. Analysts get more help. But underneath, the same queues, handoffs, ownership gaps, and evidence problems often remain.
But if AI speeds up one step while the rest of the process stays unchanged, the gain is limited because the tempo of a security program is set by its slowest handoff. If AI accelerates one step but the next step still waits for a manual queue, an unclear owner or a legacy approval path, the program has not really changed.
The solution is not only in AI tools. It is also in reviewing and updating the underlying processes, decision paths, ownership models, and control workflows. Otherwise, the program remains only as fast as the handoff to the next human-led process.
Keep humans in command, not in the queue
AI does not remove humans from cybersecurity. It changes where they add the most value.
People should not spend their time gathering the same evidence, enriching the same alert, or routing the same ticket. That is exactly the work AI can help prepare, accelerate or automate within clear limits. Humans are needed where judgment matters: setting a risk appetite, defining boundaries, approving high-impact actions, resolving ambiguity, and taking responsibility when a decision affects customers, operations, legal exposure or trust.
This is the shift security leaders need to manage. Some work should remain human-led and AI-assisted. Some can become AI-led and human-approved. Some low-risk actions can be AI-executed within guardrails.
The design question is practical: what can AI do, what must a human approve, and what should AI never do?
That is how security programs gain speed without giving up control.
Measuring maturity in the AI era
AI can make a security program look more advanced without making it more effective. New tools, dashboards, and autonomous workflows can signal progress without improving outcomes. What really matters is whether the program actually performs better.
Maturity shows up under pressure
Does detection happen faster? Is containment quicker? Are false positives reduced? Are teams focusing on the exposures that truly matter? Are access decisions informed by real risk context? Can audit evidence be produced in a way that holds up to scrutiny?
That is the measure. Control performance, not AI activity. But that measure will be tested as AI gains autonomy and agency. As AI moves from support to recommendation and execution, maturity depends on three things:
- Governance must be built into the workflow. The process should clearly state what AI can do, what evidence it must show, when it must escalate, and where human approval is non-negotiable.
- Assurance has to become continuous. Annual reviews and point-in-time audits still matter, but they cannot keep pace with systems that change constantly. AI-enabled controls must be able to flag drift, declining confidence, accumulating exceptions, and moments where human intervention is required.
- Security of AI must be a core part of the AI-speed cyber program. AI cannot become the next unmanaged layer. Teams need visibility into active AI capabilities, the data they touch, the permissions they hold, and the actions they can trigger. That visibility must extend across the AI supply chain: models, prompts, retrieval sources, agents, tools, and runtime behavior.
That is the difference between moving fast and staying in command.
AI should not simply make cyber work faster. It should make the program more precise, more accountable, and more able to prove that control is still working as the environment changes.
Leaders are now faced with a strategic challenge — to ensure their cybersecurity programs can operate at AI speed and scalability without compromising governance, accountability or human authority. I would like to hear from you on how your organization is embracing this change at machine speed and bracing for the AI era in a pragmatic manner. Let’s connect.






