AI doesn’t need another dashboard. Needs permission to act – Unite.AI
For years, cybersecurity has been obsessed with visibility. We wanted to see more areas of the network, collect more telemetry data, correlate more events, and detect threats earlier. So we created dashboards. So we built better dashboards. Then we added machine learning to those dashboards. Now we are adding artificial intelligence.
But at some point we have to ask ourselves the obvious question: Once we see the attack, what are we actually prepared to do about it? I don’t think the next big cybersecurity problem will be detection. I think it will be authority.
AI potentially gives us something security teams have wanted for decades: the ability to identify, understand, and respond to an attack at machine speed. This is important because attacks are increasingly happening at a rate that the traditional SOC model simply cannot keep up with.
Yet many organizations are implementing AI in exactly the same operating model as before. The technology can detect something in seconds, perhaps figure out what’s happening and recommend the appropriate response, but someone still has to sign off on what happens next.
At that point you have not yet built an autonomous defense. You’ve built an extraordinarily sophisticated alarm system. There is a contradiction here that we must face. We’ve spent years saying security teams are overwhelmed. There are too many alarms, too much infrastructure, too few qualified people and not enough time to investigate everything. We complain that humans can’t respond quickly enough.
So we introduce technology that can respond faster than humans and refuse to give it permission to act.
It doesn’t make sense. If I don’t have a mandate to respond to something while it’s happening, I will always do an autopsy afterwards. It doesn’t matter how smart the detection technology is. If the response mechanism is still waiting for someone to make a decision, the attacker retains the advantage.
Autonomous defense requires clear response authority
And this isn’t simply a problem created by AI. Most organizations have not adequately addressed the issue of response authority for their human security teams either.
Who is actually authorized to isolate a car? Who can take a server offline? Who has the authority to stop a production process because there is evidence of an attack? In many organizations, such decisions are still unclear, are negotiated during an incident or escalated through management levels.
AI simply reveals how unsustainable that model has become.
If we truly want autonomous defense, the mandate must come from above. Boards and executive teams need to decide what authority they are willing to give their security systems before the attack occurs, not while everyone is watching it unfold. But giving AI permission to act creates another problem.
AI needs asset intelligence and business context
You also need to provide enough context to make the right decision. Imagine that an AI system detects an infiltration on a machine and determines that the safest technical response is to isolate it. From a cybersecurity perspective, this may be absolutely correct.
Now imagine that the machine controls a production line generating a million pounds an hour.
Suddenly the technically correct decision could be the wrong business decision.
Perhaps the threat is contained enough that a repair can be made over several hours without shutting down the machine. Perhaps taking it offline does far more harm than allowing it to continue to function temporarily under tighter controls.
The AI can’t make this distinction unless the organization has told it what that asset is, what it does, and what happens to the business if it disappears. This is why asset knowledge and business context become so important in an AI-powered SOC.
Security teams have been talking about asset management for decades, and frankly, many organizations still don’t know what they have.
Shadow IT has made this difficult enough. Business units purchase servers, deploy applications, and connect devices without security necessarily knowing. Then we added cloud infrastructure, remote working, SaaS and increasingly distributed environments. The idea of an orderly perimeter containing a perfectly maintained inventory disappeared years ago.
We tolerated this when the operating model was largely reactive. When something serious happened, an analyst would investigate and try to establish the context.
This becomes much more complicated when AI is expected to make decisions autonomously.
An autonomous system needs to know that it’s not just IP address
Without such knowledge, autonomy becomes a hypothesis. Paradoxically, this is also an area where AI itself can help. It can discover and classify assets, identify relationships, find systems no one realized existed, and contact entrepreneurs for missing context. Maintaining an accurate asset database doesn’t have to remain the horrible, manual, multi-year exercise that organizations have historically done.
However, the information must exist somewhere. If the organization itself doesn’t understand what an asset does or how important it is, we can’t reasonably expect an AI system to make an intelligent business decision about it.
Defining the boundaries of autonomous cybersecurity
This is why I believe the conversation about AI in SOC needs to go beyond models and detection rates.
The technology is becoming powerful enough.
The more important question is whether organizations are ready to use this capability operationally.
That means answering some uncomfortable questions. What decisions can AI make independently? What can isolate? What can it block? Under what circumstances should it wait for human approval? Which resources are so critical that different rules apply? And who within the organization has the authority to establish these rules?
These are governance issues, but they are also cybersecurity issues.
The answer cannot simply be that a human being must approve of every consequential thing. It seems safe until you consider the environment we are trying to defend.
When an attack can unfold in less than a minute, waiting ten minutes for someone to understand an alert, find the right person, and approve a response is not caution. It’s a vulnerability.
Obviously there will be errors. Autonomous systems sometimes make decisions we would rather they not make. This is exactly why organizations need clear mandates, good asset intelligence, business context and carefully defined boundaries.
But eliminating autonomy because we are afraid of the consequences misses the point.
The goal should not be to build an AI that can never make a bad decision. It should provide the AI with enough knowledge, context, and authority to make the right decision quickly enough to matter.
Otherwise we will continue to do what the security industry has done for years: detect attacks, generate alerts, populate dashboards, and later explain what happened.
Artificial intelligence gives us the opportunity to change the situation, but only if we finally give it permission to act.



Post Comment