Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

3 reasons to reconsider automating cybersecurity

By Randall Richard
cyber security
March 30, 2022

Given the growing number and complexities of today’s cyberattacks, it is no secret that implementing cybersecurity products and services comes with a substantial price tag. However, when considering what level of cybersecurity is needed, insufficient security measures can lead to disastrous consequences and significantly affect a business’ reputation and budget.

Deciding the level of cybersecurity an organization needs can be a challenge. On the one hand, companies likely want to find effective yet cost efficient solutions, while on the other, the cost of an error when introducing cheaper tools is far too high. One solution could be to automate incident prevention, as it can reduce costs and eliminate the human mistake factor. However, in practice, effective cyber protection is only possible with a combination of automated solutions and human effort.

Why is that? The main reason is that cybercrimes are committed by human beings. Attackers constantly come up with new ways to bypass security systems, invent and implement new sophisticated cyberattack tactics and actively use people’s weaknesses to gain access to a company’s infrastructure. Even the most sophisticated artificial intelligence (AI) can’t combat the variety of malicious activities because it works on the basis of previously acquired and learned experience.

With this in mind, it is important to explore and consider several cybersecurity practices that require human involvement.

Detection of complex threats

Even the most carefully tuned sensors can’t detect previously unknown malicious activities. This is because such attacks usually consist of a series of separate and legitimate actions that could easily be confused with system administrator or common user actions.

AI that analyses telemetry from sensors also has limitations, as it can’t collect and process all possible data or actions that occur at different times. Even if that was possible, situational awareness becomes a challenge. This term refers to the availability of information about all the processes currently taking place in the infrastructure. For example, AI could observe what it believes to be a human-driven APT, but it turns out to be a dedicated employee conducting research. This can only be uncovered by contacting the user directly. Situational awareness is crucial to differentiate true incidents from false-positive alerts such as this, no matter if the alert logic is based on a particular attack technique behavior pattern or anomaly analysis.

This doesn’t mean that AI is ineffective in terms of threat detection. In fact, it can successfully combat 100% of known threats and, when properly configured, can significantly reduce the burden on analysts. The joint force approach of human involvement paired with artificial intelligence requires special skills, high-grade analyst experience and constant algorithm adjustment. 

When identifying new threats, proactive manual threat hunting is also required. Proactive threat hunting allows security teams to identify current cybercriminal and cyber espionage activity in the network, understand the reasons behind these incidents and the possible sources, and effectively plan mitigation activities that will help avoid similar attacks. 

In summation, analysts are needed to constantly adjust and retrain the AI-based algorithm, enabling it to detect new threats as well as test the efficiency of the improvements. 

Advanced security assessments

Assessments are crucial to gain a detailed perspective of a company’s cybersecurity readiness. There are automated solutions designed for this, such as vulnerability assessments that can help discover publicly-known vulnerabilities among a strictly defined set of systems. This service uses a database of already known security issues, but can’t test security system resilience towards sophisticated attacks and unconventional adversaries’ behavior. 

To ensure that the company is able to protect itself, more advanced assessment processes should be implemented. For example, services that can actually simulate a cyberattack, such as penetration testing and red teaming, that are mostly manual and based on a specialist’s knowledge and experience. These approaches use a mix of techniques, tactics and procedures and adjust to the company’s specific cyber defense capabilities, imitating the real behavior of attackers.

Security awareness 

Studies indicate that the average organization faces over 700 social engineering attacks each year. Moreover, weak passwords and phishing emails are still among the top initial attack vectors. 

While cybercriminals are inventive, an organization’s defense team can’t completely withdraw themselves from security awareness processes. A company’s employees need to have a clear understanding of the importance of cybersecurity policies as well as the consequences of their actions. That is why it is not enough to simply develop an awareness manual or test that is only used for onboarding new team members. The cybersecurity team should keep an eye on the relevance of their security education and invent new and non-standard approaches to deliver crucial information to their colleagues or outsource their security awareness training.

When considering whether or not to fully automate an organization’s cybersecurity needs, the all or nothing approach to AI should be reconsidered. Instead, the solution lies somewhere in the middle. Only a smart mix of automated services with human creativity, skills and control can ensure comprehensive cyber defense.

KEYWORDS: artificial intelligence (AI) automation cyber attack detection cyber security awareness hacking penetration testing social engineering

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Randall Richard is Head of Enterprise Sales for Kaspersky North America.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • people-business-freepik170x658v4.jpg

    3 reasons why cybersecurity must be people-centric

    See More
  • It's Time to Reconsider Security Officer Stereotypes

    See More
  • dataminr-gsoc6

    3 key reasons why SOCs should implement policies over security standards

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • into to sec.jpg

    Introduction to Security, 10th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing