The future of inequality in cybersecurity has been coming to light since the beginning of the AI evolution. Greg Notch, the Chief Technology Officer (CTO) at Expel, recently predicted that the “AI poverty line” is projected to be more severe than the traditional security line.
"The AI poverty line will be even crazier in some ways because you will either have the ability to understand and wield AI properly or you will not,” he stated. “That gulf is going to be interesting."
In the recent episode of The Security Strategist podcast, host Brad LaPorte, Gartner Veteran and Advisor at Lionfish Tech Advisors, sat down with Greg Notch, CTO at Expel, to address the impact of AI on security operations. They discuss the AI poverty line and lay out a plan for how enterprises can adapt to the rapid pace of change introduced by AI.
They also explore the balance between automation and human oversight, trust versus impact, and future trends in AI-driven security.
What is the AI Poverty Line?
According to Notch, the AI poverty line is the growing divide between security capabilities and one’s ability to effectively optimise AI.
While a security poverty line has existed for a long time, an AI version will begin appearing. It could be more complex and niche. Security teams may face difficulties defining their roles and responsibilities, and only those who can wield AI skillfully and effectively.
For instance, he alludes to an example of a large tech enterprise such as CrowdStrike, Palo Alto or even Microsoft. As a large enterprise employing AI-skilled professionals, “you would want to leverage as much of that as you can because your head count is is is limited. If you can't hire enough people to manage the operation, you may have to outsource that” to an AI-skilled professional.
However, with attackers' increasing sophistication, the enterprise should be capable of equally able to detect and responding to vulnerabilities. This is why automation alone is not enough.
A resilient cybersecurity strategy requires a team equipped to use AI-backed security tools to actively monitor, manage, and respond to threats, using automation. This should help human decisions rather than replace them with a bot.
Also Read: What Is AI Value Management and Why Are Enterprises Suddenly Prioritising It?
When AI Runs the SOC
How AI SOC managers compress detection and response times while keeping humans on critical judgment calls across the threat lifecycle.
Where Does AI Belong in the Security Operations Centre (SOC)?
AI and automation ultimately exist to aid Security Operations Centre (SOC) teams. Its capabilities allow assistance to human analysts, acting autonomously and contribute to how enterprises can effectively optimise AI to boost their security posture.
Both LaPorte and Notch agree that the role of AI in SOC is collaborative. It’s a hybrid model where humans maintain control.
LaPorte takes the example of a motorcycle, stating it’s like a motorcycle “with a sidecar.” “The human is riding the motorcycle, but the AI is along for the ride. It adds additional capability, additional storage and functionality.
“It's a new world, but it's a hybrid world."
While Notch rhetorically questions whether a SOC is needed. He asks the audience to imagine a scenario without SOC analysts. It’s not possible even if it’s intermediated by AI. “I believe we’ll have more humans in the loop.”
Mapping AI Across the SOC
Use a trust–impact matrix to align automation, ML, genAI and agents with each SOC task, from alert triage to response execution.
Why Automation is Essential?
As attackers become more sophisticated in their threat intelligence strategies, enterprises too have to keep up. That means they too need to leverage automation capabilities of AI.
Some easy actions that can be automated without human intervention are to block known malicious IPs or contain compromised devices. This becomes extremely crucial during high-stakes situations where time is of the essence.
Automation is essential to address two primary business and operational challenges – mitigating the risk of active attackers and resolving the inefficiency caused by alert fatigue.
Notch argues that the risk of failing to stop an active attack outweighs the risks associated with introducing automation into the environment. "All security leadership decisions should be grounded in risk.”
Security leadership should think about “what is the risk of not doing a particular task versus the risk of doing it? For instance, automation.”
“We're accepting different risks, but we believe the risk of not being able to stop an active attacker in our environment is worth that. That's the trade-off you have to make,” Notch tells LaPorte.
Balancing GenAI And Creatives
Cannes limits AI-led films even as studios pursue automation, underscoring tensions between efficiency gains and human-led storytelling.
Where Expel comes in?
Notch describes Expel's approach as a solution for security operations—specifically pertinent to auto-remediation before AI was a thing.
Expel launched an auto-remediation feature about seven or eight years ago based on heuristics. It wasn't driven by AI back then. It was unclear whether Expel’s customers would adopt it, as trust had to be established before adoption.
Notch explains that's because customers had to be comfortable letting a third-party security provider automatically take actions. For instance, letting the party isolate infected laptops, shutting down compromised cloud systems, stopping malicious programs, and responding to attacks without waiting for someone from the company to approve it.
Expel discovered that customers were willing to trust this automation because it could stop attacks much faster than waiting for a person within the company to act.
Today, many enterprises would rather let the system stop or contain an attack immediately and investigate what happened afterwards.
By understanding where AI can effectively assist or act autonomously, enterprises can enhance their cybersecurity posture while managing risks.
The key is to develop a thoughtful approach that balances automation with human expertise, ensuring that AI serves as a powerful ally in the fight against cyber threats.
Watch the podcast on em360tech.com for a deeper understanding and expert thought leadership insights.
For further information, visit expel.com.
Why AI Productivity Feels Off
Shows how AI speeds up tasks while expanding expectations, shifting how value is created without clearly shrinking anyone’s workload.
Takeaways
- AI is transforming the speed and nature of cyber attacks.
- Automation in security must be balanced with human oversight.
- Trust is crucial when implementing AI in security operations.
- AI can enhance detection but requires careful implementation.
- The future of SOCs will involve more human-AI collaboration.
- Organisations must adapt to the evolving threat landscape.
- False positives remain a significant challenge in SOCs.
- AI can help streamline operations but is not a silver bullet.
- Security decisions should be grounded in risk management.
- The hype around AI in cybersecurity often oversells its capabilities.
Chapters
- 00:00 Introduction to AI in Cybersecurity
- 03:03 The Speed of AI-Driven Attacks
- 06:00 Automation and Trust in Security Operations
- 09:01 AI's Role: Acting Alone vs. Assisting
- 12:00 The Future of AI in Security Operations
- 14:46 The Hype vs. Reality of AI in SOCs
- 17:59 Navigating the AI Landscape in Cybersecurity
- 20:51 Conclusion and Key Takeaways
Comments ( 0 )