The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Blue Team Diaries
Blue Team Diaries artwork

Navigating the AI Revolution in Cybersecurity: An Investor's Perspective

Blue Team Diaries · 2025-03-18 · 41 min

0:00--:--

Key moments - from our scoring

Substance score

46 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality9 / 20
Guest Caliber11 / 20
Specificity & Evidence9 / 20
Conversational Craft7 / 20

First Analysis, a long-standing investor in cybersecurity with over 30 years in the space, published research examining AI's actual impact versus the hype. Howard Smith and Liam Moran argue that while AI has potential, the industry faces critical tensions: full transparency in AI systems creates security vulnerabilities by exposing defensive logic to adversaries, yet black-box AI leaves security teams unable to understand attack vectors or harden their infrastructure for future threats. The report identifies where AI genuinely delivers value - large language models for querying security data, automating repetitive SOC tasks, and triaging alerts - versus where it falls short, particularly in detecting zero-day exploits without generating overwhelming false positives. The optimal model combines AI capabilities (pattern recognition, data correlation, alert generation) with human analysts (contextual judgment, strategic decision-making, infrastructure evolution) and traditional rule-based detection methods to validate AI findings. This hybrid approach enables faster response times, reduced alert fatigue, and continuous organizational learning as teams refine both their AI models and network defenses based on real-world attack patterns.

Key takeaways

  • →AI excels at automating repetitive SOC tasks and enabling natural language queries of security data, but struggles to reliably detect novel attacks without generating excessive false positives.
  • →Complete transparency in AI security solutions creates a vulnerability paradox - exposing defensive algorithms to adversaries allows them to reverse-engineer attacks that circumvent those same protections.
  • →A hybrid security model combining AI detection, traditional rule-based tools, and human analyst judgment provides better long-term resilience than black-box AI alone because it allows organizations to understand attack vectors and continuously evolve their defenses.
  • →Black-box AI systems can leave organizations unable to respond strategically when sophisticated attackers probe multiple branches or systems with slight variations, potentially requiring binary choices between inaction and drastic shutdowns.
  • →The most valuable AI applications in cybersecurity involve augmenting human decision-making - translating technical alerts into executive dashboards, suggesting remediation steps, and providing detailed reasoning for flagged threats - rather than replacing human judgment.

Guests

Howard SmithLiam Moran

Topics in this episode

SOC automationAlert fatigue and false positivesBlack box AI limitationsLarge language models for security data queriesZero-day threat detectionHybrid security modelsRules-based detectionNetwork behavior anomaliesTransparency vs. security trade-offsAI explainability challenges

Questions this episode answers

Why does making AI cybersecurity solutions fully transparent make them less effective?

Complete transparency exposes defensive algorithms to adversaries, who can use that information to reverse-engineer attacks designed to circumvent those protections. Additionally, adding explainability overhead to AI systems requires significant computational resources and makes it difficult to translate statistical probabilities into human-understandable language without revealing security secrets.

Where is AI proving most effective in cybersecurity today?

AI is most effective at augmenting human capabilities through large language models that enable natural language queries of security data, automating repetitive SOC tasks like alert triage and report generation, and providing analysts with context and remediation suggestions for anomalous activities.

What is the learning organization dilemma with black-box AI security solutions?

When organizations rely entirely on black-box AI that provides only blocked/detected alerts without visibility into attack vectors, they cannot evolve their network defenses for future variants of the same attack, potentially leaving them vulnerable when attackers adapt their approach.

What does a hybrid security model look like in practice?

A hybrid model uses AI to detect anomalies and flag potential threats with detailed reasoning, human analysts to validate and investigate with contextual judgment, and traditional rule-based tools to definitively confirm whether issues are real threats or false positives, enabling faster and more accurate response while reducing alert fatigue.

Why can't AI solve zero-day threat detection as effectively as the industry hoped?

AI struggles to distinguish between real novel threats and benign anomalies, generating overwhelming false positives; it also operates as a black box, making it impossible for analysts to understand what triggered detection and therefore unable to harden defenses against similar attack variants.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

A handful of non-obvious points emerge - transparency as an exploitable attack surface, and the black-box AI leaving organisations in a worse posture as attacks evolve - but large portions of the episode are padded with standard industry platitudes about hybrid models, LLMs in the SOC, and skill shifts that offer little a well-read practitioner hasn't already heard.

as an adversary, as a bad actor, I will use that information to change my line of attack to defeat what you're telling me. So by its nature it has issues
The more you're just dependent on this black box against unknown attacks could leave you in actually a worse posture than if you're getting the data

Originality

9 / 20

The transparency-as-attack-surface argument is the episode's most genuinely counterintuitive insight, and the adoption-by-false-positive-tolerance framing (nuclear vs. finance) is a useful organising lens, but the remaining content - hybrid AI/human models, LLMs for SOC querying, changing skill sets - is widely recycled material in any 2024 cybersecurity discussion.

if I'm highly automated, I can set an AI attack vector to say, analyze the transparency of this AI engine and create an attack that will circumvent the uh, algorithms and protections inherent in this AI solution
the tolerance for I'm gonna have some false positive rate is very different among industries

Guest Caliber

11 / 20

Howard Smith brings genuine 30-year investment experience in cybersecurity and delivers the episode's more substantive analysis; however, the guests are investors rather than operators who have built or run security products at scale, Liam Moran is a junior associate whose contributions are largely generic, and the host's undisclosed commercial relationship with Howard (board member of the sponsor) compromises the independence of the conversation.

We've been investing in CyberSecurity for over 30 years and unlike some areas of technology where there's a discrete issue or problem and technology comes and solves it
Howard is actually on the board of directors for Samus Networks

Specificity & Evidence

9 / 20

The 60-branch attack scenario and the nuclear-reactor false-positive example are concrete and illustrative, and there are specific tool references (Splunk, SQL, SPL) and sample natural-language queries, but the episode is entirely free of named vendors under analysis, real market data, deal sizes, or empirical research findings from the cited quarterly report.

let's say you have, uh, a large organization with 60 branches and somebody systematically going through with an attack
show me all the login attempts from a new device in the last 48 hours that failed more than three times before succeeding

Conversational Craft

7 / 20

The host follows a coherent thread tied to the guests' published report and lands one genuine correction when his misreading of the 'learning organisation' section is pushed back on, but the conversation is fundamentally a friendly promotional exchange - the host leads the sponsoring company, Howard sits on its board, and no claim goes unchallenged or stress-tested throughout the 41 minutes.

Wow, thanks for that clarification. I think I might have misinterpreted that section of the report
in full disclosure, I should mention that Firstanalysis, uh, is an investor in Stammis Network, my company, which is a sponsor of this podcast

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C38%
  • Speaker A32%
  • Speaker B31%

Most-used words

security32cybersecurity25threats24alert14organizations14analysts13tools13data13report12seeing12traditional12making11solutions11real11attack11threat10

Episode notes

In this episode of Blue Team Diaries, guest host Mark Durrett sits down with Howard Smith and Liam Moran of First Analysis to discuss the real-world applications of AI in cybersecurity. Their conversation is inspired by First Analysis's recent report, "Challenges and Promise of AI and Cybersecurity," which provides valuable insights into the practical issues facing cybersecurity practitioners. Howard and Liam delve into the challenges and opportunities that AI presents for security professionals, exploring topics such as transparency, explainability, and the potential for AI to revolutionize threat detection. They share their insights on how AI is being used to augment security teams, improve efficiency, and help organizations make better decisions about their security posture. They also discuss the importance of a hybrid approach, combining AI with traditional security methods to create a more effective overall solution. This episode is a must-watch for anyone interested in the future of cybersecurity and the role that AI will play in shaping it. Tune in to learn how AI is transforming security operations and what it means for the future of cyber defense.

Full transcript

41 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: AI making decisions without clear explanations. That's concerning. Um, but this hybrid model would mitigate this by ensuring that AI generated alerts come with that detailed reasoning, giving those analysts insight into why that threat was flagged and allowing them to refine their AI models over time. Um, in practice, this means that security teams can respond faster threats and more accurately while reducing alert fatigue.

Speaker B: Welcome to Blue Team Diaries, the podcast that celebrates and honors the professionals who work tirelessly to defend their organizations and those who build tools to support defenders. In each episode, host Peter Manav invites his guests to share their stories and experiences in a fun and lighthearted conversation. Blue Team Diaries is sponsored by Stamis Networks, a uh, global provider of network based threat detection and response solutions. Learn more@stammist networks.com hi there, my name is Mark Durrett and this week I am the guest host of the Blue Team Diaries and I am excited because for the first time we have two guests, Howard Smith and Liam Moran from FirstAnalysis. Howard Smith is a managing director at First Analysis and is a Managing Partner of the firm's venture funds. He has over three decades of experience at First Analysis and works with entrepreneurs as an investor and as an advisor on growth transactions to help build leading technology businesses. Howard leads the firm's work in the cybersecurity, Internet infrastructure and Internet of Things sectors. He has also built the firm's historical franchises in call centers and computer telephony. His thought leading research in these areas has been cited for excellence by the Wall Street Journal and other publications. He's provided strategic advice to numerous technology companies in capital raising and buy as well as sell side M M and A transactions and as a board member. Prior to joining first analysis in 1994, he was a Senior Tax Consultant with Arthur Anderson and Company. He earned an MBA with honors from the University of Chicago and a Bachelor's degree in Accounting with the highest honors from the University of Illinois at Urbana Champaign. Liam Moran is an Associate with First Analysis. Prior to joining FirstAnalysis in 2020, he was in the executive development program with Macy's where he was responsible for managing the financial modeling surrounding Macy's $3 billion asset based loan capital project valuations and corporate forecasting business. Liam graduated from Kenyon College with a Bachelor's degree in Economics and a concentration in an integrated program in Humane Studies. He was a four year member of the Kenyan Varsity Swimming team. Today I'm joined by Howard Smith and Liam Moran of First Analysis. Welcome Howard and Liam. Thank you. Thank you for joining me today on Blue Team Diaries.

Speaker C: It's good to be here.

Speaker B: Great, thank you. Before we get started, in full disclosure, I should mention that Firstanalysis, uh, is an investor in Stammis Network, my company, which is a sponsor of this podcast. And Howard is actually on the board of directors for Samus Networks. So. Okay, look, several weeks ago you published a report as part of your quarterly Insights into Cybersecurity. And every quarter I look forward to reading these because they give me different insights, and particularly those insights on the, uh, you know, from the perspective of an investor. And in this most recent edition, which I think you entitled Challenges and Promise of AI in Cybersecurity, you really dug deep and exposed me to some of the real practical issues facing cybersecurity practitioners around the AI value proposition. And I found it to be really thought provoke, provoking. And I think our listeners will also find it to be. So if you don't mind, I'd like to just dive right in and ask you a couple of questions about it, uh, and maybe backing up a little bit first. Um, can you just briefly share with our audience why you're so interested in the subject and why you even bother tracking the cybersecurity industry?

Speaker A: Yeah, thanks, Mark. I appreciate you taking time today. Um, so, as you know, cybersecurity is already a complex and rapidly evolving field. Um, but the introduction of AI is taking both the challenges and the opportunities to a whole new level. The industry is at an inflection point where AI is being integrated into security solutions at an unprecedented pace. And some believe AI, uh, will revolutionize cybersecurity, making threat detection fully autonomous, while others are remaining skeptical, pointing out the limitations of AI in handling those novel attack scenarios. Um, Howard and I track this space closely because the stakes are incredibly high. Um, cyber threats are evolving faster than they ever have, and organizations are under a lot of pressure to protect their digital assets from those increasingly sophisticated attackers. Um, AI, ah, has the potential to be a game changer, but really only if it's applied effectively. What we're seeing is that while AI isn't the silver bullet many had hoped for, especially in areas like detecting zero day threats, it is proving to be highly effective in augmenting those security teams and improving their efficiency m and ultimately helping those organizations make better decisions about their security structure. Um, by tracking this industry, we're really trying to separate the reality from the hype. Where is AI really making the measurable impact? Where is it falling short? What are the real world applications that security teams can rely on today? And what does the future hold? These are the questions that Howard and I are trying to answer that are driving a lot of uh, our research and they're important because they shape how organizations invest in cybersecurity and ultimately how they defend against the ever growing array of these pervasive threats.

Speaker B: Okay, well, I think that makes complete sense. I guess maybe one additional question is why as um, as investors are you tracking the space?

Speaker C: We've been investing in CyberSecurity for over 30 years and unlike some areas of technology where there's a discrete issue or problem and technology comes and solves it, um, and then maybe it solves it again as it moves to the cloud or SaaS, different business models, um, we have found this a particularly enduring area of investment because as soon as you solve one problem, the bad actors change the game. So it's a cat and mouse games, which makes for very dynamic investment, uh, environment. And so it's been a great area for us over the years and we think that will continue into the future. It's kind of this never ending cycle of opportunity.

Speaker B: Yeah, uh, well that certainly makes sense and uh, thanks for uh, sharing your perspective on um, and it's really, it's fascinating that you've been involved in this space that long and uh, that you continue to see the value in the solutions and in the development of new and novel solutions because of that, the sort of changing landscape and the cat and mouse element of it. Yeah, very, very interesting. So turning to the report, this, uh, this report that you delivered last month, um, mentions that making AI cybersecurity solutions more transparent, um, is seems uh, important but often comes at the expense of accuracy and effectiveness. Can you help us kind of understand, maybe explore this tension a little further and uh, discuss whether or not you see any promising approaches that might eventually offer both transparency as well as high performance threat detection?

Speaker C: Yeah, I'll take this. And there's a couple of dimensions to it. One has to do with the very nature of transparency and uh, as a defensive measure. So uh, let's say you had a perfectly transparent AI solution that everybody could see how it comes to its conclusion, what it's doing, what the algorithms are all about, that might be helpful to understand the threats. But as an adversary, as a bad actor, I will use that information to change my line of attack to defeat what you're telling me. So by its nature it has issues. And if I'm highly automated, I can set an AI attack vector to say, analyze the transparency of this AI engine and create an attack that will circumvent the uh, algorithms and protections inherent in this AI solution. So that's probably one of the most important dimensions of why completely transparent AI cybersecurity can't be as effective. Um, there are other dimensions as well which are more practical limitations of the technology today. So AI in itself is a resource, um, compute intensive application. And so just getting the statistical correlations for the AI engines to do what they do creates a little bit of latency, takes compute power, et cetera. If you wanted to throw on the overhead of explaining what is happening as it's happening, you're adding a whole new dimension. And I haven't seen too many that do it, but it could be orders of magnitude more compute power and complexity. So there's a practical limitation kind of in that dimension. And then just the simple do you want to tell your adversaries what you're doing to protect your network, uh, and your organization? And so do we see a, you know, some sort of transparent, uh, AI in the future? I think you can solve some of that compute power over time using, you know, Moore's Law and extending it here. Uh, eventually you might be able to explain things in such a way that people can understand it without revealing the deep dark secrets behind it. I think we're a long way from that. So in what we consider the investment horizon, I'm not too hopeful for fully transparent uh, AI, uh, for threat detection itself, other applications, other tangential things within cybersecurity might hold more promise.

Speaker B: Okay, gotcha. And I had a whole separate thread on explainability, but I think you covered that completely. So, uh, yeah, so it sounds like transparency has sort of a compute challenge as well as a, you know, a risk, exposure and even vulnerability element to it. But the explainability is just super difficult to achieve at this stage.

Speaker C: Yeah, there's a nature in addition to just trying to put into human understandable language, particularly by people who aren't AI experts, the logic that's going into an alert. And that's another practical consideration. If you have a rules based engine or something based on very concrete logic, you can say if I see A, if condition A is present and B is present and an underlying atmosphere of C, X, you know, uh, I'll alert on X. The nature of AI is kind of statistical probabilities that are more if it feels like A is present and it seems like B is present and condition C is most likely here than X. And then you can say, well, what made you think that A is likely? And you can do the words that it keys on or ah, what data it Logically used. Most prevalently it can report that back. But that's very different than having a conversation that you and I might have that normal language. Why did you think A was present? Um, and then in the just pure logic based, historical, statistical, M. Uh, not AI based, it's very clear A was present because by definition this is A. And here's the condition. So it does, from a language standpoint, it is difficult for the algorithms to explain themselves today.

Speaker B: Yeah, absolutely, absolutely. So in. And I think this is related to sort of a comment that you made a little bit earlier in some of the other areas where you might see AI having some applicability. In the report you noted that AI is not the silver bullet that many hoped for preventing novel attacks, but you are seeing success with what you referred to as more mundane AI capabilities, like large language models for quantum querying data. Could you elaborate a little bit more on some of these less hyped but potentially even more transformative applications?

Speaker A: Yeah, so there's a lot a ton of early excitement around AI's ability to detect and block those novel attacks, those zero day threats that a cybersecurity team had never seen before. The idea that AI could recognize those anomalies in real time, automatically respond and prevent the breach before they could cause damage was astounding. But in practice, we've seen that AI struggles with the unpredictable nature of novel threats. It can detect the unusual behavior, but distinguish it's distinguishing between that real threat in a benign anomaly really remains the real challenge. Um, those false positives are significantly overwhelming those cybersecurity teams. And many AI driven detection systems operate as black boxes, making it really, really difficult for the analyst to understand why that alert was triggered. Um, where we're seeing the most success, however, is in applications that enhance how security teams interact with cybersecurity tools. Um, those large language models, for example, are transforming the soc, the security operations center, by enabling analysts to query security data in a natural language. So instead of manually searching logs and writing complex queries, an analyst can simply ask the AI tool what Were the top five anomalous login attempts from external IPs in the last 24 hours? And then they can get a clear, concise, relevant response. And then further, they have the ability to drill down in all of those alerts to get a better understanding of their current security posture, how those threats got in, and then how they can bolster that security posture to make it more impervious for future threats. Um, this is a huge deal because the security analysts are being so Overwhelmed with data, they spend a significant amount of time correlating logs, researching alerts and trying to understand the context behind all these potential threats. And AI powered assistance can significantly reduce the workload by just providing a quick summary or suggesting remediation steps, or even translating that technical security data into something that's more executive friendly. So another thing that we're seeing a lot of is the cybersecurity analysts may need all that technical understanding and will use AI to understand that alert. But your CISO or whoever's running the organization needs to understand that the system is running, uh, as it should and the threats are being taken care of so they can translate into those executive friendly dashboards. Um, another way area where we're seeing AI, um, as being significantly valuable is in automating those repetitive cybersecurity tasks. For instance, um, AI can triage the alerts, prioritize the threats and even generate the security reports, um, freeing up those analysts to work on more of that higher level threat hunting and that incident response. Um, those applications that you were talking about may not be as flashy as the autonomous AI driven threat prevention, but they're really having a tangible immediate impact on the security teams, um, making them so much more efficient and effective at managing those threats.

Speaker B: Yeah, super, I think, ah, what you highlighted is a super powerful capability of AI and relieving some of the security personnel, the mundane work that the security personnel are doing. But you also, in your report talk about this sort of dilemma, the learning organization dilemma, where the organizations that are using AI detection solutions, especially those that don't provide a lot of details behind sort of what happened and why, um, they may, those organizations may actually lose their ability to harden their own organizations against future defenses because they've sort of let go of some of their basic traditional cyber defenses and they haven't maybe evolved them at the pace that they traditionally have been because now they're relying more on AI. Um, could you discuss a little bit about how organizations might think about sort of balancing that AI automation while maintaining the kind of competency and the continuous learning that organizations uh, have really leaned on to get better and better and better over time.

Speaker C: You bring up a good point that wasn't really the intent of the report, which is just kind of keeping the SOC organization and the people on it at the cutting edge of seeing those things, which was, uh, which is a good point. They have to continue to exercise that muscle. But the point we were making in the report and um, probably we want to emphasize has to do with more of Evolving the network for the threats that are coming in. So let's just say you have, uh, a large organization with 60 branches and somebody systematically going through with an attack. And each branch, they're starting at 1 and they take about 10 minutes and it fails or never. And then they're putting their resources on the next one. If you have a black box AI and it's pretty good, it just blocks, it will maybe send an alert said, uh, we detected this type of attack and it's blocked, but it's not telling you all the details of the type of attack. The vectors you might be able to drill down somewhat. You may not, depending on the tool, uh, but as it goes through your 30th branch that it's going to attack may have something slightly different that had you gotten full visibility as to what was triggering that, how the attack was being done, you're going to say, oh, let me check all my branches, make sure this part is locked down, or make this change. The black box approaches, it's blocked, it's blocked, it's blocked. You're feeling really good until they get to that 30th branch and all of a sudden you've penetrated and you don't know why, and you don't know if the other 30 branches, you should be immediately taking them offline or they're not susceptible for this type of thing. So you're left with some pretty binary decisions. Either take drastic action to eliminate kind of threats in general or hope your AI black box catches it and done it. So that's where it could leave you. The more you're just dependent on this black box against unknown attacks could leave you in actually a worse posture than if you're getting the data and maybe it's a little slower or, or something, but you're evolving your organization to be able to defend broadly against these attack vectors that are being developed.

Speaker B: Wow, thanks for that clarification. I think I might have misinterpreted that section of the report. So. Great, great clarification.

Speaker C: But they're both, I mean, I think, you know, having these security personnel that aren't, um, digging in and seeing how do we harden the network in that type of environment, you start to lose that, as I say that muscle memory as well as to how to harden your network. So they're both dynamics of it.

Speaker B: Yeah. And I think that leads to, uh, the next element in the report, which talks about recommending that organizations look at a hybrid approach, somehow combining AI models with traditional detection methods so that you can create this more effective overall solution in the near term. And, and so my guess is that also applies to the human element, right? Like continue to let your team uh, in on, you know, gain visibility into what's going on in the network and don't just sort of expect your tools to do everything. Um, but could you help paint a picture of what, you know, what this sort of optimal collaboration might look like between AI systems and, and the human security professionals?

Speaker A: Yeah, that's a great question. Um, the most effective cybersecurity strategy today isn't probably about choosing between AI and those traditional detection methods. It's about finding the right balance between those humans, that human expertise and those AI capabilities. Um, as we know and we've discussed, AI excels at that pattern recognition, they can identify those anomalies and they can process vast amounts of data at lightning speed. But it really lacks the intuition that contextual awareness and ultimately that strategic thinking, that human in the loop, that that security professional will bring to the table. Um, a hybrid security model would leverage AI to handle the heavy lifting like scanning the network traffic for anomalous data, anomalous threats, correlating data across multiple sources and flagging those potential threats. While the human analyst would focus on validating investigating threats and the strategic decision making, um, and using the AI to help inform how they would bolster their security posture over the time to become more resistant for future threats. Um, for example, let's say an AI system detects unusual behavior. They flag multiple failed authentication attempts from an unusual geographic location followed by a successful login. In a fully AI driven model, this might trigger an automatic alert and it would automatically block it. Um, but in a hybrid model, AI would provide the security analysts with relevant context. Is this a known user who's just traveling for business? Is this mark in a different location? Is this IP been associated with past malicious activity? Um, what other, you know, network behaviors have been observed from this account? And then so rather than acting blindly on all these alerts, the analyst has the information that they need to make an informed decision. And AI can suggest the remediation actions based on past incidents, like in this case forcing multi factor authentication or just temporarily restricting that access, um, until further review. Um, transparency again is the key problem here. Uh, all of those tools in the anomalous detection, there's that black box problem and AI making decisions without clear explanations that's concerning. Um, but this hybrid model would mitigate this by ensuring that AI generated alerts come with that detailed reasoning, giving those analysts insight into why that threat was flagged. And allowing them to refine their AI models over time. Um, in practice, this means that security teams can respond faster threats and more accurately while reducing alert fatigue, um, from those black box models. And so instead of drowning in false positives and chasing down every anomaly, the analyst can focus their attention to where it matters most, um, on those real threats that require human intervention, um, rather than just a machine.

Speaker C: And I'll just add there's another kind of hybrid approach. There's the human with the AI. There's also AI based models with more traditional rules based and uh, other type of logic, pure logic rule model. And what I would say is I could see where the AI would point to an issue may or may not be, uh, an actual problem. So a false positive or a positive positive, and you would bring focus of those traditional tools and kind of shine a light on the specific area so you run more tools and, and more of those traditional things so you can try to get to the answer. So where AI is not providing that context, an explanation, why was this triggered? What is the actual issue? In a language that analysts are used to seeing, highlight the problem that there may be a problem, then throw all your traditional tools at it and, and get those traditional answers the way you're used to seeing it. So you know, definitively, yes, real problem or no, false, false alignment.

Speaker B: Yeah, yeah, right, right. So, so two different sort of approaches on hybrid, but both leveraging AI and traditional mechanisms or traditional tools to bring together, to bring together the best of both of those worlds. Yeah, uh, I think the hybrid model also sort of brings to mind another question. As we humans are interacting with these AI machines, does that sort of change the skill set that the analyst team needs? Or are we thinking that the analysts, you know, the analysts don't really need to up level their skills to take advantage of some of this machinery, or is there, is there, does it change hiring? Does it change training? What are your thoughts on that? And I think you guys covered a little bit of that in the report.

Speaker A: Yeah, so security professionals, they need to develop new skills in order to interact, uh, effectively with AI driven systems, period. They need it. This doesn't need, they, this doesn't mean that they need to become AI engineers necessarily, but it does mean that they need to understand how AI works and how to ask the right questions and how to interpret those AI generated insights. Um, one of the most immediate skill shifts we're seeing is the ability to craft those effective prompts and queries for AI driven security tools. Um, security analysts already work with query languages Like SQL or spl, used in tools like Splunk. But interacting with AI models requires kind of a different approach. The analyst needs to learn how to phrase the questions in a way that yields the most relevant and actionable insights. So I'll give an example. Um, instead of sifting through thousands of logs manually, an analyst using an AI driven SoC might ask something like, show me all the login attempts from a new device in the last 48 hours that failed more than three times before succeeding. Or summarize all critical vulnerabilities identified in our environment this week and rank them by exploitability. So these kinds of natural language queries allow the analyst to retrieve that information faster, but they also require that deep understanding of how AI, uh, interprets that data. And the security professional needs to know how to refine these queries, validate the AI generated responses, are they true because they're coming from AI, and ultimately cross check the findings, um, against those traditional security data sources that we were talking about that Howard was mentioning earlier. Um, you know, from a hiring and training perspective, this shift means organizations are placing an even greater emphasis on AI literacy. Um, security teams need that training, um, in traditional cybersecurity practices, but also in those AI driven workflows. And some companies are even revising, uh, you know, a lot of their hiring criteria to prioritize those candidates that have experience working with, uh, AI enhanced security tools or other kind of data analysis tools. Um, you know, ultimately, AI, it's lowering. I, I believe that it's lowering the technical barrier for entry for some cybersecurity rules by making these complex tasks a little bit more accessible. Um, this could alleviate the ongoing shortage for, you know, skilled cybersecurity professionals by allowing less experienced analysts to perform those tasks where you needed deep technical expertise. But, um, this also means that the security teams consistently need to, uh, and continually need to upscale to stay ahead of the evolving AI landscape. Because AI is changing just as fast as those threats are, so you have to keep up with it.

Speaker B: Yeah, so I guess historically, security teams have always needed to stay on top of the latest technology and the latest threats. And this just adds another, another element. Well, it'll be interesting to see where, where that goes and how, you know, as you mentioned, Liam, the. It might be lowering the bar and bringing, you know, bringing more folks into the fold and really helping staff fill those shortages of skilled analysts. So that, I mean, I think really it will be very interesting to watch that progress over time.

Speaker C: Yeah, I do think the skill set, uh, necessary to kind of query Large language models and things like that will be that you see in many industries will carry over to cybersecurity. So hopefully there'll be a, a nice pool to choose from. I still think you're going to need that really deep cybersecurity technical expert on your staff. It may be that there are lower level staff or querying staff on one side and then when something is picked up that requires that second third level attention, you bring it to the true experts. So you might see a stratification where you have need fewer people with that deep technical expertise on um, um, cybersecurity threats. But it may be very deep when they have them and you don't need as many of them because you can pull from a broader population.

Speaker B: Yeah, got it, got it. Um, so the adoption of AI, where is that happening? Where are you seeing the focus? Uh, is it vertical, industry specific or size of organization? Um, how do you see? How do you see? I think you mentioned in the report that high stakes organizations like critical infrastructure, finance and healthcare, um, you know, can't really tolerate the false positives. And so how do you see all of that playing out?

Speaker C: So when we talk about kind of AI and cybersecurity, we've been talking about a couple different uses and dimensions of it. One is for kind of querying and making sense of data and things that we see is pretty pervasive across large organizations, small if they can afford it and the solutions are providing it, uh, critical infrastructure, et cetera. But the more what we refer to as a silver bullet, let's identify and stop zero day attacks, uh, take action. That novel anomaly that's malicious that we've never seen before. There is where we're seeing industries with different adoption cycles and um, enthusiasm. So if you think about an organization like First Analysis, an investment firm and the risk of taking a, triggering an action on um, an AI generated alert that could, you know, disconnect somebody, uh, or take down our network, heaven forbid for 10 minutes. That is not a catastrophic thing. Frustrating as it may be that I can't get my email, uh, it's not causing any natural disasters as opposed wondering

Speaker B: where you were going with that one.

Speaker C: But as opposed to the nuclear, uh, industry, um, certain electric grid, you know, if there is an alert, you better be sure because if you, if it's a real alert and you don't take action, the consequences can be truly catastrophic. However, taking alert on a false positive, something that isn't, it's not going to be quite as catastrophic. But reactors, they will shut down and they take days to restart. So you could lose electricity generating power for a community for days, triggering on a false alert. Uh, so the tolerance for I'm gonna have some false positive rate is very different among industries. So where do we see it being adopted? It's where there's a high risk of somebody trying to attack, but a low consequence to taking action on a false alert. A lot of financial firms like ourselves, banks, things like that, they can tolerate that they can slow down a transaction without catastrophic consequences. Things where you're dealing with real assets, hardware, health monitors, MRI machines, where, you know, taking an action has real life, potentially life and death consequences. That's where we don't see it being adopted.

Speaker B: Right, okay. So this notion of an autonomous SOC needs, uh, to start in industries and organizations where the risk of an automated action disrupting operations, affecting their resilience is, is tolerable.

Speaker A: Right.

Speaker C: But I would say it's also happening where the threat environment is high.

Speaker B: Yes.

Speaker C: Because you're gonna pay for it. There's a premium to it. And I know that the consequences of not taking an action are high. You know, millions of dollars get sent to the wrong account or whatever. So it is a bad outcome, but it's not catastrophic if I stop, ah, the action or slow it down.

Speaker B: Right, right. Okay. Makes, makes total sense. Thanks. Um, so, you know, that's, those are sort of the topics that I wanted to cover. Are there any insights from your research that you'd like to share that maybe we haven't touched on?

Speaker C: I just say it's really dynamic. What makes it fun from our perspective as researchers and investors is things are moving quickly. Um, we haven't talked about the adversarial side of AI and we've talked about using it in solutions for the good guys. But the bad actors are the earliest and fastest adopters. They don't care about transparency and, you know, taking things down the wrong way. So they're, um, setting the bar and it's, it's, you are going to need these tools and these AI solutions to battle AI adversaries. There's, there's no getting around it. So it's fun to see the challenge. Um, the industry's responding very aggressively and with some fascinating solutions. It's just a joy to kind of watch it all happen real time and try and stay on top of it.

Speaker B: Yeah, great. Well, I'll say, uh, being on the inside of, uh, an organization that's working on these kinds of solutions, I'd say it's also fascinating time to be part uh, of that. So. So, yeah. Well, Howard and Liam, thank you so much for taking time to be with us on Blue, uh, Team Diaries.

Speaker C: Well, thank you and thank you for some great questions. Really appreciate it.

Speaker B: Thank you for celebrating and honoring the defenders with Blue Team Diaries. You can find this and all our previous episodes on Spotify, Google Podcasts, Apple Podcasts, and YouTube. If you're interested in learning more about our sponsor networks, please visit.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Security Bulldog's Jeff Majka on AI, Grit, and Fighting Human NatureDesigning Successful Startups · on Alert fatigue and false positives77 / 100
  • AI, Automation, & Humans' Role In Security: A View From Rsac 2026 With Jeff Man and Dwayne McDanielThe Security Repo · on SOC automation58 / 100
  • Elevating the SOC with Prophet SecuritySecurity You Should Know · on SOC automation55 / 100

More from Blue Team Diaries

All episodes →
  • Blue Team Diaries E015: Tony Wilson
  • Blue Team Diaries E014: TJ Nelson
  • Blue Team Diaries E013: Brent Deterding
  • Blue Team Diaries E012: Danny Quist
  • Blue Team Diaries E011: Josh Stroschein
Explore the best B2B Engineering & DevTools podcasts →
All Blue Team Diaries episodes →