Close Menu
    • ABOUT
    • BOOK STORE
    • ENTREPRENEURSHIP
    • ESG
    • EVENTS & AWARDS
    • POLITICS
    • GADGETS
    • CONTACT
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Business explainer
    Sunday, September 27
    • TRENDING
    • EXECUTIVES
    • COMPANIES
    • STARTUPS
    • GLOBAL
    • AGRICULTURE
    • DEALS
    • Ai
    • ECONOMY
    • MOTORING
    • TECHNOLOGY
    Business explainer
    Home » Your SOC Cannot Outrun AI
    Ai

    Your SOC Cannot Outrun AI

    September 26, 20264 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News
    Troye technical director Kurt Goodall
    Share
    Facebook Twitter LinkedIn Email Copy Link

    Cybersecurity has acquired a speed problem. Attackers are increasingly using AI to automate work that once required specialist skills, while security teams are still trying to make sense of thousands of alerts.

    The uncomfortable question for CISOs is no longer whether the organisation has enough security technology. It is whether its security operation can keep up.

    That matters because AI has moved beyond being a useful assistant for cybercriminals. Check Point Research’s 2026 AI Security Report found evidence of AI operating inside live attacks, including generating commands, supporting intrusions and producing sophisticated malware. The report describes a shift from AI as a force multiplier to AI as an operator. 

    For defenders, this changes the equation. Traditional security controls remain important, but they cannot work in isolation. An attacker moving across identity, email, endpoints, cloud applications and networks can create a trail of individually insignificant events that becomes highly significant when viewed together. The ability to connect those dots quickly is becoming as important as the ability to block an individual threat.

    This is where managed detection and response (MDR) becomes particularly relevant. A modern security operation needs more than another dashboard or a stream of alerts. It needs continuous monitoring, threat hunting, investigation and response with the ability to connect events across the environment and act quickly.

    Arctic Wolf’s 2026 research shows why this is becoming an operational issue. Its global survey found that 94% of organisations are now using large language models. It also found that AI capabilities are influencing cybersecurity purchasing decisions for 94% of organisations.

    The irony is that organisations are adopting AI to improve productivity while simultaneously creating another security problem to manage. Check Point’s latest research found that organisations use an average of ten different AI applications each month.

    High risk GenAI prompts doubled from 2% to 4% over the past year, with between 87% and 93% of organisations experiencing at least one high risk GenAI interaction each month. 

    That makes visibility critical. Security teams need to know what is happening across the environment, not just what individual products are reporting. If an employee’s credentials are compromised, for example, the important question is not simply whether the login looked unusual. It is what happened next. Did the account access sensitive data? Did another endpoint communicate with it? Was an unusual cloud application involved? Did the behaviour resemble an existing attack pattern?

    This is also where cyber resilience needs to move beyond the disaster recovery conversation. Resilience means being able to detect an attack, understand its scope, contain it and recover before the business impact becomes disproportionate. It requires security operations that can respond at machine speed while still applying human judgement where the consequences matter.

    The CISO therefore has a difficult balancing act. AI needs to be adopted because competitors and attackers are already using it. It also needs to be governed because the same technology can expose corporate data, create new attack surfaces and accelerate attacks. Security cannot simply become another obstacle to AI adoption. Nor can the business introduce AI and hope the security team catches up later.

    The answer is not another pile of security tools. It is a security operation capable of bringing prevention, detection, intelligence and response together. Check Point’s 2026 research shows how quickly the attack landscape is changing, while Arctic Wolf’s latest findings demonstrate how rapidly AI is becoming embedded in enterprise security decisions.

    For South African CISOs, the message is fairly simple: if attackers can automate the attack, defenders need to automate the response. Otherwise, the SOC will always be playing catch up.

    Written by Troye technical director Kurt Goodall

    Follow on Google News
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link WhatsApp

    Related Posts

    Lesotho First Country to Implement United Nations (UN) AI Blueprint

    September 26, 2026

    Human Capital in Transition

    September 25, 2026

    The AI Notetaker has Become a Corporate Liability

    September 24, 2026

    Working with AI can Transform Employee Wellbeing

    September 24, 2026
    Top Posts

    Absa Launches Grant Fund to Back Young Entrepreneurs

    July 26, 20263,224

    Old Mutual Shareholders Reject CEO Pay Plan

    July 16, 20263,044

    PIC Board Suspends Its CEO

    July 13, 20262,809

    Avatar Confirms Ngubane’s Abrupt Exit as Co-Chief Creative Officer

    July 22, 20262,487
    Don't Miss

    Dangote Calls on Africa to Keep its Capital at Home

    September 26, 2026 INVESTING

    Africa must stop sending its capital abroad and start investing in its own industrial future,…

    ACSA Turns to Former CFO for Top Job

    September 26, 2026

    The Supply Chain Crisis Never Ended. We Just Stopped Talking About It

    September 26, 2026

    ONE Campaign launches ONE Academy

    September 26, 2026
    Stay In Touch
    • Twitter
    • LinkedIn
    • Facebook

    Business Explainer proudly displays the “FAIR” stamp of the Press Council of South Africa, indicating our commitment to adhere to the Code of Ethics for Print and online media which prescribes that our reportage is truthful, accurate and fair. Should you wish to lodge a complaint about our news coverage, please lodge a complaint on the Press Council’s website, www.presscouncil.org.za or email the complaint to khanyim@presscouncilsa.org.za Contact the Press Council on 011 4843612.

    Facebook X (Twitter) LinkedIn
    Categories
    • TRENDING
    • EXECUTIVES
    • COMPANIES
    • STARTUPS
    • GLOBAL
    • AGRICULTURE
    • DEALS
    • Ai
    • ECONOMY
    • MOTORING
    • TECHNOLOGY
    contact us
    • Get In Touch
    Facebook X (Twitter)
    • Privacy Policy
    © 2026 Business Explainer .

    Type above and press Enter to search. Press Esc to cancel.