惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Y
Y Combinator Blog
F
Fortinet All Blogs
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
aimingoo的专栏
aimingoo的专栏
博客园 - Franky
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
量子位
博客园 - 三生石上(FineUI控件)
I
InfoQ
Engineering at Meta
Engineering at Meta
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿
D
Docker
美团技术团队
雷峰网
雷峰网
U
Unit 42
Stack Overflow Blog
Stack Overflow Blog
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理

Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS What CISOs need to get right as identity enters the agentic era Stopping AiTM attacks: The defenses that actually work after authentication succeeds EDR-Software – ein Kaufratgeber
AI becoming an SOC imperative for curtailing emerging cyb...
by John Leyden Senior Writer · 2026-05-21 · via Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Security experts urge cyber leaders to evolve their operations from reactive monitoring to autonomous, real-time protection.

The cybersecurity profession is on the verge of a sea change, and security pros must begin to master AI tools to combat emerging threats by building more autonomous, real-time protections.

Expert panelists at a recent DTX conference session in Manchester, titled “Bot vs Bot: Surviving the Era of Autonomous Cyber Warfare,” highlighted how bringing AI into the security stack without weakening security fundamentals as become a security operations centre (SOC) essential. They also stressed the importance of maintaining human oversight over such systems.

While powerful, AI technologies are no panacea for immature enterprise security architectures, and they can only be applied successfully after the fundamentals of cyber defence are well covered, multiple security practitioner panellists argued. This ground layer, they said, includes system hardening, patching, access control, monitoring, and the like.

Darren Kimuli, information security lead at reinsurance firm Canopius Group, told delegates that AI deployments need to match the expectations of the business — including how an organisation meets its regulatory obligations.

“I’m more concerned about what AI fits rather than what it replaces,” Kimuli said.

Changing roles

Divine Uzodinma, cybersecurity analyst at managed services and telecom vendor Radius, said AI systems help security analysts correlate and triage security logs, a traditionally labour-intensive task.

“AI can analyse and correlate logs and triage alerts while analysts continue with their investigation,” Uzodinma said.

Muhammad Khan, head of cybersecurity at Bridgewater Finance Group, added that AI-based security tools minimise alert fatigue — a perennial problem in the industry and a leading cause of staff burnout.

The more widespread use of AI systems has meant that the role of security analysts has evolved beyond monitoring and response to “validating inputs” and assessing the risk of AI model hallucination.

Enterprises need to test the resilience of AI-based security systems against modern attack paths, such as those found waged against applications and the cloud, as well as supplier access and phishing, according to cybersecurity consultancy Secarma.

George Rees, senior cybersecurity consultant at Secarma, noted that AI is already redefining cyber rules in areas such as risk management and resilience.

Cyber battle ground redrawn

The DTX conference panel also discussed how autonomous attacker tooling is changing the threat landscape.

The enterprise threat environment is evolving into a machine-versus-machine battle ground, meaning that CISOs and other security professionals need to drive change across their organizations or risk becoming hopelessly outflanked by adversaries who are making greater use of AI technologies to mount attacks.

Moreover, there needs to be clarity on cyber team roles and oversight when automation is used to make decisions.

Cyber job roles must be redefined to ensure humans can interpret and oversee autonomous security decisions, according to the panellists.

These changing roles mean that skills such as prompt engineering and risk analysis are becoming more important for security professionals and hiring managers, according to Rees.

“AI is creating opportunities for more GRC [governance, risk, and compliance] hires” because the skillset is well-suited to the new threat environment, Rees added.

Rees compared the scope and pace of change heralded by AI to the period in the 1970s and 1980s when enterprises moved from reliance on typewriters to running a business using computers.

Lessons from Microsoft’s war against scammers

Kelly Bissell, a former corporate VP of product abuse and risk at Microsoft, who gave a keynote on cyber resilience and AI at the start of the DTX conference, told CSO after the show that an arms race is under way between cybersecurity professionals and attackers.

“Early adopters — in general — have the advantage,” Bissell said.

Here, according to Bissell, cybersecurity attackers gain an upper hand because they can ignore rules and regulations such as privacy laws, but defenders can claw back an edge on other fronts.

“Because of the scale of data we handled at Microsoft we could use machine learning techniques to see behavioural trends,” Bissell explained.

For example, Microsoft developed a neural network that was capable of identifying typosquatted domains being set up prior to impersonation attacks with very low false positive rates. “Our mission was to apply pressure to bot gangs” and frustrate their activity, Bissell said.

According to Bissell, CISOs fall into one of three camps: compliance-orientated, package-focused, or elite practitioners.

“Elite practitioners will love to use AI to improve their operations,” said Bissell, adding that AI technologies should be introduced through a process akin to a software development life cycle with extensive pen testing and guardrails prior to being left anywhere near production systems.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.