AI-powered cyberdefensive innovation
AI is changing cybersecurity at a speed that few organizations expected. The important lesson is not simply that attackers are using AI. It is that they have already shown what works. Security leaders do not need to invent an entirely new operating model. They can study how adversaries use AI and apply many of the same principles to defense.
This is a shift from reactive security to adaptive security. AI can continuously analyze large volumes of security data, identify patterns that humans would likely miss, and help security teams respond before incidents become major business disruptions. Instead of spending most of their time investigating alerts after an attack begins, teams can use AI to detect unusual behavior earlier, prioritize the highest-risk events, and automate parts of the response.
For executives, this changes how cybersecurity investments should be evaluated. AI should not be viewed as another software tool added to the technology stack. It should become part of the organization’s operating model. The companies that integrate AI into security operations today will be in a much stronger position as attacks become faster, more targeted, and increasingly automated.
There is also an important governance challenge. AI can accelerate decision-making, but it should not replace human oversight for high-impact actions. Organizations need clear policies for how AI recommendations are reviewed, when automated actions are allowed, and how security teams validate AI-generated results. Trust in AI comes from consistent performance, transparency, and measurable outcomes.
At the Gartner Cybersecurity and Risk Management Summit 2026, Leigh McMullen, Gartner Analyst at Gartner, argued that the AI processes used by attackers are “not necessarily particularly exquisite, elaborate or all that involved and actually present us with an opportunity to create the mirror of them in defense.” His point is practical: organizations can learn directly from attacker behavior and use those lessons to strengthen their own defenses.
Upscaling capabilities with AI
One of AI’s biggest advantages is scale. It allows attackers to do more work, more quickly, and with fewer people. A criminal with limited technical knowledge can use AI to write convincing phishing messages, generate malicious code, or automate repetitive tasks. Experienced threat actors use the same technology to increase the speed and complexity of sophisticated attacks.
Security teams should approach AI with exactly the same mindset. AI should increase the capability of every analyst. It can process enormous amounts of network activity, identify suspicious behavior across multiple systems, and reduce the time required to investigate potential threats. This allows experienced professionals to focus on decisions that require judgment while routine work is handled automatically.
For business leaders, this is especially important because cybersecurity talent remains difficult to hire and retain. AI helps organizations extend the impact of existing teams instead of relying solely on expanding headcount. That creates operational resilience while improving efficiency and reducing response times.
The quality of AI also depends on the quality of the data it learns from. Organizations that maintain accurate asset inventories, well-structured security logs, and current threat intelligence will see significantly better results than those with fragmented or incomplete data. Investing in data quality is therefore as important as investing in AI itself.
Leigh McMullen, Gartner Analyst at Gartner, noted that defenders should use AI to expand their own capabilities by training models that become more effective at identifying threats, containing intrusions, and protecting systems. His recommendation reflects a broader industry shift: AI is becoming a force multiplier for cybersecurity teams rather than simply another security product.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Enhanced target selection through AI-driven intelligence
AI has significantly improved how attackers gather information before launching an attack. They no longer need to spend days manually collecting public data. AI can quickly analyze websites, social media profiles, company announcements, regulatory filings, and other public sources to build detailed profiles of organizations and individuals. This information can then be used to create highly convincing phishing emails, business email compromise campaigns, or deepfake-based social engineering attacks.
This means organizations should assume that any publicly available information can become part of an attacker’s research process. Executives are especially attractive targets because they often have a strong public presence. Interviews, conference presentations, press releases, and professional networking profiles all contribute to an organization’s digital exposure. Reducing unnecessary public information does not eliminate risk, but it does reduce opportunities for attackers to create highly personalized attacks.
The same AI capabilities can strengthen defense. Organizations can deploy AI agents to continuously monitor what information about the business is publicly available, identify accidental data exposure, and track emerging threats targeting executives or critical business units. Instead of relying on periodic reviews, AI enables continuous monitoring and faster identification of new risks.
Leigh McMullen, Gartner Analyst at Gartner, recommended using retrieval-augmented generation (RAG) pipelines to improve AI-driven security research. RAG enhances large language models by grounding responses in trusted external data rather than relying only on the model’s internal knowledge. He suggested building custom threat intelligence feeds that continuously monitor personally identifiable information (PII) breaches involving key executives and potential targeting vectors.
McMullen also highlighted practical data sources that organizations can integrate into these systems, including RSS feeds, AI-generated scripts, web crawlers, Information Sharing and Analysis Center (ISAC) feeds, and Common Vulnerabilities and Exposures (CVE) feeds. Security teams can also direct AI research agents toward known threat actor groups to improve intelligence gathering and identify evolving attack patterns before they become active threats.
For executives, this is an opportunity to shift from static threat intelligence to continuous intelligence. AI enables organizations to maintain a current understanding of both their own exposure and the changing tactics used by adversaries, supporting faster and more informed security decisions.
Countering attack obfuscation with AI-enhanced deception
Threat actors are increasingly using AI to hide how they operate. They can modify malware, vary attack sequences, and change indicators that security tools traditionally rely on for detection. This makes attacks more difficult to identify using conventional security approaches that depend on known signatures or predictable behavior.
Organizations can respond by using AI to create controlled deceptive environments that attract attackers while protecting production systems. These environments provide security teams with an opportunity to observe attacker behavior, collect intelligence, and understand emerging tactics without exposing critical business assets. Rather than simply blocking attacks, organizations gain visibility into how adversaries operate and adapt over time.
Leigh McMullen, Gartner Analyst at Gartner, suggested using AI-generated synthetic data to occupy threat actors while monitoring their activity. He also recommended deploying authentic-looking honeypots, test ranges, look-alike tools, fake websites, bogus vulnerabilities, and dead-end backdoors. These techniques encourage attackers to interact with controlled environments, allowing defenders to capture valuable information about their tactics, techniques, and procedures (TTPs).
For executives, deception technology should be viewed as an intelligence capability rather than only a defensive control. The insights collected from these environments can improve incident response planning, strengthen threat detection models, and support more effective risk assessments. As attackers continue to evolve their methods, organizations that learn from every attempted intrusion will be better positioned to anticipate future threats instead of responding only after damage has occurred.
Successful implementation also requires governance. Deception environments should be carefully designed so they remain isolated from production systems, are continuously monitored, and comply with legal and regulatory requirements. When managed properly, AI-powered deception becomes an effective source of operational intelligence that strengthens long-term cyber resilience.
Automating cybersecurity tasks to redirect human resources
AI is becoming an essential part of cybersecurity operations because it can handle repetitive work at a speed and scale that is difficult for human teams to match. Attackers already use AI to automate time-consuming activities, including living-off-the-land attacks, maintaining persistent access, and executing automated kill chains. Organizations should respond by applying the same level of automation to strengthen their own security operations.
Many security teams spend a significant portion of their time on operational tasks that are necessary but repetitive. AI can continuously monitor systems, correlate security events from multiple sources, prioritize alerts based on risk, and assist with routine investigations. This reduces alert fatigue and allows analysts to focus on incidents that require human judgment, strategic thinking, and business context.
Leigh McMullen, Gartner Analyst at Gartner, said that AI agents can take responsibility for activities such as tracking threat actors, supporting offensive security testing, running security simulations, and assisting with call center governance. By automating these operational functions, security leaders can dedicate more attention to innovation, business priorities, and long-term risk management.
For executives, automation should not be measured only by the number of manual tasks eliminated. Its value comes from improving consistency, increasing response speed, and enabling security teams to operate more effectively without relying solely on additional hiring. As cyber threats continue to grow in both volume and sophistication, scaling security operations through automation becomes an important business capability rather than simply a technology initiative.
Successful adoption also requires thoughtful governance. Not every security decision should be fully automated. Organizations should establish clear policies defining which actions AI can execute independently and which require human approval. High-impact actions, such as isolating critical systems or responding to incidents that affect business operations, should include appropriate oversight to reduce operational risk.
Another important consideration is continuous improvement. AI systems become more effective when they are regularly updated with current threat intelligence, organizational policies, and feedback from security teams. Organizations should monitor AI performance, validate its recommendations, and refine models over time. This creates a security operation that improves continuously instead of remaining dependent on static rules.
The broader opportunity is clear. AI allows cybersecurity teams to shift their focus from repetitive operational work toward strategic initiatives such as improving organizational resilience, strengthening cyber risk governance, supporting secure digital transformation, and enabling faster business innovation. Organizations that combine human expertise with well-governed AI automation will be better positioned to respond to an increasingly complex threat landscape while making more effective use of limited cybersecurity resources.
Main highlights
- Learn from attacker AI strategies: Threat actors have already demonstrated how AI can accelerate cyber operations. Security leaders should adapt those proven techniques for defense to improve detection, response, and overall cyber resilience.
- Use AI to scale security capabilities: AI enables security teams to increase effectiveness without relying solely on larger headcounts. Prioritize AI models that strengthen threat detection, automate routine analysis, and support faster incident response.
- Turn AI into a continuous intelligence engine: Attackers use AI to identify high-value targets, and defenders should do the same to understand their own exposure. Invest in AI-driven threat intelligence, RAG pipelines, and continuous monitoring to identify risks before they become attacks.
- Deploy deception to gather better intelligence: AI-powered deception technologies can expose attacker behavior while protecting production systems. Use honeypots, synthetic data, and controlled environments to collect actionable intelligence that improves future defenses.
- Automate routine security work to focus on strategy: AI should handle repetitive cybersecurity tasks so skilled professionals can concentrate on high-value decisions and business priorities. Establish clear governance to ensure automation delivers speed and consistency while maintaining appropriate human oversight.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


