AI as an accelerator of deception in cybersecurity

AI has fundamentally changed the economics of cyberattacks. A single attacker can now generate thousands of convincing phishing emails, fake identities, and personalized messages in the time it once took to prepare a handful of attacks. The cost has dropped, the speed has increased, and the quality of deception has improved. That changes the competitive landscape for every enterprise.

Many security discussions still focus on better detection. Detection is important, but it is no longer enough. The bigger challenge is verification. Every security decision depends on knowing what is actually true. Did a user really log in? Was a configuration actually changed? Is an alert connected to a real business risk or just another false positive? Those answers must be available immediately.

The advantage for defenders has always been access to the truth. Attackers can create unlimited false information at very low cost. Organizations cannot respond with more guesses or more alerts. They need systems that can verify events, identities, and business impact at machine speed. AI should help answer questions with confidence.

For executives, this represents an important shift in investment priorities. AI-powered security tools deliver value only when they are connected to reliable and complete data. If the underlying information is fragmented or outdated, faster AI simply produces faster uncertainty. The organizations that gain a lasting advantage will be those that make trusted evidence available as quickly as attackers can generate deception.

This is becoming even more important as AI agents begin performing security tasks automatically. These systems will increasingly investigate incidents, recommend actions, and execute approved workflows. Every automated action must be supported by evidence that can be reviewed, explained, and trusted. Speed without confidence creates unnecessary business risk.

The centrality of evidence quality in defense

Cybersecurity is increasingly becoming a data problem before it becomes a detection problem. Every security platform depends on evidence, and the quality of that evidence determines the quality of every decision that follows. AI cannot compensate for missing information. It can only work with the data it receives.

Organizations generate enormous amounts of information every day. Authentication records, endpoint activity, cloud logs, configuration changes, asset inventories, support tickets, and network telemetry all contribute pieces of the same picture. The challenge is not collecting this information. The challenge is preserving it, accessing it quickly, and connecting it into a complete and trustworthy view of what happened.

Business context matters just as much as technical data. An unusual login has limited value by itself. The situation changes completely when security teams know the identity belongs to a contractor, the affected system supports customer payments, recent configuration changes occurred, and unusual network activity happened at the same time. Context transforms isolated events into actionable intelligence.

This has direct implications for executive leadership. Security investments should prioritize data governance, evidence retention, and cross-platform visibility alongside AI capabilities. Organizations often focus on acquiring new detection tools while overlooking the quality of the information feeding those tools. That creates blind spots that become more expensive as operations become increasingly automated.

The next generation of AI-powered security systems will make decisions much faster than human teams can. That creates a higher standard for data quality. Every automated recommendation or action should be traceable to reliable evidence that can be audited later. This is essential for security operations and for regulatory compliance, internal governance, and board-level accountability.

The organizations that perform best in the AI era will not necessarily be those with the most advanced models. They will be the ones with the most trustworthy data. Reliable evidence allows both people and AI systems to make faster, more consistent decisions with confidence. That is becoming one of the strongest competitive advantages in cybersecurity.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

Fragmentation of security data impedes effective response

Modern enterprises have security data spread across dozens, sometimes hundreds, of systems. Identity platforms, endpoint security tools, cloud services, network infrastructure, asset management systems, and IT service platforms all generate information that matters during an investigation. The problem is not that this data exists. The problem is that it rarely exists in a form that supports fast, confident decisions.

A suspicious login is a good example. On its own, it may appear to be a routine authentication anomaly. To determine whether it represents a real threat, analysts often need identity history, endpoint activity, cloud access logs, configuration changes, asset ownership, network telemetry, ticket records, and business information. If each data source requires a different tool, a different team, or a separate approval process, valuable time is lost before the investigation even begins.

This creates unnecessary operational friction. Security teams spend too much time collecting information instead of evaluating risk and responding to incidents. As attacks become faster and increasingly automated, delays caused by fragmented data become more expensive. Even a well-trained security team cannot make high-quality decisions if the required evidence is scattered across disconnected systems.

AI increases the urgency of solving this problem. AI systems can retrieve and process information quickly, but they cannot create missing evidence or restore context that was never captured. If the available data is incomplete, outdated, or inconsistent, AI will simply produce conclusions based on those limitations. Faster processing does not improve data quality.

For business leaders, this changes the conversation from buying more security products to improving how information moves across the organization. Security architecture should reduce barriers between data sources and allow evidence to be accessed where it already exists. This improves response times while avoiding the cost and complexity of moving every dataset into a single repository.

Organizations that solve data fragmentation create a stronger operational foundation for AI. Analysts gain faster access to complete evidence, AI systems receive richer context, and executive teams gain greater confidence that important security decisions are supported by reliable information rather than assumptions.

Transitioning from passive repositories to a defensive control plane

For many years, organizations viewed security platforms, Security Information and Event Management (SIEM) systems, and data lakes primarily as storage platforms. They collected logs, retained records, and supported investigations after an incident occurred. That approach is becoming insufficient as AI takes on a larger operational role.

Modern security requires a defensive control plane. This is not simply another repository for security data. It is an operational layer that connects technical events, business context, governance policies, and approved actions into a single decision framework. Instead of only storing evidence, it makes evidence immediately useful for both human analysts and AI systems.

This shift changes the questions security platforms must answer. Organizations no longer need only an official record of events. They need to understand what happened, why it matters, what evidence supports the conclusion, and which actions are permitted under company policy. Every recommendation and every automated response should be transparent, explainable, and supported by verifiable information.

The importance of governance also increases as AI agents become more capable. Future security systems will enrich alerts, open investigation cases, trigger workflows, isolate affected assets, update policies, and escalate critical decisions. Every one of these actions must remain within defined authority, follow established policies, and leave a complete audit trail that explains why the action was taken.

For executives, this is an architectural decision as much as a security decision. Organizations should evaluate whether their existing platforms can connect evidence, business priorities, and governance into a unified operating model. AI will continue to improve rapidly, but its value depends on the quality and transparency of the environment in which it operates.

A defensive control plane also supports broader business objectives. Regulatory compliance, internal audits, board oversight, and customer trust increasingly depend on demonstrating that important decisions are evidence-based and reviewable. Security architecture that provides this level of transparency strengthens both operational resilience and organizational accountability.

The four pillars of an effective defensive control plane

A defensive control plane succeeds only if it consistently delivers trustworthy information and supports reliable action. This depends on four core capabilities: preserving evidence, accessing data wherever it resides, adding business context, and governing actions. Together, these capabilities create an operating model that supports both human analysts and AI systems.

The first capability is preserving evidence. Security investigations often depend on information that appeared unimportant before an incident occurred. Logs, metrics, traces, identity records, configuration changes, tickets, and asset states all contribute to understanding what happened. Organizations need retention strategies that preserve this evidence long enough to support investigations, regulatory requirements, and future analysis. Missing evidence can prevent teams from understanding the full scope of an attack or proving how an incident unfolded.

The second capability is making data accessible wherever it lives. Enterprise data is already distributed across cloud platforms, operational systems, object storage, business applications, and security tools. Attempting to move every dataset into a single location is often slow, expensive, and difficult to govern. A more practical approach is to analyze data where it already exists while maintaining consistent visibility across environments. This allows organizations to respond more quickly without creating unnecessary operational complexity.

The third capability is adding business context. Technical events alone rarely indicate business impact. Security teams need to understand which applications support critical services, which assets contain sensitive information, which users have privileged access, and which business processes could be disrupted. When technical evidence is connected to business priorities, organizations can allocate resources more effectively and respond according to actual business risk rather than technical severity alone.

The fourth capability is governing actions. AI will increasingly move beyond identifying incidents to executing operational tasks. It may enrich alerts, create investigation cases, trigger workflows, isolate devices, recommend policy updates, or escalate critical events. Organizations need governance frameworks that define what AI systems are allowed to do, what evidence supports each action, and how every decision can be reviewed afterward. Transparency becomes essential as automation expands.

For executives, these four capabilities should be viewed as long-term strategic investments rather than isolated technology features. AI adoption will continue to accelerate, but sustainable value depends on reliable evidence, broad data visibility, meaningful business context, and strong governance. Organizations that build these capabilities today will be better positioned to scale AI safely while maintaining trust across customers, regulators, employees, and shareholders.

The overwhelming challenge of context in modern SOCs

Security Operations Centers (SOCs) generate and process enormous volumes of information every day. The challenge is not a shortage of alerts or data. The challenge is turning that information into decisions that security teams can trust and act upon quickly. Without sufficient context, even advanced detection systems produce limited business value.

Findings from the Splunk State of Security 2025 report reinforce this issue. According to the report, 59% of SOC analysts struggle with too many alerts, 55% report excessive false positives, and 46% say alerts lack sufficient context. These figures suggest that the primary operational bottleneck is not detection capability but the ability to connect fragmented information into a complete understanding of an incident.

This affects both efficiency and decision quality. Analysts frequently switch between multiple tools, manually gathering evidence from different systems before they can determine whether an alert represents a genuine threat. Every additional step increases response time and introduces opportunities for inconsistency. As organizations adopt AI-assisted operations, these inefficiencies become more significant because automated systems are only as effective as the context they receive.

Business leaders should recognize that reducing alert volume alone will not solve this problem. An organization can deploy better detection models and still struggle if alerts remain disconnected from identity information, asset ownership, business processes, or recent infrastructure changes. Context determines whether a security event becomes an informed business decision or another unresolved investigation.

Improving context requires integrating technical and business information into a unified operational view. When analysts can immediately see how a security event relates to critical applications, sensitive data, privileged accounts, or customer-facing services, they can prioritize incidents with greater confidence and consistency. This also enables AI systems to generate recommendations that align more closely with business priorities.

For executive teams, stronger contextual intelligence produces measurable business benefits beyond cybersecurity. Faster investigations reduce operational disruption, improve resource allocation, support regulatory reporting, and strengthen organizational resilience. As AI becomes a larger part of security operations, organizations that invest in richer context will make better decisions while reducing unnecessary operational overhead.

Embracing a data fabric architecture for trusted AI-driven defense

AI is changing security operations, but AI alone is not the solution. The real differentiator is the quality of the data infrastructure that supports it. A data fabric architecture addresses this challenge by creating a unified layer that connects information across Security Operations (SecOps), IT Operations (ITOps), and Network Operations (NetOps) without requiring organizations to centralize every dataset into a single repository. The objective is not consolidation for its own sake. It is to ensure that trusted information is available wherever and whenever it is needed.

Most enterprises already have significant investments in security tools, cloud platforms, business applications, and operational systems. Replacing those systems is rarely practical or necessary. A data fabric builds on these existing investments by enabling data to be discovered, accessed, and correlated across different environments. This improves visibility while allowing organizations to maintain the governance and ownership models that already exist within different business units.

The value of this approach extends beyond operational efficiency. AI systems become more effective when they can retrieve complete, current, and contextual information from across the enterprise. Instead of producing isolated recommendations based on a limited dataset, AI can evaluate technical events alongside business priorities, governance policies, asset ownership, and historical evidence. This results in decisions that are both faster and more reliable.

Cisco Data Fabric powered by the Splunk Platform is an example of this architectural direction. The platform combines machine data, data federation, business context, governance, and provenance into a unified operational model. This enables organizations to move from individual security signals toward evidence-based actions while maintaining visibility into how conclusions were reached and which data supported each decision.

For executives, the important takeaway is that a data fabric should be viewed as an operating model rather than simply another technology purchase. The architecture creates the foundation that allows AI, automation, and security teams to work from the same trusted information. As organizations continue adopting AI across security operations, fragmented data environments will increasingly become a strategic limitation rather than just a technical challenge.

This architectural approach also supports broader business priorities. Organizations are under growing pressure to demonstrate regulatory compliance, strengthen cyber resilience, improve operational efficiency, and manage risk across increasingly complex digital environments. A unified data layer helps address all of these objectives by creating consistent access to evidence while preserving governance and auditability.

The competitive advantage ultimately comes from trusted action. Attackers will continue using AI to make deception faster, cheaper, and more personalized. Organizations cannot expect to match that advantage by generating more alerts or deploying more isolated security tools. They need systems that connect evidence, context, policy, and automation into a single decision process. When every action is grounded in verifiable information that both people and AI can trust, security becomes faster, more consistent, and better aligned with business objectives.

Concluding thoughts

AI is changing cybersecurity at a pace that few organizations can afford to ignore. The question is no longer whether attackers will use AI more effectively. They will. The real question is whether your organization can make trusted decisions just as quickly.

That requires a different way of thinking about security. Detection remains essential, but it is no longer the defining advantage. The organizations that will lead are those that can verify events, connect evidence across the business, and automate responses without sacrificing governance or accountability.

This is ultimately an architectural challenge. AI can only deliver meaningful outcomes when it operates on complete, reliable, and contextual data. If information remains fragmented across disconnected systems, even the most advanced AI models will produce inconsistent results. Trust cannot be added after the fact. It has to be built into the foundation.

For executives, this makes cybersecurity a strategic business capability rather than a standalone technology function. Investments in data architecture, governance, and operational integration will increasingly determine how effectively AI can reduce risk, improve resilience, and support business growth. These decisions will also influence regulatory readiness, customer confidence, and the organization’s ability to respond to future threats.

Attackers will continue to improve the speed, scale, and sophistication of AI-driven deception. That trend is unlikely to slow. Organizations do not gain an advantage by matching that speed with more alerts or more isolated security tools. They gain it by ensuring every decision is grounded in evidence that people and AI systems can trust.

In the AI era, trusted data is no longer just a security requirement. It is becoming a core business asset. Organizations that recognize this shift early will be better positioned to move faster, make better decisions, and build resilience in an increasingly complex digital environment.

Alexander Procter

August 4, 2026

14 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.