AI changes the analyst’s job

At the 17th annual Billington Cybersecurity Summit in Washington, D.C. this month, public-sector cybersecurity leaders from the U.S. and allied nations described how AI is changing security analysis. Representatives from the Canadian Centre for Cyber Security, Australian Cyber Security Centre Signals Directorate, NSA’s Cybersecurity Directorate, UK National Cyber Security Centre and New Zealand’s National Cyber Security Centre approached the change through different operational problems. Together, their examples put machines on high-volume analysis and people on validation, context and decisions.

That division changes the analyst’s job because supervision requires different work from performing every analytical step by hand. Analysts increasingly have to validate automated findings, provide organizational and threat context, and decide how to act on the results. The speakers lead agencies that deploy, oversee or depend on cyber capabilities, so they have an institutional stake in making AI adoption effective while maintaining the expertise those operations require. Their examples show how that balance can work in practice.

AI has a clear job in repetitive, high-volume analysis

The balance starts with an operational constraint: security teams have growing quantities of logged and monitored information to process while threats place greater demands on them. Repetitive workflows are natural early candidates for automation because machines can apply the same process across large, disparate bodies of information. Moving those workflows to AI can bring patterns, risks, vulnerabilities and other actionable findings to analysts sooner.

Stephanie Crowe, head of the Australian Cyber Security Centre Signals Directorate, expects that processing advantage to matter as incident response comes under greater pressure. “I think what’s going to change in terms of the threat environment is the speed and scale at which we are now expecting and responding to cyber incidents,” she said. Greater speed and scale increase the value of processing more defensive information within the available response time.

That pressure changes workflow design and how much information defenders can use. “For cyber defenders, this is a new opportunity to think about different ways of working, using the opportunities that AI gives us in automated workflows, but also being able to go through large troves of data that we have to now log and monitor.” In Crowe’s model, automation lets analysts draw findings from a larger body of monitored information while machines handle more of the repeated processing.

Larger information volumes also create a filtering problem, which David Imbordino, director of the NSA’s Cybersecurity Directorate, describes as separating useful information from irrelevant volume. “I think AI is giving us the opportunity to go through that volume of noise to get to the signal a lot quicker.” That filtering matters because extra telemetry, meaning machine-generated security data, becomes useful when teams can connect and interpret it in time to influence a response.

Once AI can filter that volume, the next opportunity is connecting information that currently takes substantial analytical work to bring together. Imbordino expects systems eventually to examine disparate pieces of information and surface something people can act on: “I think in the future, it will evolve to the point where the future of analysis [is AI] looking at disparate pieces of information to get to things that humans can act on much more quickly than is happening now, which can take days or weeks depending on the problem you’re looking at.” His “days or weeks” estimate for some current problems shows the operational value: faster analysis can put useful information in defenders’ hands while action can still affect the outcome.

That progression makes repetitive, high-volume analysis a strong use for automation. A team can automate a workflow, apply it to more logged and monitored information, connect disparate inputs and surface a candidate risk sooner. Once that candidate appears, a different kind of work begins because the organization has to determine what the finding means in its environment and what action it warrants.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

Machine-scale analysis still requires human decisions

A machine-generated finding moves the problem from processing to judgment because security priorities depend on an organization’s environment and the threats it faces. An analyst has to determine whether a finding deserves attention and how urgently it matters. Faster detection gives the analyst more time and information for that decision, while organizational context determines the decision itself.

Catriona Robinson, deputy director general of New Zealand’s National Cyber Security Centre, states that boundary directly: “Machines can’t make those decisions,” she said. A system can receive an objective and find an effective route toward it, while a person with broader context can judge whether that route is appropriate. Achieving an assigned task is one capability; choosing an acceptable course of action is another.

The distinction becomes concrete when a tool finds an unexpected way to satisfy its objective. “We‘ve all seen examples where a tool is set a task and it finds a way to achieve that task in a way that a human would not assess as the best way to achieve that task. So, yes, we see that the AI tools amplify the impact of clever humans, but actually clever humans can amplify the impact of the machines, too.” Robinson’s example makes human expertise an input to automated performance because people determine whether successful task completion also produces an acceptable result.

The same requirement applies to findings that appear more concrete, including newly identified vulnerabilities. An AI system may discover risks across far more information than an analyst could manually examine, but an organization still needs to establish whether a specific vulnerability can actually be exploited in its environment. Exploitability changes operational priority, so validation becomes part of deciding what to do with the finding.

That need for validation shapes how Crowe thinks about confidence in AI. “We talk a lot about trusting AI. I‘m not sure it’s trust,” she said. For her staff, confidence develops through a working process in which people understand potential failures, examine important outputs and test whether expert validation supports a result.

Crowe ties that process directly to automated vulnerability discovery. “I think it’s building confidence in using AI because AI will make mistakes, and having the human validation component has been really important for our staff because while [AI] can identify lots of risks or new vulnerabilities, whether or not those vulnerabilities can be exploited is something that a human needs to actually validate and understand.” Machine-scale discovery can expand the supply of findings, while expert validation determines which ones warrant action in a particular environment.

Those examples put expert judgment inside the AI workflow. AI extends an experienced analyst’s reach by processing more information and connecting relevant data faster, while analysts add threat context, organizational priorities, exploitability assessment and judgment about an acceptable course of action. With oversight built into the operating model, the next problem is how an organization develops people capable of providing it.

Some automatable work may need to remain human work

Developing that judgment can require analysts to keep doing parts of the underlying work themselves. Richard Horne, CEO of the UK National Cyber Security Centre, says his organization deliberately preserves opportunities for analysts to perform work even when machines could perform all of it. His agency adopts AI-enabled practices and depends on skilled analysts to oversee them, giving it an institutional incentive to preserve the expertise required for that oversight.

Horne connects hands-on practice directly to skill development. “One thing we‘re very focused on across all our agencies is how we maintain human skills and allow humans to do tasks which could be completely automated,” Horne said. “We actually need to be able to develop [analysts] to have the judgment that we need to be able to oversee AI effectively.” Under that model, technical automability is one factor in task design, while the task’s role in developing analyst judgment is another.

That development matters because validation depends on understanding the work behind the result. Analysts who assess exploitability, recognize an unacceptable route toward an objective or challenge an AI finding need enough practical knowledge to explain why the output should or should not drive action. If automation removes every chance to build and exercise that knowledge, the organization can reduce the expertise available to supervise its automated systems.

The earlier examples make the skill requirement specific. Horne uses hands-on work to develop oversight judgment; Robinson’s task example requires people who can recognize an unacceptable approach; Crowe’s vulnerability example requires people who can assess exploitability. Together, those requirements turn analyst development into an automation-design question because assigning work to machines changes the experience available to people.

Automation can still handle the repetitive work where Crowe and Imbordino see gains in scale and speed. The harder management choice is selective: leaders have to decide which workflows should move to machines for throughput and which opportunities for underlying analysis should remain with people because those tasks develop or test supervisory judgment. A manual task can therefore be valuable for the expertise it creates for later automated operations.

Rajiv Gupta, head of the Canadian Centre for Cyber Security, describes the potential gain in terms of increasing what his security experts can accomplish, “but really augmenting them — a 10X, 20X, 100X type improvement.” Gupta leads an agency introducing AI into its security operation, so he has an institutional stake in realizing those gains. His framing also keeps the expert at the center of the improvement: AI expands the capacity of skilled people, while the organization still has to maintain the skills needed to direct and assess that capacity.

That relationship makes automation an organizational-design problem alongside a technical one. A team that treats every manually performed task as removable can eliminate work that contributes to analyst development even when automation improves short-term throughput. A more deliberate design can automate repetitive analysis where scale and speed matter while retaining enough human practice, validation and decision-making to sustain competent oversight.

The operating model is still emerging

Because task allocation also shapes future expertise, agencies are developing the operating model while they deploy AI. The potential scale of augmentation has to coexist with decisions about which human skills organizations must preserve as automation expands. These officials have an institutional interest in making that combination work because their agencies depend on effective cyber operations and people capable of governing them.

That combination will change working practices as teams gain experience. Robinson said, “I think we will all discover over time that, as in any time of turbulent technology change, the ways that your people work has to change, and we‘re working out what cyber defense looks like in a world that is truly enabled by AI,” she said. Her formulation makes the unresolved issue operational: security leaders have to arrange machine-scale processing and human judgment so faster analysis produces decisions their organizations can confidently act on.

The early stage makes today’s workforce choices consequential because automation determines which analytical work future practitioners will learn through direct experience. Robinson captured that uncertainty directly: “But we‘re at the beginning of the journey, not the end.” Security teams are already assigning work to machines, and those assignments also determine where future analysts will get the experience required to supervise what the machines produce.

Key executive takeaways

  • Automate high-volume analysis: Security teams can use AI to process telemetry, filter noise and connect disparate data faster, reducing analytical work that can otherwise take days or weeks.
  • Keep human judgment in the workflow: Analysts need to validate AI findings, assess exploitability and apply organizational context before findings drive action. Build these review points into automated security workflows.
  • Preserve the work that builds expertise: Some automatable tasks provide the hands-on experience analysts need to supervise AI effectively. Security organizations should identify and retain work that develops validation skills and operational judgment.
  • Design the operating model alongside the technology: AI changes both security workflows and how future analysts gain experience. Cybersecurity leaders need to decide deliberately which tasks AI performs, which decisions remain human and how analysts will maintain the expertise required for oversight.

Alexander Procter

October 5, 2026

10 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.