Why Cybersecurity Can No Longer Move at Human Speed
George Ralph of RFA argues that AI is reshaping cybersecurity, making AI-powered defense essential to keep pace with increasingly fast and automated cyberattacks.
In 2026, cybersecurity should be a top priority for every organization. The reason is simple: the cost of getting it wrong is enormous. Even after a 9% decline, the global average cost of a data breach (according to IBM’s 2025 security report) still sits at $4.44 million.
In financial services, that figure rises to $6.08 million per incident. That’s why investing in the right defenses is always cheaper than dealing with the aftermath.
What's changed is how those defenses need to work. A decade ago, human-led security was the standard — analysts monitoring, detecting, and responding at every stage. That model is no longer viable today. Attackers are already using AI to move faster, strike harder, and automate at scale.
Defenders have to match that pace. In today’s piece, I will share my thoughts on why that matters, and what it means for your security strategy.
The Numbers Don't Lie
CrowdStrike's 2026 Global Threat Report was released earlier this year with a statistic that should have ended every boardroom debate about AI in security operations: the average cybercrime breakout time has dropped to 29 minutes. This represents a 65% increase in speed year-over-year.
The fastest recorded breakout was just 27 seconds. In one documented intrusion, data exfiltration began within four minutes of the initial compromise. Most organizations cannot even open a security ticket in that amount of time. Only ten years ago, no one imagined attackers could operate at such extraordinary speeds.
The primary driver behind this dramatic increase in speed is recent technological advancements, particularly in AI and computing. AI-enabled adversary activity grew 89% year-over-year.
Attackers now leverage AI to automate reconnaissance, accelerate credential dumping, generate polymorphic malware that mutates faster than signature-based defenses can detect, and erase forensic evidence as they exit. Tasks that once required skilled human operators now occur at machine speed, at scale, and on demand.
The SOC Can't Run on Human Speed Alone
For close to two decades working in IT and security, I have observed how analysts operate under pressure — alert fatigue, tool sprawl, talent shortages, and clients who want answers instantly. That pressure is nothing new. But the math has changed.
When a breakout can happen in 29 minutes and your SOC is still triaging alerts through human-led ticket queues, you have a structural problem that no amount of hiring will fix. The talent market is not going to bail you out.
The 2026 AI SOC Leadership Report found that 97% of security leaders are confident AI can handle alert triage — yet only 35% are actually using it there. That gap points to something deeper than a technology problem. It reflects an operational and cultural shift that most organizations have yet to make.
The scale of what analysts are up against makes that shift more urgent. Automated traffic is now growing eight times faster than human traffic, according to HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report. The volume of attempted attacks increased by almost 47% from 2024 alone.
The internet increasingly runs on automation — and so do the attacks traversing it. Relying on human analysts alone is no longer a viable strategy given the volume, speed, and complexity of what they face.
Human expertise remains essential for judgment, verification, and escalation — those capabilities cannot be automated away. But triage, enrichment, pattern correlation, and initial containment need to run at machine speed, or they simply do not run in time.
What a Modern Security Operating Model Should Look Like
The modern security operations model should be an AI-first one. Rebuilding around AI doesn't mean replacing your analysts. The evidence points clearly in the other direction. You need to have teams using AI to monitor, detect, and resolve attacks.
Hack The Box research published earlier this year found that AI-augmented security teams significantly outperformed both human-only and AI-only teams — with nearly 3.9 times higher solve rates on mid-complexity challenges.
The strongest performance came from teams where experienced practitioners directed the AI, validated results, and made final decisions. Humans must supervise and steer the system rather than performing every triage step themselves.
In practice, this means:
AI-driven triage at scale. Agentic AI investigates alerts — it does not just flag them. It enriches events with context, correlates signals across the stack, and reaches a verdict before a human analyst needs to engage.
Tier 1 work handled autonomously, consistently, at machine speed. Automated containment. Isolating endpoints, disabling compromised accounts, blocking IPs — executed in seconds via automated workflows rather than through manual coordination between analyst and client IT team.
This approach frees security teams to focus on what actually requires their expertise. When AI handles the repeatable, high-volume work, analysts can concentrate on threat hunting, incident response, client advisory, and the complex judgement calls that genuinely require human insight.
It is worth noting that AI is the underlying capability, not a product in itself. To realize its benefits, you need security tools that are built to take advantage of it. Whether that is your SOAR or SIEM platform, ensure your provider has AI meaningfully integrated — not just bolted on as a feature.
You can also leverage dedicated AI security tools such as Microsoft Security Copilot and also deploy AI agents to accelerate everyday security operations across your environment.
The Honest Question
I have helped scale MSSPs from single-country operations to global businesses. The strategic conversations I am having now are fundamentally different from anything I navigated five years ago.
The question is no longer whether to adopt AI. That decision has already been made by the threat actors on the other side of every client environment you are protecting.
The right question is how quickly you can automate the security tasks that no longer need a human in the loop — and whether that speed is sufficient to keep pace with attacks that are growing more sophisticated by the day.
Investing in AI and cutting-edge security technology does come at a cost, particularly at this stage where computing overheads remain high. But in my view, that cost is worth it. The time it frees up for your team and, more importantly, the attacks it can help you avoid — far outweigh the initial investment.
If you are navigating this shift and want to discuss what an AI-ready security strategy looks like for your organization, feel free to connect or send me a message. I am always happy to share what I have seen work — and what has not.