cvtoken.vip

Council Post: AI Isn’t The Biggest Cybersecurity Risk. Yesterday’s Security Model Is

Senthil Muthu is a global cybersecurity strategist | Cybersecurity Executive | CISO | Cybersecurity Researcher | Founder.gettyOver the past twenty-five years, I have watched cybersecurity evolve through firewal...

Senthil Muthu is a global cybersecurity strategist | Cybersecurity Executive | CISO | Cybersecurity Researcher | Founder.

getty

Over the past twenty-five years, I have watched cybersecurity evolve through firewalls, cloud computing, ransomware, Zero Trust and operational technology. Every wave changed the tools we used to defend organizations. Artificial intelligence (AI) is different, as it is changing the operating model of cybersecurity itself.

Much of today's discussion focuses on AI discovering vulnerabilities or generating more convincing phishing attacks. Those developments are real, but they distract us from a more fundamental shift: AI is not simply creating new cyber risks; it is changing the speed at which cyber risk evolves.

For decades, cybersecurity assumed people would remain at the center of security operations. Analysts investigated alerts. Incident responders coordinated containment. Executives gathered information before making decisions. Technology enabled those activities, but people determined the pace.

That assumption is disappearing.

Cybersecurity Has Always Been A Race Against Time

Cybersecurity has never been only about technology. Every attack follows a familiar progression: reconnaissance, exploitation, persistence, lateral movement and impact. Historically, that unfolded over days or weeks, giving defenders time to detect, investigate and respond before significant damage occurred. There has always been a time component to it too.

AI compresses that timeline from weeks to hours and increasingly, to minutes. As a result, attackers do not need to become more sophisticated. They need to become faster. Therefore, every security process built around human decision-making comes under pressure when time becomes the deciding factor.

From Human-Speed Security To Machine-Speed Security

Most cybersecurity operating models were built for a different era. Security Operations Centers assumed analysts would manually investigate alerts before responding. Incident response plans assumed teams had time to coordinate across business functions. Vulnerability management often operated on monthly or quarterly cycles.

None of that was wrong, but it was built for what I call Human-Speed Security. AI is now moving organizations toward Machine-Speed Security, where detection, analysis and containment increasingly occur faster than humans can reasonably intervene.

Although human judgment remains indispensable in Machine-Speed Security, human execution can no longer be the bottleneck. Operating models must adjust accordingly.

Compliance Measures Control. Resilience Measures Survival.

Just as human judgement remains indispensable, frameworks and audits remain essential. These establish governance, accountability and a common language for managing cyber risk.

But compliance has never guaranteed resilience. An organization can pass every audit and still lack the ability to detect, contain and recover from a fast-moving attack.

Compliance asks whether the right controls exist. Resilience asks whether the business continues operating when those controls are tested. AI raises the importance of the second question.

I believe the next generation of cybersecurity maturity will be measured by four critical latencies:

In the AI era, speed becomes a security capability in its own right.

The Challenge Extends Beyond Traditional IT

This shift is even more significant in operational technology environments.

Manufacturing, energy and industrial control systems increasingly rely on connected technologies and AI-driven automation to improve efficiency and reliability. Those innovations create tremendous opportunity, but they also reduce the margin for delayed decision-making.

Unlike a typical IT incident, a cyberattack on an industrial environment can simultaneously disrupt production, supply chains, worker safety and business continuity. Protecting information remains important, but protecting operational resilience is what keeps the business running.

The Next Evolution Of Cybersecurity Leadership

​Earlier this year, in my Forbes Technology Council article, From Triangle To Pentagon, I argued that the CISO's responsibility has expanded beyond technical security into governance, business strategy and organizational resilience. AI is also redefining the role of the CISO.

Machine-Speed Security is defining the next chapter in this evolution, requiring the role of CISO to expand in speed as well as scope.

Boards are no longer asking only how AI changes cyber threats. They are asking how AI changes operational risk, regulatory expectations and business resilience. In this new chapter, the future CISO will not simply manage cyber risk. They will enable their organizations to move at machine speed without compromising trust, resilience or safety.

A Final Reflection

Every generation of cybersecurity has been defined by a technological shift. Firewalls defined the perimeter era, cloud transformed infrastructure, Zero Trust reshaped identity.

AI is defining the next era not because it changes the objective of cybersecurity, but because it changes the speed at which trust must be established and resilience must be demonstrated.

AI is not replacing cybersecurity professionals, but it is replacing the assumptions modern cybersecurity was built upon. Organizations that continue defending AI-enabled businesses with Human-Speed Security will increasingly find themselves fighting yesterday's threats with yesterday's operating model.

The future belongs to organizations that combine machine-speed detection and response with human judgment, governance and accountability. AI did not change the mission of cybersecurity. It changed the clock.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?