If your organization starts using generative AI for security ops (like threat hunting or incident response), does that impact how you think about your team's roles/responsibilities? Would you expect to need fewer staff for SecOps, or even more? More or fewer high-skilled employees?

2.7k viewscircle icon1 Upvotecircle icon3 Comments
Sort by:
CIO in Telecommunication2 years ago

I'd argue it's relatively unchanged.  As the industry continues to consolidate tools and automate security functions, the threat actors are also innovating and using the same tools against you.  In my experience we are simply shifting resources from older, but still necessary, security tools as they mature into newer threat defenses.

Chief Information Security Officer in Healthcare and Biotech2 years ago

Yes. It will be concerning; if the employees are not trained enough. I would be limit this services till the time we don't identify the potential risks.

Information and Security Office & Enterprise Data Governance/AI in Finance (non-banking)2 years ago

In short, 'yes', as we leverage AI for security ops the role of first-level soc analyst becomes redundant. Basic questions that first-level analyst performs such as reviewing the logs and creating events/alerts, can be automated based on prompt questions that can be responded to by the LLM model or ChatBot AI functionality. Even if you pay extra for the capability, the human expense is reduced. 
I am not saying it today, but that is how we see it in the next 12 to 18 months as the features mature.

Content you might like

Worth it43%

Not worth it41%

Haven’t decided16%

View Results

To automate routine tasks and workflows (e.g., scheduling, data entry, basic customer/patient service inquiries)25%

To enhance decision-making through advanced analytics and insights generation (e.g., risk assessment, market forecasting)43%

To create new products, services, or customer/patient experiences (e.g., personalized recommendations, virtual assistants)22%

To improve cybersecurity and fraud detection (e.g., threat analysis, anomaly detection)10%

We are not currently planning to implement AI agents within the next 12-18 months

View Results