We ran 1,060 autonomous attacks. Here's what the industry gets wrong. 100+ experts across 30+ countries recently published the most comprehensive AI safety assessment ever. Their assessment: AI can assist cyber operations -- but full autonomy is yet to be observed. We respectfully disagree, and we have the (security) receipts. If you don't read the full post (linked below), here's my TLDR: The International AI Safety Report 2026 is excellent. Genuinely worth reading. But its conclusions are calibrated to general-purpose AI. When you build purpose-built offensive systems, the picture looks very different. ⚡️ XBOW runs fully autonomous pentests against real production systems. Every day. → 1,060+ vulnerabilities on HackerOne → 48-step exploit chains → Broke a cryptographic implementation in 17 minutes The report says AI "cannot reliably execute long, multi-stage attack sequences." Our agents do exactly that. The difference isn't the model. It's the *architecture*: thousands of short-lived agents, each with a narrow objective, orchestrated by a persistent coordinator, validated by deterministic logic. If one agent hits a dead end on step 4, another starts fresh and finds a different path. The window between vulnerability and exploitation is shrinking to hours. Annual pentests leave you exposed for most of the year. 🙂 The good news: the same AI powering offense also powers defense. Continuous, autonomous security testing isn't theoretical. It's being built as we speak. Full post 👇
How Automation Improves AI Security Assessments
Explore top LinkedIn content from expert professionals.
Summary
Automation in AI security assessments means using automated tools and processes to help identify, explain, and resolve vulnerabilities in AI systems faster and more reliably. By automating tasks like data collection, analysis, and security testing, organizations can quickly spot risks and reduce the chances of cyberattacks, making AI systems safer and more trustworthy.
- Build strong guardrails: Set clear rules for when automated systems can act, how decisions are made, and ensure every action is traceable to increase trust in AI-based security.
- Integrate and audit: Regularly review AI usage, approve new tools, and audit automated processes to keep hidden vulnerabilities and unauthorized activities in check.
- Use automation for insights: Let automation gather data and signals across your environment so AI can spot unusual patterns and highlight risks without overwhelming security teams.
-
-
Anthropic 's Claude new code security capability didn’t introduce a better scanner — it introduced a new layer in AppSec. For years, we scaled detection: more tools, more alerts, more triage. But security never scaled at the same speed as software. What changed now is simple but structural — security reasoning moved into the developer workflow. AI doesn’t just find patterns, it explains risk, understands intent, and proposes secure alternatives. That shift compresses the distance between detection and remediation, which is where most AppSec friction has always lived. This doesn’t replace the AppSec stack, but it forces consolidation. Lightweight SAST, standalone review workflows, and parts of manual code assessment will increasingly become capabilities rather than products. The value moves upward — toward orchestration, governance, runtime validation, and decision quality. In other words, security is moving from tools to intelligence. From a CISO perspective, this is an operating model change, not a tooling trend. Teams that embed AI as a control layer will scale expertise without scaling headcount at the same rate. Teams that treat it as a developer feature will see incremental gains but miss the structural advantage. Within the next two years, most mature engineering organizations will run an AI reasoning layer inside their SDLC — formally or organically. The real risk is not adopting early. The real risk is adoption without design. AI-native code security doesn’t eliminate AppSec. It reveals which parts were process — and which parts were expertise. #AI #CyberSecurity #AppSec #DevSecOps #CISO #AIsecurity #Claude #SoftwareSecurity
-
In 2025, we tried every possible way to align automation with AI in our SOC. Here’s what turned out to be for us the game changer. Before scaling automation and AI in your SOC, design control. Automation and AI are no longer experimental. They are becoming operational components. As soon as systems execute actions and AI produces recommendations, the SOC is no longer just observing. It is shaping outcomes. That’s where most teams struggle. Not with models. Not with prompts. But with missing guardrails. The challenge is no longer building AI. It’s controlling it. That’s why we designed our six SOC AI guardrails: #1 Response modes: Define upfront when automation may act, when humans must decide, and where automation is never allowed. #2 Confidence scoring: Measure how safe it is to act on an interpretation, not how bad an incident might be. #3 Context as a dependency: Automation and AI are only reliable when asset, identity and behavioral context are non-negotiable inputs. #4 Deterministic response actions: Every decision must map to predictable, pre-approved actions, with no improvisation at runtime. #5 Boundaries for AI agents: AI components are treated like privileged systems, with strict scopes, permissions and execution limits. #6 Auditability by design: Every automated or AI-supported action must be explainable, traceable and reproducible. Only after implementing these six guardrails do automation and AI become truly usable in our SOC. Not as theory. As operational design. If you’re building an automated or AI-enabled SOC, this control layer is non-negotiable. Without guardrails, AI scales uncertainty. With them, it scales trust. Full breakdown in the article below 👇 PS: If this approach resonates, let me know. Next posts will break down how each guardrail looks in practice.
-
𝐖𝐡𝐞𝐫𝐞 𝐡𝐚𝐯𝐞 𝐈 𝐬𝐞𝐞𝐧 𝐚𝐠𝐞𝐧𝐭𝐢𝐜 𝐀𝐈 𝐝𝐞𝐥𝐢𝐯𝐞𝐫 𝐯𝐚𝐥𝐮𝐞 𝐭𝐡𝐚𝐭 𝐭𝐫𝐚𝐝𝐢𝐭𝐢𝐨𝐧𝐚𝐥 𝐚𝐮𝐭𝐨𝐦𝐚𝐭𝐢𝐨𝐧 𝐜𝐨𝐮𝐥𝐝 𝐧𝐨𝐭? The answer requires a bit of precision. Agentic AI does not replace automation. In many environments, it should not. Traditional automation remains one of the most stable and governed ways to run enterprise systems. It provides predictable execution, clear guardrails, and reliable integration with legacy platforms. In most organizations, automation still acts as the bridge between technical debt, infrastructure, and modern systems. Agentic AI becomes valuable when it is layered on top of that operational foundation, not when it replaces it. The real value appears when AI introduces what I call intelligence at scale. Automation ensures the enterprise environment is producing reliable operational signals, logs, telemetry, system events, and structured data pipelines. AI can then interpret those signals at scale and surface patterns that would otherwise require large amounts of human analysis. A few examples illustrate the difference. ▫️ Cybersecurity operations. Automation continuously collects logs, asset data, and system events across the environment. AI can analyze patterns across those signals, identify anomalies, and prioritize potential responses for human teams to review. ▫️ Operational decision support. Automation gathers and updates enterprise data from multiple systems. AI synthesizes that information to highlight emerging trends, operational risks, or strategic opportunities leaders should evaluate. ▫️ Knowledge work acceleration. Automation ensures research inputs, enterprise knowledge, and data pipelines remain structured and accessible. AI can then synthesize that information into scenarios, summaries, and recommendations. Without those automated data pipelines and operational controls, AI lacks the grounding required to produce reliable outcomes. When organizations skip that step, they often mistake generated answers for trustworthy insight. That is where risk begins. Organizations must avoid what I call intellectual surrender, accepting AI outputs without understanding how those outputs were derived or what information they were based on. The most successful deployments combine both disciplines. ▫️ Automation provides structure, governance, and reliable system integration. ▫️ AI provides interpretation, contextual reasoning, and intelligence at scale. When those two work together, organizations move beyond simple task execution and toward informed decision making at enterprise scale. Forbes Technology Council InsightJam.com PEX Network Theia Institute VOCAL Council IgniteGTM IA FORUM Thinkers360 𝗡𝗼𝘁𝗶𝗰𝗲: The views within any of my posts, or newsletters are not those of my employer or the employers of any contributing experts. 𝗟𝗶𝗸𝗲 👍 this? Feel free to reshare, repost, and join the conversation!
-
AI breaches are no longer hypothetical, and most teams aren’t ready. IBM’s 2025 Cost of a Data Breach report puts numbers behind what many of us are seeing on the ground. Here’s what we learned reviewing it end-to-end: • 13% of organizations reported breaches of AI models or apps, and 97% of those lacked basic AI access controls. • Shadow AI hurts. 1 in 5 breaches involved unsanctioned AI, adding about $670,000 to breach costs and exposing more PII and IP. • Attackers use AI too. 16% of breaches involved AI tools, often for phishing or deepfake impersonation. • The U.S. hit a record $10.22M average breach cost while the global average fell to $4.44M. • Using AI and automation across security saved ~$1.9M and cut breach lifecycles by 80 days. • Post-breach investment is slipping. Only 49% plan to increase security after a breach. Why this matters for Midwest and Main Street: ungoverned AI is creating easy, high-value targets in firms that already run lean. The fix isn’t a moonshot. It’s fundamentals applied to new tooling. Small businesses can implement this by: ✅Turning on least-privilege for AI systems and secrets (RBAC to models, data, prompts). ✅Discovering and approving AI usage to kill shadow AI, then auditing it monthly. ✅Training teams to spot AI-boosted phishing and deepfakes with real examples. ✅Putting AI to work in SecOps – detection, triage, playbooks – to speed response. ✅Measuring time-to-detect and time-to-contain weekly. What gets measured gets fixed. The results speak for themselves: governance plus automation lowers risk and cost. What’s the one AI control you’ll implement this quarter?
-
Is your SOC understaffed — or under-automated? Many security leaders assume the answer is headcount. More analysts, more coverage, better outcomes. But the real constraint has never been people. It's been the model — one built around human triage of infinite alerts, where severity thresholds exist not because of risk logic, but because the team couldn't physically handle the volume. AI SOC changes that equation. But only if you run it the right way. Here are 5 best practices shared by Jon Hencinski and Gourav Nagar from deploying AI-enabled security operations: 1️⃣ Investigate everything, not just what's "high severity" When AI handles the investigative workload, severity becomes an input — not a triage gate. Low-severity signals get worked while they're still early indicators. The backlog disappears as a permanent operating condition. 2️⃣ Enforce investigative consistency Human analysts vary by fatigue, experience, and time of day. AI automates and documents every step in the investigation — every single time. That consistency turns output anomalies into real signals, not artifacts of human variance. 3️⃣ Expand your detection library aggressively Engineers hesitate to write more detections because the SOC can't handle the volume. With AI, that constraint disappears. Deploy behavioral rules with high false positive rates if they occasionally catch critical breaches. AI handles the noise. You get the coverage. 4️⃣ Don't rush to full autonomy Automated investigation ≠ automated remediation. Banning IPs or disabling accounts without a human decision gate can cause outages harder to unwind than the original threat. Optimize for decision support first — let AI gather evidence at machine speed, then hand high-impact actions to humans. 5️⃣ Validate with a parallel run Trust in an autonomous system must be statistical, not anecdotal. Run a 15-30 day test where AI processes the same queue as your team. Compare verdict accuracy, data sources examined, and conclusions reached. Move from "I think it works" to "the data proves it works." The goal isn't to replace analysts. It's to move manual and repetitive tasks off the human queue — so your team spends time where it actually changes outcomes. Think role elevation, not role elimination.
-
I recently watched Endor Labs fantastic fireside chat featuring Ammar Alim, a Senior DevSecOps Manager at Adobe, who shared a refreshingly grounded perspective on integrating AI into security. He discussed how they're leveraging LLMs to automate the creation of WAF (Web Application Firewall) rules and streamline the onboarding of new vendors onto their WAF platform. But what truly stood out was his pragmatic approach: instead of attempting to build a monolithic, all-encompassing LLM system, they're starting small and smart. Each WAF team is being assigned its own LLM (powered by RAG - Retrieval-Augmented Generation) specifically tailored to the vendors and rules they manage. This is a brilliant strategy because it allows them to: - Leverage Deep Domain Expertise: Each WAF team has unique, specialized knowledge about their assigned vendors. By providing them with a dedicated AI assistant, they can train the model on highly relevant data, leading to more accurate and effective solutions. - Iterate Faster: This decentralized approach allows teams to experiment, refine, and deploy solutions much more quickly. They're not held back by the complexities of a large, centralized system. - Empower, Not Replace: He emphasized that his WAF teams are irreplaceable. Their deep security expertise is critical for constantly evaluating the AI's performance and, more importantly, for creating new AI security solutions that were previously unimaginable. The AI serves as a powerful tool to augment their capabilities, not replace them. This grounded, team-centric approach to AI integration is a powerful lesson for all leaders. It’s about empowering your experts with the right tools to amplify their impact, rather than chasing a one-size-fits-all solution. This is a great example of how to successfully navigate AI transformation in a practical, impactful way. #AI #Cybersecurity #DevSecOps #SecurityEngineering #Adobe #Leadership #Innovation #WAF
-
**5 Key Lessons from Automating Security Decisions with Arcanna Ai & Google Siemplify** In the past year, I've integrated Arcanna AI with our security operations, significantly improving our response time and accuracy. Here are five insights that I gained from this experience, each saving time and reducing effort. If you're involved in security operations, these insights could potentially streamline your workflows. *Lesson 1: Embrace Integration for Efficiency* A major challenge in security operations is handling vast amounts of data. Many teams try to manage manually, which leads to delays. The reality is, integrating platforms like Arcana AI with systems such as Siemplify SOAR can transform your operations. By automating decision-making, we cut our incident response time by 30%. Ensure key integrations are up to date. This maximizes the systems' potential and effectiveness. *Lesson 2: Use AI for Decision Support* Security teams often rely solely on human judgment, which can be inconsistent. Arcanna AI provides consistent decision support based on accumulated data and learning. When we started, initial skepticism faded as the reliability became evident through reduced false positives. Implement AI-based decision support. It enhances accuracy and confidence in security measures. *Lesson 3: Provide Continuous Feedback for Improvement* A common misconception is that AI models are static and unchanging. In reality, providing feedback improves AI models significantly. Initially, our models struggled with identifying complex threats. With continuous feedback, detection rates improved. Keep offering feedback to the AI to refine its decision-making capabilities. *Lesson 4: Prioritize Retraining for Relevance* AI solutions can become outdated without regular updates, leading to ineffective responses. Regular training ensures the AI evolves with new data inputs. The changes we introduced increased the model's precision by almost 40%. Schedule regular retraining sessions. This maintains the relevance and efficiency of your AI tools. *Lesson 5: Prepare for Initial Learning Curves* New implementations can face resistance due to unfamiliarity. However, after initial adjustments, Arcana AI's integration became a crucial part of our team. The initial phase took time, but results soon aligned with expectations. Anticipate an initial learning period. The benefits solidify over time as familiarity grows. These lessons highlight the potential of integrating AI tools like Arcanna into security operations. Trust in technology, ongoing improvements, and adapting processes are key to maximizing performance. Ready to enhance your security operations? Start by integrating and trusting decision intelligence platforms within your workflow. https://lnkd.in/eNJFX59k
-
Your AI coding assistant is shipping PRs faster than your security team can review them. Surprise, surprise. I've been saying for years that the real API security killer isn't SQL injection (your scanner catches that, you just don't fix it). It's the boring, invisible stuff that's dangerous. A missing role check. A body field that quietly accepts "role: admin" from anyone who asks nicely. The OWASP API Top 10 hits that account for the majority of real-world breaches, and that no regex in the world is going to find for you. Intent vs. implementation drift is the problem. Your spec says "admins only." Your Friday-afternoon code says "sure, come on over." So we did something about it. Our team built a system using Postman’s Agent Mode that actually reads the spec (the intent), reads the code (the implementation), spots the gap, generates a security test plan, and produces a runnable Postman collection, all without a human holding its hand through every step. No, it's not magic. It requires you to have a maintained API spec with security annotations. I'll wait while half of you go update yours. But for teams shipping API-first with AI? This is the missing piece. Automated, scalable security review that keeps pace with your velocity…and turns your security tests into a continuous contract monitor, not a one-time checkbox. Details on the full pipeline from Anurag Mewar (including the part where the agent chains skills without being re-prompted, which honestly still impresses me): https://lnkd.in/ghkPRfUq Read it. Then go check if your POST handlers are actually enforcing the role checks your spec promises they are. #APISecurity #CISO #SecurityEngineering #Postman #AI
-
I’ve been following the research on how AI is reshaping gap analysis in compliance. Many CISOs and compliance leaders already know. Manual gap analysis is slow, costly, and often a major blocker for businesses trying to stay ahead of audits and regulations. As a virtual CISO, I saw this first hand. GRC work was always mission critical but also one of the biggest drains on time and budget. Every client I support struggles with the same thing. We all need clear and fast answers about where we stand against standards and regulations. Early evidence shows how much of a difference AI is making. Providers using AI in their compliance and vCISO practices are reporting a 68% workload reduction in tasks like assessments and reporting. That’s time CISOs can now put back into strategy, risk reduction, and security execution. Key stats: Manual processes take weeks, while AI can complete tasks in hours. - AI achieves up to 95% accuracy, compared to 60–70% with manual reviews. - Companies using AI report a 40% reduction in compliance incidents. That’s why we built Audit CADDIE at BLodgic. We want to take what was once a painful, drawn-out process and make it something that saves teams time, effort, and cost, while giving leaders more confidence in their compliance posture. The GRC field is moving quickly and it’s encouraging to see more voices showing how AI can make compliance smarter, faster, and more accessible. https://lnkd.in/ewqjC5ti