Cybersecurity needs actual intelligence before artificial intelligence

June 2026 Information Security, AI & Data Analytics


Ray Hall

In a security operations centre, incidents rarely arrive neatly labelled. Analysts do not get a single perfect alert saying, “This is the problem. Here is the business impact. Here is the safest response.”

What they usually see is something far messier: an unusual login, a file moving where it should not, a strange endpoint, an email that looks almost legitimate, or a user action that could be a simple mistake, or a sign that someone is exploiting pressure, trust, and timing.

For DigitalShield, this is where AI has become increasingly useful. It can connect signals faster, cut through alert noise, and support threat detection, investigation, and response. Given the pace of modern attacks, no serious security team can afford to ignore it.

“I do not believe the future of cybersecurity is artificial intelligence on its own. In a SOC, the better model is AI²: actual intelligence and artificial intelligence. Human judgment comes first; AI strengthens it,” says Ray Hall, SOC manager at DigitalShield.

That is because cybersecurity depends on interpretation. A tool can tell you something unusual has happened, but people still need to work out whether it is a genuine risk, what it means for the business, and how to respond without unnecessary disruption.

Actual intelligence is the analyst’s understanding of the environment: which systems matter most, which user roles carry greater risk, which alerts need escalation, and which events need more context. It is the judgment that separates a quick reaction from the right response.

When AI exposes old weaknesses

The AI conversation has become more urgent as both defenders and attackers adopt it. Microsoft’s 2025 Digital Defense Report notes that threat actors are using AI to scale phishing and automate intrusions, while defenders need faster detection, automated response and strategies built for scale. Attackers are not waiting for businesses to finish internal AI discussions.

At the same time, AI is exposing weaknesses that were already present in many organisations. IBM’s Cost of a Data Breach Report 2025 found that 63% of organisations lacked AI governance policies, while 97% of those reporting an AI-related security incident lacked proper AI access controls. That should give any business pause before connecting AI to sensitive data, workflows and decision-making without understanding who can access what.

In South Africa, the pressure is sharper because many businesses are modernising with uneven security maturity, stretched IT teams, and complex legacy environments. If the basics are not under control, AI can magnify the risk.

The concern is rarely the AI tool alone. More often, the deeper issue is the underlying data environment. Sensitive information may be spread across systems, access rights may have expanded, classification may be inconsistent, and permissions may no longer match what people need. If that environment is already exposed, AI can accelerate the problem.

The human signal

Verizon’s 2026 Data Breach Investigations Report found that the human element was present in 62% of breaches. Mimecast’s State of Human Risk 2026 also points to pressure on email, collaboration tools, insider risk, credential misuse, and AI-powered attacks.

DigitalShield argues that describing people as the weakest link encourages lazy security thinking. While people are part of the risk, they are also part of the defence. The same employee who clicks on a convincing phishing email may also flag something unusual early enough to stop a broader incident. The question is whether that signal is noticed, understood, and acted on.

AI can prioritise alerts, identify patterns and help analysts move faster. Analysts still need to apply judgment, test assumptions, understand business context and decide what happens next. After an incident, people still need to refine detection rules, tighten access controls, review configurations, update awareness training and strengthen response plans.

The basics have to become operational

For businesses, the AI conversation should start with the parts of security that too often receive too little attention. Sensitive data needs to be identified, access rights controlled, over-permissioned accounts reduced, and continuous monitoring maintained. Incident response plans also need testing in advance, with alerts reviewed by people who understand both the technical signal and the business consequence.

Buying more tools will not solve a visibility problem if no one is watching the environment. Automation will not fix uncontrolled data access. Awareness training also falls short when suspicious behaviour is never connected to technical signals. This is where managed security services and SOC capabilities become valuable for organisations without the people, time, or specialist depth to maintain continuous internal oversight.

AI will keep improving, and defenders should use it. But AI should make security teams sharper, not passive, by combining machine speed with human context, disciplined monitoring, and clear response processes.

Find out more at www.digitalshield.co.za.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
You will not get your files back with VECT
Information Security
If the newbie to the ransomware scene, VECT, comes knocking at your organisation’s door, do not pay the ransom! The decryption keys simply do not exist. They were discarded at the moment of encryption by the malware itself.

Read more...
Industrial sector is a primary cyber target
Information Security
Threats in industrial environments are distributed with striking uniformity: APT-driven incidents constitute 17,8%, malware 14,9% and social engineering 13,9%. This pattern suggests that industrial organisations attract a broad range of adversaries with different capabilities and objectives.

Read more...
Key attributes of an effective cybersecurity leader
BlueVision Information Security
In an evolving technology landscape, an effective cyber leader must combine technical acumen, foresight, and adaptive leadership to mitigate risks, and risks can only be mitigated once accurately identified and remedial processes are in place.

Read more...
Employees are SA’s biggest cyber threat
Security Services & Risk Management Information Security
South Africa experienced a 46% increase in insider cyber risk in 2026, surpassing the global average of 44%. What is more, 63% of South African companies surveyed expect insider-driven data losses to increase.

Read more...
Surge in AI-enabled cybercrime and a 389% increase in ransomware
News & Events Information Security
Cybercrime no longer functions as a series of isolated campaigns; it operates as a system, with malicious hackers operating across an end-to-end life cycle and compressing the attack life cycle with shadow agents.

Read more...
Tackling enterprise security ‘tool sprawl’
NEC XON Information Security
South African ICT solutions provider NEC XON is advocating a shift away from fragmented cybersecurity toolsets towards unified platforms, arguing that ‘tool sprawl’ is undermining the effectiveness of enterprise security operations.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.