The impact of AI on security

Issue 6 2025 Information Security, AI & Data Analytics

Today’s threat actors have moved away from signature-based attacks that legacy antivirus software can detect. They leverage ‘living-off-the-land’ techniques, using legitimate system tools such as PowerShell, WMI, and built-in Windows utilities to move laterally through networks. Attackers are now capable of spending days or longer in a network before detection. This is where AI has a critical role to play.


Peter Chan.

Artificial Intelligence (AI) in security systems is defined as the use of technologies such as machine learning, deep learning, and natural language processing to enhance the detection, analysis, and mitigation of security threats. It is further endorsed as beneficial for predictive threat detection and adaptive responses. Such solutions offer early detection of cyber threats in endpoint devices, including laptops, desktops, smartphones, and all things that fit into the ‘Internet of Everything’ world.

AI is capable of identifying patterns and anomalies that indicate potential threats faster and more accurately than traditional methods. Moreover, it enables behavioural analysis of devices and users to detect anomalies that may indicate a cyber-breach that can be blocked immediately by isolating affected devices. Further benefits of AI technologies include the ability to predict and pre-empt potential future threats, as well as the capacity for continuous learning from new data, which in turn improves accuracy and effectiveness.

Efficient identification and resolution

The future is being shaped by the evolution of Endpoint Detection Response (EDR) into Extended Detection and Response (XDR) platforms, which automate processes and enable security teams to more efficiently identify and resolve cyberattacks through AI and machine learning. These capabilities do not just rely on known signatures; they analyse behaviour across endpoints, networks, and identities to detect anomalies and stop attackers before they can fully establish themselves. AI-driven models are increasingly crucial to spotting subtle deviations that humans or traditional tools would miss.

The concept of a bad actor spending days or longer in your network may make your flesh crawl, but it is the reality behind the sophistication of cybercrime today. This is called dwell time, and it allows them to establish persistence, escalate privileges, and exfiltrate data using techniques that traditional endpoint protection simply was not designed to address.

Endpoints have become the launchpad for identity-based attacks, but many organisations still rely on perimeter-focused security models that assume the endpoint itself is trusted. Throwing tools at the situation is an obvious choice for many businesses, but in fact, it can actually make matters worse, as what is called ‘tool proliferation’ has become a significant challenge.

The answer lies with better integration. Companies using integrated security platforms detect threats faster and reduce false positives compared to those relying on disparate point solutions.

Security is a business issue, not a technical one

Effective measurement requires focusing on business-relevant outcomes rather than tool outputs. You need to measure Mean Time to Detection (MTTD) and Mean Time to Response (MTTR) – calculating the number of days it takes to identify and contain a breach. You must also examine what percentage of your endpoints provide real-time behavioural analytics. This is crucial. What you are seeking is reduced downtime from incidents and faster recovery times.

The most mature organisations also measure security friction through employee productivity metrics. If your endpoint security is generating help desk tickets or pushing users towards shadow IT, then your strategy is counterproductive, regardless of how many threats are blocked. Your security teams must be capable of testing your endpoint strategy against real-world attack scenarios, providing practical assurance that defences actually work under pressure.

Zero Trust principles offer a framework, but implementation must be pragmatic. Cost is always a major consideration with many organisations applying uniform policies that either over-protect low-risk endpoints (driving up costs) or under-protect critical assets. Cost optimisation comes from recognising that not all endpoints require the same level of protection.

A smarter approach is to implement adaptive authentication and conditional access policies that consider user behaviour, device posture, location, and data sensitivity. This can reduce friction, while improving protection for high-risk scenarios. The real challenge is instrumenting your environment so you understand the impact of controls on business workflows, then optimising them around actual risk.

In a nutshell, if companies want to win with endpoint security, they need to stop treating it as a technical barrier and instead view it as a business capability that engenders trust, resilience, and growth.

Find out more at www.bitm.co.za


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

SanDisk MAX ENDURANCE microSD card
Technews Publishing SMART Security Solutions Smart Home Automation Products & Solutions
SMART Security Solutions received a 128 GB SanDisk microSD card for the video surveillance market to put to the test. The storage card is designed for edge-recording cameras, dashcams, and more.

Read more...
The dangers of parked domains
Information Security
Kaspersky warns that fraudsters are exploiting so-called ‘parked domains’ to harvest sensitive personal data from unsuspecting users. These deceptive sites often masquerade as error pages or ad-filled placeholders, exposing users to privacy breaches and potential identity theft.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Buying more security tools is not building a defence
Information Security
Sophisticated attacks are specifically engineered to bypass individual security tools, and companies absorbing the damage are those who have confused procurement with protection, says Richard Frost from Armata Cyber Security.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
BlueVision launches Fusion Cloud
BlueVision Information Security Products & Solutions
Most businesses have moved to the cloud, including Microsoft 365, Azure, AWS and more, and in doing so assume they're protected because they're using a reputable platform; however, the reality is somewhat different.

Read more...
Tools detect threats: Cyber resilience protects businesses
Information Security
If your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it ‘done’, then someone has sold you a story, not a strategy.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.