Monday 9 March, 2026
[email protected]
Resilience Media
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • About
  • News
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

AI in cybersecurity remains a tool for understanding, not response

Analysis of thousands of real-world security queries shows practitioners are using AI primarily to contextualise risk, rather than to automate remediation.

Carly PagebyCarly Page
January 22, 2026
in News
Laptop screen showing a search bar.
Share on Linkedin

Despite industry hype around autonomous defence, new research shows security teams spent 2025 using AI mainly to explain and contextualise security data, not to take action.

You Might Also Like

Trump cyber strategy outlines tougher stance on cybercrime and adversaries

Augur, a ‘grey-zone’ national security startup, raises $15M

Ukrainian autonomy company The Fourth Law unveils an anti-Shahed drone

That’s according to a new report based on anonymised prompts from more than 2,000 users of the Sola Security platform between May and December 2025. The data shows security teams turning to AI for explanation and investigation, with close to 60 percent of prompts focused on understanding issues rather than triggering automated response. This reflects what the report describes as a persistent “clarity bottleneck” inside security teams.

The report cites earlier ISC2 research showing limited AI adoption in security teams, with only one in three professionals using it day to day.

Looking across all 7,592 prompts, Sola Security found that most questions clustered around a small number of areas, led by application security, followed by cloud and infrastructure, security operations, and identity and access management. Application security alone accounted for more than a quarter of all queries, with risk assessment standing out as the most common concern. Many of the requests were narrowly focused, referring to specific GitHub repositories, OWASP frameworks, APIs, and known vulnerabilities in live code.

Most cloud questions focused on exposed or misconfigured resources, particularly systems left publicly accessible and the extent of the impact. Identity and access requests were often messier, pulling in several platforms at once as teams tried to untangle permissions across large environments.

The data also shows that security concerns change as organisations get bigger. Smaller teams mostly worry about cloud configuration issues, mid-sized firms spend more time on application vulnerabilities as development ramps up, and larger organisations are preoccupied with access controls, audit requirements, and creeping privileges.

While early users mostly asked AI to help them identify issues, behaviour changed over the course of 2025. Requests to “Monitor and Track” activity grew by 8.8 percentage points in the latter part of the year, while simple discovery declined. As the report puts it, early questions asked “what is this?”, while later ones asked “keep watching this”.

The report references comments from Andrew Ng, a leading AI researcher, who has argued that organisations are moving beyond single prompts towards “very complex workflows in these iterative multi-step agentic workflows”.

Even so, the report is clear that full autonomy is not the goal. Based on what practitioners actually asked AI to do in 2025, the priority remains helping security teams understand, prioritise, and monitor their environments more effectively – not replacing human judgement or decision-making.

Tags: AIsecurity
Previous Post

Capital under siege: Sanctions, supply chains and politics now drive VC decisions

Next Post

Inside Dronamics bid to become the unmanned logistics carrier for future conflicts

Carly Page

Carly Page

Carly Page is a freelance journalist and copywriter with 10+ years of experience covering the technology industry, and was formerly a senior cybersecurity reporter at TechCrunch. Bylines include Forbes, IT Pro, LeadDev, The Register, TechCrunch, TechFinitive, TechRadar, TES, The Telegraph, TIME, Uswitch, WIRED, & more.

Related News

shallow focus photo of flag of United States of America neon light

Trump cyber strategy outlines tougher stance on cybercrime and adversaries

byCarly Page
March 9, 2026

The White House last week published a new national cyber strategy promising a more assertive response to digital threats, signalling...

high angel photography of football stadium

Augur, a ‘grey-zone’ national security startup, raises $15M

byIngrid Lunden
March 9, 2026

Augur, a London cybersecurity startup co-founded by Palantir alums that is building an AI-based analytics platform to “read” data from...

Ukrainian autonomy company The Fourth Law unveils an anti-Shahed drone

Ukrainian autonomy company The Fourth Law unveils an anti-Shahed drone

byJohn Biggs
March 6, 2026

Ukraine-based autonomy company The Fourth Law has unveiled Zerov, an autonomous interceptor drone built to engage long-range strike UAVs in...

Ukraine’s autonomous weapons makers push for industrial scale

Ukraine’s autonomous weapons makers push for industrial scale

byLuke Smith
March 6, 2026

In the past five months in Ukraine, Major Maksym Gromov's unit launched 608 autonomous Lupynis drones against Russian adversaries. Four...

asphalt road between trees

MSC got the urgency right. The hard part comes next

byRobin Dechant
March 6, 2026

A few weeks on from the Munich Security Conference, something many of the Resilience Media community no doubt attended, I...

NATO Innovation Fund appoints a president, Ari Kristinn Jónsson

NATO Innovation Fund appoints a president, Ari Kristinn Jónsson

byIngrid Lunden
March 5, 2026

The NATO Innovation Fund, the VC formed out of the strategic alliance of NATO countries that counts most (but not...

SkySafe Wants to Be the Air Traffic Control for Drones

SkySafe partners with major energy sector player to build out drone defence

byJohn Biggs
March 5, 2026

Southern States LLC and SkySafe announced a partnership to integrate real time drone detection and airspace intelligence into Southern States’...

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

byIngrid Lunden
March 5, 2026

The United Kingdom and Ukraine look like they may have minted their first defence tech ‘unicorn’. Uforce (stylised ‘UFORCE’) —...

Load More
Next Post
Inside Dronamics bid to become the unmanned logistics carrier for future conflicts

Inside Dronamics bid to become the unmanned logistics carrier for future conflicts

white and black mountain under blue sky during daytime

Weekly Digest: Greenland stays safe, but geopolitics still drives defence tech

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Senai exits stealth to help governments harness online video intelligence

Harmattan AI raises $200M at a $1.4B valuation from Dassault

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

No Result
View All Result
  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.