Thursday 22 January, 2026
[email protected]
Resilience Media
  • About
  • News
  • Resilience Conference
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • About
  • News
  • Resilience Conference
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

AI in cybersecurity remains a tool for understanding, not response

Analysis of thousands of real-world security queries shows practitioners are using AI primarily to contextualise risk, rather than to automate remediation.

Carly PagebyCarly Page
January 22, 2026
in News
Laptop screen showing a search bar.
Share on Linkedin

Despite industry hype around autonomous defence, new research shows security teams spent 2025 using AI mainly to explain and contextualise security data, not to take action.

You Might Also Like

Inside Dronamics bid to become the unmanned logistics carrier for future conflicts

How space could become the next battlefield

Auterion conducts live fire swarm drone strike test

That’s according to a new report based on anonymised prompts from more than 2,000 users of the Sola Security platform between May and December 2025. The data shows security teams turning to AI for explanation and investigation, with close to 60 percent of prompts focused on understanding issues rather than triggering automated response. This reflects what the report describes as a persistent “clarity bottleneck” inside security teams.

The report cites earlier ISC2 research showing limited AI adoption in security teams, with only one in three professionals using it day to day.

Looking across all 7,592 prompts, Sola Security found that most questions clustered around a small number of areas, led by application security, followed by cloud and infrastructure, security operations, and identity and access management. Application security alone accounted for more than a quarter of all queries, with risk assessment standing out as the most common concern. Many of the requests were narrowly focused, referring to specific GitHub repositories, OWASP frameworks, APIs, and known vulnerabilities in live code.

Most cloud questions focused on exposed or misconfigured resources, particularly systems left publicly accessible and the extent of the impact. Identity and access requests were often messier, pulling in several platforms at once as teams tried to untangle permissions across large environments.

The data also shows that security concerns change as organisations get bigger. Smaller teams mostly worry about cloud configuration issues, mid-sized firms spend more time on application vulnerabilities as development ramps up, and larger organisations are preoccupied with access controls, audit requirements, and creeping privileges.

While early users mostly asked AI to help them identify issues, behaviour changed over the course of 2025. Requests to “Monitor and Track” activity grew by 8.8 percentage points in the latter part of the year, while simple discovery declined. As the report puts it, early questions asked “what is this?”, while later ones asked “keep watching this”.

The report references comments from Andrew Ng, a leading AI researcher, who has argued that organisations are moving beyond single prompts towards “very complex workflows in these iterative multi-step agentic workflows”.

Even so, the report is clear that full autonomy is not the goal. Based on what practitioners actually asked AI to do in 2025, the priority remains helping security teams understand, prioritise, and monitor their environments more effectively – not replacing human judgement or decision-making.

Tags: AIsecurity
Previous Post

How geopolitics complicates venture

Next Post

Inside Dronamics bid to become the unmanned logistics carrier for future conflicts

Carly Page

Carly Page

Carly Page is a freelance journalist and copywriter with 10+ years of experience covering the technology industry, and was formerly a senior cybersecurity reporter at TechCrunch. Bylines include Forbes, IT Pro, LeadDev, The Register, TechCrunch, TechFinitive, TechRadar, TES, The Telegraph, TIME, Uswitch, WIRED, & more.

Related News

Inside Dronamics bid to become the unmanned logistics carrier for future conflicts

Inside Dronamics bid to become the unmanned logistics carrier for future conflicts

byJohn Biggs
January 22, 2026

https://youtu.be/aYt1Av6ojwQ Dronamics started as a cargo drone company, and it is now betting that the same airframe can do much...

view of Earth and satellite

How space could become the next battlefield

byPaddy Stephens
January 21, 2026

Future great power conflict is unlikely to be limited to the land, seas and skies. Great powers also rely on...

Rheinmetall and Auterion Announce New NATO-Wide Military Hardware-Software Partnership

Auterion conducts live fire swarm drone strike test

byJohn Biggs
January 20, 2026

Munich- and Virginia-based Auterion says it has completed what it describes as a first for the small drone space in...

blue and yellow striped country flag

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

byIngrid Lunden
January 20, 2026

Palantir, the US data analytics giant, has been a regular presence in Ukraine helping with its defence against Russia since...

us a flag on pole near snow covered mountain

Dominion Dynamics raises $15M to build a new arctic defence prime in Canada

byIngrid Lunden
January 19, 2026

The US has become a somewhat unpredictable neighbour to Canada, with President Trump’s threats of annexation and spiking tariffs looming...

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

byIngrid Lunden
January 19, 2026

Make way for another drone startup in the European defence tech ecosystem. Twentyfour Industries is today emerging from stealth armed...

Power outages and small checks: The perils of being a VC in Kyiv

Power outages and small checks: The perils of being a VC in Kyiv

byJohn Biggs
January 16, 2026

When I called Sasha Yatsenko, the power had just cut out. No sirens, no warning, just a few minutes of...

Equal1 Wants Quantum to Be as Simple as CPUs and GPUs — and It’s Raised $60m to Prove It

Equal1 Wants Quantum to Be as Simple as CPUs and GPUs — and It’s Raised $60m to Prove It

byFiona Alston
January 16, 2026

Equal1, an Irish quantum semiconductor company announced this week it had raised $60 million to fuel the next stage of...

Load More
Next Post
Inside Dronamics bid to become the unmanned logistics carrier for future conflicts

Inside Dronamics bid to become the unmanned logistics carrier for future conflicts

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Harmattan AI raises $200M at a $1.4B valuation from Dassault

Hydrosat raises $60M for its thermal satellite imaging tech

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Defense Unicorns lives up to its name: $136M round lifts valuation past $1B

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

No Result
View All Result
  • About
  • News
  • Resilence Conference
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.