---
title: "AI in Cyber Defence: Useful, Urgent, but Not Magic"
description: How should security teams use AI in cyber defence? Key takeaways from the ASD ACSC guidance on prioritisation, risk, and human oversight.
image: https://blog.vectra-corp.com/hubfs/Blog%20AI%20in%20Cyber%20Defence.jpg
---

[Skip to content](https://blog.vectra-corp.com/blog/ai-in-cyber-defence-useful-urgent-but-not-magic#main-content)

[![vectra](https://blog.vectra-corp.com/hs-fs/hubfs/vectra-black-use-on-white-background-ENSIGN.png?width=250&height=130&name=vectra-black-use-on-white-background-ENSIGN.png)](https://www.vectra-corp.com/)

- [All Blogs](https://blog.vectra-corp.com/blog)

Open main navigation

Close main navigation

- [All Blogs](https://blog.vectra-corp.com/blog)

 8/10/26, 2:13 pm

# AI in Cyber Defence: Useful, Urgent, but Not Magic

[Charles Spencer](https://blog.vectra-corp.com/blog/author/charles-spencer)

Share: [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.vectra-corp.com/blog/ai-in-cyber-defence-useful-urgent-but-not-magic) [Twitter icon](https://twitter.com/intent/tweet?url=https://blog.vectra-corp.com/blog/ai-in-cyber-defence-useful-urgent-but-not-magic) [envelope icon](mailto:?body=https://blog.vectra-corp.com/blog/ai-in-cyber-defence-useful-urgent-but-not-magic)

The ASD ACSC publication [‘Opportunities for AI in Cyber Defence’](https://www.cyber.gov.au/sites/default/files/2026-05/Opportunities%20for%20AI%20in%20cyber%20defence.pdf) is a timely reminder that AI is no longer sitting at the edge of cyber security as a future consideration. It is already part of the operating environment. Attackers are using it to move faster, test ideas more cheaply, and scale activity that previously required more time, tooling or expertise. Defenders cannot afford to treat AI as a novelty, but neither should they treat it as a silver bullet.

### What makes the ASD ACSC guidance worth reading?

What I appreciated most about the guidance is its balance. It does not drift into hype. It makes a practical point: AI can strengthen cyber defence when it is applied to real security problems, inside existing control frameworks, and with strong human accountability. That is exactly the posture organisations need now. The question is not “Should we use AI?” The better question is “Where can AI improve outcomes without weakening control?”

### Where can AI help security teams first?

For many security teams, the immediate opportunity is not full autonomy. It is better prioritisation. Most organisations are already drowning in alerts, vulnerabilities, asset data, logs, tickets, exceptions and incomplete context. The hard part is rarely finding something wrong. The hard part is knowing what matters first, why it matters, and what action will actually reduce risk.

This is where AI can be genuinely useful. It can help connect signals across identity, endpoint, network, cloud, code and supply chain data. It can assist analysts by summarising complex incidents, enriching evidence, identifying patterns and proposing next steps. It can help security leaders see inconsistencies across risk assessments, policies and business units. Used well, AI becomes a force multiplier for judgement rather than a replacement for it.

### How does AI fit across the six cyber security functions?

The publication’s use of the six cyber security functions — Govern, Identify, Protect, Detect, Respond and Recover — is also helpful. It keeps the conversation grounded. AI should not be bolted on as an isolated capability or a shiny interface layered over weak fundamentals. It should support the security lifecycle.

In Govern, AI can help with policy interpretation, risk comparison and supply chain visibility. In Identify, it can improve asset discovery and vulnerability prioritisation. In Protect, it can support secure code review, permission analysis and hardening decisions. In Detect, it can help correlate telemetry and identify anomalous behaviour. In Respond and Recover, it can assist with triage, incident explanation, playbook sequencing and restoration planning.

### What happens when AI is poorly implemented?

That said, the guidance is also clear on the uncomfortable bit: poorly implemented AI can increase risk. This matters. An AI tool with excessive access, unclear authority, weak logging or poor integration can quickly become another attack surface. In some cases, it may become a very privileged attack surface.

Prompt injection, model evasion, data leakage, hallucinated outputs, automation bias and supply chain opacity are not theoretical issues. They are design and governance problems that need to be managed from the start. If an AI system can read sensitive logs, recommend containment actions, query internal systems or trigger workflows, then it needs to be treated like a serious enterprise security component. It needs access control, monitoring, testing, fallback procedures and auditability.

### Why should AI support defenders rather than replace them?

The strongest line in the report, in my view, is the idea that AI should support cyber defenders, not replace human judgement. This is especially important in high consequence environments or any situation involving state-changing actions. The faster a system can act, the more carefully its authority needs to be constrained.

Human-in-the-loop approval is not a sign of immaturity. It is a control. For actions that are destructive, irreversible or operationally sensitive, human approval should remain part of the process. The goal is not to slow everything down. The goal is to make sure speed does not outrun accountability. 

There is also a procurement lesson here. Organisations should ask harder questions of AI vendors. Not “Do you use AI?” but “What measurable security outcome improves?” Not “Can it reason?” but “Where is it technically prevented from acting?” Not “Is it secure?” but “How is it protected from manipulation, misuse and degradation?” Not “Does it integrate?” but “Does it fit our existing workflows, logging, incident response and change processes?”. Learn more about [governing AI](https://www.ensigninfosecurity.com/resources/podcasts/defending-the-defender) in this commentary from Ensign's Jonathan Goh and in this [blog](https://blog.vectra-corp.com/blog/managing-ai-risk) by Adam Basedow.

This is where Secure by Demand becomes important. Buyers have more influence than they sometimes realise. If organisations reward vague AI claims, the market will produce more vague AI claims. If they demand evidence, transparency, auditability, secure integration and clear limits, suppliers will have to build accordingly.

### What does deliberate AI adoption look like in practice?

The practical takeaway for me is simple: AI should be adopted deliberately, not defensively and not fashionably. Start with the security outcome. Define the data it needs. Limit what it can access. Constrain what it can do. Test it against real operational conditions. Monitor whether it remains useful. Make sure analysts can challenge it. Make sure actions can be traced. Make sure the organisation can recover if the AI component fails or behaves unexpectedly.

### Do cyber security fundamentals still matter in the AI era?

AI will not remove the need for strong cyber security fundamentals. If anything, it raises the importance of them. Asset visibility, patching, least privilege, logging, segmentation, incident response, recovery planning and governance still matter. AI can make those activities faster and more intelligent, but it cannot compensate for their absence.

My reading of the ASD ACSC guidance is that the opportunity is real, but it belongs to organisations that are disciplined enough to use AI safely. The winners will not be the ones that automate the most. They will be the ones that know what to automate, what to constrain, what to verify and what to leave in human hands.

That is the right tone for cyber defence in the AI era: ambitious, but controlled.

[Risk Management](https://blog.vectra-corp.com/blog/tag/risk-management), [AI](https://blog.vectra-corp.com/blog/tag/ai)

## Related posts

[![](https://blog.vectra-corp.com/hs-fs/hubfs/Shaun%20Panda%20Essential%208-2.png?height=200&name=Shaun%20Panda%20Essential%208-2.png)](https://blog.vectra-corp.com/blog/unpacking-common-waf-vulnerabilities-and-configuration-pitfalls)

[Firewalls](https://blog.vectra-corp.com/blog/tag/firewalls)

## [Unpacking common WAF vulnerabilities and configuration pitfalls (week 2)](https://blog.vectra-corp.com/blog/unpacking-common-waf-vulnerabilities-and-configuration-pitfalls)

![Picture of Shaun Burger](https://blog.vectra-corp.com/hs-fs/hubfs/shaun%20-%20Edited.png?width=50&name=shaun%20-%20Edited.png) [Shaun Burger](https://blog.vectra-corp.com/blog/author/shaun-burger) 

 28/6/24, 9:15 am

Welcome back! A big thanks for following along and taking the time to read through this series,...

[Read more](https://blog.vectra-corp.com/blog/unpacking-common-waf-vulnerabilities-and-configuration-pitfalls)

[![3 Unexpected Security Risks You Might Not Have Considered (And How to Fix Them)](https://blog.vectra-corp.com/hs-fs/hubfs/4.%203%20Unexpected%20Security%20Risks%20You%20Might%20Not%20Have%20Considered.png?height=200&name=4.%203%20Unexpected%20Security%20Risks%20You%20Might%20Not%20Have%20Considered.png)](https://blog.vectra-corp.com/blog/3-unexpected-security-risks-you-might-not-have-considered)

[Managed Security Service Provider](https://blog.vectra-corp.com/blog/tag/managed-security-service-provider), [Cyber Security](https://blog.vectra-corp.com/blog/tag/cyber-security), [Cyber Security Risks](https://blog.vectra-corp.com/blog/tag/cyber-security-risks)

## [3 Unexpected Security Risks You Might Not Have Considered (And How to Fix Them)](https://blog.vectra-corp.com/blog/3-unexpected-security-risks-you-might-not-have-considered)

[Kelvin Heath](https://blog.vectra-corp.com/blog/author/kelvin-heath) 

 12/9/23, 2:49 pm

The evolving threat landscape in our dynamic business environment presents new and unexpected...

[Read more](https://blog.vectra-corp.com/blog/3-unexpected-security-risks-you-might-not-have-considered)

[![](https://blog.vectra-corp.com/hs-fs/hubfs/The%20Hidden%20Data%20Leakage%20Problem%20in%20Modern%20Websites.jpg?height=200&name=The%20Hidden%20Data%20Leakage%20Problem%20in%20Modern%20Websites.jpg)](https://blog.vectra-corp.com/blog/the-hidden-data-leakage-problem-in-modern-websites)

[Website Security](https://blog.vectra-corp.com/blog/tag/website-security), [Supply Chain](https://blog.vectra-corp.com/blog/tag/supply-chain)

## [The Hidden Data Leakage Problem in Modern Websites](https://blog.vectra-corp.com/blog/the-hidden-data-leakage-problem-in-modern-websites)

[Kelvin Heath](https://blog.vectra-corp.com/blog/author/kelvin-heath) 

 11/5/26, 1:07 pm

Every web-based interaction you have with your customers today depends on a complex web of...

[Read more](https://blog.vectra-corp.com/blog/the-hidden-data-leakage-problem-in-modern-websites)

[![Vectra](https://blog.vectra-corp.com/hs-fs/hubfs/vectra-logo.png?width=200&height=37&name=vectra-logo.png "Vectra")](https://www.vectra-corp.com)

Copyright © 2026, Vectra

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Charles Spencer",
    "url" : "https://blog.vectra-corp.com/blog/author/charles-spencer"
  },
  "dateModified" : "2026-10-08T03:15:52.552Z",
  "datePublished" : "2026-10-08T03:13:45.000Z",
  "headline" : "AI in Cyber Defence: Useful, Urgent, but Not Magic",
  "image" : [ "https://blog.vectra-corp.com/hubfs/Blog%20AI%20in%20Cyber%20Defence.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.vectra-corp.com/blog/ai-in-cyber-defence-useful-urgent-but-not-magic",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.vectra-corp.com/hubfs/vectra-black-use-on-white-background-ENSIGN.png"
    },
    "name" : "Vectra Corporation"
  }
}
```