Sunday, 28 June 2026 PDT | 02:47 AM
The 1 News Alt Logo Text Smart News for Global Indians

Cybersecurity needs actual intelligence before artificial intelligence

AI News June 24, 2026 03:00 PM
Cybersecurity needs actual intelligence before artificial intelligence

Cybersecurity needs actual intelligence before artificial intelligence

Should you have feedback on this article, please complete the fields below.Please indicate if your feedback is in the form of a letter to the editor that you wish to have published. If so, please be aware that we require that you keep your feedback to below 300 words and we will consider its publication online or in Creamer Media’s print publications, at Creamer Media’s discretion.We also welcome factual corrections and tip-offs and will protect the identity of our sources, please indicate if this is your wish in your feedback below.

As a magazine-and-online subscriber to Creamer Media's Engineering News & Mining Weekly, you are entitled to one free research report of your choice. You would have received a promotional code at the time of your subscription. Have this code ready and click here. At the time of check-out, please enter your promotional code to download your free report. Email subscriptions@creamermedia.co.za if you have forgotten your promotional code. If you have previously accessed your free report, you can purchase additional Research Reports by clicking on the “Buy Report” button on this page. The most cost-effective way to access all our Research Reports is by subscribing to Creamer Media's Research Channel Africa - you can upgrade your subscription now at this link.

The most cost-effective way to access all our Research Reports is by subscribing to Creamer Media's Research Channel Africa - you can upgrade your subscription now at this link. For a full list of Research Channel Africa benefits, click here

If you are not a subscriber, you can either buy the individual research report by clicking on the ‘Buy Report’ button, or you can subscribe and, not only gain access to your one free report, but also enjoy all other subscriber benefits, including 1) an electronic archive of back issues of the weekly news magazine; 2) access to an industrial and mining projects browser; 3) access to a database of published articles; and 4) the ability to save articles for future reference. At the time of your subscription, Creamer Media’s subscriptions department will be in contact with you to ensure that you receive a copy of your preferred Research Report. The most cost-effective way to access all our Research Reports is by subscribing to Creamer Media's Research Channel Africa - you can upgrade your subscription now at this link.

If you are a Creamer Media subscriber, click here to log in.

This article has been supplied and will be available for a limited time only on this website.

In a Security Operations Centre, incidents rarely arrive neatly labelled. Analysts do not get a single perfect alert saying, “This is the problem. Here is the business impact. Here is the safest response.” What they usually see is something far messier: an unusual login, a file moving where it should not, a strange endpoint, an email that looks almost legitimate, or a user action that could be a simple mistake, or a sign that someone is exploiting pressure, trust, and timing.

For DigitalShield, a South African cybersecurity services provider, this is where AI has become increasingly useful. It can connect signals faster, cut through alert noise, and support threat detection, investigation, and response. Given the pace of modern attacks, no serious security team can afford to ignore it.

“I do not believe the future of cybersecurity is artificial intelligence on its own. In a SOC, the better model is AI²: actual intelligence and artificial intelligence. Human judgement comes first. AI strengthens it,” says Ray Hall, SOC Manager at DigitalShield.

That is because cybersecurity depends on interpretation. A tool can tell you something unusual has happened, but people still need to work out whether it is a genuine risk, what it means for the business, and how to respond without unnecessary disruption.

Actual intelligence is the analyst’s understanding of the environment: which systems matter most, which user roles carry greater risk, which alerts need escalation, and which events need more context. It is the judgement that separates a quick reaction from the right response.

The AI conversation has become more urgent as both defenders and attackers adopt it. Microsoft’s 2025 Digital Defense Report notes that threat actors are using AI to scale phishing and automate intrusions, while defenders need faster detection, automated response and strategies built for scale. Attackers are not waiting for businesses to finish internal AI discussions.

At the same time, AI is exposing weaknesses that were already present in many organisations. IBM’s Cost of a Data Breach Report 2025 found that 63% of organisations lacked AI governance policies, while 97% of those reporting an AI-related security incident lacked proper AI access controls. That should give any business pause before connecting AI to sensitive data, workflows and decision-making without understanding who can access what.

DigitalShield says that in South Africa, the pressure is sharper because many businesses are modernising with uneven security maturity, stretched IT teams, and complex legacy environments. If the basics are not under control, AI can magnify the risk.

The concern is rarely the AI tool alone. More often, the deeper issue is the data environment behind it. Sensitive information may be spread across systems, access rights may have expanded, classification may be inconsistent, and permissions may no longer match what people need. If that environment is already exposed, AI can accelerate the problem.

Verizon’s 2026 Data Breach Investigations Report found that the human element was present in 62% of breaches. Mimecast’s State of Human Risk 2026 also points to the pressure around email, collaboration tools, insider risk, credential misuse and AI-powered attacks.

DigitalShield argues that describing people as the weakest link encourages lazy security thinking. While people are part of the risk, they are also part of the defence. The same employee who clicks on a convincing phishing email may also flag something unusual early enough to stop a broader incident. The question is whether that signal is noticed, understood, and acted on.

AI can prioritise alerts, identify patterns and help analysts move faster. Analysts still need to apply judgement, test assumptions, understand business context and decide what happens next. After an incident, people still need to refine detection rules, tighten access controls, review configurations, update awareness training and strengthen response plans.

The basics have to become operational

For businesses, the AI conversation should start with the parts of security that too often receive too little attention. Sensitive data needs to be identified, access rights controlled, over-permissioned accounts reduced, and continuous monitoring maintained. Incident response plans also need testing in advance, with alerts reviewed by people who understand both the technical signal and the business consequence.

Buying more tools will not solve a visibility problem if no one is watching the environment. Automation will not fix uncontrolled data access. Awareness training also falls short when suspicious behaviour is never connected to technical signals. This is where managed security services and SOC capabilities become valuable for organisations without the people, time, or specialist depth to maintain continuous internal oversight.

AI will keep improving, and defenders should use it. But AI should make security teams sharper, not passive, by combining machine speed with human context, disciplined monitoring, and clear response processes.

In the end, cybersecurity still depends on people who know what they are looking at, understand the business they are protecting, and can make sound decisions when an alert becomes an incident. That is actual intelligence. AI works best alongside it.

Edited by Creamer Media Reporter

To advertise email advertising@creamermedia.co.za or click here

Option 1 (equivalent of R125 a month):

Receive a weekly copy of Creamer Media's Engineering News & Mining Weekly magazine(print copy for those in South Africa and e-magazine for those outside of South Africa) Receive daily email newsletters Access to full search results Access archive of magazine back copies Access to Projects in Progress Access to ONE Research Report of your choice in PDF format

Option 2 (equivalent of R375 a month):

All benefits from Option 1 PLUS Access to Creamer Media's Research Channel Africa for ALL Research Reports, in PDF format, on various industrial and mining sectors including Electricity; Water; Energy Transition; Hydrogen; Roads, Rail and Ports; Coal; Gold; Platinum; Battery Metals; etc.