Tuesday, 01 September 2026 PDT | 11:22 PM
The 1 News Alt Logo Text Smart News for Global Indians

Rethinking cybersecurity operations in the age of artificial intelligence

AI News September 02, 2026 11:00 AM
Rethinking cybersecurity operations in the age of artificial intelligence

Rethinking cybersecurity operations in the age of artificial intelligence

AI-driven security systems allow companies to respond to threats and attacks on their technology infrastructure with speed and accuracy

[The content of this article has been produced by our advertising partner.]

Cybersecurity is evolving from a manual operation to one driven by artificial intelligence (AI). The volume, speed and sophistication of modern cyber threats now exceed the capabilities of conventional processes to handle them alone. AI is reshaping the operating model by automating repetitive, high-volume work while improving accuracy and efficiency across the security life cycle.

By accelerating threat detection through behavioural analytics and orchestrating rapid incident responses, AI enables cybersecurity professionals to focus on areas where human judgment remains essential, such as strategic planning, risk management and long-term security governance.

The traditional cybersecurity approach typically struggles on three main fronts: scale, speed and visibility. Analysts can be inundated with thousands of notifications daily and many of them are false positives. This leads to alert fatigue, increasing the risk that genuine threats are overlooked.

When a zero-day vulnerability – that is a security weakness in the system that was previously undetected – is disclosed, manually assessing the impact and testing defences can take days or weeks, leaving organisations exposed. At the same time, fragmented security tools make it difficult to see the full scope of a multi-stage attack, slowing investigations and responses.

These weaknesses leave teams overwhelmed and prone to human error, such as misconfiguring defences in ways that can create new vulnerabilities.

The reliance on manual processes also fuels the industry talent shortage, as finding enough experts to manage such sprawling workloads remains a persistent challenge. Left unchecked, these gaps can expose organisations to data breaches, regulatory penalties and loss of stakeholder trust.

The goal of AI adoption is not to replace human expertise but to enhance it. Lenovo’s AI-led approach to cybersecurity resilience is an emerging operating model that handles routine security tasks at scale while keeping human expertise and oversight at the centre.

This approach can help automate the heavy lifting of alert triage, data correlation, investigation, report generation and initial response. This shifts cybersecurity professionals from constant firefighting to higher-value work such as governance, risk-tolerance decisions, threat hunting and security architecture design.

This capability also helps tackle cybersecurity skills shortages.

Through natural-language interfaces, the operating model makes complex investigative tasks more accessible. A less-experienced analyst can use these interfaces to ask questions such as, “What happened on this machine last Tuesday at 2pm?” And then receive a clear, synthesised report without needing deep knowledge of specialised query languages or multiple security platforms.

Our estimates indicate that the model can reduce the time required to investigate the root cause of cybersecurity threats by up to 50 per cent by automating data analysis, correlation and reporting processes.

These AI-driven actions can also operate within auditable, predictable and compliant oversight frameworks, ensuring organisations retain visibility and control.

Beyond detection and response, the model transforms how organisations test their defences.

Instead of relying on periodic penetration tests that offer only a snapshot, AI-driven breach-and-attack simulations enable continuous, scalable validation. These mimic the full life cycle of a real-world cyberattack, allowing them to rigorously evaluate the security position of every technology, application and tool within the organisation’s environment under lifelike conditions.

These tools quickly convert emerging vulnerabilities into actionable simulations, giving IT teams the ability to evaluate risks in near real-time. Comprehensive documentation of all results further empowers organisations to identify critical gaps and focus remediation efforts to where they matter most.

Deploying AI at this scale hinges on trust as much as on technical performance. Responsible governance of these systems precludes what is known as a black-box model – when an IT professional will replicate the hacking process without knowing anything about the system’s internal code and architecture. Instead, the focus is on human supervision, clear transparency and comprehensive protection of the AI models.

Lenovo’s responsible AI approach is guided by six criteria: inclusion, privacy and security, accountability, explainability, transparency, and environmental and social impact.

Governance frameworks also protect the AI supply chain against model poisoning – a tactic in which attackers corrupt the training data and processes to manipulate the system’s behaviour.

The importance of responsible AI is magnified in Hong Kong, where rigorous regulations place heavy compliance requirements on industries such as insurance and healthcare.

Among the key frameworks are the Protection of Critical Infrastructures (Computer Systems) Bill and the Insurance Authority’s GL20 on cybersecurity. For regulated organisations, data sovereignty and local oversight are non-negotiable. To address this, Lenovo has set up an AI-driven Security Operations Centre in Hong Kong, offering 24/7 detection, investigation and response designed specifically for local businesses, ensuring the data governance and regulatory adherence they need.

In terms of practical implementation, Lenovo Security Services delivers end-to-end, built-in security across devices, firmware, operating systems, applications and cloud environments.

Its capabilities include firmware validation and a proactive troubleshooting system for security breaches that are driven by AI – with an 85 per cent risk-prediction accuracy and a reduction in containment and incident-response times by up to 50 per cent.

Together, these capabilities reinforce Lenovo’s approach to delivering trusted, responsible, and governed AI-powered cybersecurity that organisations can deploy with confidence.

The views and opinions expressed are those of the sponsor and do not necessarily reflect the official policy or position of South China Morning Post Publishers Limited. Any content provided by our sponsors are of their opinion, and is not intended to malign any religion, ethnic group, club, organisation, company, individual or anyone or anything.