Disclaimer: The perspectives shared here are my own and do not necessarily represent those of my employer. I use GenAI as a tool to help me compose and structure my articles.
Introduction
In today’s cybersecurity landscape, small and medium businesses (SMBs) face unique challenges. Limited budgets and resources can make it difficult to match the robust defences of large enterprises, leaving SMBs more vulnerable to threats. However, advances in Generative AI (GenAI) — a specific type of AI designed to generate text, summarise information, and provide context-sensitive responses — have opened up new possibilities for enhancing security operations and product security, even for organisations with lean security teams.
For the sake of simplicity, I’ll refer to Generative AI (GenAI) simply as AI throughout this article.
This article presents a practical framework for applying AI to security operations, broken into three levels I name as Directed, Supervised, and Autonomous. Each level represents an increasing degree of AI autonomy, progressing from AI as an assistant to AI making fully autonomous security decisions.
This framework is designed to help technical CISOs and security professionals in SMBs understand how AI can incrementally add value to their security programs, regardless of budget or staffing constraints.
The Three Levels of AI in Security Operations
Level 1: Directed Security Operations (AI Under Human Direction)
At this level, AI operates much like a well-trained assistant, responding to specific tasks directed by a human. The AI performs repetitive, data-heavy tasks — such as threat intelligence gathering, log filtering, and anomaly detection — following the guidance and input provided by security analysts. This setup is ideal for SMBs because it allows a small team to boost efficiency without requiring significant investment or complex integrations.
Typical Use Cases:
- Threat intelligence summarisation: AI compiles relevant news and threat information for easy review.
- Anomaly detection: AI identifies unusual patterns in data, like login times or IP addresses, which the team can investigate further.
- Log analysis and filtering: AI filters through security logs to highlight entries that may be more suspicious, letting analysts prioritise.
Level 2: Supervised Security Operations (AI Under Human Approval)
In this second level, AI takes a more active role, not just following direct instructions but proposing responses based on its analysis. Here, AI can suggest containment actions or triage incidents by prioritising them based on risk level. Human analysts remain in the loop to review and approve these actions, especially for higher-stakes decisions.
Typical Use Cases:
- Incident triage: AI categorises and prioritises incidents, helping security teams focus on the most critical threats.
- Semi-autonomous containment: AI can isolate a potentially compromised endpoint or restrict access until further review, with a human providing final approval.
- Threat response recommendations: AI suggests responses to incidents, such as patching vulnerabilities or blocking specific IP addresses, leaving the final decision to the analyst.
Autonomous Security Operations (Fully AI-Driven)
At the Autonomous level, AI operates with a high degree of independence, making decisions and executing responses without human intervention. This level of AI is capable of detecting, analysing, and remediating incidents in real time. While this approach requires high confidence in AI’s accuracy and ethical decision-making, it has the potential to provide 24/7 protection with minimal latency — ideal for teams that may not be able to provide round-the-clock coverage.
Typical Use Cases:
- Autonomous threat remediation: AI detects, analyses, and remediates security incidents in real time, reducing the need for human response.
- Continuous learning and adaptation: AI adjusts security controls and policies autonomously based on emerging threats and past incidents.
- Self-healing systems: AI can restore systems after attacks by reconfiguring settings or rolling back to a safe state, maintaining business continuity.
Why This Framework Works for SMBs
For SMBs, taking a gradual approach to AI in security operations can make AI adoption more achievable and affordable. Each level in this framework offers clear advantages that help augment a security team’s capabilities without requiring large-scale enterprise solutions. At the Directed level, security teams can use AI to automate tedious, time-consuming tasks, allowing human resources to be allocated to higher-value activities. As teams grow comfortable with AI and as AI capabilities mature, moving up to Supervised and eventually Autonomous operations can deliver even greater efficiencies, enabling small teams to maintain robust defences despite limited resources.
By understanding each level, technical CISOs and security engineers can better plan how to integrate AI to support their current security posture and future growth. This incremental approach allows SMBs to align AI capabilities with both their needs and their comfort level with automation.
Final Thoughts
Moving from Directed to Autonomous security operations is a journey, one that allows security teams to improve efficiency while focusing on the most critical aspects of security. SMBs with limited resources can leverage AI agents at the Directed level today, deploying them as virtual assistants to automate tedious, time-consuming tasks and allowing human analysts to dedicate their efforts to high-value activities. As familiarity and trust in AI agents grow, teams can progress to Supervised and eventually Autonomous levels, where these agents not only assist but actively make decisions and execute security responses independently.
By deploying these intelligent AI agents across various operational levels, SMBs can achieve a level of resilience and responsiveness traditionally reserved for large enterprises. Embracing AI agents — one level at a time — empowers organisations to build a more secure environment, regardless of budget constraints, creating a path toward fully autonomous, AI-driven security operations.
In the next articles, we’ll dive into each level in more detail, offering practical use cases and examples on how to implement these AI capabilities in your organisation.
Note:
I’ll maintain this article updated with links to related ones:
