{"id":3741,"date":"2024-05-24T07:31:01","date_gmt":"2024-05-24T12:31:01","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/future-proof-your-cybersecurity-ai-strategy"},"modified":"2024-05-24T07:31:01","modified_gmt":"2024-05-24T12:31:01","slug":"future-proof-your-cybersecurity-ai-strategy","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/24\/future-proof-your-cybersecurity-ai-strategy\/","title":{"rendered":"Future-Proof Your Cybersecurity AI Strategy"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd4a01a32ca5a5a52\/664fb068d0dc0d21c0c42869\/Kittipong-irasukhanont_Alamy-Stock-Photo.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With the constant onslaught of new attacks and emerging threats, one might say that every day is an exciting day in the security operations center (SOC). But arguably, today&#8217;s SOC teams are in the midst of one of the most compelling and transformative shifts in how we detect and respond to cybersecurity threats. Innovative security organizations are working to modernize the SOC with extended detection and response (XDR) platforms that bring the latest advancements in&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/dr-resources.darkreading.com\/free\/w_msf356\/prgm.cgi?a=1\">artificial intelligence (AI) to the defensive&nbsp;effort<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">XDR solutions correlate security telemetry across security domains, including identities, endpoints, software-as-a-service apps, email, and cloud workloads, to provide detection and response capabilities in a unified platform. As a result, security teams using XDR have more visibility across the enterprise than ever before. But that is only half the story. The combination of this unprecedented visibility with an AI-powered SOC assistant can enable security teams to operate at the speed necessary to turn the tables on would-be attackers.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In this rapidly evolving environment, innovative security organizations that want to confidently take advantage of today&#8217;s AI capabilities and lay the groundwork to seamlessly adopt tomorrow&#8217;s innovations require a thoughtful, future-aware implementation strategy.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"XDR Breadth Matters, Even If You Start Small&nbsp;\">XDR Breadth Matters, Even If You Start Small&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unlike traditional automated detection and blocking solutions that often rely on a single indicator of compromise, XDR platforms use&nbsp;AI&nbsp;to correlate cross-domain security signals that take the entire attack into account and identify threats with a high degree of confidence. The increased fidelity that AI brings to the table improves the signal-to-noise ratio and results in fewer false positives to manually investigate and triage. Notably, the broader the dataset the AI is operating on, the more effective it will be; as such, XDR&#8217;s native breadth is critical.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ideally, an effective XDR strategy will identify and account for the highest risk areas, cybersecurity maturity, existing architecture and tools, and budgetary constraints, among other factors. While implementation should be phased to minimize operational disruption, organizations must also consider how to best achieve the widest breadth of XDR coverage to fully unlock AI&#8217;s capabilities.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Build AI-Confident Teams\">Build AI-Confident Teams<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The goal of AI is not to replace humans in your SOC but rather to empower them. If your team does not have confidence in the tools they use, they will not unlock the full value of the platform. Minimizing false positives, as discussed above, will help build trust among users over time, but it is also essential to provide operational transparency so there is always an understanding of where data is coming from and what actions have been taken.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">XDR platforms must give SOC teams complete control when investigating, remediating, and bringing assets back online when they want them. Tightly integrating threat detection and automatic attack disruption capabilities with existing workflows will streamline triage and provide a user-friendly view of threats and remediation actions across the infrastructure.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Forward-thinking organizations can take it a step further and look to generative AI to upskill the entire SOC team via guided investigation tools, script analysis, and query assistance.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Stay Threat Intelligent\">Stay Threat Intelligent<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indicators of attack and indicators of compromise are constantly evolving. An effective, long-term XDR strategy will address the ongoing need for rapid analysis and continual vetting of the latest threat intelligence. Implementation roadmaps should address how to support the integration of timely threat intelligence and build in flexibility to scale or augment teams when complex incidents demand more expertise or support.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As more organizations look to invest in XDR and AI to improve their security operations, a thoughtful, future-aware approach to implementation will help them more effectively leverage today&#8217;s AI capabilities, while also being ready for tomorrow&#8217;s innovations. After all, successful organizations won&#8217;t just look to AI to get them ahead of attackers. They will plan investments in AI that keep them ahead.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u2014 Read more <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/program\/partner-perspectives-microsoft\" rel=\"noopener\">Partner Perspectives from Microsoft Security<\/a><\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/future-proof-your-cybersecurity-ai-strategy\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the constant onslaught of new attacks and emerging threats,<\/p>\n","protected":false},"author":12,"featured_media":3742,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3741","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?fit=1200%2C820&ssl=1",1200,820,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?fit=300%2C205&ssl=1",300,205,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?fit=640%2C438&ssl=1",640,438,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?fit=640%2C438&ssl=1",640,438,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?fit=1200%2C820&ssl=1",1200,820,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?fit=1200%2C820&ssl=1",1200,820,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?fit=1024%2C700&ssl=1",1024,700,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/future-proof-your-cybersecurity-ai-strategy.jpg?fit=1200%2C820&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3741","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3741"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3741\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3742"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3741"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3741"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3741"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}