Artificial intelligence (AI)
News
Cybersecurity teams are experiencing a shift in their scope of work. Attack surfaces are expanding, threat actors are becoming more sophisticated, and the speed of modern attacks is outpacing traditional security operations. At the same time, organisations are facing off a spike in alerts, struggling with analyst burnout, and dealing with an ongoing shortage of skilled cybersecurity professionals. Against this backdrop, Artificial Intelligence has emerged as one of the most transformative technologies in the Security Operations Centre, or SOC. Reshaping security operations Yet one question continues to surface in boardrooms and security teams alike: can AI replace SOC analysts? The short answer is no. AI is reshaping security operations, but it is not eliminating the need for human expertise. Instead, the future of cybersecurity lies in collaboration between intelligent automation and skilled analysts. AI excels at speed, scale, and pattern recognition, while human analysts provide judgement, creativity, contextual understanding, and strategic decision-making. In this article, they will explore how AI-driven SOC are changing security operations, why businesses increasingly need both AI and human analysts, and how responsibilities are being divided between machines and people. They will also examine the critical human role in threat hunting, contextual analysis, oversight, and response orchestration in modern SOC environments. AI-assisted phishing campaigns Traditional SOC is designed for a very different era of cybersecurity. Analysts manually reviewed logs, investigated alerts, relying heavily on static rules and signatures to identify threats. While this model once worked reasonably well, modern cyber threats move far too quickly for purely manual operations. Attackers are now using automation, AI-assisted phishing campaigns, polymorphic malware, and sophisticated social engineering tactics that constantly evolve. A single organisation may generate millions of security events every day, creating a tidal wave of telemetry that no human team can realistically process on its own. Interpreting complex threats This has created several operational challenges for SOC teams. Alert fatigue has become widespread, with analysts overwhelmed by false positives and repetitive tasks. Response times are often delayed because security teams cannot prioritise incidents efficiently. At the same time, cybersecurity talent shortages mean many organisations are operating with understaffed SOCs. AI-driven security operations emerged as a response to these growing pressures. By automating repetitive tasks and accelerating analysis, AI helps organisations detect and respond to threats at machine speed. However, this does not mean humans become irrelevant. Quite the opposite. As AI handles operational heavy lifting, human analysts become even more important in guiding strategy, validating decisions, and interpreting complex threats. Large-scale data analysis AI thrives in environments that involve large-scale data analysis, repetition, and pattern detection. Modern SOC platforms use machine learning and large language models to process telemetry from endpoints, networks, cloud infrastructure, applications, and identity systems in real time. One of AI’s greatest strengths is its ability to rapidly identify anomalies that might otherwise go unnoticed. Instead of relying solely on pre-defined rules, AI systems can learn behavioural baselines and flag suspicious deviations. This allows organisations to detect novel attacks, insider threats, and stealthy lateral movement more effectively. AI is also highly effective at triaging alerts. Rather than forcing analysts to manually sift through thousands of low-priority notifications, AI can correlate events, eliminate duplicates, enrich alerts with contextual data, and prioritise incidents based on risk. This dramatically reduces noise inside the SOC. Improving response times Automation also improves response times. AI-powered orchestration systems can isolate compromised endpoints, disable suspicious accounts, block malicious IP addresses, or trigger containment workflows within seconds. Tasks that once consumed valuable analyst hours can now happen almost instantly. In many ways, AI functions like a hyper-vigilant digital air traffic controller, constantly monitoring thousands of moving signals simultaneously without becoming tired or distracted. Despite AI’s impressive capabilities, cybersecurity is not purely a technical challenge. It is also a human problem involving intent, deception, business context, and strategic judgement. These are areas where human analysts remain indispensable. Critical business operations One of the most important responsibilities humans retain is decision-making during high-risk incidents. AI can recommend actions based on patterns and probabilities, but human analysts must evaluate the wider consequences of those decisions. A false containment action, for example, could disrupt critical business operations or impact customers. Human analysts are also essential for contextual analysis. AI may identify suspicious activity, but it often lacks a nuanced understanding of organisational priorities, geopolitical considerations, regulatory obligations, or industry-specific risk factors. Sensitive financial data Imagine an AI system flagging unusual access to sensitive financial data at 2am. Is it a malicious insider? A compromised account? Or simply a finance executive travelling internationally during an acquisition process? Human analysts provide the contextual reasoning needed to answer these questions accurately. Threat hunting is another area where human creativity remains critical. Skilled analysts think like adversaries. They form hypotheses, investigate subtle behavioural indicators, and connect seemingly unrelated clues across environments. While AI can assist by surfacing anomalies, human intuition and experience often uncover the deeper narrative behind an attack. There is also the issue of adversarial manipulation. Attackers are already experimenting with ways to deceive AI models through poisoned data, evasive malware behaviour, and prompt manipulation techniques. Human oversight is essential to ensure AI systems are functioning correctly and are not being misled. Automate repetitive workflows Modern cybersecurity environments are simply too complex for either humans or AI to operate effectively in isolation. Businesses increasingly require a blended approach that combines machine efficiency with human expertise. AI dramatically improves scalability. It allows SOC teams to process vast volumes of data, accelerate detection, and automate repetitive workflows. This helps organisations manage growing attack surfaces without endlessly expanding headcount. However, AI alone cannot fully understand business priorities, ethical considerations, or nuanced attacker behaviour. Human analysts provide governance, oversight, and strategic direction that machines cannot replicate. High-volume operational tasks Here is a thought-provoking question many organisations are beginning to ask themselves: If an AI system autonomously detects and contains a cyber attack in under thirty seconds, but mistakenly shuts down a hospital’s critical systems in the process, who should ultimately be accountable for that decision? The SOC of the future will almost certainly be AI-native, but it will not be human-free. Instead, we are moving towards a model where analysts and AI systems operate as collaborative partners. AI will continue handling high-volume operational tasks such as alert triage, telemetry analysis, workflow automation, and real-time response orchestration. Human analysts, meanwhile, will focus on strategic oversight, advanced investigations, adversarial thinking, and business-aligned decision-making. Accelerating threat detection This evolution can elevate the role of SOC analysts rather than eliminate it. As repetitive work decreases, analysts can dedicate more time to proactive defence, threat intelligence, and security innovation. AI is transforming security operations at an extraordinary pace, but it is not replacing SOC analysts. Instead, it is redefining their role. AI excels at analysing massive datasets, automating repetitive tasks, and accelerating threat detection and response. Human analysts contribute critical thinking, contextual understanding, creativity, and strategic judgement that machines still cannot replicate. Organisations that embrace this AI-augmented model will be better positioned to reduce alert fatigue, improve detection accuracy, accelerate response times, and defend against increasingly advanced cyber threats.
Security Operations Centres (SOC) are evolving at a remarkable pace. What once relied heavily on manual investigation and rule-based monitoring is now increasingly powered by artificial intelligence, machine learning, and automation. As cyber threats grow faster, more evasive, and more sophisticated, organisations are under pressure to modernise their SOC capabilities without sacrificing visibility, compliance, or operational control. For Chief Information Security Officers, choosing the right AI-powered SOC solution has become both a strategic opportunity and a complex challenge. The market is crowded with vendors promising autonomous detection, predictive analytics, and rapid response capabilities. Yet not all AI SOC platforms are created equal. Some offer genuine operational value, while others create additional noise, hidden costs, or compliance concerns. Massive volumes of telemetry This article explores how CISOs can evaluate AI SOC solutions effectively. Readers will learn which criteria matter most when assessing vendors, why human analysts remain essential in modern security operations, and how to follow a practical step-by-step decision-making process that aligns with business objectives, risk tolerance, and compliance requirements. Despite rapid advances in automation, AI is not replacing SOC analysts. Instead, organisations are increasingly discovering that the strongest security operations combine machine efficiency with human expertise. AI excels at processing massive volumes of telemetry, identifying anomalies, correlating alerts, and accelerating repetitive tasks. It can scan millions of events in seconds, detect suspicious behaviour patterns, and prioritise incidents based on risk. This dramatically reduces alert fatigue and enables faster response times. Unusual login behaviour However, attackers constantly adapt their tactics, exploit business context, and manipulate human behaviour. Human analysts bring intuition, contextual understanding, strategic thinking, and investigative judgement that AI alone cannot replicate. For example, AI may detect unusual login behaviour, but an experienced analyst can determine whether the activity is malicious, linked to legitimate business travel, or part of a larger attack campaign. Similarly, analysts play a critical role in threat hunting, incident containment decisions, executive communication, and regulatory reporting. Increasingly sophisticated attackers The future SOC is therefore not “AI versus humans”. It is AI augmenting human capabilities. Organisations that strike this balance are better positioned to improve detection accuracy, reduce operational pressure, and strengthen resilience against evolving threats. Choosing an AI SOC platform today is far more complex than purchasing a traditional SIEM solution. Modern environments include hybrid infrastructure, cloud-native applications, remote workforces, third-party integrations, IoT devices, and increasingly sophisticated attackers using AI themselves. A poorly selected SOC platform can create operational bottlenecks, integration failures, excessive licensing costs, and compliance headaches. On the other hand, the right solution can significantly improve visibility, streamline investigations, and reduce cyber risk. Digital transformation initiatives A question every CISO should consider: If the AI SOC automatically contained a critical system based on flawed analysis during peak business hours, would your organisation trust the technology enough to recover quickly, or would confidence collapse alongside operations? This question highlights an important reality. Trust, transparency, and governance matter just as much as automation speed. A SOC solution must scale alongside the organisation’s growth. Many businesses underestimate how quickly data volumes increase as cloud adoption, endpoint expansion, and digital transformation initiatives accelerate. Real-world enterprise workloads CISOs should evaluate whether the platform can handle growing log ingestion, support distributed environments, and maintain performance during peak activity periods. Scalability should not simply refer to storage capacity. It must also include detection speed, query efficiency, and incident response performance under operational stress. An AI SOC platform that performs well in a controlled demonstration may struggle when exposed to real-world enterprise workloads. No SOC operates in isolation. Effective AI SOC platforms must integrate seamlessly with existing infrastructure, including SIEMs, EDR tools, firewalls, identity platforms, cloud services, ticketing systems, and threat intelligence feeds. Costly custom development Strong integration capabilities reduce operational silos and enable better visibility across the environment. CISOs should assess whether integrations are native, API-driven, or dependent on costly custom development. Vendor claims around interoperability should also be tested carefully during proof-of-concept stages. Integration challenges remain one of the most common causes of delayed SOC modernisation projects. Not every platform marketed as “AI-powered” delivers meaningful intelligence. Some vendors simply apply basic automation or statistical analysis while branding it as advanced AI. CISOs should investigate how the AI models function, how frequently they are trained, what datasets support detection logic, and how false positives are managed. Mature AI SOC platforms should demonstrate measurable improvements in threat detection, incident prioritisation, and response efficiency. Detection explainability is also crucial. Security teams need visibility into why the AI reached a particular conclusion rather than receiving opaque recommendations without context. Mature AI SOC platforms Trust in AI security systems depends heavily on transparency. Black-box AI creates significant operational and regulatory risks because analysts may not fully understand how alerts are generated or why automated actions are triggered. Transparent systems provide detailed reasoning, correlation logic, confidence scoring, and audit trails. This is especially important during investigations, executive reporting, and regulatory reviews. CISOs should ask vendors difficult questions about explainability. If a vendor cannot clearly explain how its AI operates, security teams may struggle to trust or defend its decisions during critical incidents. Mature operational processes Technology alone does not guarantee success. Strong vendor support can significantly influence the effectiveness of an AI SOC deployment. Organisations should assess the vendor’s implementation expertise, incident response support, training capabilities, and ongoing advisory services. Responsive support becomes particularly important during active security incidents or platform outages. A vendor with strong security expertise and mature operational processes often delivers more long-term value than a vendor focused purely on technical features. Compliance remains a major concern for CISOs operating across regulated industries. AI SOC platforms must support data protection, logging requirements, auditability, incident reporting, and governance obligations. Local regulatory expectations Security leaders should evaluate whether the solution aligns with frameworks such as ISO 27001, GDPR, PCI DSS, NIST, SAMA, and NCA requirements where applicable. Data residency considerations are equally important, especially for organisations operating across multiple jurisdictions. AI systems processing sensitive telemetry must align with local regulatory expectations and internal governance policies. Initial licensing costs rarely reflect the true cost of a SOC platform. CISOs must assess the full operational picture, including infrastructure requirements, integration expenses, staffing needs, ongoing tuning, training, maintenance, and scalability costs. Some platforms appear affordable initially but become expensive due to hidden ingestion fees, professional services requirements, or escalating storage costs. A realistic total cost of ownership assessment helps organisations avoid budget surprises while ensuring long-term sustainability. Decision-making framework Choosing an AI SOC solution requires structured evaluation rather than reacting to vendor marketing claims. A practical decision-making framework can help organisations reduce risk and improve alignment with strategic goals. The first step is defining operational objectives clearly. CISOs should identify the organisation’s most pressing challenges, whether that involves alert fatigue, cloud visibility gaps, compliance pressure, talent shortages, or slow incident response times. The second step involves assessing the current security environment. Organisations must understand existing tools, workflows, data sources, staffing models, and operational maturity before introducing AI-driven capabilities. Faster compliance reporting The third step is developing measurable evaluation criteria. Instead of focusing on feature lists alone, CISOs should define success metrics such as reduced mean time to detect, lower false positive rates, improved analyst productivity, or faster compliance reporting. The fourth step involves conducting realistic proof-of-concept testing. Vendors should demonstrate capabilities using real organisational data and operational scenarios rather than curated demonstrations. This phase should include testing integrations, detection accuracy, workflow usability, and reporting transparency. The fifth step is evaluating governance and risk considerations. CISOs should examine data handling practices, explainability features, automated response controls, and compliance alignment carefully before deployment. Sustainable security improvements The final step is planning long-term operational adoption. Successful AI SOC implementations require ongoing tuning, analyst training, governance oversight, and collaboration between security, IT, compliance, and executive stakeholders. AI is rapidly reshaping cybersecurity operations, but successful adoption depends on thoughtful implementation rather than blind automation. Organisations that treat AI as a force multiplier for human expertise are far more likely to achieve sustainable security improvements. Making informed decisions The right AI SOC solution should enhance visibility, accelerate detection, reduce operational strain, and strengthen resilience without sacrificing transparency or governance. CISOs who evaluate scalability, integration, AI maturity, compliance alignment, and operational sustainability carefully will be better positioned to make informed decisions. As attackers continue evolving their tactics, modern SOC must evolve as well. The challenge is not simply choosing the most advanced AI platform. It is selecting a solution that aligns with organisational realities, empowers analysts, and supports long-term cyber resilience.
Cybersecurity operations are undergoing a remarkable transformation. For years, Security Operations Centres (SOC) have relied on skilled analysts, rule-based detection systems, and increasingly sophisticated automation to protect organisations from cyber threats. Today, the next evolution is already taking shape: the Autonomous SOC. In this article, users will learn what an Autonomous SOC is, how it differs from traditional and AI-assisted SOC models, why organisations are increasingly turning to AI-powered security operations, and what to look for when selecting a partner to help implement autonomous security capabilities. We will also explore how the best security partners help organisations move beyond conventional security operations towards a future of self-driving cyber defence. Increasingly complex IT environments Modern organisations face an unprecedented volume of cyber threats. Attackers are leveraging artificial intelligence to automate reconnaissance, create convincing phishing campaigns, evade detection, and accelerate attacks. At the same time, security teams are struggling with alert fatigue, skills shortages, and increasingly complex IT environments. A typical SOC may process thousands of alerts every day. Many of these alerts are false positives, while others require manual investigation and triage. Security analysts often spend significant time on repetitive tasks instead of focusing on strategic threat hunting and incident response. The challenge is clear. As attack volumes continue to rise, organisations cannot simply hire more analysts to keep pace. They need security operations that can scale intelligently, respond rapidly, and continuously adapt to evolving threats. This need has fuelled the rise of AI SOC and is now driving the emergence of Autonomous SOC. Identifying suspicious behaviours Traditional SOC rely heavily on human analysts. Security tools generate alerts, analysts investigate them, and response actions are manually executed. While effective in many scenarios, this model can struggle to keep up with today's threat landscape. The next step in the evolution was the AI-assisted SOC. In these environments, artificial intelligence helps analysts by prioritising alerts, correlating events, identifying suspicious behaviours, and providing recommendations for response actions. AI improves efficiency, but humans remain responsible for most decision-making and execution. Security operations tasks Autonomous SOC take this concept significantly further. An Autonomous SOC combines advanced artificial intelligence, machine learning, security orchestration, threat intelligence, and automated response capabilities to independently perform many security operations tasks with minimal human intervention. Rather than simply recommending actions, the system can investigate alerts, validate threats, execute predefined response measures, and continuously learn from outcomes. Think of it as the difference between a vehicle equipped with driver assistance features and a self-driving car. One helps the driver make better decisions. The other can navigate much of the journey independently while maintaining human oversight where needed. Appropriate containment measures The defining characteristic of an Autonomous SOC is its ability to act, not simply analyse. When suspicious activity is detected, an autonomous platform can automatically gather evidence from multiple systems, correlate data across the environment, determine the likelihood of a genuine threat, and initiate appropriate containment measures. For example, if a compromised user account begins exhibiting unusual behaviour, the Autonomous SOC may automatically isolate affected systems, disable credentials, collect forensic evidence, and notify stakeholders before significant damage occurs. This level of automation dramatically reduces Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), two critical metrics that directly influence the impact of cyber incidents. High-impact actions Yet autonomy does not eliminate the need for human expertise. Security professionals continue to provide governance, oversight, strategic decision-making, and validation of high-impact actions. The goal is augmentation at scale rather than complete replacement. Imagine a ransomware attack begins at 2:00 a.m. on a holiday weekend. Would you rather wait for an analyst to notice the alert, investigate the activity, and initiate a response, or have an intelligent security platform identify the threat, contain affected systems, preserve evidence, and notify stakeholders within minutes? Autonomous security operations For many organisations, the answer highlights why autonomous security operations are becoming increasingly attractive. Autonomous SOC provide several advantages over traditional security models. First, they dramatically improve response speed. Automated investigations and response actions can occur within seconds rather than hours. Second, they help reduce analyst burnout. By automating repetitive tasks, security teams can focus on higher-value activities such as threat hunting, strategic planning, and security improvement initiatives. Third, they enhance consistency. Human analysts may vary in experience and decision-making, while autonomous systems execute approved workflows consistently and reliably. Complex hybrid environments Fourth, they improve scalability. Organisations can handle growing volumes of security events without proportionally increasing staffing costs. Finally, autonomous security operations provide stronger visibility across complex hybrid environments, including cloud platforms, on-premises infrastructure, endpoints, applications, and third-party systems. Implementing an Autonomous SOC requires more than purchasing advanced technology. Success depends on choosing a partner with the right combination of expertise, processes, and operational maturity. Organisations should begin by evaluating a provider's experience in managed detection and response, threat intelligence, incident response, and security operations. Autonomous capabilities are only as effective as the security knowledge embedded within them. Another major consideration It is also important to assess the provider's approach to transparency and governance. Autonomous systems must support auditability, regulatory compliance, and human oversight. Organisations need confidence that automated decisions can be understood, reviewed, and validated. Integration capabilities should be another major consideration. The best Autonomous SOC platforms seamlessly integrate with existing security tools, cloud environments, identity systems, and business applications. Threat intelligence is equally critical. Effective autonomous operations rely on high-quality intelligence to identify emerging threats and adapt to evolving attacker techniques. Finally, organisations should evaluate the provider's commitment to continuous improvement. Autonomous security is not a one-time deployment. It requires ongoing tuning, model refinement, workflow optimisation, and adaptation to changing risks. Next-generation security automation As cyber threats continue to evolve, Rewterz is helping organisations move beyond traditional and AI-assisted security operations towards fully autonomous cyber defence. By combining advanced AI technologies, threat intelligence, security orchestration, automation, and expert human oversight, Rewterz delivers security operations that are faster, smarter, and more resilient. The organisation's approach enables businesses to reduce operational burdens while strengthening their ability to detect, investigate, and respond to sophisticated threats. Rewterz recognises that autonomy and governance must work together. Its solutions are designed to support regulatory requirements, operational transparency, and human accountability while enabling organisations to take advantage of next-generation security automation.
Pressure is increasing on modern Security Operations Centre (SOC). Cyber threats are growing in volume, sophistication, and speed, while security teams face increasing workloads, talent shortages, and alert fatigue. Many SOC analysts spend a significant portion of their day investigating alerts that ultimately turn out to be false positives, leaving less time to focus on genuine threats. Artificial intelligence (AI) is helping organisations address this challenge by transforming one of the most critical SOC functions: incident triage. Rather than forcing analysts to manually review thousands of alerts, AI can automatically prioritise, enrich, and investigate security events, allowing teams to respond faster and more effectively. AI-driven security operations In this article, users will learn what incident triage is, why it is a fundamental part of cybersecurity operations, how AI automates the triage process, and the key benefits organisations gain from AI-driven security operations. Incident triage is the process of reviewing, assessing, and prioritising security alerts and incidents to determine which events require immediate attention and which pose little or no risk. Every day, security tools such as firewalls, endpoint detection platforms, SIEM systems, identity management solutions, and cloud security tools generate enormous numbers of alerts. Not all alerts represent genuine threats. Some are duplicates, some are misconfigurations, and many are false positives. Delayed response times The purpose of incident triage is to separate meaningful threats from background noise. Analysts must determine whether an alert is legitimate, assess its severity, identify affected assets, and decide what actions should follow. Without effective triage, organisations risk overlooking critical attacks while wasting valuable resources on low-priority events. Incident triage acts as the gateway to the entire incident response process. Every investigation begins with a decision about whether an alert deserves attention. If a malicious event is incorrectly classified as harmless, attackers may remain undetected within the environment for extended periods. Conversely, if analysts spend excessive time investigating low-risk alerts, critical threats may be missed due to delayed response times. Resilience against cyberattacks Consider this hypothetical question: What if the SOC received 20,000 alerts today, but only 20 represented genuine threats capable of causing significant business disruption? Would the analysts find the right 20 before attackers achieved their objectives? This challenge highlights why effective triage is so important. The ability to rapidly identify genuine threats directly influences an organisation's security posture, operational efficiency, and resilience against cyberattacks. Multiple security tools Traditional triage processes rely heavily on human analysts. Security personnel review alerts, gather context, examine logs, correlate events, and determine whether an investigation should proceed. While this approach can be effective, it becomes increasingly difficult as organisations grow. Modern enterprises may generate thousands or even millions of security events every day. Analysts often spend hours collecting information from multiple security tools before they can make an informed decision. This creates several challenges. Alert fatigue becomes common, response times increase, false positives consume resources, and skilled analysts become overwhelmed by repetitive work. These pressures contribute to burnout and make it difficult for SOC teams to maintain consistent performance. Threat intelligence indicators AI introduces intelligence and automation into the triage process, enabling SOC to analyse and prioritise alerts at machine speed. Instead of treating every alert equally, AI systems evaluate events based on risk, context, historical patterns, and threat intelligence. This allows the SOC to focus attention where it matters most. One of the most valuable capabilities of AI is its ability to prioritise alerts automatically. Machine learning models analyse factors such as asset criticality, user behaviour, attack patterns, vulnerability data, and threat intelligence indicators. The system then assigns risk scores to alerts based on their likelihood of representing a genuine threat. Rather than reviewing thousands of alerts manually, analysts can immediately focus on the incidents with the highest probability of causing harm. This significantly reduces investigation workloads while improving detection efficiency. Automated alert enrichment A raw alert often lacks the context needed for rapid decision-making. Traditionally, analysts gather additional information by consulting multiple systems, including endpoint platforms, asset inventories, identity management tools, vulnerability scanners, and threat intelligence feeds. AI can automate this enrichment process. When an alert is generated, AI systems automatically collect and correlate relevant information. They can identify the affected asset, determine whether it contains sensitive data, check for known vulnerabilities, analyse user activity, and compare indicators against threat intelligence databases. Multiple security tools AI also helps SOC teams investigate alerts more effectively. Modern AI-driven SOC platforms can correlate events across multiple security tools and data sources. Rather than viewing alerts in isolation, the system identifies relationships between activities occurring throughout the environment. For example, AI may connect a suspicious login attempt, privilege escalation activity, unusual endpoint behaviour, and data transfer events into a single attack narrative. This broader perspective helps analysts understand the full scope of an incident without manually piecing together evidence from numerous systems. Unlike static rule-based systems, AI can learn from historical investigations and analyst feedback. Most significant benefits As analysts validate incidents and classify alerts, machine learning models refine their understanding of normal behaviour and malicious activity. Over time, this improves accuracy and reduces false positives. The result is a continuously evolving security operation that becomes more efficient as it gains experience. The impact of AI-powered triage extends far beyond simple automation. One of the most significant benefits is faster response times. By prioritising high-risk alerts and providing immediate context, AI enables security teams to begin investigations sooner and contain threats more quickly. Organisations also benefit from reduced analyst workloads. Routine investigative tasks that once required substantial manual effort can now be completed automatically, allowing analysts to focus on higher-value activities such as threat hunting, strategic analysis, and incident response. Identifying genuine threats Improved detection accuracy is another major advantage. AI helps reduce false positives while increasing the likelihood of identifying genuine threats that might otherwise be overlooked. Operational scalability also improves considerably. As organisations grow and generate more security data, AI can process increasing volumes of alerts without requiring proportional increases in staffing. Perhaps most importantly, AI helps combat analyst fatigue. By eliminating repetitive tasks and reducing alert overload, organisations can improve employee satisfaction and retain valuable cybersecurity talent. Strategic decision-making As cyber threats continue to evolve, incident triage will become increasingly dependent on AI-driven automation. Future SOC will move beyond basic alert prioritisation towards autonomous security operations, where AI systems perform much of the investigative work independently before escalating only the most significant incidents to human analysts. Human expertise will remain essential for strategic decision-making, complex investigations, and oversight. However, AI will increasingly serve as the force multiplier that allows security teams to operate more efficiently and effectively. The organisations that embrace AI-driven triage today will be better positioned to manage growing alert volumes, respond to threats faster, and strengthen their overall cybersecurity posture.
Expert commentary
Across many sectors, AI is transitioning from an experimental process to a trusted tool, but how will construction - and architectural ironmongery specifically - balance this technological opportunity with traditional practice? Artificial intelligence was once considered the trend of tomorrow, but it’s now here, and already it’s impacting the design, specification and management of the built environment. Following a period of refined development, the technology is emerging as a valuable tool for architectural professionals, with its growing role signifying far more than a passing industry trend. Passing industry trend According to the Royal Institute of British Architects’ (RIBA) Artificial Intelligence Report 2025, 59% of architectural practices now use AI on at least some projects, an increase from 41% in 2024. Furthermore, a global survey led by the Royal Institution of Chartered Surveyors in 2025 found that 56% of investors planned to increase AI investment, suggesting that the rate of adoption will continue to accelerate over the coming years. However, whilst innovation typically creates opportunity, there are challenges to address These findings represent a cultural shift, one where AI is firmly embedding itself into workflows and influencing the decision making process. However, whilst innovation typically creates opportunity, there are challenges to address. As more professionals equip themselves with an arsenal of AI-driven tools, are we in danger of becoming overly reliant on technology? Or are those reluctant to adapt likely to be left behind? Daniel May, Director at Consort Architectural Hardware, shares insight: Repetitive administration tasks “The development of the built environment has always relied on technical precision. Specifications naturally contain large volumes of product information and technical data, with professionals managing document-heavy tasks in the form of specification writing, door scheduling and BIM coordination in order to meet project requirements and compliance obligations. All of this data must be analysed and processed accurately - often in line with demanding timescales - and it is here where AI can offer the greatest value.” “Where time was once consumed by repetitive administration tasks and information processing, professionals are now embracing AI as a means of working more efficiently. For architectural ironmongery specifically, where specification accuracy is critical, AI has the potential to support architects and specification professionals as they navigate the product selection process. As a tool, AI can streamline documentation by rapidly processing performance data and certification requirements, whilst also identifying inconsistencies and absent compliance information within schedules.” Complex project requirements “AI systems are helping professionals navigate increasingly complex project requirements quickly, accurately and consistently. As machine learning and autonomous models continue to advance, these tools may further reduce the administrative burden associated with architectural work models whilst improving accuracy and minimising the risk of human error in the process. With that said, the effectiveness of AI software is very much reliant on the quality of the information it receives.” “With the sector so deeply tied to fire safety, accessibility, security and regulatory standards, the caution around adopting AI as common practice is of course justified. Historically, much of the construction industry has been measured in its adoption of new technology, partly due to the critical nature of compliance and the significant consequences of error. Though, AI feels somewhat different because of its pace and potential, and as such, organisations must be measured in their approach to it, ensuring that professional knowledge remains central to delivering safe, efficient and compliant building projects.” The human element As industry standards and the legislation surrounding the built environment continues to evolve, so too will the methods used to achieve high level design and compliance. Seemingly, AI looks set to have an increasingly prominent role, but it should be viewed as a collaborative partner capable of enhancing professional expertise as opposed to a system that can, or should, do it all. Daniel continues: “At this stage, AI alone simply can’t understand the nuances of individual projects and that has implications for both design and compliance. This is particularly relevant in the post-Grenfell regulatory landscape, where accountability, traceability and evidence-based decision-making have become fundamental to product specification and delivery.” Building greater trust “Although AI can assist with information processing, the technology is not ultimately responsible for the decisions being made. Accountability has rightly become a major focus point in construction, and as AI continues to disrupt practices, the industry must ensure that responsibility remains clearly defined. AI-driven errors could lead to serious penalties in relation to compliance, safety and project delivery, proving human expertise remains critical.” “Moving forward, greater transparency within AI systems will be key. If professionals are able to understand how or why AI recommendations have been generated, they can assess them with confidence, building greater trust in the technology.” Architectural design solutions “When it comes to architectural design, the emotional intelligence, contextual understanding and creative balance offered by a team of professionals far outweighs the speed that AI can offer. Already, AI is being used to support visualisation and concept development for multi-layered projects in hospitality, healthcare and commercial environments to name a few, helping teams to explore ideas and communicate concepts at a quicker rate.” “However, can AI effectively develop architectural design solutions based on the bespoke requirements of a project, the operational needs of its users or even the general character of the building? Most would argue that it’s not conceivable, because AI lacks the lived experience and contextual understanding that comes from being present in the project itself.” Architectural ironmongery products “For architectural ironmongery products, professionals must regularly assess how products will function in real environments. Human intuition is impossible to replace and those informed design decisions, made by human professionals, will always be essential. Whilst some question whether AI could one day plan and deliver a project from concept to completion, perhaps the more important question should be whether future generations of professionals could lose the critical design and specification skills that are needed, should the industry become too dependent on AI.” “There is a growing sense of inevitability surrounding AI’s influence on architectural ironmongery and the wider built environment. As the industry continues to embrace this new wave of technological development, it is important to remember that innovation must complement the knowledge, judgement and accountability of the professionals who create safe and functional buildings, not replace it.”
In the modern world of intelligent security, AI cameras and processing units (often called "AI boxes" or "AI servers") are transforming surveillance. They can detect specific behaviours — like someone entering a restricted area, loitering, or a vehicle parking illegally — and send immediate alerts. This represents a significant leap from older systems that merely recorded video for later review. However, a common challenge arises when organisations use devices from multiple manufacturers. Each brand often comes with its own proprietary software, creating a fragmented ecosystem. Unified video management software (VMS) platform Security personnel might need to switch between several different programs to monitor all their cameras. Furthermore, critical evidence — such as video clips triggered by an alarm — is typically stored locally on each device. If that device's storage fills up, new footage can overwrite the old, potentially erasing vital evidence before anyone has a chance to review it. Security personnel might need to switch between several different programs to monitor all their cameras This is where a Unified Video Management Software (VMS) platform becomes indispensable. Acting as a central nervous system, it integrates disparate devices into a cohesive operational framework. Solutions like SVMSPro exemplify this approach, seamlessly merging feeds from diverse AI hardware into a single, intuitive interface. Using SVMSPro as a case study, we can outline the core capabilities of a modern unified AI management platform: Simplified multi-brand management Eliminate the complexity of managing multiple software applications. A unified platform provides a single dashboard to view, control, and manage all AI devices — regardless of manufacturer. This consolidation dramatically streamlines daily operations, reduces training overhead, and provides a holistic view of the entire security infrastructure. Unifying AI surveillance application. Centralised & secure evidence storage Relying on the limited local storage of edge devices is a liability. Critical evidence from alarms is vulnerable to being overwritten and lost. SVMSPro solves this at the source. The moment any connected AI device detects an event — whether it’s intrusion, loitering, or object removal — SVMSPro receives the alert in real time and immediately triggers intelligent actions: Start high-quality alarm-triggered recording, Capture detailed snapshots, Activate PTZ tracking to track the subject automatically, And securely store everything on the centralised SVMSPro platform — not on fragmented front-end devices. This ensures evidence is permanently preserved and readily accessible. Users can swiftly search, review, and retrieve any alarm-related video or image via the web client or desktop application — anytime, anywhere. Illegal parking snapshot. Organised access & smart alerting Effective security is a team effort with tiered responsibilities. A unified platform enables precise, role-based access control. With SVMSPro, administrators can define user roles, create custom accounts, and assign specific video channels — even from different brands — to each operator. A guard may only access parking lot feeds, while a manager receives alerts for perimeter breaches. This granular control enhances operational efficiency, safeguards data privacy, and ensures team focus. Furthermore, real-time alerts can be pushed to mobile apps, guaranteeing immediate notification for the relevant personnel. User management. Integrated data analysis By aggregating data across all connected devices, a unified platform unlocks powerful analytics. It transforms scattered data points into actionable intelligence, generating comprehensive reports on event trends — from peak intrusion times in retail to occupancy heatmaps in large facilities. For instance, by ingesting people-counting data from AI cameras, SVMSPro can produce detailed daily, weekly, monthly, and annual traffic flow reports, supporting informed business and operational decisions. People flow statistics. Conclusion: From fragmented data to cohesive insight A unified management platform is the critical backbone for any multi-brand AI security deployment. It transforms a collection of isolated smart devices into a synchronised, intelligent network. The practical applications are vast: Retail: Combines loss prevention with customer behaviour analytics. Transportation Hubs: Manages vehicle flow and enhances passenger safety. Manufacturing: Monitors compliance in restricted hazardous areas. Smart Cities: Correlates events across districts to provide a unified operational picture for public safety. By centralising control, securing evidence, and delivering intelligent, role-specific alerts, platforms like SVMSPro empower organisations to evolve from simply observing events to understanding and acting upon them with unprecedented speed and clarity.
Artificial intelligence (AI) creates efficiencies throughout various industries, from managing teams to operating businesses. Key outcomes include faster investigations, fewer false alerts, automated operational checks, and quicker support experiences. These advancements free up valuable time for users, allowing them to focus on high-impact priorities that drive greater ROI. When it comes to surveillance, AI is most visibly powering a new generation of vision language-powered video analytics, a technology that has adapted systems meant solely for security into solutions capable of identifying actionable insights and streamlining workflows. Fast-moving AI landscape When choosing a surveillance system powered by AI, it’s vital to select an open platform. To stay ahead in the fast-moving AI landscape, it’s more important than ever for businesses to choose an open platform that empowers them to adapt and innovate. In contrast to closed systems, an open platform enables flexible integration with existing security and business systems. This offers businesses a greater return on their initial security investment while still providing an adaptable model built for the innovations of tomorrow. Below, we’ll look at the benefits provided by an open system in the age of AI, and how it can give you the strongest foundation to meet your goals. Supercharge your existing system An open platform also gives businesses the flexibility to scale security systems and add devices as needs evolve Having to invest in entirely new security infrastructure while simultaneously deploying AI technology presents a variety of problems and risks for businesses. Your team will have to manage both rollouts for your teams at the same time, driving up higher costs and more issues with training. By selecting an open platform, businesses can apply their newfound AI capabilities to existing cameras that weren’t built with analytics originally. Instead of having to completely replace your entire system, which can involve multiple weeks, months, or years of ripping out cabling and video security infrastructure, businesses can leverage analytics on the server itself to save valuable time while reducing deployment costs. This gives cameras a new lifespan by unlocking all the advantages video analytics brings, including basics like person and vehicle detection and line crossing analytics, to provide additional power to system alerts and visual search capabilities. An open platform also gives businesses the flexibility to scale security systems and add devices as needs evolve. This approach enables organisations to upgrade at a more optimal pace, bringing in new devices when it best fits the budget and operational priorities. Choose the solution that works best for you With an open platform, businesses have the ability to find and select the AI solutions that work best for them. This gives organisations greater flexibility when implementing a video analytics solution. AI-enabled devices can be added in the timeframe that works best for your business or according to your needs. For example, if a business needs a camera with edge-based slip-and-fall analytics for just one area of their facilities, an open platform enables integration with the best solution for that specific need without having to replace the entire system. This approach ensures you get maximum value from your investment while gaining the targeted benefits of video analytics. They can also bring onboard several analytic-enabled cameras while keeping the majority of their existing system, test different analytics offerings, or slowly phase out their old system. This is all possible thanks to the open platform which gives businesses the freedom of choice to find the best solutions for their business needs. Stay ready for what’s next AI is a refined, intelligent technological triumph, and today is the lower level of skill it will ever produce Finally, an open platform is inherently ready for future innovations, allowing businesses to stay ready for what’s next. AI is an advanced, intelligent technological achievement, and today is the lowest level of performance it will ever produce. The system investment you make today will need to be capable of taking advantage of the unknown but, undoubtedly, compelling features in five years' time. As new technologies continue to emerge, businesses can expand their ecosystem through an open platform, allowing them to integrate the applications that matter most to their business without being constrained by a single proprietary solution. This reduces the risk businesses may feel by committing to a single platform. Instead, they can leverage existing technology, including hardware, lowering the overall cost up front and providing an opportunity to adopt and integrate future solutions down the road. This also helps keep your surveillance current and up to date while mitigating timeline issues with the rollout of new AI features and helping you get the most out of your investment. It also provides a way to test new solutions and continue optimising your system for your business. Combining AI and an open platform The open video platform is one of the best ways to ensure your business is getting the most out of the exciting advancements in AI. With as many data points as there are provided by a modern security system, having a way to bring that information together in an integrated place is key. Thanks to AI, that information can be parsed more efficiently for proactive insights into potential optimizations and visibility during critical events. When finding the right video surveillance system for your business, be sure to select one that is not only AI-capable but also open. This will provide your organization with all of the benefits discussed above, including: Integrated Solutions: Thanks to the open platform, your business can still leverage existing hardware while using advanced video analytics on the recorder itself. Freedom of Choice: There’s no need to choose one system when it isn’t the best fit for your company. The open platform offers freedom of choice to leverage the best AI-powered technologies for your work. Futureproofed: As new innovations arise, you’ll be able to quickly integrate these cutting-edge technologies into your existing system without having to continually reinvent your system architecture.
Security beat
Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video security and data intelligence platform. The approach makes a difference that plays out in practical terms. A technology initiative is tactical and solution-oriented, often solving an isolated problem within a single department's silo. In other words, it might solve just a security problem. In contrast, a business initiative is cross-disciplinary, driven by executive leadership to impact the entire organisation in a measurable way. “Viewing AI tools as a business initiative ensures they adapt to multiple departmental needs and drive high-level strategic growth rather than just fixing a localised technical issue,” says Soukup. AI platform combines video and business systems Demonstrating the value of embracing AI as a business initiative is Solink’s new video intelligence platform Demonstrating the value of embracing AI as a business initiative is Solink’s new video intelligence platform that combines video with business systems to detect threats and send real-time alerts. The capabilities are designed to help security teams operate smarter and more efficiently, supporting the next generation of lean, intelligence-driven security operations centers (SOCs). And benefits of the platform extend beyond security to include other parts of the business. “At the end of the day, video cameras only tell part of the story, much like looking at a 2D shape,” says Soukup. “They capture dimensions and colors, but only from a single perspective, even with powerful AI analysis providing traffic metrics, wait times, product interaction, and compliance logs. The addition of operational data, such as inventory, shipping, labor, and sales data, fills out that shape into 3D, adding critical context.” For example, while a camera simply shows three people standing in a line, and AI data flags that those individuals have been waiting for over five minutes, operational data lets you know also that a cashier has not checked into their shift yet. Combining these data streams gives businesses full situational awareness, turning passive observation into immediate, contextual intervention. AI agents handle repetitive tasks The Solink platform uses AI Agents, which are software that operates autonomously to handle manual, repetitive, or high-volume tasks based on specific instructions and tools. For Solink users, AI Agents unify their existing camera and data source investments into a single automated workflow. “AI Agents transform Solink from a security tool into an operational investment that benefits all departments,” says Soukup. “Modern operational leaders are turning to AI to scale productivity without increasing overhead.” Integrating business intelligence Operations checks compliance, loss prevention investigates theft, and security assesses threats Customers already use Solink to centralise video, integrate business intelligence, and trigger real-world responses like real-world alerts, two-way communication, or smart locks. AI Agents tie these pieces together, analyse the data and identify what matters most, and then take action either without human intervention or with humans in the loop. Businesses currently watch video manually across separate workflows. Operations checks compliance, loss prevention investigates theft, and security assesses threats. However, a human must always watch the footage to get results. Solink AI Agents automate this entire workflow. If an operational event can be seen on camera and matters to the business, a Solink Agent can be integrated to automatically review, assess, and trigger the next step in the workflow across hundreds or thousands of locations simultaneously. Calling all stakeholders to the discussion When discussing applications, stakeholders should include revenue and marketing officers, compliance officers, and line-of-business executives. Agents leverage existing infrastructure by adding an intelligent automation layer that drives efficiency and grows revenue across the entire organisation without large capital investment. Solink AI Agents will not replace employees; they empower lean teams to maximise their existing resources. Job descriptions will shift toward human-in-the-loop workflows where humans and machines collaborate. The AI Agent handles the high volume, filtering out noise and processing data at scale. Human employees set up and guide the Agents, give feedback to improve performance over time, and step in to make final decisions, managing the nuanced situations that require critical thinking, empathy, and deep context. Passive data visualisation In contrast, a Solink AI Agent is deployed with a clear mandate for a specific task, deliverable, or outcome Given the convergence of physical and digital security, AI Agents, not dashboards, are the right unit of enterprise AI deployment. Dashboards typically aggregate data without evaluating the context or importance of the source. Data looks identical whether it comes from 10 sources or 100. In contrast, a Solink AI Agent is deployed with a clear mandate for a specific task, deliverable, or outcome. This approach shifts the focus from passive data visualisation to active intent, creating a direct path of accountability and clear attribution for business results. With dashboards, everyone can see the problem, but nobody owns it. An agent with a mandate either did the job or it did not, and you can audit exactly what it saw and why it acted or did not. Overcoming obstacles to deploy AI agents The primary obstacles to integrating AI Agents into the physical security workflow are change management, building trust, and system interoperability. Physical security requires absolute reliability, which demands rigorous initial configuration to establish trust. Furthermore, Agents are only as effective as the data they can access. Overcoming these hurdles requires comprehensive team training, shifting organisational mindsets, and ensuring seamless integration with existing tools so the Agents have the full context needed to execute tasks accurately and integrate with human workflows seamlessly. Addressing common security challenges Several use cases are driving the deployment of AI Agents among Solink's customers Several use cases are driving the deployment of AI Agents among Solink's customers. Overnight guarding, loss prevention, and store readiness will be the first wave of use cases. These are proven, high-frequency scenarios in which Solink provides pre-built template Agents to address common security challenges out of the box. The second wave of use cases will include highly customisable occupancy tracking, health and safety, and food quality. Pre-built template Agents are coming for these next. In addition, custom, niche operational use cases can be tailored to a specific business environment. Just like hiring a specialised contractor, companies can deploy custom Agents to tackle unique operational challenges rapidly across all locations. Measuring the effectiveness of AI agents The effectiveness of AI Agents can be measured by multiple factors. Core Accuracy, and consistency and accuracy of detections and automated outputs. Business Outcomes delivered, such as reduced inventory loss, reduced fraud, and faster incident resolution. Financial Impact, measured through recovered budget, reduced operational overhead, and increased per-store conversion. There is a perception that AI Agents possess predictive or flawless capabilities, like stopping crime before it happens or operating perfectly in dark, chaotic environments. Not true, says Soukup. AI cannot understand ambiguous requests like "look for suspicious activity." Success requires explicit parameters, tools, and skills, defining what is acceptable, what is unauthorised, and how to handle the gray areas. Another misconception is that Agents need a fundamentally different security model than people. “I run security for this company as well as engineering, and I hold our own Agents to the same standard I would hold a third-party vendor,” says Soukup. “That means least privilege, full audit trails, anomaly detection, random audits, and no action they can't explain after the fact.”
Combining VIVOTEK’s branded video security business with March Networks paves the way for the combined brands to meet customers’ increasing appetite for integrated solutions rather than individual components. The merger brings VIVOTEK's branded video security business together under one operating structure with March Networks’ enterprise-grade video surveillance, AI analytics, and cloud-managed security solutions. Customers now have access to a broader, more integrated portfolio spanning enterprise video management, advanced cameras, edge artificial intelligence (AI), cloud services, recording platforms, and business intelligence, says Net Payne, Chief Sales & Marketing Officer at March Networks and VIVOTEK. Distinct product strategies Given the combined companies, product development, sales, marketing, and customer support can move in step rather than in parallel. March Networks and VIVOTEK were already both part of the Delta Electronics family, but they previously operated as separate businesses with distinct product strategies, teams, and routes to market. March Networks and VIVOTEK announced the merger of their branded video security businesses last spring following Delta Electronics' acquisition of remaining VIVOTEK shares. “Aligning our complementary capabilities lets us innovate faster, simplify engagement, and respond more quickly to a market moving toward AI, cloud and intelligent video,” says Payne. This merger reflects a broader shift across the physical security industry, adds Payne. “Customers no longer see video purely as a tool for reviewing incidents after the fact,” he says. “They expect it to help identify risks earlier, simplify investigations, improve operations, and support better decisions across the organisation.” Cloud video management Meeting customer expectations requires more than bolting AI features onto existing systems Meeting customer expectations requires more than bolting AI features onto existing systems. Rather, it requires cameras, edge intelligence, recording, software, cloud services, and business data working together as one coordinated platform. “By bringing March Networks and VIVOTEK together, we combine deep expertise across the full video technology stack while preserving the relationships, sector knowledge and customer focus both companies have built over many years,” says Payne. “Our goal is to make intelligent video more integrated, scalable, and practical for customers and partners worldwide.” Both entities bring strengths to the combined companies. March Networks brings experience in enterprise software, cloud video management and large-scale deployments; while VIVOTEK brings strength in imaging, camera technology and edge intelligence. Together they seek to ensure more choice when designing systems, a clearer path for future expansion, and technologies that work together more effectively without compromising the reliability, cybersecurity, and support customers expect from both companies. Advantages for channel partners Channel partners gain a broader portfolio to address a wider range of customer requirements, combining components as each deployment demands. Channel partners also benefit from expanded geographic reach, deeper technical expertise, and greater investment in training and enablement. “Importantly, this is designed to be a seamless transition,” says Payne. “Partners keep working with the teams and relationships they already know, while gaining access to new capabilities and certification opportunities. Over time, that alignment should make it easier to design, deploy and support complete solutions.” Because they are established and respected brands, March Networks and VIVOTEK branding will continue to be used. Rebranding is not a goal, and neither identity is being replaced by the other. Coordinated decision-making “The immediate priority is organisational alignment by making it easier for customers and partners to benefit from the combined portfolio,” says Payne. Product branding will continue to reflect the relevant portfolio and market context. As product roadmaps become more closely coordinated, customers can expect greater interoperability and a more cohesive experience, says Payne. Any future branding changes will be managed carefully and communicated clearly. Combining the businesses reduces duplication and enables coordinated decision-making across product strategy, engineering, sales, marketing, operations, and customer support. “Instead of developing capabilities independently, teams can share their expertise, align roadmaps, and direct investment to where it has the greatest customer impact,” says Payne. Combining specialised knowledge globally The combined organisation operates across six continents and more than 75 countries The combined organisation includes more than 300 research and development (R&D) engineers across four Centres of Excellence in Canada, Taiwan, Italy and Poland, thus bringing together a substantial base of specialist knowledge. The unified network also sharpens the ability to prioritise global opportunities, respond to regional needs and bring innovations to market faster. The combined organisation operates across six continents and more than 75 countries, supported by more than 1,100 certified channel partners. That footprint provides greater capacity to support multinational customers while staying responsive to local market needs. Looking ahead, future growth will increasingly come from helping customers turn video into useful, actionable intelligence. “The market is moving beyond conventional surveillance toward solutions combining AI, cloud services, edge processing, video management and operational data — and our new structure brings these together as one connected solution rather than several isolated technologies,” says Payne. Broader technical expertise There will also be closer collaboration among specialists in imaging, hardware, software, analytics, and cloud, which is important given how much customer infrastructure, regulatory, and deployment requirements vary. The companies can support cloud, hybrid, and on-premise environments, giving organisations a practical path toward more intelligent video. More choice comes from bringing together complementary technologies across product groups. Greater scale is achieved through a larger engineering organisation, broader technical expertise and more capacity to invest in innovation. Challenges for the industry at large Looking to the future for the industry at large, the greatest challenge will be managing the rapid growth of AI Looking to the future for the industry at large, the greatest challenge will be managing the rapid growth of AI responsibly, securely and at scale, says Payne. Video systems will generate more data and automate more decisions, but organisations must be able to trust how that intelligence is created, protected, and applied, he adds. “Cybersecurity, privacy, data sovereignty, system interoperability and AI accuracy are more important than ever,” says Payne. Addressing these elements requires expertise across the entire technology stack: from camera and edge processing to recording, cloud infrastructure, video management and analytics. “Together, March Networks and VIVOTEK can coordinate development across all these layers, giving customers flexible architectures that balance innovation with security, transparency and operational control,” says Payne.
Artificial Intelligence (AI) had a major presence at the ISC West 2026 show in Las Vegas. Almost every booth offered some variation on AI and how intelligence is transforming the physical security industry. Several industry leaders led the way, showcasing how they are tackling complex security challenges with smarter, more efficient solutions. Obviously, the security industry will never be the same. Milestone Systems: Responsible AI and open platforms Milestone has declared 2026 the "year of delivery” on previously announced developments and enhancements. A standout feature is their new natural language AI search, which is being integrated across XProtect, Arcules, and Briefcam platforms to simplify how users interact with vast amounts of video data. A core pillar of their strategy is responsible AI development, which prioritises using licensed data over "scraped" data. They have introduced new anonymisation tools that protect privacy by replacing faces with AI-generated characteristics like hair color while keeping the person unrecognisable. Furthermore, Milestone is moving workloads to Linux to reduce costs, transitioning toward an app marketplace, and has partnered with NVIDIA for the "Hafnia" project to ensure high-quality data to train AI models. Ambarella: Powering the edge with AI chips With their presence at ISC West in a meeting room near the trade show floor, Ambarella is the "engine" behind many high-performance intelligent video products, specialising in low-power AI chips like the N1 and CV7 families. Their technology is moving beyond cameras, where they provide systems-on-chips [SOCs] to many manufacturers. They have expanded into "AI boxes" that can process 64+ video channels simultaneously. A standout feature is the Natural Language technology, which allows users to search for specific objects or abstract scenes using simple prompts. To address modern security concerns, Ambarella has implemented "agentic" programming for a no-code development of automated workflows and media signing to combat AI-generated deepfakes by verifying video integrity through metadata. Motorola Solutions: Simplifying intelligence Motorola Solutions shows physical security evolving into a real-time enterprise intelligence layer Motorola Solutions is prioritising user accessibility by integrating natural language processing into its system configuration. Motorola's portfolio demonstrates how physical security technology is evolving into a real-time operational intelligence layer across the enterprise. Instead of requiring custom coding, operators can now use simple commands—like asking the system to "show me when someone fell down"—to set up advanced analytics and search parameters. The company is also deploying AI agents designed to aggregate data and automatically flag safety or compliance risks, such as perimeter breaches or blocked fire exits. To ensure maximum utility of the hardware, Motorola Solutions’ system can ingest massive, complex physical manuals and automatically generate monitoring rules based on those standard operating procedures. Furthermore, Motorola is focusing on interoperability, using industry-standard interfaces to ingest data from various hardware brands and networks. This approach aims to provide operators with clear, recommended next steps during critical events, streamlining the decision-making process in high-pressure environments. i-PRO: Putting generative AI at the edge i-PRO is bringing generative AI directly to the edge with a new fisheye camera i-PRO is bringing generative AI directly to the edge with a new fisheye camera, which processes complex analytics locally rather than relying solely on the cloud. These cameras, on display at ISC West, have moved beyond simple attribute-based tracking to identify complex behaviors like aggression, fighting, and slip-and-fall incidents. By running on the latest Ambarella chips, i-PRO cameras can use generative AI to improve image quality and analyse scenes in real-time without external processing. This focus on edge-based intelligence ensures high-performance analytics are available even in environments where constant cloud connectivity might be a challenge. Brivo: The rise of agentic AI Brivo and Eagle Eye Networks have officially unified under the Brivo name, focusing on streamlining the experience for large integrators. They are pioneers in agentic AI, introducing features that allow users to talk to their mobile apps to initiate lockdowns or add users. Their Eagle Eye Video Assistant (EEVA) acts as a natural language AI agent that can monitor for specific threats, such as a brandished weapon or a specific vehicle, and automatically trigger access control responses. By treating access and video as a unified system, Brivo enables users to connect specific video skills—like detecting a red car or a brandished weapon—to automated access control actions. They are also using AI to achieve "zero-cost integration," linking disparate cloud systems using AI-generated instructions. Everon: Emphasis on video monitoring Everon is making a massive investment in active video monitoring, using AI-driven systems to deter crime even before it happens. “The market is ripe for it, and customers are demanding it,” says David Charney, Everon’s Sr. Vice President, Video Command Center. Employing virtual guards who can use voice commands, lights, and horns to "shoo away" unauthorised individuals. The company has implemented senior-level leadership that has facilitated more than 5,000 video-based apprehensions. Everon, specialising in integrated systems for multi-site businesses, uses a rigorous selection process to choose AI providers that can accurately filter alerts for specific applications, such as identifying when a fire door is blocked. As a "trusted advisor" to their 300,000 customers, the company focuses on delivering professional-level results that move beyond basic recording to proactive threat mitigation. Hanwha: New hybrid VMS combines cloud and on-prem Hanwha Vision highlighted the official public launch of Blaze, a hybrid video management system (VMS). The platform uses a hybrid architecture to manage on-premise and cloud-connected devices across multiple sites without complex port forwarding. Blaze features native AI capabilities, including semantic search that allows operators to find specific incidents using natural language queries, such as "person with a safety jacket." The AI security platform lets teams search surveillance footage the way they search Google. AI similarity detection allows operators to quickly trace a person’s movement and investigate incidents faster (useful in active shooter behavior, medical emergencies, or crowd panic scenarios, and more). The system also provides a "histogram" view of traffic patterns to help security professionals quickly identify anomalies in historical footage. OpenEye: Operational intelligence and shift to OpEx OpenEye unveiled AI-powered features such as visual chat and scene analysis OpenEye is redefining video surveillance by moving intelligence from the camera level to the cloud, significantly reducing the need for on-site server management. At ISC West, OpenEye introduced new AI-driven tools like visual chat and scene analysis. Beyond security, these tools provide valuable operational alerts, such as identifying overflowing dumpsters, dirty tables in restaurants, or vehicles blocking dock doors. The system also utilises natural language for search, allowing users to find specific attributes like "people wearing backpacks" within designated timeframes. OpenEye also highlighted an industry-wide shift toward operational expenditures (OpEx) billing models, as users increasingly prefer predictable monthly or yearly payments over large upfront capital expenditures (CapEx). This model aligns with their channel-based operations, meeting customers where they currently operate without the burden of high fees. IQSIGHT: New name, same mission for Bosch video Formerly Bosch Video, the newly named IQSIGHT seeks to maintain the “Bosch pedigree” under the new name. It’s the same engineering, manufacturing, etc. IQSIGHT also pledges to be "easier to do business with" by improving user interfaces and end-to-end user experiences. Despite the transition, the company has increased their pace of innovation and reinforced the open systems philosophy with enhanced integrations with Milestone, Genetec, and others. The major product release at the show is IVA Pro Context, which uses generative AI to provide human-level scene understanding. Through a partnership with Laelaps AI, a robotics startup, IQSIGHT is exploring autonomous dispatch and response. When a camera identifies a scene, it triggers a robot to provide a tailored response. Commercialisation is expected in 12 to 18 months. Verkada: How their system can solve a crime But how does AI operate in the real world? Verkada had a “themed” exhibit demonstrating how their system could solve a hypothetical theft at the Louvre museum in Paris. The exhibit took attendees through and showed how Verkada technologies (e.g., license plate recognition and search capabilities) could provide fast results to solve the crime. AI-powered tools, like their newest unified timeline, demonstrate value in the real world of investigations.
Case studies
The Adrian Public Schools Board of Education approved the renewal of its ZeroEyes AI-based gun detection and intelligent situational awareness platform during its April 13 meeting, continuing the use of artificial intelligence technology designed to enhance school safety by monitoring existing security camera systems for potential firearms. The deployment has been in place since 2023. ZeroEyes' AI gun detection and intelligent situational awareness software layers onto existing digital security cameras. If a gun is identified, images are instantly shared with the ZeroEyes Operations Center (ZOC), the industry's only U.S.-based, fully in-house operation center, which is staffed 24/7/365 by specially trained U.S. military and law enforcement veterans. Security safety enhancements If these experts determine the threat is valid, they dispatch alerts and actionable intelligence — including visual description, gun type, and last known location — to law enforcement and district officials as quickly as 3 to 5 seconds from detection. ZeroEyes is just one component of the multi-layered security safety enhancements that have taken place over the past few years. The District has implemented multiple safety enhancements including a full overhaul of its security camera systems, the addition of weapon detection K-9 support across school facilities, and the installation of bullet-resistant and shatter-resistant glass in key areas of school buildings. Proactive safety planning Superintendent Nate Parker stated that the District remains committed to proactive safety planning. “The safety of our students and staff remains our highest priority,” Parker said. “We continue to take intentional, layered steps to strengthen our security systems and ensure our schools are prepared and protected. The renewal of ZeroEyes reflects that ongoing commitment.” Officer Joshua Perry of the Adrian Police Department, who serves as a School Resource Officer and participates in District safety planning, said collaboration has been central to the District’s approach. “These improvements demonstrate a strong partnership between schools and law enforcement,” Perry said. “The combination of training, communication, and technology significantly strengthens our ability to keep students and staff safe.” Partnerships with innovative technology As these collaborative safety efforts continue to evolve, partnerships with innovative technology providers like ZeroEyes remain a key component of the district’s strategy. “Adrian Public Schools’ continued investment in layered, proactive security demonstrates a clear commitment to protecting students and staff,” said Mike Lahiff, CEO and co-founder of ZeroEyes. “By renewing their partnership with ZeroEyes, the district is strengthening its ability to identify and respond to potential threats in real time, giving first responders critical information when every second counts. We’re proud to support Adrian in creating a safer learning environment for its community."
ZeroEyes, the creators of the first AI-based gun detection video analytics platform to earn the full US Department of Homeland Security SAFETY Act Designation, announced now that Ki Charter has expanded its contract following initial success. ZeroEyes’ proactive gun detection and intelligent situational awareness solution will now be deployed across the school’s San Marcos campus. Largest residential treatment centre Ki Charter is the premier educational provider for students who reside in residential facilities (RFs) and day centres across Texas. The school serves over 6,500 students annually (500% mobility rate) with a dedicated team of educators and staff. The San Marcos campus is located within the 65-acre San Marcos Treatment Centre, the largest residential treatment centre in Texas. The centre houses approximately 200 residents (and community students) who attend Ki Charter, and employs 425 staff members, including 50 from Ki and 375 from the San Marcos Treatment Centre. Level of real-time awareness “At Ki Charter, we serve a unique population of behaviourally challenged students, so our approach to security has to be comprehensive, proactive, and intentional,” said Dr. Jerry Lager, Superintendent of Ki Charter. “Our Safety and Security Committee, campus teams, mental health staff, and local law enforcement all play a role in preventing and de-escalating potential threats, but ZeroEyes added a level of real-time awareness we simply didn’t have before. After seeing how effective the technology was, expanding its use was an easy decision.” ZeroEyes' AI gun detection ZeroEyes' AI gun detection and intelligent situational awareness software layers onto existing digital security cameras. If a gun is identified, images are instantly shared with the ZeroEyes Operations Centre (ZOC), the industry's only U.S.-based, fully in-house operation centre, which is staffed 24/7/365 by specially trained U.S. military and law enforcement veterans. If these experts determine the threat is valid, they dispatch alerts and actionable intelligence — including visual description, gun type, and last known location — to law enforcement and local security teams as quickly as 3 to 5 seconds from detection. Multi-layered safety program “Ki Charter has built a thoughtful, multi-layered safety program, and we’re proud to continue to play a role in strengthening it,” said Mike Lahiff, CEO and cofounder of ZeroEyes. “Their leadership is deeply committed to protecting students and staff, and this expansion proves that they understand that proactive security is essential on a campus of this size and complexity.”
EnGenius Technologies Inc., a pioneer in advanced connectivity and cloud-managed networking solutions, today announced that Crossroads Church in Rowlett, Texas, has completed a comprehensive security and network modernisation project using EnGenius AI cameras, multigigabit switches, and Wi-Fi 7 access points. The upgrade delivers complete visibility across the church’s 30,000-square-foot facility and 15-acre campus, providing staff, volunteers, and families with unprecedented peace of mind. Rapid growth drives need for enhanced safety Serving more than 1,200 members and hosting daily activities including worship services, youth programs, daycare, and community outreach, Crossroads Church faced increasing challenges with its aging surveillance system. The church’s legacy NVR-based surveillance system left numerous blind spots and lacked the clarity, storage, and analytics needed to support a large, active campus. “With ministry happening every day and families trusting us with their children, we needed to be sure we could clearly monitor every part of our campus,” said the church’s Executive Pastor. “Our previous system simply couldn’t keep up.” A unified EnGenius solution Crossroads Church partnered with Smart Technology Solutions to implement a full-scale modernisation built on EnGenius cloud-managed technology. The deployment includes: 57 EnGenius ECC100 AI surveillance cameras for complete indoor, outdoor, and parking-lot coverage Multi-gig EnGenius ECS2552FP and ECS2528FP switches supporting high-capacity video, livestreaming, and campus-wide traffic 12 EnGenius ECW536 Wi-Fi 7 access points providing fast and reliable wireless connectivity for staff, classrooms, and production teams A single-pane-of-glass cloud dashboard delivering centralised management, real-time monitoring, and instant event review “For the first time, we have total visibility,” said the Lead Pastor. “If something happens anywhere on our property, we can see it, isolate it, and respond immediately. That level of clarity is invaluable.” AI features unlock the future of campus security The church has begun using contextual AI analytics, including event detection, vehicle tracking, and customisable alerts. Over time, leadership plans to expand their use of EnGenius AI capabilities to detect human activity, interpret complex scenarios, analyse movement trends, and enhance after-hours oversight — further improving campus safety. Meet the AI that turns video into insight Ever spent hours scrubbing through video just to find one five-second moment? With EnGenius Cloud AI, those days are over. It eliminates the biggest headaches of traditional surveillance—false alerts, slow investigations, and endless manual review—by delivering real-time intelligence and natural language search. Instead of generic motion notifications, the system interprets what it sees, recognising behaviours with context so the team receives fewer false alarms and earlier warnings when something seems off. And when it’s time to find footage, there’s no need to dig through timelines—simply enter a description like “person in a red hoodie with a black backpack,” and the system instantly retrieves the precise clips from any camera or location. This smarter, context-aware approach helps staff work faster, respond with confidence, and stay focused on what matters most. More than a camera system, it’s a smart security assistant that makes investigations faster, simpler, and far more effective. Key camera features 5MP HDR Clarity: Sony Starvis sensor ensures clear day-and-night visuals. Ultra-Wide Coverage: 132° view and 20m IR distance for versatile environments. 8GB eMMC Flash Storage + 4GB DDR4 Memory: Delivers reliable onboard flash storage and efficient multitasking for smooth, stable performance. Built-in Storage, No NVR Needed: ECC100 includes 256GB of reliable onboard storage, supporting continuous and event recording 24/7 for immediate footage access. Durable Build: IP67 weatherproof and IK10 vandal-resistant design. Cloud Access & Mobile Monitoring: Manage cameras anytime, anywhere. The next era of intelligent surveillance With the launch of its AI Cloud Surveillance Solution and ECC100 AI Camera, EnGenius once again sets a new benchmark for intelligent security—empowering businesses to stay one step ahead with smarter, faster, and more reliable protection. “What truly sets our system apart is its ability to analyse contextual sequences rather than just single-frame images, enabling preventive alerts before incidents occur,” said Roger Liu, Executive Vice President at EnGenius Technologies. “Whether it’s spotting loitering before theft, flagging escalating conflicts, or identifying fatigued workers on a factory floor, our system helps businesses act before incidents escalate.” Availability The ECC100 is available from EnGenius authorised resellers and distribution partners.
VIVOTEK, the pioneering security solution provider, actively integrates corporate social responsibility into its operations. This year marks the fifth “Safety Map” corporate sustainability event. For the first time, the team extended its efforts beyond urban communities to the natural environment of Zhonggua River in Guoxing Township, Nantou, Taiwan. Collaborating with the National Chung Hsing University’s (NCHU) University Social Responsibility (USR) team on “Environmental Resilience and Sustainability” and the precision AI agriculture partner DATAYOO, the team launched the “Zhonggua River Ecological Restoration Safety Map” project. VIVOTEK deployed its security solutions to monitor the ecosystem, successfully capturing rare footage of the endangered crab-eating mongoose in its natural habitat. Employees also helped remove invasive species, restore native plants, and construct ecological ponds, embedding sustainability into the company’s core security expertise – extending protection from human safety to habitats and biodiversity. “Returning land to the river:” Reviving the ecosystem After a typhoon in 2004, Zhonggua River’s banks were fortified with high walls and riverbed structures for flood control, which disrupted the ecosystem. Over time, cracks formed, foundations eroded, and exposed steel reinforced the risk. In 2018, Professors Chiou-Rong Sheue and Peter Chesson from NCHU’s Department of Life Sciences began living by the river and advocated a subtraction approach: dismantling walls to “return the land to the river,” balancing flood control with conservation. This effort culminated in 2023 with Taiwan’s first community-initiated river restoration project. Today, the USR team led by Professor Hsu continues ecological monitoring and habitat maintenance, while VIVOTEK contributes technology and manpower through the “Safety Map” initiative, jointly safeguarding the reborn river. Security technology supports restoration through action and care “VIVOTEK uses ‘Concern for Others’ Cares’ as a brand catalyst. During the 2010 Chile mining disaster, our cameras were deployed deep inside the mine to monitor the vital signs of trapped miners, transmitting real-time footage to rescue teams and contributing to the miraculous rescue efforts. In Parks Victoria, Australia, we applied AI solutions to observe seal habitats in Port Phillip Bay, monitoring potential threats such as fishing lines and ropes." "VIVOTEK partnered with the NCHU’s USR team to transform our original commitment to care and social safety into active conservation of the river ecosystem and wildlife, turning technology into a bridge for harmonious coexistence between humans and nature,” said Alex Liao, President of VIVOTEK. Building safe habitats, restoring nature’s vitality Under the guidance of the NCHU’s USR team, VIVOTEK employees observed aquatic insects, native plants, and changes in the river ecosystem, gaining insight into the impact of removing cement embankments on local wildlife. To accelerate ecological restoration, they split into teams to construct ecological ponds and build new homes for the Ayers’ tree frogs using bamboo tubes. At the same time, invasive plant species such as Mimosa pudica, fragrant orchids, and elephant grass were removed, while native species including reed orchids, wild peonies, honeysuckles, purple bead trees, Taiwan mountain laurels, and orange osmanthus were replanted to stabilise the soil and restore riparian vegetation. “Being able to personally contribute to ecological restoration and give back to nature is a source of pride as a VIVOTEKer,” shared Ben, an engineer who has participated in the Safety Map event for five consecutive years. Leveraging big data monitoring to deepen corporate impact “The Safety Map event has extended from neighbourhoods, care facilities, schools, and historic settlements to Zhonggua River, engaging hundreds of employees in inspecting sites and proposing safety solutions. Through these efforts, we have expanded the definition of ‘safety’ from simply protecting people to also safeguarding wildlife and habitats, revealing the multidimensional nature of security." "Moving forward, we will continue to promote cross-industry collaboration, using our security expertise as a foundation to amplify social impact and create more inclusive safety values and practices,” said Allen Hsieh, VIVOTEK’s Spokesperson and Director of the CorpComm & Sustainability Office. This year, VIVOTEK further leveraged the expertise of DATAYOO, using its FarmiSpace PRO monitoring service and AI crop monitoring system to analyse various crop indices derived from satellite spectral data. These insights provide the NCHU’s USR team with a scientific basis for their ecological research at Zhonggua River, enabling a data-driven approach to natural habitat restoration and making technology a powerful tool for conservation. Industry and academia join forces to set a benchmark “VIVOTEK Proactively proposed initiatives and involving company employees in hands-on participation are the most powerful ways to implement ecological restoration. Through VIVOTEK’s security expertise, volunteer engagement, and AI-driven long-term ecological monitoring, we have accelerated the restoration of Zhonggua River’s ecosystem, allowing more people to witness the harmony between humans and nature,” said Chiou-Rong Sheue. The habitat restoration efforts have already shown tangible results, with the ecological ponds built by VIVOTEK employees quickly attracting creatures such as pond frogs, dragonflies, water striders, and damselflies. VIVOTEK has emerged as a key driver of environmental restoration through its security technology, demonstrating that safety is not only about protection but also stewardship and shared responsibility, and continues to foster a Safety Map where humans and nature coexist.
Round table discussion
If AI is the dominant buzzword in the physical security industry, it is the second letter (I for intelligence) that is having the biggest impact. Simply put, intelligence transforms computer systems, including those used for physical security, from rigid, rule-following calculators into adaptable, problem-solving partners to human operators. We asked our Expert Panel Roundtable: What is the changing role of intelligence in physical security?
At mid-year 2026, the broader economy tells a story of resilience under pressure. Conflict in the Middle East has triggered a shock to the energy supply, driving oil prices up and reigniting global inflation. However, a total downturn has been averted. Exceptional, historic levels of business investment and data centre construction are providing a firm floor for growth, offsetting cooler consumer spending and keeping labour markets fundamentally stable. But how are changing economics impacting the physical security market? We asked our Expert Panel Roundtable: How do changes in the broader economic climate impact physical security?
In the simplest terms, technology modernisation accelerates when older systems become too expensive to maintain or fail to support modern standards. Market competition pushes businesses to update their technologies to meet rising customer demands. Additionally, the rapid shift toward cloud-based infrastructures and artificial intelligence creates a fear of missing out, forcing companies to adapt or risk irrelevance. Focusing on the physical security market, we asked our Expert Panel Roundtable: What factors are accelerating technology modernisation in security?
Products


White papers
Technology's role in securing banks and financial institutions
Download
Integrated systems enable critical and compliant security for transportation
Download
Security technologies promote real-time awareness in K-12 schools
Download
Elevating security through multi-sensing solutions and large-scale AI
Download
The 4 pillars of AI in managing high-stakes critical events
Download
How biometrics are reshaping security in a connected world
Download
Using artificial intelligence (AI) to automate physical security systems
Download
2025 Trends in video surveillance
Download
The role of artificial intelligence to transform video imaging
Download
Total cost of ownership for video surveillance
Download
5 surprising findings from OT vulnerability assessments
Download
Guide for HAAS: New choice of SMB security system
Download
Integrating IT & physical security teams
Download
Top 7 trends to watch in the physical security industry
Download
2024 trends in video surveillance
Download

Artificial intelligence (AI): Manufacturers & Suppliers
- Dahua Technology Artificial intelligence (AI)
- Vicon Artificial intelligence (AI)
- WD Artificial intelligence (AI)
- LILIN Artificial intelligence (AI)
- Hikvision Artificial intelligence (AI)
- Anviz Artificial intelligence (AI)
- Avigilon Artificial intelligence (AI)
- Hanwha Vision Artificial intelligence (AI)
- IDIS Artificial intelligence (AI)
- Illustra Artificial intelligence (AI)
