Machine Learning
The pace of technological progress is best described as relentless. Cyber attacks have evolved from opportunistic strikes into highly automated, intelligent campaigns that move at faster than ever. Traditional security operations centres, built for a slower and more predictable threat landscape, are struggling to keep up. This is where the AI-native Security Operations Centre (SOC) enters the scene, not as a luxury, but as a necessity. An AI-native SOC reimagines security operations from the gr...
FARx, the world's only AI-fused biometrics company, has appointed former BT executive and Cambridge technology leader Chris Bruce as Chairman, as the business prepares for its next phase of UK and international growth. The move comes after FARx recently secured £625,000 in seed funding through the Seed Enterprise Investment Scheme (SEIS) and the Enterprise Investment Scheme (EIS) with plans to expand its patented biometric authentication technology into global markets. Biometric authenti...
Security operations centres of the past were pictured as quiet control room filled with blinking dashboards with constant surveillance from human analysts. Today, cyber security teams utilise high-speed decision engines; constantly interpreting signals, filtering noise, and responding to threats that evolve by the minute. In this environment, terms like AI SOC, SIEM, and SOAR are often used interchangeably, yet each plays a distinct role. In this article, users will learn what sets these three...
Security operations today can feel like trying to drink from a firehose while someone keeps turning up the pressure. Alerts sound from every direction, each demanding attention as it carries the possibility of a real threat. Somewhere in that torrent, genuine risks hide among noise. This is where many Security Operations Centres (SOCs) begin to struggle. In this article, users will learn how an AI-powered SOC transforms this experience by reducing false positives and easing alert fatigue. We wi...
As the pace of progress quickens, organisations face a growing volume of alerts and increasingly sophisticated attacks. Security teams are expected to detect and respond to threats quickly, often with limited resources. This is where an AI-native Security Operations Centre (SOC) becomes essential to improve visibility, detection accuracy, and response times. Alerts rain down, attackers adapt in real time, and defenders are expected to see patterns in the chaos. A SOC is fuelled not just by algor...
Cyber threats are evolving at a pace that bewilder even seasoned security analysts. Attackers used to be easy to detect; with their reliance on phishing emails riddled with spelling mistakes or predictable malware signatures. Today’s threat actors are harnessing artificial intelligence to automate reconnaissance, generate convincing social engineering campaigns, evade detection, and adapt their attacks in real time. Against this backdrop, many traditional Security Operations Centre, or SOC...
News
Cybersecurity teams face a difficult reality. Organisations are collecting more security data than ever before, yet many still struggle to detect threats quickly, respond efficiently, or keep pace with increasingly sophisticated attacks. Traditional Security Operations Centre (SOC), once considered the backbone of enterprise defence, are under pressure from alert overload, analyst burnout, and attackers who now use automation and artificial intelligence themselves. As a result, AI-driven SOC is rapidly shifting from emerging technology to operational necessity. Businesses are no longer debating whether AI belongs in cybersecurity. Instead, they are asking a more practical question: is investing in an AI SOC actually worth it? Modern security operations This article explores what AI-powered SOC are, why organisations are adopting them, the costs involved, and the measurable returns businesses can expect. It also examines the long-term operational and strategic value AI can bring to modern security operations. Traditional SOC were built for a different era of cybersecurity. Analysts manually reviewed alerts, correlation rules were largely static, and attacks were often slower and less complex. Today’s threat landscape moves at machine speed. AI-assisted phishing campaigns Modern organisations generate enormous volumes of telemetry from cloud environments, endpoints, SaaS applications, networks, identity systems, and third-party integrations. Security teams are expected to monitor all of this continuously while defending against ransomware, insider threats, supply chain attacks, and AI-assisted phishing campaigns. Many analysts spend large portions of their time investigating false positives, enriching alerts manually, or repeating low-value workflows. This slows response times and increases the likelihood that genuine threats will be missed. Introducing intelligent automation AI-driven SOC address these challenges by introducing intelligent automation and machine learning into security operations. Rather than relying entirely on static detection rules, AI systems can analyse behavioural patterns, correlate large datasets, prioritise high-risk incidents, and automate repetitive investigations in real time. For many organisations, this transition is becoming essential. If attackers can launch AI-assisted campaigns that adapt in seconds, organisations can no longer rely solely on manual security operations to defend themselves effectively. Existing security maturity One of the main reasons organisations hesitate to adopt AI-driven SOC models is the perception that implementation requires enormous investment. While costs can be significant, the reality is more nuanced. The overall expense depends on factors such as organisational size, infrastructure complexity, existing security maturity, and operational goals. Initial investments often include: AI-powered SIEM or XDR platforms Security automation and orchestration tools Cloud infrastructure and storage Integration services Staff training and onboarding AI-enhanced operations Some businesses also partner with managed detection and response (MDR) providers that already incorporate AI capabilities into their SOC offerings. Additional costs may involve improving data visibility and integration. AI systems depend heavily on quality telemetry and accessible data. Organisations with fragmented security ecosystems may need to modernise data pipelines before they can fully benefit from AI-enhanced operations. However, comparing AI SOC costs only against traditional SOC spending can be misleading. Conventional SOC often require continuous growth in analyst headcount to keep up with increasing alert volumes. At the same time, experienced cybersecurity professionals remain difficult and expensive to hire. Burnout and staff turnover further increase operational costs. Scaling security operations AI changes the economics of scaling security operations. Instead of increasing staffing proportionally with data growth, organisations can use automation and intelligent correlation to manage larger workloads more efficiently. In many cases, businesses discover they were already paying heavily for inefficiency long before AI entered the equation. Cybersecurity ROI can sometimes feel difficult to measure because success often means preventing incidents that never occur. However, AI-driven SOC provide several measurable indicators that demonstrate both operational and financial value. One of the most important metrics is dwell time, which refers to how long attackers remain undetected inside an environment. Reducing reputational damage The longer a threat actor operates unnoticed, the greater the potential damage. AI-powered SOC improve detection speed by analysing behavioural anomalies and correlating indicators across multiple systems simultaneously. Reducing dwell time can significantly lower breach costs, minimise disruption, and reduce reputational damage. AI SOC improve both Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). Automated workflows rapidly enrich alerts with contextual intelligence, allowing analysts to make faster and more informed decisions. Instead of spending valuable time gathering information manually, analysts can focus on containment and remediation. Strategic security tasks Operational efficiency is another major driver of ROI. Rather than manually triaging thousands of alerts, analysts can concentrate on high-priority threats and strategic security tasks. AI systems eliminate much of the repetitive work that traditionally consumes analyst time. This not only improves productivity but can also reduce burnout and staff turnover, both of which carry significant operational costs. The financial impact of a major cyber incident can include: Regulatory fines Legal costs Customer loss Operational downtime Recovery expenses Reputational damage AI-driven SOC help reduce both the likelihood and severity of successful attacks through faster detection and more consistent response capabilities. Improving compliance operations For regulated industries, AI SOC can also improve compliance operations. Automated reporting, continuous monitoring, and enhanced visibility simplify audit preparation and reduce administrative overhead. This creates both operational savings and reduced regulatory risk. The benefits of AI SOC extend beyond cybersecurity alone. Security operations now directly influence customer trust, operational resilience, digital transformation, and organisational agility. As businesses expand cloud adoption and hybrid work environments, security operations must scale without slowing the business down. Growing telemetry volumes AI SOC support this scalability by managing growing telemetry volumes and operational complexity more efficiently than traditional models. This becomes especially important during periods of rapid growth, mergers, acquisitions, or international expansion. AI-enhanced SOC also improve executive visibility. Advanced analytics and automated reporting provide leadership teams with clearer insights into risk exposure and operational performance. Security discussions become more strategic and data-driven rather than purely reactive. Another major advantage is consistency. AI-driven security operations Some organisations focus heavily on immediate implementation costs while overlooking the long-term value AI-driven security operations create. In the short term, adopting an AI SOC may require: Infrastructure modernisation Workflow redesign Staff onboarding System integrations These investments can appear substantial, particularly for organisations transitioning from legacy systems. However, the long-term value often compounds over time. As AI systems analyse more operational data, detection quality improves. Automation workflows become more refined. Security teams become more efficient. Incident response becomes faster and more predictable. Traditional SOC models Meanwhile, the costs of maintaining outdated SOC models continue to rise. Manual operations struggle to scale with expanding attack surfaces. Analyst fatigue contributes to turnover. Delayed detection increases breach risk. Compliance management becomes more difficult and resource-intensive. Over time, these inefficiencies can become more expensive than modernising security operations altogether. Organisations should therefore evaluate AI SOC investment not simply as a technology purchase, but as a long-term operational transformation. AI-driven SOC are reshaping how organisations approach cybersecurity operations. As threats become faster, more automated, and increasingly complex, traditional SOC models often struggle to keep pace. Meaningful business outcomes While implementing an AI SOC requires investment, the long-term value can be substantial. Faster detection, improved operational efficiency, enhanced scalability, stronger compliance readiness, and reduced long-term risk all contribute to meaningful business outcomes. Most importantly, AI allows security teams to move beyond endless alert firefighting and toward more strategic, intelligence-led defence operations. Businesses adopting AI-enhanced security operations today are not simply purchasing new tools. They are building more resilient, scalable, and adaptive cybersecurity capabilities for the future. If the organisation is evaluating how to modernise its SOC capabilities, Rewterz can help assess your current security posture, identify operational gaps, and implement AI-driven solutions that strengthen detection, response, and resilience across the environment.
Cybersecurity teams are experiencing a shift in their scope of work. Attack surfaces are expanding, threat actors are becoming more sophisticated, and the speed of modern attacks is outpacing traditional security operations. At the same time, organisations are facing off a spike in alerts, struggling with analyst burnout, and dealing with an ongoing shortage of skilled cybersecurity professionals. Against this backdrop, Artificial Intelligence has emerged as one of the most transformative technologies in the Security Operations Centre, or SOC. Reshaping security operations Yet one question continues to surface in boardrooms and security teams alike: can AI replace SOC analysts? The short answer is no. AI is reshaping security operations, but it is not eliminating the need for human expertise. Instead, the future of cybersecurity lies in collaboration between intelligent automation and skilled analysts. AI excels at speed, scale, and pattern recognition, while human analysts provide judgement, creativity, contextual understanding, and strategic decision-making. In this article, they will explore how AI-driven SOC are changing security operations, why businesses increasingly need both AI and human analysts, and how responsibilities are being divided between machines and people. They will also examine the critical human role in threat hunting, contextual analysis, oversight, and response orchestration in modern SOC environments. AI-assisted phishing campaigns Traditional SOC is designed for a very different era of cybersecurity. Analysts manually reviewed logs, investigated alerts, relying heavily on static rules and signatures to identify threats. While this model once worked reasonably well, modern cyber threats move far too quickly for purely manual operations. Attackers are now using automation, AI-assisted phishing campaigns, polymorphic malware, and sophisticated social engineering tactics that constantly evolve. A single organisation may generate millions of security events every day, creating a tidal wave of telemetry that no human team can realistically process on its own. Interpreting complex threats This has created several operational challenges for SOC teams. Alert fatigue has become widespread, with analysts overwhelmed by false positives and repetitive tasks. Response times are often delayed because security teams cannot prioritise incidents efficiently. At the same time, cybersecurity talent shortages mean many organisations are operating with understaffed SOCs. AI-driven security operations emerged as a response to these growing pressures. By automating repetitive tasks and accelerating analysis, AI helps organisations detect and respond to threats at machine speed. However, this does not mean humans become irrelevant. Quite the opposite. As AI handles operational heavy lifting, human analysts become even more important in guiding strategy, validating decisions, and interpreting complex threats. Large-scale data analysis AI thrives in environments that involve large-scale data analysis, repetition, and pattern detection. Modern SOC platforms use machine learning and large language models to process telemetry from endpoints, networks, cloud infrastructure, applications, and identity systems in real time. One of AI’s greatest strengths is its ability to rapidly identify anomalies that might otherwise go unnoticed. Instead of relying solely on pre-defined rules, AI systems can learn behavioural baselines and flag suspicious deviations. This allows organisations to detect novel attacks, insider threats, and stealthy lateral movement more effectively. AI is also highly effective at triaging alerts. Rather than forcing analysts to manually sift through thousands of low-priority notifications, AI can correlate events, eliminate duplicates, enrich alerts with contextual data, and prioritise incidents based on risk. This dramatically reduces noise inside the SOC. Improving response times Automation also improves response times. AI-powered orchestration systems can isolate compromised endpoints, disable suspicious accounts, block malicious IP addresses, or trigger containment workflows within seconds. Tasks that once consumed valuable analyst hours can now happen almost instantly. In many ways, AI functions like a hyper-vigilant digital air traffic controller, constantly monitoring thousands of moving signals simultaneously without becoming tired or distracted. Despite AI’s impressive capabilities, cybersecurity is not purely a technical challenge. It is also a human problem involving intent, deception, business context, and strategic judgement. These are areas where human analysts remain indispensable. Critical business operations One of the most important responsibilities humans retain is decision-making during high-risk incidents. AI can recommend actions based on patterns and probabilities, but human analysts must evaluate the wider consequences of those decisions. A false containment action, for example, could disrupt critical business operations or impact customers. Human analysts are also essential for contextual analysis. AI may identify suspicious activity, but it often lacks a nuanced understanding of organisational priorities, geopolitical considerations, regulatory obligations, or industry-specific risk factors. Sensitive financial data Imagine an AI system flagging unusual access to sensitive financial data at 2am. Is it a malicious insider? A compromised account? Or simply a finance executive travelling internationally during an acquisition process? Human analysts provide the contextual reasoning needed to answer these questions accurately. Threat hunting is another area where human creativity remains critical. Skilled analysts think like adversaries. They form hypotheses, investigate subtle behavioural indicators, and connect seemingly unrelated clues across environments. While AI can assist by surfacing anomalies, human intuition and experience often uncover the deeper narrative behind an attack. There is also the issue of adversarial manipulation. Attackers are already experimenting with ways to deceive AI models through poisoned data, evasive malware behaviour, and prompt manipulation techniques. Human oversight is essential to ensure AI systems are functioning correctly and are not being misled. Automate repetitive workflows Modern cybersecurity environments are simply too complex for either humans or AI to operate effectively in isolation. Businesses increasingly require a blended approach that combines machine efficiency with human expertise. AI dramatically improves scalability. It allows SOC teams to process vast volumes of data, accelerate detection, and automate repetitive workflows. This helps organisations manage growing attack surfaces without endlessly expanding headcount. However, AI alone cannot fully understand business priorities, ethical considerations, or nuanced attacker behaviour. Human analysts provide governance, oversight, and strategic direction that machines cannot replicate. High-volume operational tasks Here is a thought-provoking question many organisations are beginning to ask themselves: If an AI system autonomously detects and contains a cyber attack in under thirty seconds, but mistakenly shuts down a hospital’s critical systems in the process, who should ultimately be accountable for that decision? The SOC of the future will almost certainly be AI-native, but it will not be human-free. Instead, we are moving towards a model where analysts and AI systems operate as collaborative partners. AI will continue handling high-volume operational tasks such as alert triage, telemetry analysis, workflow automation, and real-time response orchestration. Human analysts, meanwhile, will focus on strategic oversight, advanced investigations, adversarial thinking, and business-aligned decision-making. Accelerating threat detection This evolution can elevate the role of SOC analysts rather than eliminate it. As repetitive work decreases, analysts can dedicate more time to proactive defence, threat intelligence, and security innovation. AI is transforming security operations at an extraordinary pace, but it is not replacing SOC analysts. Instead, it is redefining their role. AI excels at analysing massive datasets, automating repetitive tasks, and accelerating threat detection and response. Human analysts contribute critical thinking, contextual understanding, creativity, and strategic judgement that machines still cannot replicate. Organisations that embrace this AI-augmented model will be better positioned to reduce alert fatigue, improve detection accuracy, accelerate response times, and defend against increasingly advanced cyber threats.
Cybersecurity operations are evolving at the speed of a fibre-optic lightning storm. Security teams are dealing with cyberattacks, increasingly complex IT environments, and a flood of alerts that can bury analysts beneath digital noise. In response, many organisations are turning to AI-powered Security Operations Centre (SOC) to improve threat detection, automate response processes, and strengthen resilience. Yet one important question remains: can AI-powered SOC meet strict regulatory and compliance requirements? Implementing AI responsibly The answer is yes, but only when organisations implement AI responsibly, maintain human oversight, and align security operations with recognised frameworks such as the Saudi Central Bank cybersecurity requirements, the National Cybersecurity Authority Essential Cybersecurity Controls (ECC), and international standards like International Organization for Standardization ISO 27001, PCI DSS, GDPR, and NIST frameworks. In this article, users will learn how AI-powered SOC support compliance obligations, why businesses increasingly need both AI and human analysts, what challenges organisations face when using AI in regulated environments, and which best practices help maintain compliance without sacrificing operational efficiency. Identifying unusual behaviour Modern cyber threats are stealthy. Attackers use automation, AI-generated phishing campaigns, polymorphic malware, and advanced persistence techniques that can shift shape like digital smoke. Traditional SOC models that rely entirely on manual investigation are struggling to keep pace. AI-powered SOC help organisations process enormous volumes of telemetry data in real time. Machine learning models can identify unusual behaviour, correlate events across multiple systems, prioritise alerts, and automate repetitive tasks that previously consumed analyst hours. This dramatically reduces response times and improves visibility across hybrid and cloud environments. Harmless user behaviour However, AI alone is not enough. Human analysts remain essential because cybersecurity decisions often require contextual understanding, business judgement, and ethical oversight. An AI engine may identify anomalous behaviour, but a skilled analyst determines whether the activity represents malicious intent, operational change, or harmless user behaviour. Imagine a hospital network where an AI SOC suddenly detects massive data transfers outside normal working hours. Is it ransomware activity? A backup process? An emergency data migration during a crisis? The answer may require human interpretation, stakeholder coordination, and knowledge of operational context that no algorithm fully understands. This balance between automation and expertise is becoming central to compliance itself. Regulators increasingly expect organisations to demonstrate governance, accountability, and documented oversight of automated security systems. Automated security systems Compliance frameworks share a common objective: protecting sensitive data, maintaining operational resilience, and ensuring organisations can detect and respond to cyber incidents effectively. AI-powered SOCs can significantly strengthen these capabilities. Under NCA ECC requirements, organisations must establish continuous monitoring, incident management, logging, and threat detection processes. AI SOC platforms improve compliance by continuously analysing security events and identifying threats that may otherwise remain hidden within vast data streams. AI-enhanced operations Similarly, SAMA cybersecurity frameworks place strong emphasis on governance, risk management, incident reporting, and security monitoring within financial institutions. AI-driven SOCs can assist by generating faster threat intelligence, improving audit trails, and enabling real-time visibility into suspicious activity. Global standards also benefit from AI-enhanced operations. ISO 27001 requires organisations to maintain risk-based security controls and incident management processes. AI systems help automate evidence collection, improve monitoring consistency, and support faster remediation workflows. Critical security functions One particularly valuable capability is auditability. Modern AI SOC platforms can log alerts, decisions, escalations, and response actions automatically. This creates detailed records that help organisations demonstrate compliance during audits or investigations. Instead of piecing together fragmented evidence from multiple tools, compliance teams can access consolidated visibility into security events and response timelines. AI can also improve regulatory reporting. Many frameworks require timely breach notification and incident documentation. Automated workflows help organisations identify incidents more quickly, reduce investigation delays, and prepare reports with greater accuracy. Despite its advantages, AI introduces compliance challenges that organisations cannot ignore. Regulators are increasingly cautious about how AI systems process data, make decisions, and influence critical security functions. Violating privacy regulations One major concern is transparency. Some AI models operate as opaque “black boxes”, making it difficult to explain why a particular alert was generated or why a certain response action was taken. In regulated industries, this lack of explainability can create audit and governance concerns. Data privacy is another critical issue. AI systems often require large datasets for training and optimisation. If sensitive customer information is improperly collected, stored, or processed, organisations may inadvertently violate privacy regulations such as GDPR or local data protection laws. False positives and false negatives also remain a challenge. Excessive automated alerts can overwhelm analysts and reduce operational efficiency, while missed detections may expose organisations to serious regulatory consequences. AI-driven environments Here is a thought-provoking question every security leader should consider: if an AI-powered SOC autonomously suppresses a critical alert that later becomes a major breach, who carries the accountability: the technology provider, the SOC team, or the organisation itself? This question illustrates why governance frameworks remain indispensable in AI-driven environments. Organisations can strengthen compliance by treating AI as an enhancement to governance rather than a replacement for it. Human oversight must remain embedded within SOC processes, especially for high-risk decisions and incident escalation. Satisfy regulatory expectations Clear governance policies are essential. Organisations should document how AI systems operate, which decisions are automated, how alerts are prioritised, and when human intervention is required. These controls help satisfy regulatory expectations around accountability and risk management. Regular audits and testing also play a critical role. AI detection models should be reviewed continuously to ensure accuracy, fairness, and alignment with evolving threat landscapes. Compliance teams should validate that AI-generated actions remain consistent with regulatory obligations and internal policies. Data minimisation practices Data protection measures must remain central to AI deployments. Encryption, access controls, data minimisation practices, and secure logging processes help reduce compliance risks while protecting sensitive information. Organisations should also integrate threat intelligence and compliance management into a unified operational model. This enables security teams to map incidents directly against regulatory requirements, making reporting and audit preparation more efficient. Finally, employee training remains vital. Analysts, compliance officers, and executives all need a clear understanding of how AI systems function within the SOC environment. Technology alone cannot build resilience. Skilled people remain the architects behind secure operations. Faster detection capabilities AI-powered SOC is rapidly becoming an operational necessity rather than a futuristic experiment. As cyber threats continue to evolve, organisations need faster detection capabilities, scalable monitoring, and improved operational efficiency. At the same time, regulators are demanding stronger governance, greater transparency, and better protection of sensitive data. The future of compliance will likely depend on intelligent collaboration between humans and AI. Automation can process data at machine speed, while experienced analysts provide strategic judgement, ethical oversight, and contextual understanding. Together, they create a security model capable of supporting both operational resilience and regulatory compliance. For organisations operating under NCA, SAMA, and international cybersecurity standards, the goal is not simply adopting AI. The goal is implementing AI responsibly, transparently, and within a strong governance framework.
Security Operations Centres (SOC) are evolving at a remarkable pace. What once relied heavily on manual investigation and rule-based monitoring is now increasingly powered by artificial intelligence, machine learning, and automation. As cyber threats grow faster, more evasive, and more sophisticated, organisations are under pressure to modernise their SOC capabilities without sacrificing visibility, compliance, or operational control. For Chief Information Security Officers, choosing the right AI-powered SOC solution has become both a strategic opportunity and a complex challenge. The market is crowded with vendors promising autonomous detection, predictive analytics, and rapid response capabilities. Yet not all AI SOC platforms are created equal. Some offer genuine operational value, while others create additional noise, hidden costs, or compliance concerns. Massive volumes of telemetry This article explores how CISOs can evaluate AI SOC solutions effectively. Readers will learn which criteria matter most when assessing vendors, why human analysts remain essential in modern security operations, and how to follow a practical step-by-step decision-making process that aligns with business objectives, risk tolerance, and compliance requirements. Despite rapid advances in automation, AI is not replacing SOC analysts. Instead, organisations are increasingly discovering that the strongest security operations combine machine efficiency with human expertise. AI excels at processing massive volumes of telemetry, identifying anomalies, correlating alerts, and accelerating repetitive tasks. It can scan millions of events in seconds, detect suspicious behaviour patterns, and prioritise incidents based on risk. This dramatically reduces alert fatigue and enables faster response times. Unusual login behaviour However, attackers constantly adapt their tactics, exploit business context, and manipulate human behaviour. Human analysts bring intuition, contextual understanding, strategic thinking, and investigative judgement that AI alone cannot replicate. For example, AI may detect unusual login behaviour, but an experienced analyst can determine whether the activity is malicious, linked to legitimate business travel, or part of a larger attack campaign. Similarly, analysts play a critical role in threat hunting, incident containment decisions, executive communication, and regulatory reporting. Increasingly sophisticated attackers The future SOC is therefore not “AI versus humans”. It is AI augmenting human capabilities. Organisations that strike this balance are better positioned to improve detection accuracy, reduce operational pressure, and strengthen resilience against evolving threats. Choosing an AI SOC platform today is far more complex than purchasing a traditional SIEM solution. Modern environments include hybrid infrastructure, cloud-native applications, remote workforces, third-party integrations, IoT devices, and increasingly sophisticated attackers using AI themselves. A poorly selected SOC platform can create operational bottlenecks, integration failures, excessive licensing costs, and compliance headaches. On the other hand, the right solution can significantly improve visibility, streamline investigations, and reduce cyber risk. Digital transformation initiatives A question every CISO should consider: If the AI SOC automatically contained a critical system based on flawed analysis during peak business hours, would your organisation trust the technology enough to recover quickly, or would confidence collapse alongside operations? This question highlights an important reality. Trust, transparency, and governance matter just as much as automation speed. A SOC solution must scale alongside the organisation’s growth. Many businesses underestimate how quickly data volumes increase as cloud adoption, endpoint expansion, and digital transformation initiatives accelerate. Real-world enterprise workloads CISOs should evaluate whether the platform can handle growing log ingestion, support distributed environments, and maintain performance during peak activity periods. Scalability should not simply refer to storage capacity. It must also include detection speed, query efficiency, and incident response performance under operational stress. An AI SOC platform that performs well in a controlled demonstration may struggle when exposed to real-world enterprise workloads. No SOC operates in isolation. Effective AI SOC platforms must integrate seamlessly with existing infrastructure, including SIEMs, EDR tools, firewalls, identity platforms, cloud services, ticketing systems, and threat intelligence feeds. Costly custom development Strong integration capabilities reduce operational silos and enable better visibility across the environment. CISOs should assess whether integrations are native, API-driven, or dependent on costly custom development. Vendor claims around interoperability should also be tested carefully during proof-of-concept stages. Integration challenges remain one of the most common causes of delayed SOC modernisation projects. Not every platform marketed as “AI-powered” delivers meaningful intelligence. Some vendors simply apply basic automation or statistical analysis while branding it as advanced AI. CISOs should investigate how the AI models function, how frequently they are trained, what datasets support detection logic, and how false positives are managed. Mature AI SOC platforms should demonstrate measurable improvements in threat detection, incident prioritisation, and response efficiency. Detection explainability is also crucial. Security teams need visibility into why the AI reached a particular conclusion rather than receiving opaque recommendations without context. Mature AI SOC platforms Trust in AI security systems depends heavily on transparency. Black-box AI creates significant operational and regulatory risks because analysts may not fully understand how alerts are generated or why automated actions are triggered. Transparent systems provide detailed reasoning, correlation logic, confidence scoring, and audit trails. This is especially important during investigations, executive reporting, and regulatory reviews. CISOs should ask vendors difficult questions about explainability. If a vendor cannot clearly explain how its AI operates, security teams may struggle to trust or defend its decisions during critical incidents. Mature operational processes Technology alone does not guarantee success. Strong vendor support can significantly influence the effectiveness of an AI SOC deployment. Organisations should assess the vendor’s implementation expertise, incident response support, training capabilities, and ongoing advisory services. Responsive support becomes particularly important during active security incidents or platform outages. A vendor with strong security expertise and mature operational processes often delivers more long-term value than a vendor focused purely on technical features. Compliance remains a major concern for CISOs operating across regulated industries. AI SOC platforms must support data protection, logging requirements, auditability, incident reporting, and governance obligations. Local regulatory expectations Security leaders should evaluate whether the solution aligns with frameworks such as ISO 27001, GDPR, PCI DSS, NIST, SAMA, and NCA requirements where applicable. Data residency considerations are equally important, especially for organisations operating across multiple jurisdictions. AI systems processing sensitive telemetry must align with local regulatory expectations and internal governance policies. Initial licensing costs rarely reflect the true cost of a SOC platform. CISOs must assess the full operational picture, including infrastructure requirements, integration expenses, staffing needs, ongoing tuning, training, maintenance, and scalability costs. Some platforms appear affordable initially but become expensive due to hidden ingestion fees, professional services requirements, or escalating storage costs. A realistic total cost of ownership assessment helps organisations avoid budget surprises while ensuring long-term sustainability. Decision-making framework Choosing an AI SOC solution requires structured evaluation rather than reacting to vendor marketing claims. A practical decision-making framework can help organisations reduce risk and improve alignment with strategic goals. The first step is defining operational objectives clearly. CISOs should identify the organisation’s most pressing challenges, whether that involves alert fatigue, cloud visibility gaps, compliance pressure, talent shortages, or slow incident response times. The second step involves assessing the current security environment. Organisations must understand existing tools, workflows, data sources, staffing models, and operational maturity before introducing AI-driven capabilities. Faster compliance reporting The third step is developing measurable evaluation criteria. Instead of focusing on feature lists alone, CISOs should define success metrics such as reduced mean time to detect, lower false positive rates, improved analyst productivity, or faster compliance reporting. The fourth step involves conducting realistic proof-of-concept testing. Vendors should demonstrate capabilities using real organisational data and operational scenarios rather than curated demonstrations. This phase should include testing integrations, detection accuracy, workflow usability, and reporting transparency. The fifth step is evaluating governance and risk considerations. CISOs should examine data handling practices, explainability features, automated response controls, and compliance alignment carefully before deployment. Sustainable security improvements The final step is planning long-term operational adoption. Successful AI SOC implementations require ongoing tuning, analyst training, governance oversight, and collaboration between security, IT, compliance, and executive stakeholders. AI is rapidly reshaping cybersecurity operations, but successful adoption depends on thoughtful implementation rather than blind automation. Organisations that treat AI as a force multiplier for human expertise are far more likely to achieve sustainable security improvements. Making informed decisions The right AI SOC solution should enhance visibility, accelerate detection, reduce operational strain, and strengthen resilience without sacrificing transparency or governance. CISOs who evaluate scalability, integration, AI maturity, compliance alignment, and operational sustainability carefully will be better positioned to make informed decisions. As attackers continue evolving their tactics, modern SOC must evolve as well. The challenge is not simply choosing the most advanced AI platform. It is selecting a solution that aligns with organisational realities, empowers analysts, and supports long-term cyber resilience.
Cybersecurity operations are undergoing a remarkable transformation. For years, Security Operations Centres (SOC) have relied on skilled analysts, rule-based detection systems, and increasingly sophisticated automation to protect organisations from cyber threats. Today, the next evolution is already taking shape: the Autonomous SOC. In this article, users will learn what an Autonomous SOC is, how it differs from traditional and AI-assisted SOC models, why organisations are increasingly turning to AI-powered security operations, and what to look for when selecting a partner to help implement autonomous security capabilities. We will also explore how the best security partners help organisations move beyond conventional security operations towards a future of self-driving cyber defence. Increasingly complex IT environments Modern organisations face an unprecedented volume of cyber threats. Attackers are leveraging artificial intelligence to automate reconnaissance, create convincing phishing campaigns, evade detection, and accelerate attacks. At the same time, security teams are struggling with alert fatigue, skills shortages, and increasingly complex IT environments. A typical SOC may process thousands of alerts every day. Many of these alerts are false positives, while others require manual investigation and triage. Security analysts often spend significant time on repetitive tasks instead of focusing on strategic threat hunting and incident response. The challenge is clear. As attack volumes continue to rise, organisations cannot simply hire more analysts to keep pace. They need security operations that can scale intelligently, respond rapidly, and continuously adapt to evolving threats. This need has fuelled the rise of AI SOC and is now driving the emergence of Autonomous SOC. Identifying suspicious behaviours Traditional SOC rely heavily on human analysts. Security tools generate alerts, analysts investigate them, and response actions are manually executed. While effective in many scenarios, this model can struggle to keep up with today's threat landscape. The next step in the evolution was the AI-assisted SOC. In these environments, artificial intelligence helps analysts by prioritising alerts, correlating events, identifying suspicious behaviours, and providing recommendations for response actions. AI improves efficiency, but humans remain responsible for most decision-making and execution. Security operations tasks Autonomous SOC take this concept significantly further. An Autonomous SOC combines advanced artificial intelligence, machine learning, security orchestration, threat intelligence, and automated response capabilities to independently perform many security operations tasks with minimal human intervention. Rather than simply recommending actions, the system can investigate alerts, validate threats, execute predefined response measures, and continuously learn from outcomes. Think of it as the difference between a vehicle equipped with driver assistance features and a self-driving car. One helps the driver make better decisions. The other can navigate much of the journey independently while maintaining human oversight where needed. Appropriate containment measures The defining characteristic of an Autonomous SOC is its ability to act, not simply analyse. When suspicious activity is detected, an autonomous platform can automatically gather evidence from multiple systems, correlate data across the environment, determine the likelihood of a genuine threat, and initiate appropriate containment measures. For example, if a compromised user account begins exhibiting unusual behaviour, the Autonomous SOC may automatically isolate affected systems, disable credentials, collect forensic evidence, and notify stakeholders before significant damage occurs. This level of automation dramatically reduces Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), two critical metrics that directly influence the impact of cyber incidents. High-impact actions Yet autonomy does not eliminate the need for human expertise. Security professionals continue to provide governance, oversight, strategic decision-making, and validation of high-impact actions. The goal is augmentation at scale rather than complete replacement. Imagine a ransomware attack begins at 2:00 a.m. on a holiday weekend. Would you rather wait for an analyst to notice the alert, investigate the activity, and initiate a response, or have an intelligent security platform identify the threat, contain affected systems, preserve evidence, and notify stakeholders within minutes? Autonomous security operations For many organisations, the answer highlights why autonomous security operations are becoming increasingly attractive. Autonomous SOC provide several advantages over traditional security models. First, they dramatically improve response speed. Automated investigations and response actions can occur within seconds rather than hours. Second, they help reduce analyst burnout. By automating repetitive tasks, security teams can focus on higher-value activities such as threat hunting, strategic planning, and security improvement initiatives. Third, they enhance consistency. Human analysts may vary in experience and decision-making, while autonomous systems execute approved workflows consistently and reliably. Complex hybrid environments Fourth, they improve scalability. Organisations can handle growing volumes of security events without proportionally increasing staffing costs. Finally, autonomous security operations provide stronger visibility across complex hybrid environments, including cloud platforms, on-premises infrastructure, endpoints, applications, and third-party systems. Implementing an Autonomous SOC requires more than purchasing advanced technology. Success depends on choosing a partner with the right combination of expertise, processes, and operational maturity. Organisations should begin by evaluating a provider's experience in managed detection and response, threat intelligence, incident response, and security operations. Autonomous capabilities are only as effective as the security knowledge embedded within them. Another major consideration It is also important to assess the provider's approach to transparency and governance. Autonomous systems must support auditability, regulatory compliance, and human oversight. Organisations need confidence that automated decisions can be understood, reviewed, and validated. Integration capabilities should be another major consideration. The best Autonomous SOC platforms seamlessly integrate with existing security tools, cloud environments, identity systems, and business applications. Threat intelligence is equally critical. Effective autonomous operations rely on high-quality intelligence to identify emerging threats and adapt to evolving attacker techniques. Finally, organisations should evaluate the provider's commitment to continuous improvement. Autonomous security is not a one-time deployment. It requires ongoing tuning, model refinement, workflow optimisation, and adaptation to changing risks. Next-generation security automation As cyber threats continue to evolve, Rewterz is helping organisations move beyond traditional and AI-assisted security operations towards fully autonomous cyber defence. By combining advanced AI technologies, threat intelligence, security orchestration, automation, and expert human oversight, Rewterz delivers security operations that are faster, smarter, and more resilient. The organisation's approach enables businesses to reduce operational burdens while strengthening their ability to detect, investigate, and respond to sophisticated threats. Rewterz recognises that autonomy and governance must work together. Its solutions are designed to support regulatory requirements, operational transparency, and human accountability while enabling organisations to take advantage of next-generation security automation.
Pressure is increasing on modern Security Operations Centre (SOC). Cyber threats are growing in volume, sophistication, and speed, while security teams face increasing workloads, talent shortages, and alert fatigue. Many SOC analysts spend a significant portion of their day investigating alerts that ultimately turn out to be false positives, leaving less time to focus on genuine threats. Artificial intelligence (AI) is helping organisations address this challenge by transforming one of the most critical SOC functions: incident triage. Rather than forcing analysts to manually review thousands of alerts, AI can automatically prioritise, enrich, and investigate security events, allowing teams to respond faster and more effectively. AI-driven security operations In this article, users will learn what incident triage is, why it is a fundamental part of cybersecurity operations, how AI automates the triage process, and the key benefits organisations gain from AI-driven security operations. Incident triage is the process of reviewing, assessing, and prioritising security alerts and incidents to determine which events require immediate attention and which pose little or no risk. Every day, security tools such as firewalls, endpoint detection platforms, SIEM systems, identity management solutions, and cloud security tools generate enormous numbers of alerts. Not all alerts represent genuine threats. Some are duplicates, some are misconfigurations, and many are false positives. Delayed response times The purpose of incident triage is to separate meaningful threats from background noise. Analysts must determine whether an alert is legitimate, assess its severity, identify affected assets, and decide what actions should follow. Without effective triage, organisations risk overlooking critical attacks while wasting valuable resources on low-priority events. Incident triage acts as the gateway to the entire incident response process. Every investigation begins with a decision about whether an alert deserves attention. If a malicious event is incorrectly classified as harmless, attackers may remain undetected within the environment for extended periods. Conversely, if analysts spend excessive time investigating low-risk alerts, critical threats may be missed due to delayed response times. Resilience against cyberattacks Consider this hypothetical question: What if the SOC received 20,000 alerts today, but only 20 represented genuine threats capable of causing significant business disruption? Would the analysts find the right 20 before attackers achieved their objectives? This challenge highlights why effective triage is so important. The ability to rapidly identify genuine threats directly influences an organisation's security posture, operational efficiency, and resilience against cyberattacks. Multiple security tools Traditional triage processes rely heavily on human analysts. Security personnel review alerts, gather context, examine logs, correlate events, and determine whether an investigation should proceed. While this approach can be effective, it becomes increasingly difficult as organisations grow. Modern enterprises may generate thousands or even millions of security events every day. Analysts often spend hours collecting information from multiple security tools before they can make an informed decision. This creates several challenges. Alert fatigue becomes common, response times increase, false positives consume resources, and skilled analysts become overwhelmed by repetitive work. These pressures contribute to burnout and make it difficult for SOC teams to maintain consistent performance. Threat intelligence indicators AI introduces intelligence and automation into the triage process, enabling SOC to analyse and prioritise alerts at machine speed. Instead of treating every alert equally, AI systems evaluate events based on risk, context, historical patterns, and threat intelligence. This allows the SOC to focus attention where it matters most. One of the most valuable capabilities of AI is its ability to prioritise alerts automatically. Machine learning models analyse factors such as asset criticality, user behaviour, attack patterns, vulnerability data, and threat intelligence indicators. The system then assigns risk scores to alerts based on their likelihood of representing a genuine threat. Rather than reviewing thousands of alerts manually, analysts can immediately focus on the incidents with the highest probability of causing harm. This significantly reduces investigation workloads while improving detection efficiency. Automated alert enrichment A raw alert often lacks the context needed for rapid decision-making. Traditionally, analysts gather additional information by consulting multiple systems, including endpoint platforms, asset inventories, identity management tools, vulnerability scanners, and threat intelligence feeds. AI can automate this enrichment process. When an alert is generated, AI systems automatically collect and correlate relevant information. They can identify the affected asset, determine whether it contains sensitive data, check for known vulnerabilities, analyse user activity, and compare indicators against threat intelligence databases. Multiple security tools AI also helps SOC teams investigate alerts more effectively. Modern AI-driven SOC platforms can correlate events across multiple security tools and data sources. Rather than viewing alerts in isolation, the system identifies relationships between activities occurring throughout the environment. For example, AI may connect a suspicious login attempt, privilege escalation activity, unusual endpoint behaviour, and data transfer events into a single attack narrative. This broader perspective helps analysts understand the full scope of an incident without manually piecing together evidence from numerous systems. Unlike static rule-based systems, AI can learn from historical investigations and analyst feedback. Most significant benefits As analysts validate incidents and classify alerts, machine learning models refine their understanding of normal behaviour and malicious activity. Over time, this improves accuracy and reduces false positives. The result is a continuously evolving security operation that becomes more efficient as it gains experience. The impact of AI-powered triage extends far beyond simple automation. One of the most significant benefits is faster response times. By prioritising high-risk alerts and providing immediate context, AI enables security teams to begin investigations sooner and contain threats more quickly. Organisations also benefit from reduced analyst workloads. Routine investigative tasks that once required substantial manual effort can now be completed automatically, allowing analysts to focus on higher-value activities such as threat hunting, strategic analysis, and incident response. Identifying genuine threats Improved detection accuracy is another major advantage. AI helps reduce false positives while increasing the likelihood of identifying genuine threats that might otherwise be overlooked. Operational scalability also improves considerably. As organisations grow and generate more security data, AI can process increasing volumes of alerts without requiring proportional increases in staffing. Perhaps most importantly, AI helps combat analyst fatigue. By eliminating repetitive tasks and reducing alert overload, organisations can improve employee satisfaction and retain valuable cybersecurity talent. Strategic decision-making As cyber threats continue to evolve, incident triage will become increasingly dependent on AI-driven automation. Future SOC will move beyond basic alert prioritisation towards autonomous security operations, where AI systems perform much of the investigative work independently before escalating only the most significant incidents to human analysts. Human expertise will remain essential for strategic decision-making, complex investigations, and oversight. However, AI will increasingly serve as the force multiplier that allows security teams to operate more efficiently and effectively. The organisations that embrace AI-driven triage today will be better positioned to manage growing alert volumes, respond to threats faster, and strengthen their overall cybersecurity posture.


Expert commentary
Across many sectors, AI is transitioning from an experimental process to a trusted tool, but how will construction - and architectural ironmongery specifically - balance this technological opportunity with traditional practice? Artificial intelligence was once considered the trend of tomorrow, but it’s now here, and already it’s impacting the design, specification and management of the built environment. Following a period of refined development, the technology is emerging as a valuable tool for architectural professionals, with its growing role signifying far more than a passing industry trend. Passing industry trend According to the Royal Institute of British Architects’ (RIBA) Artificial Intelligence Report 2025, 59% of architectural practices now use AI on at least some projects, an increase from 41% in 2024. Furthermore, a global survey led by the Royal Institution of Chartered Surveyors in 2025 found that 56% of investors planned to increase AI investment, suggesting that the rate of adoption will continue to accelerate over the coming years. However, whilst innovation typically creates opportunity, there are challenges to address These findings represent a cultural shift, one where AI is firmly embedding itself into workflows and influencing the decision making process. However, whilst innovation typically creates opportunity, there are challenges to address. As more professionals equip themselves with an arsenal of AI-driven tools, are we in danger of becoming overly reliant on technology? Or are those reluctant to adapt likely to be left behind? Daniel May, Director at Consort Architectural Hardware, shares insight: Repetitive administration tasks “The development of the built environment has always relied on technical precision. Specifications naturally contain large volumes of product information and technical data, with professionals managing document-heavy tasks in the form of specification writing, door scheduling and BIM coordination in order to meet project requirements and compliance obligations. All of this data must be analysed and processed accurately - often in line with demanding timescales - and it is here where AI can offer the greatest value.” “Where time was once consumed by repetitive administration tasks and information processing, professionals are now embracing AI as a means of working more efficiently. For architectural ironmongery specifically, where specification accuracy is critical, AI has the potential to support architects and specification professionals as they navigate the product selection process. As a tool, AI can streamline documentation by rapidly processing performance data and certification requirements, whilst also identifying inconsistencies and absent compliance information within schedules.” Complex project requirements “AI systems are helping professionals navigate increasingly complex project requirements quickly, accurately and consistently. As machine learning and autonomous models continue to advance, these tools may further reduce the administrative burden associated with architectural work models whilst improving accuracy and minimising the risk of human error in the process. With that said, the effectiveness of AI software is very much reliant on the quality of the information it receives.” “With the sector so deeply tied to fire safety, accessibility, security and regulatory standards, the caution around adopting AI as common practice is of course justified. Historically, much of the construction industry has been measured in its adoption of new technology, partly due to the critical nature of compliance and the significant consequences of error. Though, AI feels somewhat different because of its pace and potential, and as such, organisations must be measured in their approach to it, ensuring that professional knowledge remains central to delivering safe, efficient and compliant building projects.” The human element As industry standards and the legislation surrounding the built environment continues to evolve, so too will the methods used to achieve high level design and compliance. Seemingly, AI looks set to have an increasingly prominent role, but it should be viewed as a collaborative partner capable of enhancing professional expertise as opposed to a system that can, or should, do it all. Daniel continues: “At this stage, AI alone simply can’t understand the nuances of individual projects and that has implications for both design and compliance. This is particularly relevant in the post-Grenfell regulatory landscape, where accountability, traceability and evidence-based decision-making have become fundamental to product specification and delivery.” Building greater trust “Although AI can assist with information processing, the technology is not ultimately responsible for the decisions being made. Accountability has rightly become a major focus point in construction, and as AI continues to disrupt practices, the industry must ensure that responsibility remains clearly defined. AI-driven errors could lead to serious penalties in relation to compliance, safety and project delivery, proving human expertise remains critical.” “Moving forward, greater transparency within AI systems will be key. If professionals are able to understand how or why AI recommendations have been generated, they can assess them with confidence, building greater trust in the technology.” Architectural design solutions “When it comes to architectural design, the emotional intelligence, contextual understanding and creative balance offered by a team of professionals far outweighs the speed that AI can offer. Already, AI is being used to support visualisation and concept development for multi-layered projects in hospitality, healthcare and commercial environments to name a few, helping teams to explore ideas and communicate concepts at a quicker rate.” “However, can AI effectively develop architectural design solutions based on the bespoke requirements of a project, the operational needs of its users or even the general character of the building? Most would argue that it’s not conceivable, because AI lacks the lived experience and contextual understanding that comes from being present in the project itself.” Architectural ironmongery products “For architectural ironmongery products, professionals must regularly assess how products will function in real environments. Human intuition is impossible to replace and those informed design decisions, made by human professionals, will always be essential. Whilst some question whether AI could one day plan and deliver a project from concept to completion, perhaps the more important question should be whether future generations of professionals could lose the critical design and specification skills that are needed, should the industry become too dependent on AI.” “There is a growing sense of inevitability surrounding AI’s influence on architectural ironmongery and the wider built environment. As the industry continues to embrace this new wave of technological development, it is important to remember that innovation must complement the knowledge, judgement and accountability of the professionals who create safe and functional buildings, not replace it.”
In the ever-evolving struggle between cyber offence and defence, attackers have almost always moved first. In the emerging domain of artificial intelligence, this pattern appears to be repeating itself. Yet, global cybersecurity pioneers appear disconcertingly disengaged. Just over half even agree that AI-driven attacks are set to become dramatically more complex and widespread. Equally concerning is the widespread apathy regarding AI’s role in expanding an already sprawling corporate attack surface. This is no small oversight. A recent global Trend Micro study showed that 73 percent of organisations have already suffered cybersecurity incidents due to unknown or unmanaged assets. In an era where digital blind spots are both common and consequential, hesitation is a risk few can afford. Security has to shift from reactive protection to proactive risk exposure management. The opportunity and the risk of AI Threat actors are now using jailbroken versions of legitimate generative AI tools such as ChatGPT The potential for AI to transform enterprise operations is enormous, but so is the risk. The warnings have been loud and clear. As early as the first quarter of 2024, the UK’s National Cyber Security Centre (NCSC) stated that AI would “almost certainly increase the volume and heighten the impact of cyber-attacks over the next two years.” Their prediction is proving accurate. Threat actors are now using jailbroken versions of legitimate generative AI tools such as ChatGPT, freely traded as services on the dark web, as well as malicious models like FraudGPT, built on open-source large language models (LLMs). These tools are no longer just about automating tasks; they are turbocharging the entire attack lifecycle. From more convincing phishing emails and precise target selection, to sophisticated malware creation and lateral movement within breached systems, AI is driving a step-change in threat actor capability. Integrating open-source models However, this is only one side of the coin. The other, often overlooked, is AI’s impact on the corporate attack surface. Even well-meaning employees can unintentionally expand organisational risk. The widespread use of AI-as-a-service tools like ChatGPT introduces significant shadow IT concerns, especially when sensitive business information is input without proper oversight. Data processing and storage practices for many of these services remain opaque, raising additional compliance concerns under regulations like the UK GDPR and the EU’s AI Act. For those organisations that choose to build or customise their own LLMs, the risks multiply. Integrating open-source models may expose businesses to vulnerabilities, misconfigurations and flawed dependencies. Each new tool and environment adds to the complexity of an attack surface already strained by remote work setups, sprawling cloud deployments, IoT ecosystems, and accelerating digital transformation programmes. Managing the expanding risk landscape Many have already shared security incidents where a lack of asset visibility was the root cause Many security pioneers do understand what is at stake. Nine in ten agree that effective attack surface management is tied directly to business risk. They cite a long list of potential consequences, disruptions to operations, reputational damage, declining competitiveness, strained supplier relationships, financial losses and reduced staff productivity. Many have already experienced security incidents where a lack of asset visibility was the root cause. Despite this recognition, however, the response remains largely inadequate. Fewer than half of global organisations use dedicated tools to monitor their attack surface proactively. On average, only a quarter of cybersecurity budgets are allocated to managing cyber risk exposure. Third-party risk management is similarly neglected: fewer than half of firms actively monitor their vendors for vulnerabilities. This inertia creates an obvious contradiction. Security pioneers understand the business implications of unmanaged risk, but they are not equipping themselves with the tools or processes to respond. That needs to change—and fast. How AI can help defenders take the lead There is good news: AI is not only a weapon for cybercriminals. It can also be a powerful ally for defenders, particularly in the field of Cyber Risk Exposure Management (CREM). The best tools in this category use AI to continuously scan an organisation’s entire digital footprint. They can automatically detect vulnerabilities, spot misconfigurations, identify rogue or shadow assets, and provide prioritised remediation recommendations. CREM platforms apply contextual filtering to reduce false positives and elevate the most urgent threats Intelligent algorithms can also analyse network behaviour to identify anomalies that could signal a breach in progress. Unlike traditional tools, which often drown analysts in noise, CREM platforms apply contextual filtering to reduce false positives and elevate the most urgent threats. For overburdened security teams, this enables a far more focused and effective response. However, the keyword here is “continuous.” The nature of today’s IT environments, especially in the cloud, is dynamic and fast-moving. Assets appear and disappear within minutes. Static, point-in-time assessments are no longer sufficient. Yet more than half of organisations still lack continuous scanning processes. This leaves them exposed to risks that might persist undetected for weeks or months. Overcoming barriers to adoption So what is holding organisations back? In many cases, it’s not the technology itself but the internal politics of investment. Security pioneers interested in CREM tools often prioritise real-time alerting, clear dashboards, and seamless integration with their existing environments. All of this is now achievable. The challenge lies in securing board-level support. Many security teams still work in silos, disconnected from the broader business Boards are often cautious when it comes to cybersecurity investment, particularly when immediate ROI is not clear. To gain their trust, security pioneers must learn to speak the language of business risk, not technical threat. They must frame cyber exposure in terms of reputational impact, regulatory liability, operational continuity, and investor confidence. There is also a cultural component. Many security teams still work in silos, disconnected from the broader business. This limits their influence and makes it harder to embed security as a strategic enabler. In the AI era, this divide must be bridged. Cybersecurity must become a board-level concern, and risk exposure must be treated as a fundamental operational issue. Time to act We are at a critical inflection point. The AI revolution is not on the horizon, it is already here. Threat actors are moving rapidly to exploit it, leveraging tools and techniques that were unthinkable just a few years ago. Meanwhile, organisations remain slow to respond. Too few are investing in the tools, processes, and people needed to manage their risk exposure effectively. AI can be used not only to attack but to defend. CREM tools powered by AI offer a powerful way to regain visibility, restore control, and build lasting resilience. They enable proactive rather than reactive security. And they help organisations align their cybersecurity strategy with their broader business objectives. Security teams have to elevate the conversation. They must advocate not just for new tools, but for a new mindset, one that treats cyber risk as an enterprise risk, and one that prioritises continuous visibility as a prerequisite for resilience.
Artificial Intelligence isn’t just a buzzword anymore. It has become part of our lives, and its uses and applications are growing every other day. Even the public sector, which usually is a late adopter of new technologies, has come onboard this new train. Law enforcement, in particular, has seen the advantages different AI technologies can offer to their work and has started to integrate them into their workflow and daily routines. But there is much more to come. Task automation: AI as a workhorse Due to the increasing importance of media files in police investigations, current police cases have an increasing amount of digital files to be analysed. Videos from mobile phones, computer files, sound recordings, voice messages from chat applications…the list is almost endless. But, in contrast to other types of digital files, like documents or PDFs, it is not possible to search directly a certain information in a video. It has to be watched by someone. And that takes an inordinate amount of time for a human being, as there can be hundreds of videos in a case. This is one of the areas where artificial intelligence shines. Modern analytics systems are able to find almost any kind of information in media files due to the improvement of artificial vision, object recognition and face biometrics. It is simply a matter of feeding the hundreds or thousands of media files to a AI analyser, which will work through them and find specific sounds, words, faces, cars, etc. Case of law enforcement On top of that, an analyser does not tire after long work hours and does not make errors What is more, unlike human officers, these systems can work 24/7 which speeds up investigations considerably, as more evidence is found in less time. On top of that, an analyser does not tire after long work hours and does not make errors. This is why police work can be helped greatly by AI Analytics, as it frees police officers to do high value work, instead of endlessly watching videos on a computer of listening to audio recordings, in search of evidence. As soon as the system finds what the officer has specified (a face, name, number plate, object, etc.) it sends an alarm to the officers’ phone, so he or she can take a look and decide what to do with that information. Despite AI being touted as a danger to many workplaces, in the case of law enforcement, it is a valuable tool to help police do more, with more accuracy, and in less time, freeing officers from the repetitive and boring work of checking mountains of evidence in search of clues. The AI Analyser landscape The field of AI analytics is expanding constantly and new types of analysis are being discovered that may be helpful to police or intelligence. The most used analysers today are probably Automatic Licence Plate Recognition (ALPR), object and face recognition. But OCR is equally useful not just for reading documents, but also signs and logos that may appear in pictures or videos, to help identify a location. And for audio (as in interception or surveillance recordings) there is speech-to-text (S2T), translation, Speaker ID, audio fingerprinting (AFP) and natural language processing (NLP) which is able to extract sentiment from what is said. All of these have their application in daily police work and can save time in investigations or make them possible in the first place. But looming on the horizon are new possibilities, which we will discuss later and that are even more powerful. So the field of AI Analytics is, by no means, a closed one. Generative AI in law enforcement LLMs will be an important part in all those tasks related to investigate large sets of documents For the past year, the term “Generative AI” has become part of our general vocabulary, although most of the time we just say ChatGTP, Copilot o similar. The large language models (LLM) use Deep Learning and different AI strategies to, amongst other things, analyse and summarise vast amounts of information, in order to generate a short report with the highlights. This can be of use for Law Enforcement in all those cases that have great amounts of documents that may contain evidence. Again, this is a case like the above, where AI helps speed up operations by doing the grunt work much quicker than any person could. The difference is in the Deep Learning part. The model can be tuned to specific needs (like financial crimes, for example) and will get better over time when dealing with specific sets of documents. Thus, LLMs will be an important part in all those tasks related to investigate large sets of documents during a case. What the future holds As with all technology, it is virtually impossible to predict what the future will hold. Because any breakthrough can upend complete sectors, as demonstrated by ChatGPT not that long ago. However, there are several promising AI technologies in the pipeline, some of which are already being tested and perfect around the world: Behaviour analysis: as facial recognition systems get better and better, they are not only able to recognise faces, but also facial expressions. This means that AI systems could be assisting during interrogations, to evaluate the truthfulness of what is being said. Combined with the analysis of small voice inflections, they can be a non-invasive “lie detector”. Robotics: already in use by many police forces around the world, robots are going to be ever so important. Particularly the autonomous kind, which is able to do missions on its own, without a human behind the controls. This, combined with swarm technology, could be an incredible help in disaster areas, where time is of the essence in locating victims. Predictive policing: thanks to pattern analysis, predictive policing, which has been to the test several times already, will be an important part of police work, to figure out where to send units or concentrate surveillance efforts. In short, AI has much more to offer, and we are going to see and incredible evolution of this technology applied to law enforcement, over the next years.
Security beat
Anyone who has been in a proverbial cave for the last couple of years faced a language barrier at this year’s ISC West 2025 trade show. The industry’s latest wave of innovation has brought with it a new bounty of jargon and buzzwords, some of which I heard at ISC West for the first time. As a public service, we are happy to provide the following partial glossary to promote better understanding of the newer terms. (Some are new to the security industry but have been around in the IT world for years.) Obviously, if we can’t understand the meaning of the industry’s lexicon (and agree on the meaning of terms!), we will struggle to embrace the full benefits of the latest industry innovation. Not to mention, we will struggle to communicate. Generative AI Generative AI can identify an object in an image based on its understanding of previous objects This was perhaps the most common new(ish) term I heard bouncing around at ISC West. While the term artificial intelligence (AI) now rolls off everyone’s tongue, the generative “version” of the term is catching up. Generative AI uses what it has learned to create something new. The name comes from the core function of this type of artificial intelligence: it can generate (or create) new content. It doesn’t just copy and paste; it understands the underlying patterns and creates something original based on that understanding. In the case of video, for example, generative AI can identify an object in an image based on its understanding of previous objects it has seen. Video and security Generative AI can tell you something digitally about what is happening in an environment. There is no longer a need to write “rules;” the system can take in data, contextualise it, and understand it, even if it does not exactly match something it has seen before. In the case of video and security, generative AI offers more flexibility and better understanding. From 2014 to 2024, the emphasis was on detecting and classifying things; today AI is expanding to allow new ways to handle data, not so prescriptive and no more rules engines. Agentic AI Agentic AI refers to artificial intelligence systems that can operate autonomously to achieve specific goals Agentic AI refers to artificial intelligence systems that can operate autonomously to achieve specific goals, with minimal to no direct human intervention. In addition to the capabilities of generative AI, agentic AI can take action based on what it detects and understands. Use of agentic AI typically revolves around an if/then scenario. That is, if action A occurs, then the system should proceed with action B. For example, if an AI system “sees” a fire, then it will shut down that part of the building automatically without a human having to initiate the shutdown. There is a lot of discussion in the industry about the need to keep humans involved in the decision-making loop, so the use of truly autonomous systems will likely be limited in the foreseeable future. However, the ability of agentic AI to act on critical information in a timely manner, in effect to serve as an “agent” in place of a human decision-maker, will find its place in physical security as we move forward. Inference Inference is another common term related to AI. It refers to the process by which an AI model uses the knowledge it gained during its training phase to make predictions, classifications, or generate outputs on new, unseen data. The direct relationship of this term to physical security and video is obvious. In the simplest terms, an AI system is “trained” by learning patterns, relationships, and features from a large dataset. During inference, the trained model is presented with new questions (data it hasn't seen before), and it applies what it learned during training to provide answers or make decisions. Simply put, inference is what makes AI systems intelligent. Containerisation Dividing a massive security management system into several separate containers enables management of the various parts In IT, containerisation is a form of operating system-level virtualisation that allows you to package an application and all its dependencies (libraries, binaries, configuration files) into a single, portable image called a container. This container can then be run consistently across any infrastructure that supports containerisation, such as a developer's laptop, a testing environment, or a server in the cloud. In the physical security industry, you hear “containerisation” used in the context of separating out the various components of a larger system. Dividing a massive security management system into several independent containers enables the various parts to be managed, updated, and enhanced without impacting the larger whole. Genetec’s SecurityCentre cloud platform Think of it like shipping containers in the real world. Each container holds everything an application needs to run, isolated from other applications and from the underlying system. This ensures that the application will work the same way regardless of the environment it is deployed in. “It took us five years to containerise Genetec’s SecurityCentre cloud platform, but containerisation now simplifies delivering updates to products whenever we want,” says Andrew Elvish, Genetec’s VP Marketing. Among other benefits, containerisation enables Genetec to provide more frequent updates--every 12 days. Headless appliance Headless appliance is a device that is managed and controlled remotely through a network or web interface A headless appliance is a device that is managed and controlled remotely through a network or web interface. The device is like a “body without a head” in the traditional sense of computer interaction: It performs its intended function, but without any visual output or input device for local interaction. In physical security, such devices are increasingly part of cloud-based systems in which the centralised software manages and operates all the disparate “headless” devices. A headless appliance does not have a Windows management system. “The whole thing is managed through the as-a-service cloud system,” says Elvish. With a headless device, you just plug it into the network, and it is managed by your system. You manage the Linux-based device remotely, so configuring and deploying it is easy. Democratising AI You hear the term democratising AI used by camera manufacturers who are looking to expand AI capabilities throughout their camera lines, including value-priced models. For example, even i-PRO’s value-priced cameras (U series) now have AI – fulfilling their promise to democratise AI. Another approach is to connect non-AI-equipped cameras to the network by way of an AI-equipped camera, a process known as “AI-relay.” For instance, i-PRO can incorporate non-AI cameras into a system by routing/connecting them through an X-series camera to provide AI functionality. Bosch is also embracing AI throughout its video camera line and enabling customers to choose application-specific analytics for each use case, in effect, tailoring each camera to the application, and providing AI to everyone. Context Cloud system also enables users to ask open-ended queries that involve context, in addition to detection Context refers to an AI system that can understand the “why” of a situation. For example, if someone stops in an area and triggers a video “loitering” analytic, the event might trigger an alarm involving an operator. However, if an AI system can provide “context” (e.g., he stopped to tie his shoe), then the event can be easily dismissed by the automated system without involving an operator. Bosch’s IVA-Pro Context product is a service-based model that adds context to edge detection. The cloud system also enables users to ask open-ended questions that involve context in addition to detection. For example, rather than asking "do you see a gas can?" you can ask "do you see any safety hazards in this scene?" The pre-trained model understands most common objects, and understands correlations, such as "a gas can could be a safety hazard.” A scaled-down on-premise version of the IVA Context product will be available in 2026. Bosch showed a prototype at ISC West. Most video data is never viewed by an operator. Context allows a system to look at all the video with "almost human eyes." Cameras are essentially watching themselves, and understanding why something happened and what we can do. All that previously unwatched video is now being watched by the system itself, boosted by the ability to add “context” to the system. Any meaningful information based on context can trigger a response by an operator. Data lake A data lake is a centralised repository that allows one to store vast amounts of structured, semi-structured, and unstructured data in its native format. In the case of the physical security marketplace, a data lake includes data generated by systems outside the physical security infrastructure, from inventory and logistics systems, for example. A data lake is where an enterprise can accumulate all their data, from the weather to Point-of-Sale information to logistics, to whatever they can gather. Putting the data in one place (a “data lake”) enables them to mine that data and parse it in different ways using AI to provide information and insights into their business. Notably, a data lake contains all a company’s data, not just security or video data, which opens up new opportunities to leverage the value of data beyond security and safety applications. Crunching the various information in a data lake, therefore, security technology can be used to maximise business operations.
With the year 2025 stretched out before us, there are many techniques one could use to predict what will happen in the new year. You might analyse historical data and analyse future trends. Or you could try statistical or economic modelling. Or you could develop multiple scenarios based on various assumptions to explore potential outcomes. Or you could just check your email. At this time of year, my email is full of industry folks looking to predict what the future holds in 2025. Ranging from artificial intelligence (AI) to privacy, the retail market to drones, here is a sampling of forecasts for 2025 provided by various players in the security market, courtesy of my email messages. What’s Ahead for AI? From Faisal Pandit, VP & GM, Global Security Products, Johnson Controls (JCI): “The future of security operations includes customisable, scalable solutions where users can control if, when, and how they use AI to improve efficiency depending on the size and function of their organisation.” Says Kevin Woodworth, Vice President, Global Product Management, Intrusion, JCI: “Next year will see a growing focus from product developers on designing systems that streamline setup and configuration through increased AI integration. This reflects a broader trend of leveraging AI to simplify use and enhance adaptability as solutions evolve, rather simply employing it because it’s popular.” From Peter Evans, CEO of Xtract One Technologies: “AI algorithms will significantly advance in distinguishing between harmless, everyday items and potential threats. With this, we will see false alerts become even more rare.” Says JP Castellanos, Director of Threat Intelligence, Binary Defense: “Machine learning (ML)-powered anomaly detection will move beyond proof-of-concept to become mission-critical, enabling teams to uncover unknown threats and behavioural anomalies in real time – well before they escalate.” Evans of Xtract: “As AI becomes more advanced in threat detection, it will lead to more sophisticated protection of individual privacy. We can expect to see more AI techniques utilised for threat identification that do not capture personal data and are privacy-first.” Predictions on interoperability and compliance Woodworth of JCI: “New products added to singular systems must be interoperable. In 2025, organisations will need to embrace interoperability. AI will progress past reactive measures to achieve predictive capabilities.” Pandit of JCI: “With organisations increasing their focus on the regulatory environment, there will be an uptick in specialised certification programs to meet these needs. New security roles will emerge that will be focused on tracking and applying relevant regulatory changes.” Expanding capabilities for video cameras Woodworth of JCI: “Beyond capturing images, cameras will be able to detect potential threats and also mitigate them instantly, issuing vocal warnings, controlling access, or escalating issues without human intervention.” Looking ahead to retail developments Hansel Oh, Director of Product Marketing at Brivo: “Centralized, cloud-based security platforms will enhance credential management and monitor logistical operations to enable retailers to battle cargo theft.” Stephen Burd, Vice President, Essence Security: “With an increase in police response times, sophisticated crime, and smash and grabs, 2025 will see a huge demand for security solutions that go beyond simply notifying the police and will look to actively intervene and prevent damage or loss from occurring.” The role of drones and training Mary-Lou Smulders, CMO, Dedrone by Axon: “Drones will transition from being viewed as supplementary tools to becoming essential components of public safety operations. As departments recognise their effectiveness in various scenarios, the perception of drones will shift, and they will be integrated into core operational frameworks alongside traditional assets like patrol cars while replacing helicopters as a cost-effective and versatile alternative.” Erik Hohengasser, Electrical Technical Lead at NFPA: “As the skilled trades evolve, there will be an increasing demand for specialised and technical training. Predictive analytics, virtual simulations and hands-on experiential learning will become especially valuable due to allowing employees to gain real-world expertise in safe and controlled environments.”
Security applications for drones have evolved to provide benefits such as bird's-eye views of large areas, easy access to remote locations, and rapid deployment. However, to date, most drone applications have been outdoors. Not for long. Today, indoor drones are also finding unique opportunities for enhanced surveillance, security, and operational efficiency in indoor environments such as offices, warehouses, self-storage facilities, and malls. Indoor drones can navigate complex indoor spaces, providing real-time data and monitoring without the limitations of fixed cameras. New era of autonomous robotics A significant advantage of using drones indoors, as opposed to outdoors, is their ability to operate fully autonomously, circumventing U.S. Federal Aviation Administration (FAA) regulations that restrict such autonomy in outdoor environments. A new era of autonomous robotics enables drones to work seamlessly for users without the need for specialised flight training. A single security manager can oversee multiple indoor drones simultaneously with simple map clicks or prompts. A new era of autonomous robotics enables drones to work seamlessly for users Indoor monitoring and inspection Indoor Robotics is a company seeking to revolutionise indoor monitoring and inspection through its Control Bridge platform guiding indoor drones. Since its founding in 2018, Indoor Robotics has evolved through years of market engagement and product development. After initially recognising a demand for autonomous indoor monitoring, the company found that existing hardware fell short. “However, we understood the challenges of full autonomy and knew we would solve it using drones,” says Bar Biton, Marketing Manager of Indoor Robotics. Indoor Robotics has evolved through years of market engagement and product development Hardware challenges Seven years later, with the hardware challenges addressed, the company is shifting focus to continually increasing value for security managers, especially with generative AI (artificial intelligence). In 2018, the problem was charging methods, which has been solved with ceiling docking stations and five patents. “Today it’s about making indoor environments safer and even saving lives by identifying blocked emergency exits, missing safety gear, leaks, fire hazards and more,” says Biton. While indoor navigation presents challenges—such as the unreliability of GPS and the need for precision — Indoor Robotics has dedicated significant resources to achieve centimeter-level accuracy and ensure the utmost safety, maintaining a record of zero safety incidents to date, says Biton. Indoor navigation presents challenges—such as the unreliability of GPS and the need for precision Advanced AI-driven navigation systems Navigation challenges for indoor drones include manoeuvering through confined spaces, avoiding obstacles, and maintaining stable flight in varied lighting conditions. To address these, Indoor Robotics employs advanced AI-driven navigation systems, real-time 3D mapping, and robust obstacle avoidance technologies. These solutions enable drones to adapt to dynamic environments, ensuring precise and safe navigation. Additionally, the Control Bridge platform provides real-time data and monitoring, allowing drones to adjust their routes and respond to changing conditions effectively, thus enhancing their operational reliability. Highly versatile indoor drones find applications across numerous vertical markets such as retail, logistics, healthcare, and corporate settings. Key use cases encompass security surveillance, where drones monitor premises continuously; maintenance checks, especially in hard-to-reach areas; safety inspections to comply with regulations and company policies; and emergency response to provide real-time data during incidents. In warehouses, drones efficiently inspect high shelves. Healthcare facilities and data centres use them to oversee restricted zones. Additionally, corporate offices employ drones to automate after-hours security, safety and maintenance routines. Indoor Robotics employs advanced AI-driven navigation systems, real-time 3D mapping, and robust obstacle-avoidance technologies Alerts to the remote management team One Indoor Robotics client, a global tech company, deploys drones to enhance site surveillance and operational efficiency across six offices in three countries. The drones conduct regular security patrols after-hours, monitor facility activities, and ensure compliance with safety standards. This deployment has significantly improved the overall safety and security of their offices. The drones provide real-time alerts to the remote management team, enabling prompt responses to any anomalies, such as maintenance issues or unauthorised access. “The key advantage is the unified security standard provided by our Control Bridge operating system, allowing them to oversee all their sites from one centralised platform, ensuring consistent security management across all locations,” says Biton. When indoor drones co-exist with human workers, primary challenges include ensuring safety and preventing disruptions. Drones are equipped with advanced sensors and AI-driven obstacle avoidance systems to detect and navigate effectively around people. Strict operational protocols and designated flight paths are implemented to minimise interactions. Additionally, many drone operations are scheduled for after-hours to further reduce potential disruptions. “Safety is our top priority, and we invest significant resources to ensure it,” says Biton. “We are proud to report zero safety issues to date, reflecting our commitment to maintaining a secure environment for both drones and human workers.” Deploys drones to enhance site surveillance and operational efficiency across six offices in three countries Implementation of indoor drones Indoor drones are significantly more cost-effective and affordable when compared to traditional security methods like additional cameras, sensors, manpower, and even ground robots, says Biton. They cover larger areas and provide dynamic surveillance in less time, offering real-time data collection and enhanced flexibility. Unlike cameras or ground robots, drones eliminate blind spots and adapt to environmental changes autonomously. They also offer substantial indirect savings by optimising maintenance routines, according to Indoor Robotics. For instance, a drone can instantly identify issues in hard-to-reach areas, allowing for immediate, targeted responses, instead of requiring an inspector first and then a technician, thus streamlining maintenance processes. “The biggest obstacle to greater implementation of indoor drones is education and awareness,” says Biton. “Many people are not yet exposed to the concept of autonomous indoor drones and may find it hard to believe they really work.” To overcome this, Indoor Robotics focuses on creating awareness and educating customers about the reliability and benefits of the technology. Demonstrations, case studies, and clear communication about the capabilities and safety of drones are key. By showcasing successful implementations and providing hands-on experiences, Indoor Robotics seeks to build trust and drive wider adoption of indoor drone technology in security applications. Control Bridge operating system Drones are designed with strict privacy controls and advanced AI to ensure they respect privacy norms A common misconception is that indoor drones are intrusive and pose significant privacy risks. However, drones are designed with strict privacy controls and advanced AI to ensure they respect privacy norms. They operate primarily during off-hours and are programmed to avoid sensitive areas, focusing solely on enhancing security and operational efficiency. The solution also includes rigorous data protection measures to safeguard any collected information, ensuring compliance with privacy regulations and addressing concerns effectively. Soon, automation will become integral to tasks across all facility types, from manufacturing and logistics to retail and office spaces. Using Indoor Robotics’ Control Bridge operating system, facility managers will deploy fleets of robots to identify issues, collect data, and gain insights to enhance operations, maintenance, and safety. Facilities will benefit from 24/7 AI-driven monitoring, eliminating the need for occasional surveys. Managers will receive immediate alerts for any anomalies, with preventive maintenance tasks seamlessly integrated into building management platforms, ensuring optimal performance and safety. New standards in the industry The Indoor Robotics platform-agnostic approach provides flexibility and scalability. “As we continue to evolve, we support more and more platforms, enabling our clients to tailor their indoor monitoring solutions to their specific needs,” says Biton. “We believe that the future of security lies in intelligent, automated systems that can adapt to dynamic environments and provide real-time insights,” says Biton. Indoor Robotics seeks to be at the forefront of this transformation, setting new standards in the industry and paving the way for a safer, more efficient future.
Case studies
The client, a large telecommunications provider, had teams working across multiple time zones and operated a sprawling and complex IT system. The scale and density of this system made gaining visibility into IT services extremely difficult, leaving the security team blind to what was happening with its IT environment. With little-to-no operations monitoring tools in place to proactively monitor these systems, the team had no visibility on the availability of its IT services or KPIs, such as failure rates, send request times, and response times. This lack of oversight made it difficult for the team to prioritise issues — and nearly impossible for them to find the root cause of any problem. Proactive measures Without the ability to investigate the source of issues, the team was unable to take proactive measures to prevent them from reoccurring, severely impacting service performance. This was not only a problem for IT teams, but also for executives, who lacked the insight into IT business operations that would help them make decisions. The solution The company needed a solution that would map KPIs to critical service components, enabling the operations team to effectively drill down into issues in real time and conduct in-depth investigations to find resolutions. RiverSafe had previously implemented Splunk Enterprise Security for the customer and given the success of the implementation and the positive client feedback on the platform, RiverSafe was again engaged to deploy Splunk’s IT Service Intelligence (ITSI) tool to help it tackle its visibility problem. Data collection metrics Splunk ITSI uses machine learning to analyse existing data and predict future issues. As well as forecasting potential services bottlenecks, it can also troubleshoot problems and help users resolve issues fast. Delivering comprehensive monitoring across the entire IT environment, Splunk ITSI would also give the team full observability of their IT infrastructure. In particular, the engineering team wanted to gather metric data relating to the Kubernetes platform. RiverSafe reconfigured and implemented data collection metrics used elsewhere in the IT environment in Splunk to allow engineers to collate and access this information from different data sources in one place. The outcome: Actionable insights in days, not weeks In less than a week, the RiverSafe team implemented Splunk ITSI and began running monitoring services. With data from existing KPIs already indexed by the Splunk platform, the team are now able to access service insights even faster. These KPIs allow the operations team to identify trends, detect patterns, and proactively address any anomalies that occur before issues arise. Instant visibility with glass table visualisations To enable rapid and proactive issue resolution, RiverSafe implemented custom glass table visualisations in Splunk ITSI. This enables the team to navigate large volumes of data and reduce the time needed to identify and resolve problems. This simple and accessible dashboard gives the team an instant, digestible overview of its web portal performance metrics. These KPIs included the number of open tickets and failed login attempts, memory usage, API call success rates, average response times, and overall health of container services. Event analytics in Splunk ITSI As a result of RiverSafe’s work, the team has been able to centralise events from all its previously siloed solutions into a single interface with Splunk ITSI. The event analytics in Splunk ITSI help to prioritise responses and react more quickly to customers’ infrastructure events, empowering them to provide a better service. This is thanks in part to Splunk ITSI’s ability to identify and filter out false positives from the event management process. Excluding these invalid events reduced the total event volume by 40%, helping operators focus on the events that really matter. With fewer events to process, a single interface to work from, and a streamlined event analytics framework in Splunk ITSI, operators now process events eight minutes faster on average. This boost in efficiency has led to a major improvement in the company’s SLA performance. Best practices for using Splunk ITSI Overall, Splunk ITSI has delivered enhanced operational visibility, meaning the team can locate bottlenecks in workflows quickly and deliver fast recovery and troubleshooting solutions. Along the way, RiverSafe also provided best practices for using Splunk ITSI and recommended the most effective ways to collect data, including proposing an alternative metric type that would save on storage space when collecting logs.
With an extensive network of customers spanning the globe, cybersecurity is a primary concern for our client. Protecting extensive infrastructure and customer data requires a robust cybersecurity posture and effective tools, but the team found its SIEM solution lacking. Flooding its security team with an unmanageable number of false positives, the solution was diverting attention away from genuine threats and leaving them vulnerable. A substandard SIEM solution was not the only security issue. With no UEBA platform in place to help detect insider threats and data breaches, the company was faced with a number of gaps and weak spots in its security infrastructure that needed to be addressed. Three key issues The biggest concerns centred around three key issues: A lack of insider threat detection: Without a UEBA solution, the company had difficulty identifying insider threats and anomalous user behaviour within the network. Time spent on manual investigation: Security analysts spent significant amounts of time manually correlating events and investigating incidents, leading to delays in incident response and inefficient use of resources. Alert fatigue: The company’s existing SIEM solution generated a high volume of alerts, making it challenging for analysts to identify genuine threats among the many false positives. The solution The company engaged with RiverSafe to create a bespoke implementation plan that would address its primary issues and properly secure its digital infrastructure. Working in collaboration with the in-house security team, RiverSafe got to grips with existing infrastructure, gathered requirements and outlined the desired outcomes of the project. With all challenges and end goals collated, the RiverSafe team developed a solution that would meet all requirements and eliminate current security weaknesses. The team suggested Exabeam’s Fusion SIEM platform as it addressed the key concerns: Incident management: Delivering streamlined incident management processes by automating the correlation and enrichment of security events, Fusion SIEM equips analysts with actionable insights and real-time alerts. This improved visibility helps analysts hone in on genuine threats more quickly and reduce response times. Behaviour analytics: Tackling the company’s lack of UEBA issue, Exabeam’s advanced machine learning algorithms were configured to establish baseline behaviour for all users and systems. Any deviation from this baseline alerts analysts, enabling them to investigate anomalous activities and potential security issues, including insider threats. Data integration: The platform was integrated with various data sources, including logs from firewalls, servers, applications, and network devices to ensure comprehensive visibility across the organisation’s infrastructure. The outcome The implementation of Exabeam’s Fusion SIEM solution has yielded significant benefits, including: Enhanced threat detection: Exabeam’s behavioural analytics (AA) and machine learning (ML) capabilities have improved the accuracy of threat detection, enabling analysts to identify and respond to security incidents more effectively. Faster incident response: Exabeam’s automated incident enrichment and real-time alerts are helping the security team to respond to incidents promptly, minimising the impact of potential breaches. Reduced alert fatigue: The platform’s next-generation event analysis capabilities have reduced the number of false positives generated, reducing alert fatigue and giving analysts more time to focus on genuine threats. Improved insider threat detection: With its advanced behaviour analytics, Fusion SIEM is enabling the team to detect insider threats by identifying abnormal user activities and deviations from established behavioural patterns.
Honeywell has been selected as the building automation provider for LG Energy Solution’s cylindrical EV battery manufacturing facility being built in Queen Creek, near Phoenix, Arizona. Set for completion in 2026, this state-of-the-art project represents a critical milestone in LG Energy Solution’s strategy to lead EV battery innovation in North America, and it also supports Honeywell’s alignment of its portfolio to three compelling megatrends, including automation and the energy transition. New standard for operational efficiency Deployment of Honeywell’s building automation technologies at the Queen Creek facility Global battery demand is projected to quadruple by 2030 according to Bain, and the deployment of Honeywell’s building automation technologies at the Queen Creek facility will help set a new standard for operational efficiency in high-tech manufacturing environments. This 1.3-million-square-foot standalone facility will integrate a suite of Honeywell technologies to help optimise performance, enhance safety and support sustainability outcomes. Future of automation “By developing and delivering solutions that blend cutting-edge technology and energy management, we are driving the future of automation," said Billal Hammoud, president and CEO of Honeywell Building Automation. "Honeywell’s collaboration with LG Energy Solution demonstrates how advanced building automation can help empower companies to achieve operational excellence in their facilities while also accelerating the shift to a more secure energy future.” Honeywell’s innovative solutions Honeywell’s innovative solutions will provide the Queen Creek facility with the following: Unified Systems Integration: Honeywell’s Enterprise Buildings Integrator platform will help enable seamless control of building management and safety systems via integration into Honeywell Forge, which provides advanced monitoring and analytics. Honeywell Forge, an IoT platform, enables condition-based maintenance to improve the resiliency of critical systems around the clock, helping to reduce unplanned reactive work and help lower energy costs. Its machine learning capabilities will continuously study a building's energy consumption patterns, which will enable LG Energy Solution to automatically adjust the facility to optimal energy-saving settings. Comprehensive Fire and Safety Solutions: Honeywell’s VESDA smoke detection and advanced self-testing fire alarm system offers automated and continuous air sampling enabling early warning of an impending fire hazard, often even before heavy smoke or flames are detected. VESDA and the networked fire alarm solution will be integrated into the facility’s building management system to allow coordinated and near-instant responses from the HVAC system if smoke is detected. Mission Critical Control and Advanced Cybersecurity: The QronoX Programmable Logic Controller will enable LG Energy Solution to enhance operational performance and resilience by providing advanced cybersecurity for its facility. The Honeywell technology will also help ensure asset security and compliance while reducing downtime for critical systems. Honeywell’s scalable solutions are designed to support the future expansion of the project as well, reinforcing its role as a key collaborator in this transformative industrial sector.
Artificial Intelligence Technology Solutions, Inc., a pioneer in AI-driven security and productivity solutions for enterprise clients, along with its subsidiary Robotic Assistance Devices (RAD), announced recent successes in St. Louis, Missouri, where the Downtown St. Louis Community Improvement District (CID) has embraced RAD’s solutions as part of its public safety initiatives. The CID has deployed multiple ROSA™ security devices, showcased RAD’s ROAMEO™ and RADDOG™ LE2 during the NCAA Frozen Four Championship, and is actively developing a citywide program that would introduce hundreds of RADCam™ units across St. Louis. RAD’s added layer of security RAD’s ROAMEO and RADDOG LE2 were actively deployed in St. Louis as part of the city’s public safety From April 10 to 12, RAD’s ROAMEO and RADDOG LE2 were actively deployed in downtown St. Louis as part of the city’s public safety and engagement efforts during the NCAA Frozen Four Championship. These high-visibility units provided an added layer of security, engaged with residents and visitors, and generated strong public interest. Steve Reinharz, CEO/CTO of AITX and RAD, was interviewed on-site by KSDK, the St. Louis NBC affiliate, where he discussed how RAD’s technologies enhance urban safety while fostering meaningful community interaction. RAD security solutions During the event, representatives from several local organisations, including casino operators, professional sports teams, and major property management firms, visited with RAD and the Downtown St. Louis CID to see firsthand how ROAMEO, ROSA, RADDOG LE2, and other RAD security solutions could be used to support safety and operational efficiency in real-world environments. Of particular interest to many of these organisations was RAD’s multiple SARA™ (Speaking Autonomous Responsive Agent) and ROSS™ (RAD Operations System Software) platforms. RAD’s analytics and automation capabilities Software solutions allow clients to reimagine the role of their existing security infrastructure These software solutions allow clients to reimagine the role of their existing security infrastructure by adding an intelligent, agentic AI layer to legacy hardware. By leveraging RAD’s analytics and automation capabilities, organisations can unlock powerful new functionality from their current systems, enhancing performance, accelerating incident response, and delivering significant cost savings without the need for full system replacement. RAD’s technology: public safety efforts “RAD’s technology has been an impactful addition to our public safety efforts,” said Kelli McCrary, Executive Director of the Downtown St. Louis CID. “The presence of ROSA, ROAMEO, and RADDOG has not only helped deter unwanted activity, but also brought positive attention and community engagement, especially during the excitement of the Frozen Four Championship. This kind of innovation supports our vision for a safer, more welcoming downtown experience.” RAD over traditional security solutions RAD secured deployments of ROSA and RIO units following a competitive review, with city leadership RAD’s momentum extends beyond St. Louis. In Cleveland, RAD partnered with Downtown Cleveland, Inc. to launch a smart security initiative in Public Square, featuring the RIO™ 360 tower with live video integration into the city’s crime centre. In Nashville, RAD secured deployments of ROSA and RIO units following a competitive review, with city leadership opting for RAD over traditional security solutions to enhance monitoring and deterrence in key public areas. How RAD’s solutions meet the evolving security needs As municipalities and CIDs search for scalable, cost-effective ways to secure public spaces, RAD has emerged as a trusted partner in redefining how cities approach safety. From high-traffic districts to major public events, RAD’s AI-powered devices provide 24/7 monitoring, advanced detection capabilities, and autonomous responses that relieve the burden on human personnel. The recent deployments in St. Louis, Cleveland, and Nashville illustrate how RAD’s solutions meet the evolving security needs of urban centres while reinforcing community confidence. RAD's effective security solutions “We’re seeing growing interest from CIDs and public sector organisations that are eager to rethink how they secure their communities,” said Reinharz. “RAD is executing a nationwide campaign to deliver meaningful, affordable, and effective security solutions to cities, towns, and districts across the country. Our technology gives these organisations the tools to protect public spaces, ease the strain on human resources, and deliver a stronger sense of safety for residents and visitors alike.” Outdated approaches and deployments RAD welcomes inquiries from municipalities, CIDs, BIDs, DDAs, and other organisations “It’s incredibly rewarding to see our devices actively supporting the safety goals of communities like St. Louis, Cleveland, Nashville, and others,” said Troy McCanna, Chief Security Officer at RAD. “These deployments represent a shift away from outdated approaches and a move toward intelligent, responsive technology that delivers results. We’re proud to be working hand-in-hand with local pioneers who are committed to creating safer urban environments through innovation.” How its AI-powered security solutions can support safety goals RAD welcomes inquiries from municipalities, Community Improvement Districts (CIDs), Business Improvement Districts (BIDs), Downtown Development Authorities (DDAs), and other organisations focused on public safety and urban revitalisation. The Company offers personalised consultations to explore how its AI-powered security solutions can support local safety goals, improve operational efficiency, and strengthen community trust. RAD's security guarding and monitoring model RAD solutions are precisely designed to provide cost savings to businesses of between 35%-80% AITX, through its subsidiary, Robotic Assistance Devices, Inc. (RAD), is redefining the nearly $50 billion (US) security and guarding services industry through its broad lineup of innovative, AI-driven Solutions-as-a-Service business model. RAD solutions are specifically designed to provide cost savings to businesses of between 35%-80% when compared to the industry’s existing and costly manned security guarding and monitoring model. RAD AI-based analytics and software platforms RAD delivers these tremendous cost savings via a suite of stationary and mobile robotic solutions that complement, and at times, directly replace the need for human personnel in environments better suited for machines. All RAD technologies, AI-based analytics and software platforms are developed in-house. RAD has a prospective sales pipeline of over 35 Fortune 500 companies and numerous other client opportunities. RAD expects to continue to attract new business as it converts its existing sales opportunities into deployed clients, generating a recurring revenue stream. Each Fortune 500 client has the potential of making numerous reorders over time.
CCOM Global Technologies, experts in managing video surveillance on cruise liners is leveraging Pimloc’s Secure Redact privacy platform, the world’s pioneering automated video redaction AI software solution, to ensure the privacy of uninvolved individuals when disclosing footage to third parties or in response to subpoenas. The security challenges onboard cruise ships – effectively small towns with up to 5,000 ‘residents’ are huge, and Secure Redact has proven to be highly effective in maintaining passenger privacy during video surveillance. Automatic blurring Secure Redact’ automatically blurs personal and sensitive data in captured and live security videos. This enables organisations such as CCOM Global Technologies to quickly and responsibly handle footage from CCTV by protecting and redacting personal data, such as faces and automatically redacting and anonymising the information 200 times faster than traditional video editing services. Secure Redact platform The technology can be deployed selectively, removing some or all faces or other identifying information Pimloc has developed world-pioneering AI solutions, trained to perform on real-world security footage, through its Secure Redact platform to protect personal data in images and video automatically. The technology can be deployed selectively, removing some or all faces or other identifying information. As a result, video clips that have been selectively anonymised with Secure Redact can be supplied externally, while staying compliant with data privacy laws and regulations. Privacy, safety, and security “When we are looking at security challenges, we have thousands of people that we need to keep safe and secure, maintaining their well-being,” says Daniel Ginat, Director of Technology at CCOM Global Technologies. “It's a small town, or a Vegas scale of the hotel, with hundreds and hundreds of CCTV cameras. Privacy, as well as security, is key, and Secure Redact helps us to deal with security issues for our clients, while effectively keeping bystanders and other innocents out of the picture.” Advanced features After comparing other solutions, CCOM Global Technologies chose Pimloc’s Secure Redact privacy platform for its advanced features and fair pricing, making it the ideal choice. But it wasn't only the features and value that secured the contract with CCOM Global Technologies; communication was also key. “From the start, we felt like the team at Pimloc was very knowledgeable of the system,” Ginat adds. “They could show us exactly all of the features and how to use them. This level of expertise, combined with the platform's capabilities, made Secure Redact the clear choice for us to partner with.” Face detections Secure Redact creates the final redacted video for download by blurring all the detected personal data Secure Redact automatically processes and ingests any uploaded video from CCOM GlobalTechnologies’ CCTV footage onboard ship, before reformatting it and running machine learning algorithms over each frame to detect all faces. These detections are then marked for redaction as orange boxes on the video and are only viewable by CCOM Global Technologies operatives, who review the results before Secure Redact creates the final redacted video for download by blurring all the detected personal data, ready for export and delivery to their cruise liner client. Data privacy compliance requirements “We’re delighted to be helping CCOM Global Technologies to maintain privacy during cruise ship video surveillance,” says Pimloc CEO Simon Randall. “Secure Redact meets international data privacy compliance requirements when dealing with personal data in images and video files, and it is the fastest solution on the market. We’re enabling cruise liners to supply video clips externally to employees, customers, or even corporate insurance companies, law enforcement, and lawyers while staying compliant with data privacy laws and regulations.”
In a hyperconnected world, a lack of proactive communication can disrupt operations significantly, particularly in access control and time-attendance management. With over 2 billion global users, WhatsApp stands as a powerhouse in dynamic communication. This widely popular messaging platform provides a seamless way to streamline notifications and approvals, enabling real-time interactions and swift decision-making. Benefits of integration Matrix not only boosts efficiency and productivity but also fortifies security and HR operations Matrix, renowned for its cutting-edge access control and time-attendance solutions, harnesses the power of WhatsApp to redefine proactiveness. By seamlessly connecting essential workplace systems with a globally trusted communication platform, organisations can achieve unparalleled convenience and reliability in managing workforce operations. Through WhatsApp integration, Matrix not only boosts efficiency and productivity but also fortifies security and HR operations. This ensures that critical access and attendance data are managed with exceptional precision and responsiveness. To maximise the benefits of this integration, it's crucial to understand the steps required to seamlessly connect WhatsApp with the Matrix COSEC system. Matrix COSEC notifications Integrating WhatsApp with COSEC ensures instant and seamless notifications for attendance approvals, access events, and other important updates. This integration simplifies the way employees and management interact by streamlining the process of receiving and responding to time-attendance notifications. Be it leave approvals, late arrivals, or early departures, the integration ensures timely updates to all relevant stakeholders, enabling quick and informed decision-making. WhatsApp integration with COSEC Input these details into the Alert Message Configuration within the Admin Module of COSEC To enable WhatsApp integration with COSEC for alerts and notifications, start by creating a WhatsApp Business account through the Meta Developer Portal. Gather the required details, including the Permanent Access Token, Phone Number ID, WhatsApp Business Account ID, App ID, and Security Token. Input these details into the Alert Message Configuration within the Admin Module of COSEC. Then, specify the types of alerts they wish to receive on WhatsApp and validate the setup by sending test alerts to ensure everything functions smoothly. Team's attendance and access events with WhatsApp integration Receiving real-time updates on a team's attendance and access control events via WhatsApp offers unmatched convenience. Managers and HR personnel can instantly access attendance records, detect access control violations, and review unusual entries directly on their devices. This streamlined approach eliminates the hassle of switching between systems, ensuring immediate access to essential information and enabling quicker responses. With attendance and security event notifications delivered straight to WhatsApp, managers achieve full visibility into attendance trends and security incidents. Proactive approach Integration boosts active efficiency by centralising touch and streamlining access to critical data Daily summaries of these events enhance organisational transparency, enabling swift resolution of attendance discrepancies and rapid responses to potential security breaches. This integration boosts operational efficiency by centralising communication and streamlining access to critical data. Managers can make timely decisions, whether addressing attendance issues or responding to access violations, with alerts delivered directly to WhatsApp. By ensuring key information is readily available, this proactive approach enhances efficiency and responsiveness throughout the organisation. Integration in time-attendance and access control systems Advanced communication integration for notifications and alerts in time-attendance and access control systems will leverage cutting-edge technologies to enhance efficiency and security. Below are some of the key potential advancements: Anomaly Detection Capabilities: AI-driven algorithms will analyse regular attendance and access patterns to identify anomalies, such as unusual entry times or unauthorised access attempts. These irregularities can be instantly flagged and notified to security personnel or administrators in real-time for prompt action. Personalized Notifications: AI-powered customisation will enable role-based notifications tailored to individual preferences and responsibilities. For instance, management may receive strategic alerts related to security breaches or policy violations, while employees are notified of attendance updates or access approvals, ensuring relevant and focused communication. Predictive Maintenance Alerts: Leveraging predictive analytics, the system can anticipate maintenance needs for attendance and access control systems. Administrators will receive timely notifications about potential issues, allowing them to address concerns proactively before they impact operations. Implementing these advanced features will rely on robust API frameworks, secure data handling practices, and intuitive user interfaces to effectively manage notifications and alerts. With these foundations in place, these developments can significantly improve operational efficiency and security while delivering a superior user experience for time-attendance and access control systems. Revolutionising workplace control with WhatsApp integration The integration of WhatsApp with Matrix time-attendance and access control solutions is set to transform workplace management like never before. This cutting-edge integration delivers real-time notifications and streamlines approval processes, offering unparalleled ease in monitoring and managing workforce dynamics. The result? Enhanced productivity, operational efficiency, and a more connected organisation. Discover how Matrix’s innovative integration solutions can elevate the security and management systems.


Round table discussion
Future-proofing your skillset is about embracing continuous learning and developing a versatile set of competencies that remain valuable regardless of technological shifts or industry changes. In the security marketplace, it is not about predicting the exact jobs of the future, but rather equipping yourself to adapt and thrive in the uncertain security landscape. But where to begin? The emerging technology shifts in the security industry provide clues, such as the growing importance of cybersecurity and artificial intelligence (AI). We asked our Expert Panel Roundtable: How can physical security professionals “future-proof” their skillsets to prepare for emerging technologies?
If recent physical security events are a guide, the topic of artificial intelligence (AI) will be everywhere at the upcoming ISC West 2025 exhibition in Las Vegas. Cybersecurity solutions are another core focus at today's physical security events, and ISC West will likely follow the trend. Attendees will also be looking for advancements in access control systems, including biometric technologies and integrated security platforms, among other hot topics. We asked our Expert Panel Roundtable: What will be the big topics of discussion at ISC West 2025?
Technology innovations and an evolving threat landscape will be core factors impacting the physical security market in 2025. Technology elements such as artificial intelligence (AI), multi-factor access control, and mobile devices will continue to drive growth in the greater industry. We asked our Expert Panel Roundtable: What is the outlook for the physical security industry in the year ahead?
White papers
AI in security solution
Download
Unlocking wide-angle camera dewarping
Download
Empowering cameras with AI
Download
The rise of ethical facial recognition
Download
Connected video technology for safe cities
Download
How security systems ensure healthy workplaces during COVID and after
Download
Artificial intelligence: Understanding its place in physical security
Download

Security technologies promote real-time awareness in K-12 schools
Download
Technology's role in securing banks and financial institutions
Download
Integrated systems enable critical and compliant security for transportation
Download
Modernising physical access control
Download
Access. Intrusion. One estate.
Download
