AI-powered cyber defence: Poor decision-making turns a speed advantage into extra work

Kategorie "Wirtschaft"
© vadishzainer, iStock

An AI system is capable of blocking access or triggering automated countermeasures within seconds on the basis of faulty data – even before a human realises the mistake has been made.

IT security teams are using Artificial Intelligence (AI) to lighten their workload and fend off cyberattacks more quickly. However, Frank Lange, Technical Director at Anomali Germany, addresses the fact that it is precisely this speed of AI that can become a risk if the underlying data is incorrect. He explains that an analyst wastes time when there is a false alarm. An AI system, however, could block access or trigger automated countermeasures within seconds on the basis of faulty data – even before a human realises the mistake has been made.

At the same time, IT security specialists already spend 40 per cent of their working hours consolidating data from different systems. The data foundation is therefore a crucial factor in the use of AI in cyber defence. His key recommendation centres on ‘threat intelligence’, which – when integrated into the security process to automatically cross-reference newly arriving log data – could help reclaim 60 to 70 per cent of working time that would otherwise be lost unproductively whilst investigating false alarms.

The greater the level of AI autonomy, the greater the potential damage

Lange describes the problem as follows: Companies invest in AI to solve a real and ever-growing problem – security teams are overburdened, analysts are reaching their limits, and the volume of threats exceeds what humans could handle manually. What is often underestimated is that the more autonomy an AI system is given, the greater the damage if it fails to make accurate decisions.

A security analyst who responds to a false alarm purely manually wastes a lot of time. An AI system, on the other hand, which continues to operate despite inaccurate data, wastes no time: It takes action; it blocks access and triggers automated countermeasures.

By the time a human realises the error, the system may have repeated the same error several times. The speed that makes AI so valuable in security on the one hand is the very same speed that can become a danger if the data on which it is based is flawed.

The adversary is using AI for phishing campaigns and the development of malicious code

New entrants to the IT security sector remain in this role for an average of twelve to 18 months, with each new appointment costing around 50,000 Euros. According to Lange, the reason for this is a system structure that forces qualified specialists to spend the majority of their working hours checking false alarms rather than carrying out interesting security analysis. AI systems built on the same basis inherited the same problem and exacerbated it.

The threat landscape is further exacerbating this situation. Attackers are now using AI to generate phishing campaigns, develop new variants of malware and constantly change the technical infrastructure from which they operate. The volume of incoming threats consistently exceeds what security teams can handle manually.

IT security specialists spend 40 per cent of their working hours consolidating and processing data from various systems, rather than focusing productively on the actual security work. At board level, companies could probably report on how many alerts they have dealt with. What they would not be able to report, however, is whether they are more secure today than they were last year.

A key question to be clarified at the outset: What must happen if the AI malfunctions?

The reason for this uncertainty is that security systems are designed to count alarms, not to measure their protective effect. This makes it structurally impossible to demonstrate whether investments in security are actually effective. This gap is not a problem of presentation – but a problem with the underlying system structure.

When using AI, companies rarely asked the most important question: “What happens if the AI gets it wrong?” For a human analyst, a wrong decision costs only a few minutes

With an AI system operating at the speed of a machine using unverified data, it takes seconds for an error to occur and hours to rectify it across all affected systems. “This is not a theoretical risk. It is the reality that most companies are currently facing!” Lange points out.

The data used by the AI system influences the extent of the damage

Reliable AI in cyber security requires a different approach. According to Lange, Anomali cross-checks every incoming threat indicator against current attack data and the company’s own IT environment before it reaches an analyst or triggers an automated response.

Analysts therefore make more decisions, not fewer.

However, they focus on those cases that require human judgement – rather than wasting their working time on alerts that should never have been triggered in the first place. According to Lange’s experience, analysts at clients who have switched to this approach recoup 60 to 70 per cent of the time lost to false alerts.

Key findings from the DS editorial team

  • The ambivalence of the impact of modern IT systems should always be taken into account in advance: The supposed advantage of faster response times can, if based on an unsuitable data set, be turned into exactly the opposite and cause damage – autonomously operating AI exacerbates the situation.
  • The quality of the AI and the expected benefits depend directly on the quality of the data used as a reference.
  • False alarms, just like the failure to issue legitimate alerts, have the potential to cause significant damage to businesses.
  • IT users – and therefore AI users too – should be aware of the inherent characteristics of such systems and use them with realistic expectations – in other words, they should also be prepared for malfunctions.
  • The fine art of using AI efficiently and effectively lies in a goal-oriented, synergistic interaction between AI systems and human staff.

More information

DATENSICHERHEIT.DE, 07|18|2026
KI-Einsatz: Blinder Fleck der Cybersicherheit liegt in den Daten

DATENSICHERHEIT.DE, 06|15|2026
Wechselwirkung zwischen KI und Cybersecurity als zentrale Führungsfrage 2026

DATENSICHERHEIT.DE, 02|12|2026
Datenschutz in Echtzeit: Wie Daten-Streaming die Kunden in einer KI-gesteuerten Welt schützt

Weitere Beiträge