MSSP, MSP, Security Management, AI benefits/risks, Application security, Data Security, SOC, Security Operations

Simbian Wants to Help SecOps Teams Cut Through the AI Hype

AI and automation offer a lot of promise for understaffed and overwhelmed IT teams, but they come with their share of challenges, from steep learning curves to sorting through what’s real and what’s not as the emerging technology takes center stage throughout the tech world.

Executives with two-year-old startup Simbian, an AI security company that uses AI agents for security operations, want to help security teams and service providers wend their way through the roiling waters churned up by the technology.

“SecOps and SOC [security operations center] teams are in a tough position right now,” Simbian Chief Marketing Officer David Greene told MSSP Alert. “They are already overloaded and now have to navigate a new set of AI security threats they have never seen before, with limited expertise and tight budgets.”

The Mountain View, California, company has worked with a range of customers as they look to implement AI into their security environments, and has developed what it calls an AI Roadmap for Security Operations.

The New 'Cloud Washing'

“Remember ‘cloud washing,’ when in the early days of the cloud, every new and every old product was suddenly a cloud product?” Greene said. “The same thing is happening today with AI-powered security tools, which just creates confusion.”

Security teams and service providers like MSSPs and MSPs are going to need to lift that confusion, because AI in security has a dual nature. Not only are SecOps groups integrating the technology into their stacks, but threat groups are rapidly incorporating it into their attacks.

“Defenders need weapons that are at least as powerful as those of the attackers,” he said. “AI-armed attackers can operate at a speed, scale, and stealth that quickly overruns the most mature SecOps team. These teams will need to use AI to confront this head-on, while also harnessing the biggest advantage they have over any attacker — their deep knowledge of their users, applications, and infrastructure.”

AI is Reshaping the Cybersecurity Industry

The expanding AI arms race can be seen in the market numbers. According to analysts with Statista, the market for AI in cybersecurity is expected to grow from more than $30 billion last year to about $134 billion by 2030.

“AI is reshaping nearly every industry and cybersecurity is no exception,” executives with global investment firm Morgan Stanley wrote. “Because of the nature of AI, which can analyze enormous sets of data and find patterns, AI is uniquely suited to handle tasks such as detecting cyberattacks more accurately than humans, creating fewer false-positive results, and prioritizing responses based on their real-world risks.”

It can also identify and flag suspicious emails and messages often used in phishing campaigns, simulate social engineering attacks to help security teams detect vulnerabilities before bad actors exploit them, and rapidly analyze massive amounts of incident-related data, they wrote.

Understanding AI's Security Role

Multiple surveys indicate that security pros understand the important role AI will play in cybersecurity and the AI-powered threats they face. A survey of 1,500 cybersecurity specialists around the world by Darktrace found that 95% believe AI-powered security solutions improve the speed and efficiency of prevention, detection, response, and recovery, and 88% say it’s important for giving security teams time to be more proactive.

That said, 45% indicated they didn’t feel prepared for the reality of AI-driven cyber threats.

Simbian is working to help organizations gain more confidence by giving them tools and advice for integrating AI into their security operations. In a blog post in October, Varun Anand, Simbian’s head of product and one of the presenters at this week’s webinar, outlined a three-step plan to help guide CISOs as they implement AI for cybersecurity.

That includes running pilots using high-volume, but low-complexity alerts, which show how AI can recognize false alerts, free up security pros from having to do the time-consuming work. Teams can then scale AI to address advanced persistent threats that include multiple stages and attack vectors, before moving on to full autonomous operations with human oversight.

MSSPs and AI for SOCs

MSSPs and MSPs, which increasingly are embraced by particularly smaller organizations to take on most if not all of their security operations, need to understand the AI-powered threats facing them and their clients and how AI with the security stack can counter them, Greene said.

Many firms need the capabilities of a SOC, but don’t yet have a comprehensive SecOps program that’s needed to support a SOC, which makes an MSSP “often the most pragmatic path forward,” he said.

“The scale and expertise of MSSPs often exceed what an enterprise can do on its own,” he said. “For MSSPs, AI-powered SOC tools enable delivery of a higher quality service at a better margin by leveraging AI for much of the ‘grunt work’ in delivering SOC services.”

Doing this allows trained security staffs to focus more on higher value service and customer support.

“No more struggling with unexpected alert spikes or delaying onboarding until more analysts can get hired,” Greene said.

Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds