Skip to main content
Cybersecurity

AI Adoption Surges in Security Operations

Security analysts collaborate around a large screen and conference table in a brightly lit operations center.

"Almost everyone is moving toward AI in their security operations, mostly because the bad guys are already using it," Prophet Security's State of AI in Security Operations 2026 report concludes, drawing on a ViB survey of more than 250 cybersecurity professionals.

Alert volumes, analyst capacity, and the containment clock

The report paints a simple arithmetic problem turned operational crisis. The average security team receives about 100 alerts per day; larger companies see close to 1,000, and more than a quarter of teams face upwards of 500 alerts daily. Team sizes vary widely — some organizations have more than 100 analysts while many run on fewer than ten — but capacity has not kept pace with volume. Investigating a single alert thoroughly takes an average of 75 minutes, and alerts commonly sit untouched for nearly an hour before anyone looks at them.

That gap matters because attackers can break out and start moving through a network in 29 minutes. With investigation cycles often stretching toward two hours, what begins as an efficiency problem becomes a containment problem.

Missed alerts, real harms, and how teams respond

The human cost of overload is measurable. About 28% of alerts are never investigated, and 60% of respondents said an alert they ignored or missed later turned into a serious issue such as a data breach or system downtime. For roughly one-third of those respondents, that sequence happened three or more times in the past year. Faced with volume and limited manpower, up to 40% of organizations have disabled certain security alerts entirely — a step that narrows coverage where it can do the most damage.

AI adoption, measurable gains, and the adversary's mirror

AI has moved from experiment to operational tool: 40% of security teams now use AI daily, another 56% are testing it, and only 4% have no plans to adopt it. Security teams place both securing AI systems and using AI for security at the top of their priority lists, surpassing traditional concerns like cloud and data security. The operational drivers are explicit — faster response times (73%), better detection coverage (71%), doing more with the same team (56%), and reducing analyst burnout (37%).

Those priorities are yielding measurable results. Nearly three-quarters (72%) of AI users report investigation-time reductions of at least 25%, roughly 25 minutes returned per alert, alongside better 24/7 coverage and fewer false alarms. At the same time, respondents report that attackers are using the same toolset: 56% saw an increase in AI-driven attacks, especially in finance and healthcare. The most common threats cited were AI-written phishing, deepfake audio and video scams, large credential-stuffing campaigns, and AI-generated malware.

DIY AI, trust limits, and explainability/privacy hurdles

Many teams tried to build their own AI: 72% attempted internal AI tools. But DIY showed mixed durability — almost half (46%) of those projects were abandoned, never reached production, or were replaced by commercial products. Building in-house produced no clear speed advantage: DIY teams reported investigation-time gains at roughly the same rate as AI users overall (73% versus 72%).

Trust remains cautious. While most respondents say AI conclusions usually match a human expert's, 57% still require a human review of every AI decision before closing an alert. Fifty percent-plus use AI as an assistant: 44% have it recommend actions for human execution and 30% allow low-risk automated remediation; not a single respondent reported granting full unsupervised autonomy. Regulatory and technical frictions top the obstacle list — 44% cited worries about data privacy and how models are trained, and 41% flagged explainability as a problem.

How technologists, procurement leads, and regulators will respond

  • Technologists and security teams: When AI frees capacity, teams are redirecting it to threat hunting. About half hunt regularly; 38% of teams reported finding malicious activity their automated tools had missed. Teams that hunt weekly or more report a 49% hit rate compared with 8% for teams that never hunt.
  • Procurement and operations leaders: The report points to vendor features that address the top hurdles — complete audit trails, single-tenant deployments, and data-plane options that run inside a customer's own VPC. Prophet Security says its platform records every query and piece of evidence, returns "inconclusive" when warranted, and converts investigative findings into backtested detections.
  • Regulators and compliance officers: Privacy of training data and explainability top the worry list for 44% and 41% of respondents respectively, signaling that deployment choices (single-tenant models, data residency) and vendor transparency will shape procurement decisions.

Prophet Security offers a concrete example of the gains reported: at JB Poindexter, Prophet AI reduced mean time to investigate to under four minutes and avoided 1,469 analyst hours. The broader survey suggests a clear operating playbook emerging: use AI to investigate broadly, validate its work, give it measured autonomy as it earns trust, and spend the recovered hours hunting for threats human systems miss.

https://thehackernews.com/2026/08/what-data-says-about-ai-in-security.html