AI in Cybersecurity Won't Replace Defenders, But It Will Automate the Toil
thecyberexpress.com

AI in Cybersecurity Won't Replace Defenders, But It Will Automate the Toil

Tech News
3 min read

Published by AINave Editorial • Reviewed by Ramit

TL;DRHarsha Reddy argues AI will augment cybersecurity by automating repetitive toil like log review and alert triage, but human judgment and governance remain critical. He advocates guardrails and an internal AI enablement committee to prevent data leaks.

The debate over whether AI will replace cybersecurity jobs misses the real shift. According to Harsha Reddy, Head of Information Security at Veterinary Emergency Group (VEG), AI is absorbing the repetitive toil that keeps analysts from doing actual defense work. The analyst who refuses to use AI will be replaced by one who does, not by the AI itself.

What Reddy Actually Argues

Reddy pushes back on the narrative that AI will hollow out security teams. He points to Gartner research showing cybersecurity is expected to gain jobs even as other fields shrink. In his view, AI mainly handles log review, alert triage, and evidence gathering. Those are the tasks that burn out analysts and slow down incident response.

But adoption without governance creates new risks. Reddy cites a 2024 Microsoft-LinkedIn survey where most executives called AI critical yet lacked formal plans, and most employees were already bringing their own tools. That gap, he argues, is why organizations are seeing AI-related data leaks. His fix is not more restrictions. Blocking AI pushes it into the shadows. Instead, he advocates guardrails, an internal AI enablement committee, and measuring business value instead of token consumption.

What This Means for AI Builders

If you are building security tools or deploying AI inside a security team, the takeaway is direct. Your product needs to slot into a governance structure, not bypass it. Reddy's framing of onboarding AI like staff rather than like software is a useful design principle. Builders should expect customers to demand guardrails, audit trails, and clear accountability for AI-driven decisions.

The emphasis on business value over token counts also matters. If your pricing or reporting focuses on tokens consumed, you are measuring the wrong thing. Security leaders want to know whether the tool reduces mean time to detect, cuts false positives, or frees analysts for higher-value work.

Practical Steps for Security Teams

Reddy's approach translates into concrete actions. First, establish an internal AI enablement committee that reviews tools before deployment. Second, implement guardrails that prevent data leakage without blocking innovation. Third, define metrics tied to business outcomes, not usage volume. These steps apply whether you are evaluating a commercial AI security tool or building your own agent.

Caveats to Keep in Mind

The evidence here comes from a single interview with Harsha Reddy and the sources he references. Gartner projections and the Microsoft-LinkedIn survey are cited but not independently verified in this context. The practical advice is grounded in one practitioner's experience, which may not generalize to every organization. Still, the core argument that AI automates toil rather than replaces defenders aligns with broader industry consensus.

The Bottom Line

AI in cybersecurity is not about headcount reduction. It is about shifting analysts from repetitive triage to strategic defense. The teams that get this right will be the ones that treat AI as an augmented team member, not a cost-cutting tool.

FAQs

AI is expected to automate repetitive tasks like log review, alert triage, and evidence gathering, but not replace human defenders. Harsha Reddy cites Gartner projections that cybersecurity may gain jobs even as other fields shrink. The analyst who refuses to use AI may be replaced by one who does, but the role itself remains.

Sources

Latest Tech News