The Cybersecurity advantage is shifting from Humans vs. Machines to Humans + Machines

Cybersecurity is entering a phase where attack speed may soon outpace the speed of human response. As AI and automation enable adversaries to move faster, scale campaigns and compress the window available for defenders, traditional manual security processes are becoming increasingly difficult to sustain.

The answer is not to choose between human expertise and machine intelligence, but to combine them deliberately: let machines operate at speed and scale, while people provide the context, judgement and accountability that machines cannot.

Diwakar Dayal, Managing Director and Area Vice President – India & SAARC at SentinelOne



The shift from human-led to human + machine security

Every major technology shift has forced the security industry to reinvent itself, from client-server environments to cloud, and from perimeter-based security to Zero Trust. Today, AI is creating another inflection point.

Security teams are dealing with growing volumes of signals across endpoints, identities, cloud environments and applications. At the same time, attackers are increasingly able to automate reconnaissance, exploitation and other parts of the attack chain. This creates a widening gap between the speed at which threats can develop and the speed at which a human-led security operation can
investigate them. India’s threat landscape illustrates the pressure. According to the Government of India, CERT-In handled
more than 29.44 lakh cyber security incidents in 2025, up from 14.02 lakh in 2021. The significance of this number is not simply that there are more incidents to investigate. It is that security teams need to make more decisions, across more environments, in less time. That makes a model built around manual triage increasingly difficult to scale.

From manual triage to governed autonomy

AI can take on more of the repetitive work involved in security operations: analysing large volumes of telemetry, correlating signals, enriching investigations and identifying patterns that might otherwise take analysts hours to uncover.

The bigger opportunity is to move from AI-assisted analysis towards governed autonomy, where machines can investigate and, in clearly defined situations, take response actions at machine speed while humans retain accountability for the operating model.

Not every security decision requires human intervention. A known malicious file, for example, may be suitable for an automated containment workflow. A response that could disrupt a critical production system, affect sensitive data or have wider business consequences may require human approval.

The question for security leaders is therefore not simply what can be automated, but what should be automated. That means establishing clear guardrails around where AI can act independently, where it should recommend an action and where human approval remains necessary.

This is less about removing people from the security process and more about removing unnecessary manual effort while preserving human control over consequential decisions.

What this means for CIOs

For CIOs and security leaders, the shift to humans and machines working together has three distinct priorities.

First, define the boundaries of autonomy. Organisations should identify which workflows can safely run without intervention and which require human approval. The objective is not maximum automation. It is ppropriate automation, based on business criticality and risk.

Second, make autonomous decisions accountable. As AI takes on greater responsibility, organisations need visibility into the evidence behind an action, the rules or policies governing it and the ability to review what happened afterwards. Accountability cannot disappear simply because a decision was automated.

Third, redesign the role of the security team. As automation takes on repetitive alerts and triage, security professionals can focus on complex investigations, threat hunting and decisions that require business context and judgement.

India’s broader push towards digital resilience reinforces the same principle: cybersecurity needs to operate at the scale and speed of the digital systems it protects. As enterprises expand their use of cloud, AI and connected infrastructure, security operations will need to become more adaptive without compromising accountability.

The future of cybersecurity is not humans versus machines. It is knowing where each should lead machines handling speed and scale, and people applying judgement were context and accountability matter most.

Authored by Diwakar Dayal, Managing Director and Area Vice President – India & SAARC at SentinelOne

Author