CISO ME Issue 02 | Page 16

COVER story

We realise that today many attackers are trying to weaponise AI. If you are trying to detect and protect against these threats using non-AI approaches, obviously, you are not going to be successful. proactive and address issues before they turn into business problems.
This was also a key part of our decision-making process. Today, obviously, our partnership with Palo Alto Networks makes that very possible.
The platform comes with extensive AI and automation capabilities. Can you tell us how are you leveraging it?
We realise that today many attackers are trying to weaponise AI. If you are trying to detect and protect against these threats using non-AI approaches, obviously, you are not going to be successful.
In the past, it could take days and sometimes weeks to address a particular incident. Now, with AI, things are moving within hours, minutes and, in some cases, seconds. By the time you respond, it could already be too late. AI definitely brings huge value.
What percentage of your security workflows are automated today?
Today, I think we are at around 70 %. I was actually reviewing this earlier in the week and, in some cases, we have achieved even more than 70 %.
Do you see a scenario where AI could actually replace analysts in the SOC, or will you always need a human in the loop?
I don’ t believe it will be either / or. It will be humans and AI working together. Human-centred security on its own is not sufficient and I don’ t think AI by itself is sufficient either.
Sometimes, you have a large number of vulnerabilities that need to be assessed and you need to make a decision on whether to remediate them. That is where the human factor comes in.
As an organisation, we also do a lot of acquisitions. By design, as part of the due diligence process, we engage our security team to carry out assessments. We would rather automate routine activities and allow our team to focus on the strategic elements of the business.
We have never been in a position where we wanted to staff the organisation with tens of SOC analysts. At the end of the day, we are an FMCG company and we will continue to focus on our core business. We simply want to ensure that we have a lean structure in place and that structure will continue to exist.
16 WWW. INTELLIGENTCISO. COM / MIDDLE-EAST