drj logo

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Zip Code*
Please enter a number from 0 to 100.
Strength indicator
I agree to the Terms of Service and Privacy Policy*
Yes, of course I want to receive emails from DRJ!

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

x
Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Why Subscribe to DRJ
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Fall 2026
    • Call for Presentations
    • DRJ Spring 2027
    • DRJ Scholarship
    • Tracey Rice Memorial Scholarship
    • Other Industry Events
    • Schedule & Archive
  • WEBINARS
    • Upcoming Webinars
    • On Demand
    • DRJ Showcase Series
  • MENTOR PROGRAM
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • DRJ Glossary of Business Continuity Terms
    • Careers
    • The BCI Partnership
  • ABOUT
    • About DRJ
    • 2026 Media Kit
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • DEI
      • Glossary Committee
      • Rules and Regulations Committee

AI Appreciation Day: Cybersecurity Is Finally Having a More Honest Conversation About AI

by Jon Seals | July 15, 2026 | | 0 comments

When generative AI exploded into the mainstream, cybersecurity found itself caught between excitement and anxiety. AI promised to help security teams move faster, uncover more threats and automate repetitive work. At the same time, it gave attackers new ways to scale phishing, discover vulnerabilities and exploit systems at unprecedented speed.

A few years later, the conversation has become far more grounded. AI is no longer viewed as either a silver bullet or an existential threat. Instead, security leaders are learning where it genuinely adds value and where human judgment, governance and operational discipline remain irreplaceable.

That may be the biggest reason to appreciate AI this year.

AI is accelerating both sides of the cybersecurity battle

Few technologies have compressed the pace of cybersecurity like AI. Security teams can analyze more data, uncover vulnerabilities faster and respond more quickly than ever before. Unfortunately, attackers are benefiting from the same capabilities.

As Dhruv Majumdar, VP of Security Solutions at Fleet Device Management, explains, AI is dramatically shortening the gap between discovering a vulnerability and seeing it weaponized.

“AI is helping security researchers uncover vulnerabilities faster than ever before, but it’s also accelerating the speed at which those same weaknesses can be exploited, from days to hours.”

That changing reality makes AI-assisted and eventually autonomous patching inevitable. But Majumdar argues that automation alone isn’t enough. Autonomous systems must understand business context as well as technical risk. A patch shouldn’t reboot a trader’s workstation during a billion-dollar transaction or disconnect a CEO from an important board meeting simply because an update became available. The organizations that combine AI-driven speed with intelligent operational guardrails will ultimately have the advantage.

The cybersecurity workforce is changing

One of the most persistent misconceptions surrounding AI is that it will replace cybersecurity professionals. In reality, it’s changing what expertise looks like.

Laurent Halimi, CEO and founder of Cyberr, believes AI knowledge is rapidly becoming as fundamental as traditional cybersecurity skills. Understanding prompt engineering, LLM risks and the ways attackers weaponize AI is quickly becoming part of the baseline skillset, even for entry-level security practitioners.

“Cybersecurity professionals who invest in AI skills today will likely be the ones leading security teams tomorrow.”

Rather than eliminating jobs, AI is creating new specializations and raising expectations across the industry. The next generation of security leaders will likely be those who combine strong security fundamentals with practical AI expertise.

AI still needs experienced humans

For all of AI’s capabilities, cybersecurity continues to demonstrate that context matters.

According to Gunter Ollmann, CTO at Cobalt, organizations are becoming more realistic about where automation succeeds and where it doesn’t. Cobalt’s research found that 78% of security teams have seen automated scanning tools miss critical vulnerabilities, while support for fully automated pentesting has fallen to just 9%.

Those findings reinforce an important lesson: AI excels at scale, repetitive analysis and identifying patterns, but human researchers remain essential for uncovering business logic flaws, behavioral weaknesses and complex attack paths that require judgment rather than pattern matching.

As organizations increasingly deploy AI applications themselves, that balance between intelligent tooling and expert adversarial testing will become even more important.

Identity isn’t just for humans anymore

As enterprises deploy AI agents capable of making decisions and interacting with sensitive systems, identity management is entering unfamiliar territory.

According to Bojan Simic, CEO and co-founder of HYPR, organizations need to apply the same identity principles they’ve developed for people to non-human actors.

“If you can’t answer exactly who an agent is acting on behalf of, what its boundaries are, and how to stop it in real time, you don’t have a policy.”

That means every AI agent should have verifiable ownership, clearly defined permissions and real-time oversight that allows humans to intervene immediately if an agent behaves unexpectedly. Governing non-human identities may become one of the defining security challenges of the AI era.

Organizations need to prepare for AI failures

Much of the industry’s focus has centered on AI governance, but governance alone won’t prevent incidents.

Models hallucinate. Agents make unintended decisions. Sensitive information leaks.

As AI becomes embedded across customer service, finance, software development and healthcare, those failures increasingly resemble operational crises rather than isolated technology issues.

Arvind Parthasarathi, CEO and founder of CYGNVS, points to Gartner research showing that both sanctioned and unsanctioned AI agents are already widespread inside enterprises, while the OECD AI Incidents and Hazards Monitor recorded hundreds of AI-related incidents in a single month.

“When an AI agent misbehaves, organizations need to activate a cross-functional machinery spanning IT, security, legal, executives, as well as external providers like law firms.”

Preparing for AI incidents may soon become just as important as defending against ransomware.

Better AI begins with better data

While attention often focuses on increasingly powerful models, Amit Shuster, VP of Product and Engineering at Vetric, argues that data deserves far more recognition.

“The real workhorse of the AI era is the data underneath it.”

Attackers are already using AI to automate fraud, impersonate executives and scale cybercrime. Defenders can only keep pace if their own AI systems have access to richer, broader and more timely data than the attackers they’re trying to stop.

AI is finally giving security tools context

Traditional security products have spent decades relying on rules, signatures and pattern matching. They could detect activity, but rarely understood whether it actually mattered.

Roi Vanunu, Director of Product Management at Jazz, believes AI fundamentally changes that equation.

For years, legacy data loss prevention tools struggled because they lacked business context. They could identify that data had moved but couldn’t understand whether the action was legitimate or risky. AI now makes it possible to evaluate intent, user behavior and business context at a scale humans alone could never achieve.

“For the first time, it’s possible to build security tools that don’t just detect—they understand.”

Appreciating AI also means understanding its limits

Perhaps the healthiest perspective comes from Corey Thuen, CEO and co-founder of Gravwell, who argues that AI’s greatest misconception is that it somehow changed how computers think.

It didn’t.

Instead, AI changed how humans interact with computers. That distinction matters because attackers are now “social engineering computers” through prompt injection rather than simply social engineering people.

AI deserves enormous credit for helping researchers uncover vulnerabilities at scale, Thuen says, but organizations shouldn’t mistake fluent language for genuine reasoning. AI predicts text exceptionally well, yet it still lacks the situational understanding needed to distinguish between a legitimate instruction and a cleverly crafted malicious one.

As AI becomes embedded across every aspect of enterprise security, organizations must understand both its extraordinary capabilities and its very human limitations. Learning how to achieve that balance together is worth celebrating.

Related Content

  1. Integration of Cybersecurity into Physical Security Realm
  2. Quantifying Cybersecurity Risk in Alumni CRM Systems
    Quantifying Cybersecurity Risk in Alumni CRM Systems
  3. eDiscovery and Cybersecurity: Protecting Sensitive Data Throughout Legal Proceedings

Recent Posts

Built for Florida First Responders: Public Safety Agencies Across the State Modernize Public Safety Operations with Mark43

August 15, 2026

95% of IT Teams Aren’t Getting the AI ROI They Were Promised – Bridging the Gap Between AI Ambition and Execution

August 13, 2026

Enterprise AI Has Entered Its Operational Era: Stack Automation by Quali Is Now Generally Available

August 13, 2026

Keeper Security Issues Cybersecurity Guidance for Education IT Teams As Students Return to Campus

August 13, 2026

Flashpoint Releases 2026 Global Threat Intelligence Report: Midyear Edition Revealing the Operationalization of AI-Driven Cybercrime

August 13, 2026

Rubicon Professional Services Surpasses One Gigawatt Of Battery Energy Storage Capacity As AI Accelerates Data Center Demand

August 12, 2026

Archives

  • August 2026 (38)
  • July 2026 (83)
  • June 2026 (78)
  • May 2026 (67)
  • April 2026 (70)
  • March 2026 (89)
  • February 2026 (76)
  • January 2026 (61)
  • December 2025 (45)
  • November 2025 (58)
  • October 2025 (78)
  • September 2025 (65)
  • August 2025 (59)
  • July 2025 (70)
  • June 2025 (54)
  • May 2025 (59)
  • April 2025 (90)
  • March 2025 (57)
  • February 2025 (47)
  • January 2025 (73)
  • December 2024 (82)
  • November 2024 (41)
  • October 2024 (87)
  • September 2024 (61)
  • August 2024 (65)
  • July 2024 (48)
  • June 2024 (55)
  • May 2024 (70)
  • April 2024 (79)
  • March 2024 (65)
  • February 2024 (73)
  • January 2024 (66)
  • December 2023 (49)
  • November 2023 (80)
  • October 2023 (67)
  • September 2023 (53)
  • August 2023 (72)
  • July 2023 (45)
  • June 2023 (61)
  • May 2023 (50)
  • April 2023 (60)
  • March 2023 (69)
  • February 2023 (54)
  • January 2023 (71)
  • December 2022 (54)
  • November 2022 (59)
  • October 2022 (66)
  • September 2022 (72)
  • August 2022 (65)
  • July 2022 (66)
  • June 2022 (53)
  • May 2022 (55)
  • April 2022 (60)
  • March 2022 (65)
  • February 2022 (50)
  • January 2022 (46)
  • December 2021 (39)
  • November 2021 (38)
  • October 2021 (39)
  • September 2021 (50)
  • August 2021 (77)
  • July 2021 (63)
  • June 2021 (42)
  • May 2021 (43)
  • April 2021 (50)
  • March 2021 (60)
  • February 2021 (16)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Fall 2026
    • Spring 2026

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal (DRJ) is the leading resource for business continuity, disaster recovery, crisis management, and risk professionals worldwide. With a global network of more than 138,000 practitioners, DRJ delivers essential insights through two annual conferences, a quarterly digital magazine, weekly webinars, and a rich library of online resources at www.drj.com. Our mission is to empower resilience professionals with the knowledge, tools, and connections they need to protect their organizations in a fast-changing world. Join our community by attending our events, subscribing to our publications, and following us on social media.

    LEARN MORE

    LINKEDIN AND TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates

    LinkedIn

    @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2026 Disaster Recovery Journal
    • Terms of Use
    • Privacy Policy

    Register to win a Free Pass to DRJ Fall 2026 | Resilience In Motion

    Leave your details below for a chance to win a free pass to DRJ Fall 2026 | Resilience In Motion. The winner will be announced on August 31. Join us for DRJ's 75th Conference!
    Enter Now