{"slug": "ai-security-operations-and-the-new-race-against-time", "title": "AI, security operations and the new race against time", "summary": "Anthropic's Project Glasswing and Mythos model, alongside OpenAI's Daybreak and DeepSeek advances, are accelerating AI capabilities in cybersecurity, compressing vulnerability discovery and response cycles from weeks to days or hours, according to CSOonline. Security leaders now prioritize operational speed over information gathering as AI simultaneously accelerates offense and defense, with the bottleneck shifting to how quickly organizations can act on intelligence.", "body_md": "When Anthropic unveiled Project Glasswing and the Mythos model, much of the discussion focused on the capabilities themselves.\n\n[Security leaders debated](https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html?utm=hybrid_search) what these systems could mean for vulnerability discovery, exploit development and the pace of offensive innovation. Researchers examined technical benchmarks. Industry observers questioned how quickly these capabilities might fall into attackers’ hands.\n\nThose conversations are important. They also point to a larger question that predominates my discussions with CISOs: How much time do we have?\n\nOver the past year, conversations about AI in cybersecurity have changed noticeably. Twelve months ago, security leaders wanted to understand whether AI could meaningfully improve security operations. They wanted to know whether it could accurately investigate alerts, reduce analyst workload and operate reliably in production environments.\n\nToday, security leaders are asking about timelines, implementation, how quickly AI is changing the threat landscape and what that means for [how security teams operate](https://www.csoonline.com/article/4158008/the-ai-inflection-point-what-security-leaders-must-do-now.html).\n\nAnthropic’s Mythos and Glasswing, OpenAI’s Daybreak and advances in DeepSeek accelerate those conversations. Each development provides another glimpse into the pace at which AI capabilities are advancing.\n\nAI now reasons through security problems that historically required highly specialized expertise. The implications span vulnerability discovery, attack-path analysis, reconnaissance, social engineering and security operations.\n\nThe shift reflects a broader reality: cybersecurity is entering a period where the pace of adaptation may matter as much as the quality of defenses themselves. AI is accelerating both offense and defense simultaneously. Organizations are quickly redesigning security operations around that reality.\n\nOne consequence is becoming increasingly visible. For years, cybersecurity teams invested enormous effort in discovering threats, identifying vulnerabilities, gathering telemetry and collecting intelligence. AI is accelerating many of those activities simultaneously. Visibility is improving. Discovery is accelerating. Investigations are becoming faster and more comprehensive.\n\nThe bottleneck is beginning to move. The challenge increasingly centers on how quickly organizations can act on what they know. The organizations that gain an advantage may not be the ones with the most information. They will be the ones who can operationalize that information the fastest.\n\nCybersecurity has experienced many major technology transitions. Cloud computing changed infrastructure. Mobile devices expanded the attack surface. Digital transformation connected systems that were previously isolated.\n\nAI introduces a different dynamic.\n\nMost technology transitions unfolded over years. Organizations had time to evaluate, pilot, deploy and gradually adapt operating models.\n\nThe current AI cycle moves at a different pace.\n\nCapabilities improve continuously. New models arrive every few months. New research emerges every few weeks. Security teams absorb developments at the same time attackers do.\n\n[Vulnerability discovery](https://www.csoonline.com/article/4155342/what-anthropic-glasswing-reveals-about-the-future-of-vulnerability-discovery.html) provides a useful example. Security teams have long operated around a familiar cycle of discovery, validation, remediation and protection. AI systems accelerate every stage of that process. Similar patterns exist in phishing, reconnaissance, social engineering and attack planning.\n\nA vulnerability that once moved through that cycle over weeks increasingly now moves through those stages in days or, in some cases, hours.\n\nAttackers are already operating at the speed of AI. Defenders are now focused on reaching the same level of operational speed.\n\nThis shift is changing the questions CISOs ask.\n\nEarly discussions focused on capability. Could AI investigate alerts accurately? Could it operate reliably in production environments? Could it be trusted with meaningful security work?\n\nAs organizations gained experience with AI, the discussion shifted toward implementation. Security teams began evaluating where AI could create operational leverage and how quickly they could deploy it into existing workflows.\n\nToday, many CISOs are focused on timing.\n\nThe pace of advancement is influencing planning horizons, budget decisions and operating-model discussions. Security leaders are evaluating how quickly they can introduce AI into investigations, threat hunting, detection engineering and response workflows. Boards are asking questions. Executive teams are paying attention.\n\nSecurity programs that once viewed AI as a future initiative increasingly view it as a current operational priority.\n\nThe industry is moving from evaluating AI as a technology to incorporating AI as a security capability.\n\nThe timeline compression creates pressure on the traditional security operations model. Investigation speed, response speed and defensive coverage increasingly determine whether organizations can keep pace with adversaries operating with AI assistance.\n\nThe impact of AI is becoming particularly visible inside the SOC.\n\nMany security operations centers were built around a straightforward assumption: alerts flow to human analysts who conduct investigations. Operational capacity scales primarily through hiring.\n\nThe volume of security data, the number of alerts and the complexity of modern environments have steadily increased. Security teams have responded by building processes, adding tools and creating specialized analyst roles.\n\nAI introduces a new source of operational capacity.\n\nInvestigations that require analysts to examine dozens or hundreds of artifacts across endpoint, identity, cloud, network and email systems can now be performed in minutes. Analysts gain access to investigative depth and consistency that would be difficult to achieve manually at scale.\n\nMany security leaders now view this capability through the lens of operating model design. They are examining how investigations are performed, how work is distributed and where human expertise creates the greatest value.\n\nOne of the most important developments emerging from early production deployments is the [evolution of analyst responsibilities](https://www.csoonline.com/article/4163299/the-manager-of-agents-how-ai-evolves-the-soc-analyst-role.html).\n\nSecurity analysts remain central to security operations. Their expertise becomes even more valuable as AI systems take on larger portions of investigative work.\n\nThreat hunting, detection engineering, response strategy, governance and oversight are receiving increased attention. Analysts spend more time shaping how investigations are conducted, evaluating outcomes and improving overall security operations.\n\nMany organizations are already beginning this shift.\n\nTeams are investing more heavily in proactive security activities. Detection engineering programs are expanding. Threat hunting is becoming more accessible. Analysts are spending more time improving systems and less time repeating investigative tasks.\n\nThese changes create what I think of as an analyst-amplified SOC: an environment where AI expands the reach of security professionals and enables deeper security work across the organization.\n\nFaced with a compressing timeline, the instinct is to treat speed and trust as a trade-off, i.e., move faster, verify less. That trade-off feels inevitable. It isn’t.\n\nYou don’t trust AI in the abstract. You trust that a system understands your tools, your telemetry and the edge cases that only exist in your network. The problem was never speed. It’s speed without context. The faster a context-blind system runs, the more decisions you’re left unable to verify.\n\nThe tension eases when the system is quick to deploy and tunes to your environment once it’s there, rather than treating every network the same. Speed stops being the thing you trade against trust. The more it learns about your environment, the sharper and more trustworthy it becomes, so the two compound rather than compete. Trust still develops through operational evidence such as measurable outcomes, visibility into decisions and consistent performance. But where that evidence accrues matters.\n\nThe organizations making the fastest real progress understand this. They don’t compromise quality and trust for speed. They invest in AI that earns trust inside their own environment, so they don’t have to choose.\n\nThe conversations surrounding Mythos and Glasswing reflect a broader reality facing security leaders.\n\nAI is becoming part of both offense and defense. Security teams are incorporating it into investigations, detection engineering, response workflows and threat hunting. Attackers are incorporating it into their own operations.\n\nSecurity leaders have an opportunity to modernize operating models, expand defensive capacity and build organizational experience while these capabilities continue to evolve.\n\nThe organizations making progress today are investing in readiness. They are building experience, adapting workflows and preparing teams for a new model of security operations.\n\nThe next phase of cybersecurity will be defined by how effectively organizations combine human judgment with machine-scale execution.\n\nThe question facing security leaders is increasingly clear: How quickly can their organizations adapt to a continuously changing threat environment?\n\n**This article is published as part of the Foundry Expert Contributor Network.****Want to join?**", "url": "https://wpnews.pro/news/ai-security-operations-and-the-new-race-against-time", "canonical_source": "https://www.csoonline.com/article/4198963/ai-security-operations-and-the-new-race-against-time.html", "published_at": "2026-07-22 09:00:00+00:00", "updated_at": "2026-07-22 09:30:02.532310+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy", "ai-research"], "entities": ["Anthropic", "OpenAI", "DeepSeek", "CSOonline"], "alternates": {"html": "https://wpnews.pro/news/ai-security-operations-and-the-new-race-against-time", "markdown": "https://wpnews.pro/news/ai-security-operations-and-the-new-race-against-time.md", "text": "https://wpnews.pro/news/ai-security-operations-and-the-new-race-against-time.txt", "jsonld": "https://wpnews.pro/news/ai-security-operations-and-the-new-race-against-time.jsonld"}}