{"slug": "cyber-security-is-shifting-from-stacking-tools-to-building-one-defence", "title": "Cyber Security Is Shifting From Stacking Tools to Building One Defence", "summary": "Sophos is rebuilding its Sophos Central management platform into Sophos Fusion and launching the Sophos AI-Native Cybersecurity Defense System, an open architecture that connects endpoint, firewall, e-mail, cloud, network and identity controls into a shared security context with more than 500 third-party integrations. Cyber Insight CEO Deon Smal said the shift matters because \"attackers do not operate within those boundaries\" and AI is compressing the time attackers take to move across them, so security teams must focus on how fast a connected environment can detect, decide and respond as a single unit rather than buying more tools.", "body_md": "Organisations are being pushed to abandon a habit that has defined cyber security for more than a decade: buying a new product every time a new threat surfaces. According to Cyber Insight, the rise of AI-driven attacks has exposed the limits of that approach, and the industry is now moving toward environments where security systems share information and act together instead of operating as isolated point solutions.\n\nThe shift is taking concrete form through the Sophos AI-Native Cybersecurity Defense System, an open architecture built to connect security products, services, data sources, AI and human analysts into a single defence. Alongside it, Sophos Central is being rebuilt into Sophos Fusion, the management layer through which customers and partners will interact with this combined system.\n\nThe change matters because attackers no longer respect the boundaries between endpoint, identity, e-mail, network and cloud defences, and AI is compressing the time it takes them to move across those boundaries. What comes next for security teams, according to Cyber Insight CEO Deon Smal, is less about acquiring more tools and more about how fast an already-connected environment can detect, decide and respond as a single unit.\n\n## Why fragmented security struggles against AI-era attacks\n\nFor years, cyber security matured by becoming more specialised. Endpoint protection, identity management, e-mail security, firewalls, cloud security and network monitoring each developed into their own disciplines, often sold and managed as separate products.\n\n“Cyber security has spent years becoming more specialised, but in the process many organisations have also become more fragmented,” says Smal. “Endpoint, identity, e-mail, firewalls, cloud and network security may all be protecting different parts of the business, but attackers do not operate within those boundaries. They move across them.”\n\nThat fragmentation becomes a liability once an attacker gains a foothold. A compromised identity, for instance, can let an intruder move rapidly between applications, endpoints, cloud services and network resources. In a disconnected environment, each security tool may only see its own slice of that activity, leaving analysts to manually piece together whether isolated alerts add up to a coordinated attack.\n\n### A shared context instead of separate silos\n\nThe Sophos AI-Native Cybersecurity Defense System is built to close that gap. Endpoint, firewall, e-mail, cloud, network, identity and other control points feed telemetry into a shared security context, and more than 500 third-party integrations can contribute additional data. That design lets organisations build on security investments they have already made rather than facing an all-or-nothing replacement.\n\nAt the centre of the architecture sits Synchronized Security, which allows something detected by one control point to trigger coordinated action across the rest of the environment.\n\n“Detecting something suspicious is only the beginning,” Smal says. “The real value is what happens next. If an identity system identifies a compromised account, the endpoint, firewall, network and other relevant controls should not have to wait for someone to manually connect the dots before the organisation starts responding.”\n\n| Fragmented security model | Connected defence model | \n|---|---|\n| Each tool detects activity in isolation | Telemetry is shared across a common security context | \n| Analysts manually correlate alerts | Synchronized Security links detection to coordinated action | \n| Response depends on sequential human review | AI and automation compress the gap between detection and response | \n| Adding a threat means adding a new tool | Adding capability means extending an already-connected system | \n\n## AI is changing what happens inside the security operations centre\n\nTraditional security operations have relied on a sequential process: an alert fires, an analyst reviews it, more information is gathered, and only then is a decision made about what action to take. Cyber Insight argues that human judgment is still essential in that process, but the time it takes has become the weak point.\n\nModern attacks can spread across multiple systems while an analyst is still working through the first suspicious event, and as attackers lean further into automation and AI themselves, manual investigation at every stage risks a widening gap between the speed of an attack and the speed of a response.\n\n“The objective is not to remove the analyst,” says Smal. “It is to remove unnecessary delay. Machines are extremely good at processing large volumes of information, identifying relationships and performing repetitive investigative work quickly. Human analysts remain essential where context, judgment and accountability are required.”\n\n### From AI assistance to agentic security operations\n\nA key part of the Sophos system is agentic AI, which does more than surface information for analysts to review. Within boundaries set by security specialists, it can carry out elements of detection, investigation and response itself, letting security work happen at machine speed while people retain oversight of the process.\n\nAI within the system helps correlate signals, investigate suspicious behaviour and initiate defined response actions, while analysts stay responsible for complex decisions, escalation and outcomes. Sophos says the intelligence behind this is continually reinforced across more than 625,000 organisations worldwide, meaning detection and response benefit from patterns observed well beyond any single customer’s environment.\n\n“The discussion should not be framed as AI replacing security analysts,” Smal explains. “The better question is how we use AI to perform the work machines can do at a speed humans cannot, while allowing experienced analysts to concentrate on decisions where context, judgment and accountability matter.”\n\n#### How managed services fit into the model\n\nThis same logic is showing up in the evolution of Sophos Managed Detection and Response (MDR) and Sophos XDR Powered by Secureworks. Sophos MDR now includes agentic threat hunting alongside additional integrations, while Sophos XDR has gained enhanced AI-assisted workflows and capabilities drawn from Secureworks. The intent is to bring telemetry, automated investigation, threat intelligence and human oversight together in one coordinated response model, which also helps organisations that struggle to staff a fully resourced, round-the-clock security operations centre on their own, since cyber attacks do not keep business hours. Cyber Insight pairs Sophos’ global capabilities with a local security operations centre, giving South African organisations access to international threat intelligence alongside locally based expertise.\n\n“Technology can identify activity at enormous speed, but understanding the organisation you are protecting still matters,” says Smal. “That is where the combination of global intelligence, AI-driven capability and local human expertise becomes particularly valuable.”\n\n## Faster response still needs clear boundaries\n\nCyber Insight is careful to note that a faster response does not mean automating every security decision. Blocking an identity, isolating an endpoint or cutting off a connection can be critical during an active attack, but those same actions can also disrupt legitimate business operations if applied without care. That is why organisations need clearly defined boundaries around what should happen automatically and where a human still has to make the call.\n\nAI can handle scale, and automation can carry out established actions, but human experts remain responsible for setting those boundaries and applying judgment when a technical response could carry wider business consequences.\n\n“The strongest security operations model is not the one with the most automation,” says Smal. “It is the one that understands what should be automated, what requires human judgment and how the two work together when an incident is unfolding.”\n\n### Why this matters specifically for South African organisations\n\nCyber Insight frames the shift toward connected defence as especially relevant in South Africa, where many businesses are dealing with rising cyber risk, limited security resources and increasingly complex IT environments at the same time. Adding another product to that mix can mean more licence costs, more dashboards and more alerts without a matching improvement in how quickly the organisation can respond, while the need for continuous monitoring and rapid response keeps growing regardless of whether a business has the resources to build that capability in-house.\n\n“Security complexity ultimately becomes a business problem,” says Smal. “A company can invest heavily in cyber security and still carry unnecessary risk if its technologies, people and processes are operating in isolation.”\n\nCyber Insight’s approach pairs local cyber security expertise and managed security services with Sophos’ global technology and threat intelligence, aiming to help organisations work out how their existing security investments can be folded into a broader, more responsive defence rather than replaced outright.\n\nAs attacks continue to move faster and rely more heavily on automation, Cyber Insight expects organisations will increasingly be judged not just on whether they can detect a threat, but on how much time passes between the first sign of an attack and meaningful action being taken.\n\n“The future of cyber security is not human versus AI,” Smal concludes. “It is about combining machine-speed detection and response with experienced human judgment, within a security environment that operates as one rather than as a collection of disconnected tools.”\n\n*Disclaimer: This content was partially produced with the help of AI tools*", "url": "https://wpnews.pro/news/cyber-security-is-shifting-from-stacking-tools-to-building-one-defence", "canonical_source": "https://www.kobaran.com/cyber-security-is-shifting-from-stacking-tools-to-building-one-defence/", "published_at": "2026-09-10 07:23:52+00:00", "updated_at": "2026-09-10 07:52:42.238892+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-products"], "entities": ["Sophos", "Sophos AI-Native Cybersecurity Defense System", "Sophos Central", "Sophos Fusion", "Cyber Insight", "Deon Smal", "Synchronized Security"], "alternates": {"html": "https://wpnews.pro/news/cyber-security-is-shifting-from-stacking-tools-to-building-one-defence", "markdown": "https://wpnews.pro/news/cyber-security-is-shifting-from-stacking-tools-to-building-one-defence.md", "text": "https://wpnews.pro/news/cyber-security-is-shifting-from-stacking-tools-to-building-one-defence.txt", "jsonld": "https://wpnews.pro/news/cyber-security-is-shifting-from-stacking-tools-to-building-one-defence.jsonld"}}