Issue 1 · June 2026
The conference floor is a warning
Every conference I have attended this year has shown me the same uncomfortable pattern. The AI booths are full, and the cybersecurity conversation is getting thinner. Walk onto any technology show floor today and you feel the pull immediately. AI is everywhere: AI for operations, for compliance, for governance, for support, for development, for risk, even AI for cybersecurity itself. Every product has it bolted on, wrapped around, or printed in large letters behind the booth, and the crowds move toward it the way crowds always move toward the loudest promise.
I have watched it happen. Delegates walk into the exhibition hall and their eyes go straight to the booths making the biggest claims: autonomous this, agentic that, a copilot for everything. The bigger the claim, the thicker the crowd. Then some of them stop at the Elytra booth, and I explain what we actually do: security posture you can evidence, telemetry you can trust, detection logic that holds up, compliance gaps and operational risk that boards, regulators and customers should genuinely care about. And while I am speaking, I watch their eyes drift over my shoulder to the AI vendors behind me. They are standing in front of me, but they have already left.
That is the moment the realisation landed. This is not simply technology adoption. It is a kind of market spell, and AI has become the shiny object that makes otherwise intelligent people suspend their judgment. Not always, not everyone, but often enough to matter.
Let me be clear, because this is not an anti-AI article. AI is genuinely useful. Used well it summarises, correlates, enriches, drafts and accelerates; it removes drudgery and gives skilled people better leverage. But what I am seeing on these floors is not careful adoption. It is surrender. And in cybersecurity, surrendering your judgment is dangerous.
AI has become the shiny object that makes otherwise intelligent people suspend their judgment.
The layoff logic
Across the world, companies large and small are cutting people by the thousands: product companies, service companies, startups, large enterprises, even cybersecurity firms. The explanations are well rehearsed: restructuring, efficiency, market correction, resource reallocation, AI-led transformation, future readiness. The language is polished. The direction is blunt: fewer people, more automation, and a growing belief that the technology can simply absorb the work.
On paper it looks attractive. Headcount is expensive: salaries, benefits, training, management, patience. AI subscriptions look scalable, automation looks modern, and announcing an AI investment while trimming roles looks decisive. It may even impress investors for a quarter or two.
But cybersecurity is not an ordinary productivity function, and cutting experienced security people is not the same as automating invoice routing or summarising meeting notes. Security is not a workflow. It is an adversarial discipline. The moment leadership forgets that, the organisation starts confusing efficiency with resilience, and that is a dangerous mistake.
The expendable A-Team
The title of this piece is deliberate. It borrows from two familiar cinematic ideas: The A-Team and The Expendables. In both, the people who matter most are not the polished new faces in the room. They are the veterans, the operators who have seen too much and survived too much, who know exactly how things break when theory meets reality. They are written off as old, outdated, no longer part of the shiny future. In a word: expendable. Right up until the mission goes wrong, at which point the same people everyone dismissed turn out to be the ones who can read the situation, improvise under pressure, see the trap and get everyone out alive.
That is precisely what is happening in cybersecurity. Experienced defenders are becoming the corporate version of that expendable team. They may not speak in the fashionable language of the moment, or own the slickest booth or the loudest slogan. But when a real attack is unfolding, they are often the only ones who can look at a weak signal and say, “that is not normal”, and that single sentence is sometimes worth more than an entire stack of automation.
Cybersecurity is not a clean dataset
The current AI conversation tends to assume enterprise problems are simply sitting there waiting to be automated. Feed the data, train the model, build the agent, automate the workflow, shrink the team, improve the margin. It is a convenient story. It is also incomplete.
Cybersecurity does not behave like a tidy enterprise process. Attackers do not raise tickets or follow your process maps. They do not wait for complete context or trip high-confidence alerts on cue. They live in the gaps: abusing legitimate access, exploiting timing, chaining weak signals, hiding inside normal activity, taking advantage of overworked teams, fragmented telemetry, poor asset visibility, weak identity hygiene and executive overconfidence.
They do not need your whole system to fail. They need one assumption to fail.
That is what makes security different. A normal automation problem asks how to make a known process faster. A security problem asks what happens when an intelligent adversary deliberately avoids the known process. That difference is everything.
AI analyses. Humans notice.
One of the biggest misunderstandings in this debate is the assumption that intelligence always means analysis. In security, some of the most important human contribution is not analysis after the fact. It is recognition before the facts are complete.
An experienced analyst does not always need a full report to know something is wrong. They look at an authentication trail and the timing feels off. They glance at a process tree and the parent-child relationship is clearly wrong. They notice an account behaving in a way that technically passes policy but operationally makes no sense, or a system that has gone suspiciously quiet, or a sequence of events that would never trip a critical alert individually but together has the unmistakable shape of compromise. Sometimes the problem is not in any single log. It is in the rhythm, and in the change in rhythm.
That recognition is not magic, and it is not gut feel in the careless sense. It is compressed experience: the accumulated memory of incidents, false positives, bad implementations, strange exceptions, failed controls, attacker tradecraft and business reality. A model may need the logs assembled, normalised, enriched, queried and interpreted; it needs a prompt, a workflow, a confidence score, and a human to ask the right question in the first place. A human who knows the environment can see the anomaly in seconds.
And during an active attack, seconds matter. A few seconds can change the containment decision. A few minutes can change the blast radius. A few hours can change the regulatory and customer impact. The first person to notice often decides whether an event becomes an incident, and whether an incident becomes a crisis.
The novel attack problem
AI is strongest when the pattern is known, inferable, or well represented in the data. But attackers win by breaking patterns. They go looking for the grey zone: where the signal is weak, where the activity is strange but not obviously malicious, where the tool hesitates and the dashboard shows yellow rather than red, where the alert looks like a false positive until the third move. That grey zone is exactly where human defenders earn their keep.
Novel attacks do not arrive with labels. They do not announce themselves. They look like noise, like edge cases, like business as usual with one small thing wrong. A good defender is the person who keeps pulling on that one small wrong thing until the larger pattern finally shows itself. None of this romanticises human analysts: people get tired, make mistakes and miss things; they need tools, automation, better data and better interfaces. But replacing human judgment with tool confidence is not modernisation. It is fragility dressed up as progress.
The boardroom misread
Many boards and executive committees are asking the wrong question. They are asking how much work AI can replace. In some functions that is reasonable. In cybersecurity it is insufficient. The better question is where AI improves resilience, and where removing humans creates risk the business cannot accept.
That question forces leadership to separate tasks from capability. The two are not the same thing, and treating them as interchangeable is how a company hollows itself out.
| What you automate | What you cannot |
|---|---|
| Alert summarisation | Incident judgment |
| Log classification | Adversarial reasoning |
| Report drafting | Board-level risk interpretation |
| Playbook execution | Knowing when the playbook is wrong |
This is where organisations get confused. They see tasks that can be automated and assume the underlying capability can be reduced. The visible work disappears first, the invisible judgment disappears quietly, the savings show up immediately, and the risk compounds in the background, until an incident finally exposes the gap.
Failed pilots, real consequences
A large share of AI proof-of-concept projects still never become durable production systems. Plenty of organisations are experimenting aggressively, spending heavily, and still struggling to turn pilots into measurable value. That should give leaders pause. If companies struggle to make AI work reliably in ordinary workflows, why are they so confident it can replace human judgment in one of the most adversarial, ambiguous and high-consequence domains in the business?
Too often that confidence is not evidence-based. It is fashion: vendor pressure, board pressure, investor pressure, the fear of looking outdated, the career risk of being the person who says “we should slow down and think.” But slowing down and thinking is precisely what leadership is for. A company recovers from a failed AI pilot. It does not recover as easily from a breach caused by missing judgment.
The customer inherits the risk
This is not only an internal workforce question. When companies hollow out their security teams, customers inherit the consequences: slower detection, weaker escalation, poorer incident judgment, delayed containment, more fragile vendor ecosystems, and teams that have tools but not enough experienced people to challenge them. The same decision wears a different name depending on who is describing it:
| Internal framing | External consequence |
|---|---|
| A company calls it efficiency | A customer experiences exposure |
| A board calls it transformation | A regulator may call it failure of due care |
| An executive calls it modernisation | An attacker simply calls it opportunity |
The false comfort of autonomous defence
There is a phrase that worries me every time I hear it: autonomous cybersecurity. It sounds powerful, inevitable, like the future. Autonomous action genuinely helps in defined scenarios: blocking known-malicious indicators, isolating endpoints under set conditions, enriching alerts, suppressing noise, executing low-risk playbook steps. The trouble is that the more ambiguous the situation, the more dangerous blind autonomy becomes.
Should we isolate this server in the middle of peak business hours? Disable this executive’s account? Notify customers now, or preserve evidence first? Escalate to legal? Assume compromise even though the indicators are incomplete? These are not purely technical decisions. They are business decisions made under uncertainty, and they require judgment, accountability and context.
A tool can recommend. A human must own.
The work AI should actually do
The answer is not to reject AI. That would be foolish. It is to put AI where it increases resilience without weakening accountability. Let it remove drudgery and cut noise; let it summarise long logs, enrich indicators, cluster related events, assist detection engineering, help junior analysts make sense of unfamiliar artefacts and draft first-pass reports. The correct operating model is not AI versus humans. It is human-machine teaming with clear accountability.
| Machines | Humans |
|---|---|
| Handle scale | Handle ambiguity |
| Accelerate | Judge |
| Correlate | Challenge |
| Draft | Decide |
The cost of calling experience expendable
Experienced security professionals are being badly misread: seen as expensive, as legacy, as replaceable by tools. But experience is not legacy. In cybersecurity, experience is threat memory: the ability to recognise how small failures turn into large incidents, to see how business pressure quietly creates control bypasses, to know the first answer is usually incomplete, and to smell trouble before the dashboard confirms it. That is most missed at the exact moment the organisation is already in trouble.
Questions a serious board should ask
- Which security tasks are genuinely repetitive enough to automate safely?
- Which decisions must still require explicit human approval?
- Which parts of detection and response depend on tacit knowledge?
- Who actually understands our environment well enough to spot a weak signal?
- What expertise would be painfully hard to rebuild if we cut it now?
- Could we defend our AI-led security decisions to a regulator, insurer, auditor or court?
- Where might automation be creating a false sense of security?
- Which of our AI pilots have measurably reduced risk, not merely produced a demo?
The closing signal
The AI booths are full, the market is excited, and the promises are loud. But behind the noise, a quieter decision is being made inside many organisations: experienced defenders are being treated as expendable. That is a mistake. When the attack is novel, the indicators are weak, the logs are incomplete, the business impact is unclear and the clock is running, no organisation is saved by fashion. It is saved by people who know how to notice, who can think under pressure, who will challenge the tool, and who recognise the break in the pattern before it becomes obvious.
AI will be part of the future of this field; there is no doubt about that. But if companies use it as an excuse to discard the very people who make security resilient, they will not be building that future, they will be weakening it. The future of cybersecurity is not fewer humans. It is better humans, supported by better machines.
The A-Team looks expendable when the lights are bright, the booths are polished and the slogans come easy. When the mission goes wrong, they are the ones everyone wishes they had kept.
The closing signal
Cybersecurity is not just pattern matching. It is pattern breaking.
