Cybersecurity companies look to artificial intelligence as they struggle to find human workers

If you’re going to the play the “AI” drinking game at RSA Conference 2019, you may not make it out alive.
Ahead of the industry’s largest trade show in San Francisco, vendors are already touting AI-based solutions meant to address one of the industry’s most pressing issues: a scarcity of workers qualified to defend against cyberattacks. Over the past week, both Palo Alto Networks Inc. PANW, -0.70% and Microsoft Corp. MSFT, +0.50% announced new AI-branded services to address an often-cited lack of cybersecurity workers qualified to keep on top of an exponentially growing number of cyberattacks.
In a report released Thursday, however, Cisco Systems Inc. CSCO, -0.58% said that the industry may actually be cooling to AI-powered cybersecurity. In a survey of more than 3,000 security experts, two-thirds said they would rely upon AI, down from the 74% who said they would in 2018.
Cisco found that chief information security officers, also known as CISOs, “are increasingly confident that migrating to the cloud will improve protection efforts, while apparently decreasing reliance on less proven technologies such as artificial intelligence.”
“AI and machine learning, used right, are essential to the initial stages of alert prioritization and management,” the Cisco report said. “However, reliance on these technologies has decreased as respondents possibly perceive the tools to be still in their infancy or not ready for prime time.”
But cybersecurity firms may have little choice to go after AI solutions as they struggle to find qualified workers who can develop products or respond to threats. When Microsoft announced its Azure Sentinel offering this week, Ann Johnson, who heads Microsoft’s cybersecurity solutions group, said in a blog post that the AI security product is meant to address an projected shortage of about 3.5 million qualified cybersecurity workers by 2022, citing an estimate from research firm Cybersecurity Ventures.
Microsoft touted its Azure Sentinel product as the first native security information and event management, or SIEM, tool within a major cloud platform. Johnson said early adopters of Azure Sentinel have reported an up to 90% reduction of alert fatigue, where already stressed cybersecurity workers find themselves chasing what prove to be false alarms, and that threat hunting times which used to take hours have been reduced to seconds.
Microsoft unveiled Sentinel just two days after Palo Alto Networks discussed its own new offering, the Cortex XDR security product, which Palo Alto Networks touted as “the industry’s only open and integrated, AI-based continuous security platform.” That was announced late Tuesday in conjunction with a huge earnings beat and outlook from Palo Alto Networks.


