Reducing Fifty Thousand Cyber Ale...

Reducing Fifty Thousand Cyber Alerts to Fifty Decisions With Tanium

The Business of Cybersecurity by Neil C. Hughes
E46
Sep 12, 2026
19:23

Episode notes

What happens when a security team receives 50,000 alerts but only 50 genuinely need human attention?

In this episode of The Business of Cybersecurity, I speak with Harman Kaur, CTO of Tanium and a reserve cyber officer in the U.S. Air Force, about how AI is changing the pace, structure, and responsibilities of modern security operations.

The long-running cybersecurity talent shortage has not disappeared, but Harman believes the conversation is changing. Security teams now have tools that can assist with specialist work, which places greater weight on processes, interpretation, and decision-making. Training increasingly includes knowing how to ask the right question, assess an AI-generated response, and decide whether the proposed action makes sense.

That change matters because the old pattern of threat response is becoming too slow. Security teams once had time to identify a threat trend, respond to it, and prepare for the next one. Harman says those cycles can now collapse to seconds as AI helps attackers find vulnerabilities and develop exploits. Defenders therefore need to consider whether the same technology can support remediation and patch creation at a comparable pace.

We discuss why traditional scripted automation cannot solve this problem by making the existing workflow slightly faster. If an analyst can manually process 100 alerts and automation raises that number to 200, the improvement offers little comfort when the queue reaches thousands or hundreds of thousands. Harman argues that organizations need to reconsider how the security operation itself is designed while retaining people as judges for decisions with meaningful consequences.

Autonomy, in her view, should be treated as a spectrum rather than an all-or-nothing destination. One process may be suitable for full automation, another may require approval, and a third may remain entirely human-led. That approach also helps CIOs and CTOs respond to pressure for rapid AI adoption without pretending that a single governance model can answer every risk.

Harman also warns against allowing the AI conversation to distract teams from familiar security weaknesses. Shadow AI matters, and companies need visibility into the models and tools being used across the organization. At the same time, phishing, compromised credentials, unpatched machines, end-of-life devices, unused applications, and exposed ports remain common sources of risk. AI may amplify those weaknesses, but it does not erase the need to address them.

The episode’s clearest example concerns alert fatigue. Harman describes an AI system that processes and triages alerts while reporting its confidence and showing how it reached its conclusion. Verification mechanisms can then ask what additional context should be considered. The goal is to narrow 50,000 alerts to perhaps 50 that deserve manual investigation, giving analysts a manageable decision set without asking them to trust a model blindly.

We also discuss operational resilience and why prevention must begin before a security alert appears. Harman challenges organizations to explain why routine patching is not automated in 2026, while recognizing that no company can apply every patch instantly. Reducing the attack surface by removing unused applications and closing unnecessary ports can make the business a smaller target while teams address the vulnerabilities that matter most.

Finally, Harman asks leaders to question why they are applying AI to a given problem. Some tasks can be handled by established automation. If the organization chart, business processes, and toolset look exactly the same after an AI program, the company may have added technology without redesigning the work. Where should your organization allow AI to act, where should it advise, and where must a person make the final decision? Listen to the episode and share your thoughts.

Keywords

Tanium