- CISO Series Newsletter
- Posts
- Join us tomorrow for "Hacking Productivity with AI"
Join us tomorrow for "Hacking Productivity with AI"
Join us TOMORROW, Friday [08-21-26], for "Hacking Productivity with AI"
Join us Friday, August 21, 2026, for “Hacking Productivity with AI: An hour of critical thinking about where these tools save you time.”
It all begins at 1 PM ET/10 AM PT tomorrow, with guests Jason Howell, host, AI Inside, and Gerald Auger, founder and host, Simply Cyber. We'll have fun conversation and games, plus at the end of the hour we'll do our meetup in breakout rooms.
Or register once for every upcoming Super Cyber Friday event. No need to sign up week to week.
Defense in Depth
Will AI Replace Detection Roles in Cybersecurity?
AI agents are already starting to handle the grunt work of detection engineering, or essentially finding malware. If AI is now doing the job, what's the future of this role? Or will it completely vanish?
Check out this post from Caleb Sima of Whiterabbit for the discussion that is the basis of our conversation on this week's episode co-hosted David Spark, the producer of CISO Series, and Yaron Levi, CISO, Dolby. Joining is Adrian Ludwig, CSO, Rippling.
Listen to the full episode here.
The messy middle
The challenge facing detection engineering teams goes well beyond writing better rules. "The problem isn't just context and predicting what types of possible threats exist, and it's also not just creating detection rules," said Fred Wilmot of Detecteam. "It means we also have to be able to accurately and completely represent what happens to that contextual value." That scope extends well past detection engineering, he said, into "change management, audit, data provenance, and governance." Meny Har of Spectrum Security described the current model as "entirely unsustainable." The sharpest people on security teams are spending 70% of their time in what he calls the "Messy Middle" — "reconciling threat behaviors with log realities and legacy SIEM logic." Compress that time-to-coverage from weeks to minutes, he said, and the game changes. The 2030 team, in his view, isn't a skeleton crew. "It's a full team of senior practitioners who have transitioned from being mechanics to being conductors. They will direct a fleet of agents to handle the 'Messy Middle' of syntax and tuning, giving them the actual bandwidth to tackle that adversary frontier."
The automatable part
Cutting detection engineers because AI can handle triage misreads the evidence. Mike McCabe of Cloud Security Partners argued the threat environment points in the opposite direction. "We're going to see an acceleration of AI-led attacks against every inch of your attack surface," he said. "Your current team wouldn't suffice, so why would you cut people to save money versus getting a higher percentage of coverage and improved reactions for alerts?" Adam Goss of Kraven Security took direct aim at the most commonly cited justification. "Google's example of automating 99% of triage on 15 years of detection-as-code infrastructure is not evidence that AI agents can replace detection engineering," he said. "It's evidence that mature, structured, labeled data pipelines enable automation downstream of the hard work." The automatable part is writing rules against known TTPs, he said. "Generating novel hypotheses about emerging tradecraft with no historical precedent is what detection engineers are actually paid to do, and that gap doesn't close even as triage automation improves."
Where automation stops
AI-driven detection holds up best against threats that are already understood. Chris Tillett of Palo Alto Networks drew the boundary clearly. "LLMs do not do anomaly detection well," he said. "Not all things anomalous are malicious, but most malicious events are anomalous," which means "you will need humans in the loop for a while." Jordan P of Rivian placed the broader replacement argument in historical context. "Historical automation has never eliminated 80% of a skilled knowledge-work professional category within 5 years," he said. "Even the most aggressive automation waves — manufacturing, data entry, call centers — took decades and rarely achieved 80% elimination in skilled roles." The cybersecurity track record runs counter to the replacement narrative, he added. "Headcount has grown alongside tool adoption — SIEM, SOAR, EDR all augmented rather than eliminated analysts."
The influence gap
Technical orchestration is only part of what the future security team needs. "You need to be able to ultimately derive some outcomes and drive changes, and that's where a lot of engineers have issues," said Anatoly Chikanov of AC Consulting. His vision of the ideal team: two engineers and "a communications/influencer guru." Technical orchestrators managing fleets of AI agents will be essential, he said, but equally critical is "someone to sell the changes upstream to the rest of tech, engineering, and the business."
Please listen to the full episode on your favorite podcast app, or over on our blog, where you can read the full transcript. If you're not already subscribed to the Defense in Depth podcast, please go ahead and subscribe now.
Thanks to our podcast sponsor, ThreatLocker
Subscribe to Defense in Depth podcast
Please subscribe via Apple Podcasts, Spotify, YouTube Music, Amazon Music, Pocket Casts, RSS, or just type "Defense in Depth" into your favorite podcast app.
Cybersecurity Headlines - Department of Know
Our LIVE stream of The Department of Know happens every Friday at 4 PM ET / 1 PM PT with CISO Series producer Richard Stroffolino, and a panel of security pros. Each week, we bring you the cybersecurity stories that actually matter, and the conversations you’ve been having at work all week long.
Friday’s episode will feature Bil Harmer, CISO, Supabase, and David Cross, CISO, Atlassian. Join us on YouTube and catch up on what shaped the week in security.
Thanks to our Cybersecurity Headlines sponsor, Vanta
No degree, no traditional background: how six security leaders broke in anyway
A construction foreman. A CPA. A Marine with a social work degree. All of them ended up running cybersecurity programs, and none took the path you'd expect.
Last month, CISO Series hosted an AMA on r/cybersecurity with six security leaders who broke into the field without a computer science degree or anything close to a traditional route. They walked through what actually got them hired, how to stand out in a brutal job market, and what they wish they'd known sooner.
Thanks to our participants:
David Cross, (u/MrPKI), CISO, Atlassian
Adam Arellano, (u/AdamTalksTheCybers), field CTO, Traceable AI
Krista Arndt, (u/thedrivermod), associate CISO, St. Luke's University Health Network
Mathew Biby, (u/RelativeWolf), director of cybersecurity, TixTrack
Russell Spitler, (u/Extra-Grand-1543), CEO and co-founder, Nudge Security
Mary Carmichael, (u/TheCyberAuditor), field CISO, western Canada, Bell Cyber
Read the full recap article here. Join us on r/cybersecurity again next week for our next AMA, starting on Sunday August 23rd. The topic will be “I left my role as a security practitioner to happily work for a vendor. Ask Me Anything about the other side of the table.”
Introducing: Super Cyber Friday Express!
Can’t make it live on Friday? We'll save the best parts for you.
Super Cyber Friday is where the cybersecurity community comes together to hash out new and challenging ideas, live with David Spark and two guests. Our live show includes a lively chat room full of practitioners, with games, giveaways, and a post-show meetup where we can all talk face-to-face.
Super Cyber Friday Express is the podcast version: the heart of the conversation, and takeaways you can actually use. It’s only 20 minutes and ready on Fridays after our live show. The shortened version of the show gets you the key points on demand, but the full experience only happens LIVE in the room.
Please subscribe to Super Cyber Friday Express via Apple Podcasts, Spotify, Pocket Casts, or just type “Super Cyber Friday Express” into your favorite podcast app.
Help us get the word out! Share next week’s Super Cyber Friday registration link on LinkedIn, tag me (David Spark) and CISO Series, and you'll be entered for a chance to win an item from our prize store. We'll randomly pick one winner from everyone who shares.
Participate! Add our live shows to your calendar
Learn more about all of the fun ways you can participate, and add our events to your calendar.
Google Calendar, iCalendar, Outlook, or export an .ics file
Cyber chatter from around the web...
Jump in on these conversations
"How many cases do you handle per shift in an MSSP SOC? Is ~100 cases per analyst per shift sustainable?" (More here)
"Microsoft warns you to stop using SMS-based passwords because of AI phishing, and it'll block you starting with Entra ID" (More here)
"I understand the job market is tough for everyone, but how is it for mid-level security engineers?" (More here)
Coming up on Super Cyber Friday:
[08-21-2026] - “Hacking Productivity with AI"
[08-28-2026] - “Hacking our Comfort with Autonomous Agents"
Register for and add all of these events to your calendar on our Events Page.
Cybersecurity Headlines - Daily News Shorts
Subscribe to the CISO Series YouTube channel, for daily shorts videos from CISO Series reporter, Rich Stroffolino. You can find all of the stories he’s covered, plus new content every weekday, at the Cybersecurity Headlines Shorts YouTube playlist.
Thank you for supporting CISO Series and all our programming
We don’t just say we appreciate your feedback; we incorporate it into our programming. Learn more about all of the fun ways you can participate.
We love all kinds of support: listening, watching, contributions, What's Worse?! scenarios, telling your friends, sharing on social media, and most of all we love our sponsors!
Everything is available at cisoseries.com.
Interested in sponsorship, contact me, David Spark.






