TL;DR: Security leaders from Wiz, Rubrik, Noname, and Abnormal discuss the threats targeting their own companies, how they prioritise defensive tools, and why automation is becoming more important amid the cybersecurity skills shortage, according to Abnormal AI. The resource is best read as a signal that operational pressure is driving security teams toward automation and tighter prioritisation, not as a product story.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “How 4 Cybersecurity Companies Protect Against Cloud Vulnerabilities”.
Key questions
Q: How should security teams decide which defence workflows to automate first?
A: Start with repetitive, well-bounded workflows that have clear inputs, clear outputs, and low exception rates.
Q: Why does automation become more important when security teams are short-staffed?
A: Because staffing pressure exposes the limits of manual governance.
Practitioner guidance
- Define automation boundaries for high-risk controls Separate routine detection and response tasks from privileged access decisions, approval gates, and exception handling so automation does not erode governance over sensitive actions.
- Map tool priorities to governance outcomes Assess each tool by the control outcome it enables, such as reduced response time, better visibility, or clearer ownership, rather than by feature volume alone.
- Shorten policy-to-response cycles Review how quickly threat intelligence becomes policy change, then how quickly that change is enforced in operations across identity and security workflows.
Bottom line: Security operations are being reshaped by the need to cope with faster threat change and limited human capacity.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Automation is becoming a governance necessity, not a convenience. When security leaders say they are turning to automation, the underlying issue is not novelty but scale mismatch. Threat volume, staffing constraints, and tool sprawl are forcing programmes to move from manual oversight to policy-driven enforcement. For identity teams, the important question is which decisions can be automated without turning governance into blind trust.
A question worth separating out:
Q: What do identity teams get wrong about automation in access governance?
A: They often treat automation as a substitute for governance rather than a way to make governance scalable. Automation still depends on clear policy, accurate entitlement data, and accountable reviewers. If those inputs are weak, faster workflows only amplify bad decisions.
👉 Read our full editorial: Security leaders on automation and emerging threats in cyber defence