Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Should organisations prioritise automation or more analysts for…
Cyber Security

Should organisations prioritise automation or more analysts for AI-driven threats?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Cyber Security

Automation should come first because the problem is speed and scale. More analysts may improve judgment, but they do not change the fact that attackers can generate more events than people can review. Organisations need software to absorb routine validation, triage, and containment so analysts can focus on high-confidence exceptions.

Automation or more analysts for AI-driven threats: what actually changes the outcome?

For AI-driven threats, the real constraint is not just headcount. It is the time gap between detection, validation, and response. Attackers can generate large volumes of plausible, adaptive activity that overwhelms manual review, so adding analysts alone rarely closes the gap. The better question is which work can be automated safely, and which decisions still require human judgment. MITRE’s MITRE ATLAS adversarial AI threat matrix is useful here because it frames the kinds of AI-specific tactics that benefit from structured detection and response rather than ad hoc triage.

In practice, many security teams discover the limit of analyst-first models only after alert volume and false positives have already outpaced their ability to investigate consistently.

How automation and analysts divide labour in AI threat response

The most effective operating model is usually a layered one. Automation should handle the repetitive, high-volume work: normalising alerts, correlating signals, scoring obvious low-risk events, triggering containment for well-defined conditions, and routing only the most relevant cases. Analysts then spend time on the parts that need interpretation, such as assessing whether a model behaviour is truly malicious, whether an output pattern indicates abuse, or whether a detected anomaly is part of a broader campaign.

This division matters because AI-driven threats often move faster than conventional response queues. Prompt injection, model abuse, automated phishing content generation, synthetic identity support, and adaptive reconnaissance can all create bursts of activity that look noisy until the pattern is already established. Automation does not replace judgment, but it does create the response capacity needed for judgment to be applied where it matters. Organisations that rely on manual review for everything tend to bottleneck at triage, not at decision-making.

  • Use automation for repeatable verification and containment steps.
  • Use analysts for ambiguous cases, exception handling, and campaign-level interpretation.
  • Measure response quality by time to triage, time to containment, and false-negative tolerance, not by case closure volume alone.

For the broader operational picture, CISA’s cyber threat advisories are a practical reminder that response speed and consistency matter most when adversary behaviour changes quickly. Where automation becomes brittle is in cases that require policy judgment, cross-system context, or high-confidence attribution of intent.

Where the balance changes, and where the simple answer breaks down

Tighter automation often reduces analyst burden, but it also increases the cost of bad tuning, requiring organisations to balance speed against the risk of over-blocking or missing edge cases.

There is no universal consensus that “more automation” is always better. In high-consequence environments, teams may keep more analyst oversight on containment decisions even while automating upstream filtering. That is especially true when AI-driven activity touches customer-facing systems, regulated data, or safety-critical workflows, because false positives can become operational incidents. Conversely, if an organisation is under-resourced and still handles review manually, it may preserve caution while quietly accepting response lag that attackers can exploit.

The best balance depends on the decision type. Routine, reversible actions are good automation candidates. Irreversible actions, policy exceptions, and cases with material business impact need analyst review. Organisations also need to distinguish between tool automation and decision automation: it is usually acceptable to automate the first pass, but not always acceptable to automate final judgment. The common mistake is hiring more people to staff a process that should have been redesigned around machine speed first.

Risk and Threat Considerations

AI-driven threats create a scale and velocity problem that can outgrow human-only operations. The main risk is not merely higher alert volume, but the attacker’s ability to generate enough plausible activity to delay triage, dilute attention, and exploit slow containment.

Failure mechanism: Adversaries use automation, generated content, and adaptive behaviour to increase event frequency, vary patterns, and force analysts into low-value review work. That widens the detection-to-response gap and makes it easier for abuse, persistence, or campaign progression to continue before intervention.

Impact: Organisations can miss early-stage malicious activity, contain incidents late, and spend analyst time on noise instead of high-confidence exceptions. Over time, this can increase dwell time, erode trust in alerting, and create operational overload in the very teams meant to absorb complex threats.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATLAS address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATLASATLAS — Adversarial Threat MatrixAI-driven threats need adversarial technique mapping and detection priorities.
Recommendation — Map AI threat patterns to ATLAS techniques and prioritise automated detection for repeatable abuse paths.
NIST CSF 2.0RS.AN-1 — Incident AnalysisThe question concerns response speed, analysis bottlenecks, and triage capacity.
RS.MI-1 — Incidents are ContainedAutomation is central to rapid containment when alert volume exceeds human review speed.
Recommendation — Use RS.AN-1 to automate initial analysis so analysts focus on high-confidence exceptions. Use RS.MI-1 to trigger containment actions that do not depend on manual queue processing.
CIS Controls v88.1 — Inventory and Control of Enterprise AssetsAI threat response depends on knowing which systems, agents, and tools are in play.
Recommendation — Maintain asset visibility so automation can target the right systems and analysts can trust scope.

Practitioner Guidance

What to prioritise: Build automation around triage, enrichment, and safe containment first. If analysts are still spending most of their time sorting routine events, the operating model is backwards for AI-driven threats.

Decision rule: If a task is repetitive, high-volume, and reversible, automate it. If the action is irreversible, policy-sensitive, or requires cross-context judgment, keep a human in the loop.

What to verify: Confirm that automation is reducing response time without simply shifting work into exception queues. A good programme shows fewer low-value reviews and faster escalation of genuinely ambiguous cases.

Practitioner takeaway: For AI-driven threats, analyst headcount is a multiplier only after automation has absorbed the repetitive load; without that, people become the bottleneck rather than the control.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org