• bitcoinBitcoin(BTC)$65,727.00-1.72%
  • ethereumEthereum(ETH)$1,784.74-2.46%
  • tetherTether(USDT)$1.00-0.03%
  • binancecoinBNB(BNB)$605.51-3.16%
  • rippleXRP(XRP)$1.21-5.06%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$73.22-2.58%
  • tronTRON(TRX)$0.317555-0.62%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.05%
  • HyperliquidHyperliquid(HYPE)$73.548.02%
  • dogecoinDogecoin(DOGE)$0.086741-3.21%
  • USDSUSDS(USDS)$1.00-0.01%
  • leo-tokenLEO Token(LEO)$9.69-1.15%
  • RainRain(RAIN)$0.0140163.24%
  • zcashZcash(ZEC)$502.07-4.86%
  • stellarStellar(XLM)$0.215402-6.96%
  • cardanoCardano(ADA)$0.173180-7.59%
  • moneroMonero(XMR)$341.01-3.00%
  • whitebitWhiteBIT Coin(WBT)$53.89-1.80%
  • CantonCanton(CC)$0.162976-3.80%
  • chainlinkChainlink(LINK)$8.19-3.48%
  • USD1USD1(USD1)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.00-0.02%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.67-7.77%
  • bitcoin-cashBitcoin Cash(BCH)$217.17-3.54%
  • daiDai(DAI)$1.00-0.01%
  • MemeCoreMemeCore(M)$3.187.95%
  • LABLAB(LAB)$12.6028.34%
  • hedera-hashgraphHedera(HBAR)$0.081268-2.33%
  • litecoinLitecoin(LTC)$45.24-1.49%
  • suiSui(SUI)$0.78-3.71%
  • Circle USYCCircle USYC(USYC)$1.130.00%
  • nearNEAR Protocol(NEAR)$2.32-6.64%
  • avalanche-2Avalanche(AVAX)$6.79-3.29%
  • shiba-inuShiba Inu(SHIB)$0.000005-3.28%
  • Global DollarGlobal Dollar(USDG)$1.000.01%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.02%
  • crypto-com-chainCronos(CRO)$0.060106-4.26%
  • tether-goldTether Gold(XAUT)$4,316.500.34%
  • BittensorBittensor(TAO)$253.34-7.03%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • worldcoin-wldWorldcoin(WLD)$0.6511.66%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.130.21%
  • pax-goldPAX Gold(PAXG)$4,327.490.37%
  • uniswapUniswap(UNI)$3.1114.51%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.060074-2.45%
  • mantleMantle(MNT)$0.56-4.79%
  • OndoOndo(ONDO)$0.365427-4.79%
  • AsterAster(ASTER)$0.650.87%
  • polkadotPolkadot(DOT)$1.00-3.05%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Attackers scale deception with AI. Defenders need truth at machine speed.

June 15, 2026
in AI & Technology
Reading Time: 5 mins read
A A
Attackers scale deception with AI. Defenders need truth at machine speed.
ShareShareShareShareShare

Presented by Splunk


AI has changed the economics of cyber deception.

An attacker can now generate thousands of convincing phishing lures, fake identities, and tailored pretexts before a defender finishes a single change-control cycle. That is the new security challenge: deception got faster and cheaper, while verification did not.

YOU MAY ALSO LIKE

Why Your Fire TV Stick Might Be Slowing Down (And How To Fix It)

Hermes Agent Adds Asynchronous Subagents, So Delegated Work No Longer Blocks the Parent Chat

Much of the discussion around AI for defense centers on detection models. Detection matters, but it is not the only bottleneck. The deeper constraint is evidence: where data lives, whether it is available when needed, how quickly it can be correlated, how long it is retained, and whether analysts or agents can trust what they retrieve.

Defense in the AI era is a data problem before it is a detection problem.

The defender’s advantage is truth

Attackers can afford to lie at enterprise scale. They can test endless combinations of messages, identities, domains, and attack paths, and most can fail at almost no cost.

Defenders do not have that luxury. Their advantage is truth: quickly knowing what happened, where, when, which identity was involved, which assets were affected, what changed, and what business process may be at risk.

That truth must be documented, governed, auditable, and defensible. Attackers are using AI to scale deception, impersonation, social engineering, and speed. Defenders need AI to scale verification.

The goal is not just to act faster than the attacker. It is to take action that people and machines can trust.

Fragmented data breaks modern defense

Consider a suspicious login from a contractor account. On its own, it is just another authentication anomaly. To know whether it matters, a security team may need identity history, endpoint activity, cloud access logs, ticketing records, asset ownership, configuration changes, network telemetry, and business context.

If those records sit in different tools, expire at different times, or require multiple teams to retrieve, defenders are not investigating the incident. They are negotiating with their own data estate.

When signals can be reached in place and correlated quickly, the issue is no longer just whether the login looks unusual. It becomes whether the enterprise has enough evidence, in enough context, to take action it can defend.

That challenge grows more urgent with AI assistants and agents. AI can only reason over what it can retrieve in time to matter. If the data is partial, stale, fragmented, unavailable, or stripped of context, AI does not create truth. It accelerates uncertainty.

The system of record must become a defensive control plane

For years, enterprises treated security platforms, SIEMs, and data lakes as passive repositories: places to store data for later search and analysis. That model is no longer enough.

What organizations now need is a defensive control plane: a layer that connects what happened, what it means, and what the enterprise is allowed to do about it. In architectural terms, it ties together raw machine data, business context, and policy. It does not just store evidence. It makes evidence usable for decisions and actions that must be explainable and trusted.

In practice, that means doing four things well: preserving evidence, reaching data wherever it lives, adding business context, and governing action. More on each below.

The old system of record answered one question: What is the official record?

A defensive control plane answers the questions that matter operationally: What happened? What does it mean? What evidence supports that conclusion? And what action can we trust?

AI does not reduce the need for authoritative records. It raises the standard for what those records must do.

A defensive control plane must do four things

  1. Preserve evidence. Logs, metrics, traces, events, identity records, configuration changes, tickets, and asset state all help establish what happened. Their value often becomes clear only after an incident begins.

  2. Make data accessible wherever it lives. Security-relevant data is already spread across object stores, cloud platforms, operational tools, and business systems. Moving every byte into one place is often too slow, too expensive, and too difficult to govern. The better model is to bring analytics to the data.

  3. Add business context. Correlating machine data with business information turns “anomaly on host X” into “the system supporting payment services for top accounts is being probed.” That is what allows organizations to prioritize correctly.

  4. Govern action. In the agentic era, systems will do more than summarize incidents. They will enrich alerts, open cases, trigger workflows, isolate assets, update policies, and escalate decisions. Enterprises need to know what evidence an agent used, what policy governed the action, whether it stayed within scope, and how the decision can be reviewed afterward.

The real SOC problem is not too little data

Modern SOCs are not suffering from a lack of data. They are suffering from a lack of usable context.

According to the Splunk State of Security 2025 report, SOC analysts continue to struggle with too many alerts (59%), too many false positives (55%), and alerts that lack context (46%). The issue is not data volume. It is the difficulty of turning fragmented signals into trusted decisions.

Today, analysts are left stitching together context manually, pivoting across disconnected tools, and making high-stakes decisions without the full picture in time. Even as AI improves, outcomes still depend on whether humans are willing to approve changes across fragmented environments.

This creates a daily crisis of context. Teams are forced to make consequential decisions based on data they cannot easily see, correlate, or trust. The result is latency, inconsistency, missed opportunities, and unnecessary risk.

Trusted action is the durable advantage

A data fabric architecture offers a way forward by creating a unified, intelligent layer across data sources spanning SecOps, ITOps, and NetOps. The goal is not centralization for its own sake. It is to break down silos and deliver context-rich insight at the speed AI-driven operations require.

This is an operating model before it is a product. AI-driven defense depends on a foundation that can preserve evidence, reach data where it lives, add context, and maintain a reviewable link between data, decision, and action. That is the architectural shift behind Cisco Data Fabric powered by the Splunk Platform, which brings together machine data, federation, business context, governance, and provenance to help teams move from signal to trusted action.

Attackers will keep making deception cheaper, faster, and more personalized. Defenders do not win that race by generating more noise. They win by making truth faster, and by grounding every action in evidence that people and machines can trust.

Learn more about the Cisco Data Fabric powered by the Splunk Platform.

Seth Brickman is VP, Global Product – Splunk Platform, Cisco.


Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact [email protected].

Credit: Source link

ShareTweetSendSharePin

Related Posts

Why Your Fire TV Stick Might Be Slowing Down (And How To Fix It)
AI & Technology

Why Your Fire TV Stick Might Be Slowing Down (And How To Fix It)

June 16, 2026
Hermes Agent Adds Asynchronous Subagents, So Delegated Work No Longer Blocks the Parent Chat
AI & Technology

Hermes Agent Adds Asynchronous Subagents, So Delegated Work No Longer Blocks the Parent Chat

June 16, 2026
Meet Atoms: A Vibe Coding Tool That Uses AI Agents to Build, Deploy, and Market Your App (No Code)
AI & Technology

Meet Atoms: A Vibe Coding Tool That Uses AI Agents to Build, Deploy, and Market Your App (No Code)

June 16, 2026
Google Cloud Introduces Open Knowledge Format (OKF): A Vendor-Neutral Markdown Spec for Giving AI Agents Curated Context
AI & Technology

Google Cloud Introduces Open Knowledge Format (OKF): A Vendor-Neutral Markdown Spec for Giving AI Agents Curated Context

June 16, 2026
Next Post
U.S. And Iran Reach Peace Deal To Reopen The Strait of Hormuz

U.S. And Iran Reach Peace Deal To Reopen The Strait of Hormuz

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Trump says ceasefire with Iran is ‘on massive life support’

Trump says ceasefire with Iran is ‘on massive life support’

June 10, 2026
A Guide to the Biggest Winners From the SpaceX IPO – WSJ

A Guide to the Biggest Winners From the SpaceX IPO – WSJ

June 14, 2026
Apple Reportedly Has Three More iOS 27 Features Coming In The Fall

Apple Reportedly Has Three More iOS 27 Features Coming In The Fall

June 14, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!