TLDR: Artificial intelligence is increasingly empowering cybersecurity defenders more than attackers, according to Steve Ledzian of Mandiant. While cybercriminals leverage AI for sophisticated phishing and deepfake-driven BEC attacks, the advent of ‘agentic AI’ is revolutionizing defensive capabilities. This advanced AI automates complex tasks, enhances efficiency in Security Operations Centers (SOCs), and reduces analyst burnout, moving towards a vision of fully autonomous security operations.
Bengaluru, India – In the ever-escalating arms race of cybersecurity, artificial intelligence is currently providing a significant edge to defenders, outpacing the capabilities of malicious actors. This perspective comes from Steve Ledzian, CTO, Google Cloud Security, JAPAC at Mandiant, who recently stated in an interaction with The New Indian Express, “But as of now, AI is helping defenders more than attackers.”
While cybercriminals are indeed harnessing AI to refine their tactics, such as eliminating spelling and grammar errors in phishing attempts to craft more believable emails, and employing deepfakes in sophisticated Business Email Compromise (BEC) attacks, the defensive applications of AI are proving more transformative. Ledzian highlighted a recent case in Hong Kong where an attacker successfully stole $25 million by using deepfake technology to impersonate an individual during a payment verification call, demonstrating the advanced nature of AI-powered threats.
However, the benefits for defenders are substantial. AI is making existing security professionals significantly more efficient, enabling them to perform their duties faster and more effectively. It automates numerous repetitive, manual tasks, freeing human analysts to concentrate on the critical 20% of work that involves complex decision-making and more engaging challenges. This automation also plays a crucial role in combating ‘SOC fatigue,’ a common issue where analysts become burned out from endlessly sifting through alerts, thereby improving retention rates within security teams.
The most exciting development, according to Ledzian, is the emergence of ‘agentic AI.’ This innovative approach combines generative AI models with specialized agents, each designed to handle distinct tasks within a Security Operations Centre. For instance, a SOC could deploy a triage agent, an investigation agent, and a response agent, all working in seamless coordination. This orchestration is propelling the industry closer to the vision of a fully autonomous SOC. Agentic AI is capable of handling sophisticated tasks, from initial alert triage to comprehensive investigation, rapid response, and even detection engineering, leading to highly efficient and precise workflows. Ledzian described the end-to-end investigations and automation capabilities of agentic AI as “jaw-dropping,” generating immense excitement within the cybersecurity community.
Also Read:
- Accenture and Microsoft Deepen Partnership with Gen-AI Cybersecurity Initiative
- Zero Trust Security Imperative Amidst Cloud and AI Expansion, Says Zscaler CEO
The stakes in this digital arms race are incredibly high. Ransomware attacks, in particular, pose a severe threat to critical services. Ledzian cited examples such as hospitals being forced to divert ambulance services, impacting patient safety, and the ransomware attack on the US East Coast pipeline, which disrupted energy supplies. These incidents underscore that cyberattacks are not merely financial issues; they profoundly affect society and national infrastructure, leading countries to increasingly equate them with acts of war. Recent trends observed in Asia further emphasize the growing prevalence and sophistication of deepfakes in BEC attacks, making advanced AI-driven defenses more critical than ever.


