AI in cybersecurity sounds impressive — but how intelligent is it really?

These days, everything is “AI”. From email filters to security dashboards, the moment there’s a single if-this-then-that rule behind it, the label gets slapped on. And honestly? At Rootsec, we think that’s a bit of a stretch.

We have a different vision — a future in which AI doesn’t merely automate something, but genuinely thinks alongside you, advises, and plays a real role in offensive and defensive security.

AI as both weapon and shield

We can already see the paradox of AI in cybersecurity today. Attackers use AI to craft smarter phishing campaigns, to mutate malware, and even to analyse the behaviour of defenders. At the same time, defensive teams use AI for behavioural analysis, anomaly detection, XDR and incident response.

In many cases the power of AI is real. Take Cynet 360 AutoXDR, where AI helps cut false positives by 90%. Those are clear, measurable wins. But if you look honestly, a lot of that “AI” is really just rule-based logic — nothing intelligent about it.

The AI we actually want: a buddy during the pentest

So where does it get genuinely interesting? It’s where AI thinks alongside you. Picture this:

You’re running a penetration test. You’re sitting on a service, and you’ve got hold of some hashes. Instead of spending hours on trial and error in Hashcat, your AI buddy says:

“Hold on. You could try cracking this hash — but you’ve got a better chance if you exploit this misconfiguration instead. That gets you an easier hash, and you’ll have domain admin in no time.”

An AI that understands what you’re doing and advises you on how to progress — based on your pentest objectives, the live situation, TTPs from MITRE ATT&CK, and perhaps even a read on time pressure or how much stealth you need.

That, ladies and gentlemen, is the AI we want.

AI for defence: real-time context, real-time action

On the defensive side, I see a similar picture of the future. Think of an AI agent that:

  • scans the internet 24/7 for new zero-day disclosures
  • understands that your environment runs Cisco or Fortinet
  • automatically hunts for indicators of attack and compromise (IOA / IOC)
  • maps those straight onto your log or SIEM data
  • and sends you an alert: “This CVE has just been published. Your network looks vulnerable. Shall I mitigate automatically?”

That isn’t just reactive — it’s almost foresight. Proactive defence, fully wired into real-time threat intelligence and your internal infrastructure.

Look at AI in cybersecurity as it stands today and you mostly see a lot of buzz. But genuine intelligence demands context and the ability to adapt.

The reality today: plenty of buzz, not much brains

Right now, AI is still far too often a marketing layer. Anyone applying a bit of scripting and logic calls it machine learning. But the real value lies in AI that understands context, recognises objectives, and helps you — as attacker or defender — decide what the smartest next move is.

And that is exactly where we want to go. Not AI as an extension of rules, but AI as a thinking partner. A kind of digital co-hacker, or a colleague in the SOC. One that, like you, doesn’t know everything — but is willing to suggest: “Why don’t you try this?”

This is why our work is built on people first. Across the UAE and the wider GCC, our AI security services pair this kind of intelligent assistance with the expertise of our consultants, so the tooling sharpens the team rather than replacing its judgement.

In closing: we believe in AI — but with nuance

At Rootsec we believe in AI — but not blindly. We want to filter out the hype and keep the real progress. Whether you’re a penetration tester or a SOC analyst, you deserve AI that does more than read out your data. You deserve AI that genuinely helps, thinks, learns and adapts to your goal: reducing risk. Through smart choices. Not buzzwords.

AI in cybersecurity only becomes truly powerful when it looks beyond detection. The next step? Advisory AI that doesn’t just read your data, but understands context and thinks alongside you, tailored to your role — whether you’re on the offence or the defence.

You can also read how our consultants put this thinking into practice in our AI security approach.

What do you think?

Are you a pentester who dreams of an AI buddy like this? Or do you work in a SOC and want that real-time alerting system too? Let us know — we might just build it.

Ready to put AI to work in your defence — without the hype? Talk to the Rootsec team about an AI security assessment for your organisation. Book a free consultation.