Skip to content
Cybersecurity

Will AI and Machine Learning Help or Hurt Cybersecurity?

Every vendor in the SOC is selling me AI. Every attacker on the other side is using it too. The teams winning right now are the ones who stopped treating it as magic and started treating it as a teammate with very specific strengths and very specific blind spots

The takeaways

  1. 01

    AI is excellent at pattern work: anomaly detection, spam filtering, botnet identification, vulnerability triage. Let it do that.

  2. 02

    Attackers use the same tools for better phishing, voice deepfakes, faster password cracking, and malware that hides inside normal traffic.

  3. 03

    Model output is not a decision. A human still owns the call, the escalation, and the accountability.

  4. 04

    The hardest part of rolling out AI in a security team is not the technology. It is the team's fear that it replaces them.

  5. 05

    Pair AI with people skills and a clear methodology. That combination beats either one alone.

I walk into any security operations center this year and I hear the same word in every demo: AI. It is in the EDR, the SIEM, the email gateway, the phishing simulator, the developer's IDE, and the slide deck my CISO is about to present to the board. It is also in the hands of the people on the other side of the firewall.

That is the part nobody likes to say out loud. The same models I use to spot anomalies are the ones attackers use to write better lures. So the honest answer to "will AI help or hurt cybersecurity" is yes. Both. At the same time. The question that actually matters is whether my team knows where the line is.

Where AI is genuinely helping

Machine learning is good at a narrow set of things, and most of them happen to be exactly what a tired analyst is bad at after hour six of a shift.

Anomaly and fraud detection. Patterns are what models do. Sudden volume spikes, odd geographies, impossible travel, a service account that has never touched a database server suddenly enumerating one. A model can flag thousands of these per minute without getting bored. A human cannot.

Email and phishing filtering. Phishing remains the front door. The 2021 report from APWG showed the highest volume of phishing attacks ever recorded, more than triple the level two years prior. Awareness training alone will not close that gap. ML-based filters cut down what ever reaches the inbox in the first place, which is the only training program that scales.

Botnet and behavioral identification. Bot traffic looks like real users until you compare it to ten million sessions side by side. That comparison is the job.

Vulnerability management. Most security teams are buried under a CVE backlog they will never finish. AI helps rank what to actually fix this week based on exposure, exploit availability, and asset criticality. Triage, not magic.

Malware classification and data loss prevention. Models trained on file behavior catch new variants that signatures miss. They also catch sensitive data leaving the building in places humans would never think to look, including images and voice recordings.

SIEM and SOAR augmentation. This is the one that quietly returns the most time. When the model can confidently auto-contain a known pattern, the analyst gets to spend the hour on the thing that actually requires judgment.

Where AI is hurting us

The same capabilities flip when the attacker picks them up.

Better reconnaissance. Profiling a target used to take hours of manual scraping. Now it takes a prompt. Pretext quality has gone up accordingly.

Phishing at native fluency. The grammar-mistake phishing email is dead. Modern lures read like internal comms because a model wrote them in the voice of someone the recipient already trusts.

Voice and video deepfakes. A few seconds of audio from a podcast or earnings call is enough to clone a voice convincingly. Finance teams are already wiring money based on calls from "the CEO" that the CEO never made.

Ransomware acceleration. The 2021 Colonial Pipeline incident was the public face of a much larger trend. AI lets attackers automate target selection, encryption, and negotiation. The dwell time keeps shrinking.

Adaptive malware. Code that watches what the endpoint does and mimics normal traffic until exfiltration is well underway. Signature-based defense has nothing to say to it.

Password and CAPTCHA cracking. If you still have anything that depends on a password alone, assume the model already has it. MFA is the floor, not the ceiling.

The human element is not optional

Here is the part the demos never cover. The model is good at the answer. It is bad at the question. It does not know your business, your regulatory exposure, your patient population, your vendor relationships, your last incident, or the political reason a particular system cannot go down on a Tuesday.

A human still has to own the decision. That is where most rollouts fall apart, and it is rarely a technical problem. It is a people problem. Engineers see the new tool as a threat to their identity as the smartest person in the room. They resist it, or they over-trust it, and either failure mode produces the same outcome: worse security than they had before they bought it.

The teams that get this right do two things at the same time. They roll the technology in, and they invest in the soft skills, the communication patterns, and the decision rights that let humans and models actually work together. That is the entire premise of the Secure Methodology and the book it came from.

AI in cybersecurity is not a war of AI versus AI. It is humans plus AI versus humans plus AI. The side with the better humans wins.

“Technology is neither good nor bad. It depends on who is holding it and what they are trying to do with it.”

Frequently asked

Christian Espinosa, headshot

About the author

Christian Espinosa · Founder & CEO, Blue Goat Cyber

I'm the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm where my team has supported 250+ FDA submissions with zero failing to clear on cybersecurity. I previously founded and sold Alpine Security. I host The Med Device Cyber Podcast and wrote The Smartest Person in the Room and The In-Between: Life in the Micro, with Medical Device Cybersecurity: An In-Depth Guide out in 2026. Air Force Academy grad, 24x Ironman, climber of two of the Seven Summits.

Keep reading