Skip to content
Vulnerabilities

Planning Your AI Security – How will You Manage All Your Resources?

AI has a role to play in Security Operations Centre (SOC) environments. According to EY, the number of senior security leaders dedicating at least a quarter of their cybersecurity budget to AI solutions for cybersecurity is expected to rise in the next two years, from nine percent today to 48 percen...

· Jul 31, 2026 · 6 min read · 👁 1 views
Planning Your AI Security – How will You Manage All Your Resources?

AI has a role to play in Security Operations Centre (SOC) environments. According to EY, the number of senior security leaders dedicating at least a quarter of their cybersecurity budget to AI solutions for cybersecurity is expected to rise in the next two years, from nine percent today to 48 percent.

The reason for this increased spend is that teams need to keep up with threat volumes and threat actor behaviour, and the recent releases around AI for vulnerability investigation and potential exploit have only exacerbated this trend.

study by Daniel Boughton and Iain Reid at the University of Portsmouth around AI SOC deployments found that AI has a significant role to play in reducing the number of alerts that analysts have to respond to, allowing analysts to concentrate their efforts where it will make the most difference.

AI was used more in the initial phases of security; around 82 percent used AI in their SOC to detect and triage threats – while 37 percent used AI to automate their ticketing and response processes.

The role for AI is to extend human analyst activity, helping them investigate alerts more deeply where it is needed and parse those that might not. AI itself is indefatiguable, and can carry on working when analysts have to change shifts or deal with other issues. The perception here is that AI just won’t stop. Like the Terminator, AI doesn’t need to sleep or eat.

But there is one resource constraint that can affect agent activity – tokens. Tokens are the units of work that AI models consume in response to requests.

Deloitte examines this in their report on AI spend dynamics, or ‘tokenomics’. The more complex the query or the bigger the request, the more tokens will be used back and forth. For security, where the volume of investigations will grow and the queries are complex, a large amount of tokens can be consumed in each investigation.

Each of these investigations therefore, has a real world cost associated with it. For security teams looking at how to build AI into their processes, understanding the real-world cost around token use is something to consider.

In our SOC team, we decided to get ahead of this as a potential issue. We looked at token consumption and processes together so we can get a more realistic view of what that spend looks like over time.

Each investigation or query is a unique scenario, even when you work at scale, so putting a standard price on this is hard. While AI can and will play an essential role in keeping a SOC productive and ahead of threat actors, the cost to run those systems will grow as a line item on the budget. 

It may even get targeted by threat actors who know the companies they want to target use AI in their SOC, and conduct attacks specifically designed to burn through or maximise token usage.

Developers already look at ‘tokenmaxxing’ for their software processes, so why shouldn’t threat actors try the same approach against IT security defenders? Burning up budgets and affecting the quality of security response that is possible at scale is a legitimate concern when you know that you will rely on AI to respond in a timely way.

We look at how we use AI within our processes and where we can make the most of what is available. Essentially, we want to prepare for a world where AI token cost is a significant factor in security performance.

To achieve this, we analysed how our SOC team processes alerts and responses in our own environment, and the role that agentic AI systems play in those procedures.

The goal here is to understand why your SOC works in the way it does, and how that process will be supported by AI. Where do you have humans in the loop processes where AI supports faster response, and what approach will you use otherwise? Are other AI or machine learning techniques better suited to this process than generative AI or agentic AI technologies? 

You can also look at how much your entry level analyst role earns and how much you are spending on tokens to achieve the same level of activity.

If your analyst spends more on tokens than is saved in their time, then you may not be achieving the efficiencies that you set out to gain.

In these circumstances, AI may actually cost you more than it saves. Conversely, by understanding the full process and what you want to achieve, you can create the right workflow for your team and for your budget.

Using agentic AI is incredibly powerful for fast response and for supporting human interaction around potential threats. More traditional AI and Machine Learning can reduce the cost of pattern matching and investigation around log data or other large data sources, while avoiding potential alert fatigue on the analyst team. 

Bringing both technologies together can reduce the time to investigate and help analysts prioritise, but also avoid that additional cost around extra token consumption over time. Most of all, the goal is to make your team more effective around issues.

The practical element here is that AI models will be used for attacks. The AI Security Institute released research on how models performed in a standard attack scenario, with models able to carry out multiple steps within attack paths automatically.

The cost for these attacks was, on average, around $80 / £60 for 10 million tokens. Following releases like Anthropic Mythos, the AISI has updated its guidance still further, with Mythos able to complete full Capture The Flag scenarios based on average runs of 50 million tokens each. 

These scenarios point to how well AI can perform based on availability of tokens. Attackers will probably take advantage of stolen access or fake credit cards to run their attacks, so budget is not an issue for them.

For defenders, understanding the cost of AI security includes looking at how AI tokens are used, how effective they are in accomplishing tasks, and putting realistic processes together that make use of agentic AI where it has the most potential.

The technology underpinning all this is based on data pipelines and how they are implemented to use the data coming in. 

For SOC teams, setting the right strategy around these kinds of technologies will involve current processes, what needs to change and an understanding of how much the cost may evolve.

Getting AI to help with triage and prioritisation is a great starting point, but the real value will come when it can implement higher order responses.

Author: Jeremy Powell, CISO at Sumo Logic.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you