Press "Enter" to skip to content

Deloitte Cyber AI Leader: The Next Cyber Bottleneck Is Decision Speed

Artificial intelligence is rapidly changing cybersecurity, but in a way many enterprise leaders might not expect.

Historically, a key challenge has been finding software vulnerabilities and fixing them before hackers can take advantage. AI has made it much easier and faster to find bugs. But companies are struggling to resolve them as quickly as AI can find them.

“There’s a threat surface that is expanding at machine speed, but … most organizations’ response capabilities are still moving at human speed,” said Mehdi Houdaigui, Deloitte’s U.S. cyber AI leader, in an interview with The AI Innovator. “That’s the gap that’s defining the challenge at the moment.”

🔍
Meet Sherlock AI
Need more clues? Ask the Sherlock chatbot in the lower right corner to summarize this story, explain technical concepts or answer other questions.

The shift is forcing enterprises to rethink cybersecurity as an organizational challenge rather than simply a technology problem. According to Houdaigui, companies that continue treating AI-powered cybersecurity as another software purchase risk falling further behind as both attackers and defenders adopt increasingly capable AI systems.

Discovery is no longer the bottleneck

Houdaigui said today’s most advanced AI systems can discover critical software vulnerabilities in hours instead of weeks or months by experienced security researchers. While organizations have historically faced more vulnerabilities than they could fix, AI is greatly increasing that volume.

“The vast majority of organizations always had more vulnerabilities identified than their capability or capacity to remediate and patch all of them, and the focus was only mainly on the criticals,” he said. “Now, that challenge has just been exacerbated by the ability to identify more vulnerabilities, but at a much faster pace.”

That means “the bottleneck is no longer finding the problem. It’s becoming the organizational readiness and the organization’s velocity and ability to fix those problems,” he added.

Meanwhile, another risk looms: AI is also shrinking the time between identifying a flaw and attackers being able to exploit it.

Decision-making as competitive advantage

To adapt to the new pace of bug discovery, enterprises must shorten what Deloitte calls “decision latency” — the time between learning about a cyber risk and deciding how to respond.

Historically, organizations often spent weeks or months determining whether to patch a vulnerability, accept the risk or implement other safeguards.

“It’s either ‘are we fixing it or do we formally accept the risk?'” Houdaigui said. “That conversation in large complex enterprises takes weeks, if not months, and now needs to be collapsed to a window of approximately 48 hours if we are to follow the guidance on the most critical ones.”

Not every critical system can realistically be patched within two days, he acknowledged. Some patches could disrupt essential operations or require extensive testing before deployment.

Instead, organizations may need to temporarily isolate applications, deploy mitigating controls or accept certain risks while permanent fixes are validated. The key is making those decisions far faster than traditional governance processes allow.

Buying another tool won’t solve the problem

Houdaigui cautioned organizations against viewing AI-powered cybersecurity as simply another technology investment.

“What we’re hearing that is resonating with our clients is not treating this as purely a technology or procurement problem,” he said. “This is not, ‘let me buy a new tool, run another scan.’ It’s a redesign of the way cyber or security organizations operate today.”

Deloitte recommends redesigning cyber operations across people, processes and technology.

That includes shifting security professionals away from spending most of their time finding vulnerabilities and toward making rapid, business-aware decisions. Human judgment remains essential, particularly in regulated industries where organizations must demonstrate compliance and accountability.

On the technology side, AI should help automate repetitive tasks such as validating findings, correlating business context and prioritizing vulnerabilities, allowing humans to focus on higher value decisions.

“The goal is to get to decision support at machine speed,” Houdaigui said.

Security becomes everyone’s job

The operating model Deloitte envisions extends well beyond cybersecurity teams.

Houdaigui said organizations are increasingly creating cross-functional groups that bring together security, IT infrastructure, software developers, application owners, legal, privacy and enterprise risk teams.

“The security team’s job is going to be mainly focused on that discovery capability,” he said. “But it’s a collaborative effort.”

Those integrated teams allow organizations to make risk decisions without waiting for approvals to move through multiple organizational layers.

Some vulnerabilities cannot immediately be patched because of operational dependencies. Instead, cross-functional teams can decide which mitigating controls to deploy while longer-term remediation proceeds.

The same approach also affects software development itself. Organizations increasingly must incorporate AI-powered security capabilities into how they write, test and validate code, including managing risks associated with open-source software and AI supply chains.

Cyber lessons could reshape enterprise AI

Houdaigui believes cybersecurity may become a model for broader enterprise AI governance.

One of the biggest mistakes organizations make, he said, is looking for a “silver bullet” technology rather than redesigning how decisions are made across the enterprise.

“In most instances, the tool is an enabler,” he said. “What really impacts the organization … is going to come down to the people and the processes part of it.”

He also argued that cybersecurity’s rapid adaptation to AI-driven threats could provide a blueprint for other business functions facing similar pressures.

“The cyber function that solves this problem within the context of security becomes more of a strategic capability to the broader enterprise and no longer just a cost center,” Houdaigui said. “We’ve been talking about security being a business enabler for ages. This is one of the best use cases I’ve seen.”

Human oversight isn’t disappearing

Despite rapid advances in AI, Houdaigui does not expect enterprises to hand critical cybersecurity decisions entirely to autonomous AI agents anytime soon.

Over the next five years, he expects many routine cyber workflows to become fully AI-enabled, with noncritical processes operating autonomously.

The highest-risk decisions, however, will continue to require human oversight, particularly in highly regulated industries where additional governance might be required.

“I do see that five years from now noncritical processes could be autonomous in nature,” Houdaigui said. “The most critical ones would be fully automated with very specific human-in-the-loop judgment and decision-making capabilities.”

The result, he said, will be a cybersecurity landscape where both attackers and defenders increasingly rely on AI — making organizational decision speed as important as technological capability itself.

Author

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

×